GEN003860 - The system must not have the finger service active

Information

The finger service provides information about the system's users to network clients. This could expose information that could be used in subsequent attacks.

Solution

Edit /etc/inetd.conf and comment out the fingerd line. Restart the inetd service via the following command:
# inetd -c

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CCI|CCI-001551, CSCv6|9.1, Rule-ID|SV-35136r1_rule, STIG-ID|GEN003860, Vuln-ID|V-4701

Plugin: Unix

Control ID: 9bfbb9f6c498e40dc4d543677c4f5ddc19b569c4baf8e992e8d170b8c7d0f459