Preface: Finger overflowLogo -Internet Security Systems

Finger overflow

advICE :Intrusions : 2001107
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary

An extremely long finger request was seen, indicating either a buffer overflow attempt or a DoS.

Details

Because finger is such an easy protocol to implement, there are numerous independently written versions of them around. Many contain the same programming mistake of making an assumption as to the size of the input.

History

The Morris worm of 1988 exploited a hole in a popular finger service of the time. Despite the fact that this bug is over a decade old, it still appears in new finger programs created today.

Trigger

This is a protocol-validation signature that looks for long content sent to the finger service. This is unlikely to be a false-positive, not only because long-content is never sent to finger, but also because finger is usually disabled on secure networks.

 more information
BugtraqID: 512   cfingerd Buffer Oveflow Vulnerability
 
Morris worm  
 
advICE: finger  
 

 parametric information
cmdThe finger command seen.
lenThe length of the command.

 
Version appeared: 2.5 

Privacy Policy |  Copyright Info