procmail
[Top] [All Lists]

Re: How do you stop finger displaying contents of .fowrawd?!

1996-01-26 13:47:48
On Thu, 25 Jan 1996, David Pesticcio wrote:
Have a problem with finger. Is it finger that is broken or the permisions 
on the file?

Make sure your finger binary is not setuid root (it does not
need to be) and that your fingerd is not run as root by inetd.
If you are not the administrator of your system, ask your admin
to check these for you.

There is no need to run finger as root, and some older fingers
have security holes that won't be that bad if run as nobody, or
some other harmless uid.

If finger is not run as root, it won't be able to read files
that are protected properly.  Some might call this a bug, I call
it a feature (a user now has control over what is displayed by
modifying the protections on .plan, .project and .forward).
--
 ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
( Kimmo Suominen                         "That's what I think" )
( Trans-Atlantic Communications              
kim(_at_)tac(_dot_)nyc(_dot_)ny(_dot_)us )
 ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''