Bugtraq mailing list archives
Breaking Finger in AIX 4.2
From: axon2017 () STUDENTS JOHNCO CC KS US (aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa)
Date: Tue, 20 Oct 1998 09:32:50 -0500
I just found this out yesterday, and I don't think it's been in the
postings before, but on AIX (I tested this on 4.2) if one's gecos field
is set to more than 99 characters, Finger starts acting really strange.
First off, it acts normal when you finger the whole host (to see who is
on) or if you finger the user with the long gecos. When you do this,
it spews out all of it's info into the "In Real Life:" part. It doesn't
truncate the gecos info. I've gotten finger to scroll through a few
pages of gecos, but 100 characters is all it takes to affect the rest.
when a user fingers any other user, existant or not, finger dumps core.
chfn (the command used to edit one's gecos info) will allow me to plop
over 100 LINES of information into it. It eventually locks up, and I
have no way to get out of it (short of opening another connection and
killing chfn or just closing the connection)
The core files generated by finger look pretty harmless. I don't know a
lot about exploits, but I'm thinking this might mean bad things for
people who allow remote finger connections.
.-= axon2017 () students jccc net =-.
Current thread:
- Last (hopefully) update on GroupWise Simple Nomad (Oct 10)
- <Possible follow-ups>
- Last (hopefully) update on GroupWise Adrian Voinea (Feb 06)
- /tmp race in mc-4.5.0 Pavel Machek (Oct 12)
- Re: /tmp race in mc-4.5.0 Bennett Todd (Oct 14)
- Re: /tmp race in mc-4.5.0 Marc Heuse (Oct 14)
- [NTSEC] DoS attack in MS - Proxy 2.0 Jason Garms (Oct 15)
- IRIX xterm(1) exploitable buffer overflow SGI Security Coordinator (Oct 15)
- IRIX Xaw library exploitable buffer overflow SGI Security Coordinator (Oct 15)
- Microsoft Security Bulletin (MS98-015) Aleph One (Oct 16)
- HP-UX 10.20 SharedX Receiver Service DoS Security Research Team (Oct 16)
- Breaking Finger in AIX 4.2 aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa (Oct 20)
- Re: Breaking Finger in AIX 4.2 Troy A. Bollinger (Oct 20)
- Alert: IE 4.0 Security Zone compromise Aleph One (Oct 20)
- /tmp race in mc-4.5.0 Pavel Machek (Oct 12)
- Re: Annoying Solaris/CDE/NIS+ bug Frank Cusack (Oct 13)
