Synopsis
The remote finger daemon appears to be a backdoor.
Description
The remote finger daemon seems to be a backdoor, as it seems to react to the request :
cmd_rootsh@target
If a root shell has been installed as /tmp/.sh, then this finger daemon is definitely a trojan, and this system has been compromised.
Solution
Audit the integrity of this system, since it seems to have been compromised
Plugin Details
File Name: finger_backdoor.nasl
Configuration: Enable paranoid mode
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: Settings/ParanoidReport