UCF STIG Viewer Logo

The system must not have the finger service active.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4701 GEN003860 M6 SV-38057r1_rule DCPP-1 EBRU-1 Low
Description
The finger service provides information about the system's users to network clients. This information could expose information to be used in subsequent attacks.
STIG Date
MAC OSX 10.6 Workstation Security Technical Implementation Guide Draft 2013-01-10

Details

Check Text ( C-37602r1_chk )
Open a terminal session and enter the following command to verify finger is disabled.

defaults read /System/Library/LaunchDaemons/finger Disabled

If a 1 is not returned, this is a finding.
Fix Text (F-32844r1_fix)
Open a terminal session and use the following command to disable finger.

launchctl unload -w /System/Library/LaunchDaemons/finger.plist

NOTE: This command is being run to adjust the overrides file; unloading errors are normal, repeat the check to verify.