finger

From: Derrick Lewis (dlewis@linuxsecurity.com)
Date: 08/13/01


Date: Sun, 12 Aug 2001 19:14:50 -0400 (EDT)
From: Derrick Lewis <dlewis@linuxsecurity.com>
To: security-discuss@linuxsecurity.com
Subject: finger
Message-Id: <20010812231450.EC20411D30C@juggernaut.guardiandigital.com>

I was thinking over some intrusion detection techniques. I was
thinking if there was a way for an attacker to possibly edit the "finger"
program code to have it not return user information for a certain user
(ultimately responding with a "finger: userAB: no such user.")? Any
ideas? Thanks.

--
Derrick Lewis    	                  LinuxSecurity.com
Assistant Site Manager        "The Linux Community's Center for Security."
(201) 934-9230	        	    http://www.linuxsecurity.com
dlewis@linuxsecurity.com

------------------------------------------------------------------------ To unsubscribe email security-discuss-request@linuxsecurity.com with "unsubscribe" in the subject of the message.