UCF STIG Viewer Logo

The system must not have the finger service active.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4701 GEN003860 SV-35136r1_rule EBRU-1 DCPP-1 Low
Description
The finger service provides information about the system's users to network clients. This could expose information that could be used in subsequent attacks.
STIG Date
HP-UX 11.23 Security Technical Implementation Guide 2015-12-02

Details

Check Text ( C-34994r1_chk )
# cat /etc/inetd.conf | tr '\011' ' ' | tr -s ' ' | sed -e 's/^[ \t]*//' |grep -v "^#" | \
cut -f 6,7 -d " " | grep -c -i fingerd

If the fingerd service is not disabled, this is a finding.
Fix Text (F-30288r1_fix)
Edit /etc/inetd.conf and comment out the fingerd line. Restart the inetd service via the following command:
# inetd -c