English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 15002
À§Çèµµ 20
Æ÷Æ® 79
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FINGER
»ó¼¼¼³¸í finger ¼­ºñ½º´Â ÇØ´ç ½Ã½ºÅÛÀÇ ÇöÀç »ç¿ëÀÚ¿¡ °üÇÑ Á¤º¸¸¦ ¾Ë·ÁÁÖ´Â ¼­ºñ½ºÀÌ´Ù. finger´Â ħÀÔÀÚ¿¡°Ô ¾Æ·¡¿Í °°Àº Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ´Ù.

Valid login names
Users' full names
Names of other systems
A user's login shell

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/48.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ÀÌ ¼­ºñ½º¸¦ disableÇØ¾ß ÇÑ´Ù.

´ÙÀ½°ú °°Àº ¹æ¹ýÀ¸·Î fingerd µ¥¸óÀ» ÁßÁö½ÃŲ´Ù.
# vi /etc/inetd.conf (finger·Î ½ÃÀ۵Ǵ ºÎºÐÀ» #·Î commentó¸®)
# killall -HUP inetd

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/finger:default

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/fingerÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL CVE-1999-0612 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)