Date: Mon, 2 Oct 2000 17:26:24 -0700 From: Alfred Perlstein <bright@wintelcom.net> To: Jordan Hubbard <jkh@winston.osd.bsdi.com> Cc: Warner Losh <imp@village.org>, Brian Somers <brian@Awfulhak.org>, security@freebsd.org Subject: Re: cvs commit: src/usr.bin/finger finger.c Message-ID: <20001002172624.C27736@fw.wintelcom.net> In-Reply-To: <78462.970531991@winston.osd.bsdi.com>; from jkh@winston.osd.bsdi.com on Mon, Oct 02, 2000 at 05:13:11PM -0700 References: <jkh@winston.osd.bsdi.com> <78462.970531991@winston.osd.bsdi.com>
next in thread | previous in thread | raw e-mail | index | archive | help
* Jordan Hubbard <jkh@winston.osd.bsdi.com> [001002 17:16] wrote: > > It is?!? Holy crap it IS - when did THAT happen? Somebody was > > And just to follow up to myself, I see by the logs that it's been on > for a very long time if not the very beginning. As I just said on > security, I guess I've been turning it off practically in my sleep > since it's not enabled on any of my systems and I don't even remember > disabling it. Since fingerd is hardly an essential service, I'm > hoping that few will argue with my recent decision to comment it out > by default. It's not like people will suddenly lose access to newly > installed systems (from Windows or some other no-ssh-by-default > environment), as was argued to be the case with telnetd. I've also found rather painfully that your smarter script kiddies will gleefully use your finger info to figure out where your DSL line is and happily smurf you to death. Or sometimes they'll just use it to fire up talk to you on your home machine which is good for a near heart attack. So can we turn this junk off? There should be no reason for a "securing FreeBSD" article to be posted somewhere. -- -Alfred Perlstein - [bright@wintelcom.net|alfred@freebsd.org] "I have the heart of a child; I keep it in a jar on my desk." To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20001002172624.C27736>
