summaryrefslogtreecommitdiff
path: root/libexec/fingerd/fingerd.8
blob: 9c933d8c6b8a4dfe0a94f3da88531f07e1a4dca6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
.\"	$OpenBSD: fingerd.8,v 1.8 1999/07/21 01:07:57 deraadt Exp $
.\"
.\" Copyright (c) 1980, 1991, 1993
.\"	The Regents of the University of California.  All rights reserved.
.\"
.\" Redistribution and use in source and binary forms, with or without
.\" modification, are permitted provided that the following conditions
.\" are met:
.\" 1. Redistributions of source code must retain the above copyright
.\"    notice, this list of conditions and the following disclaimer.
.\" 2. Redistributions in binary form must reproduce the above copyright
.\"    notice, this list of conditions and the following disclaimer in the
.\"    documentation and/or other materials provided with the distribution.
.\" 3. All advertising materials mentioning features or use of this software
.\"    must display the following acknowledgement:
.\"	This product includes software developed by the University of
.\"	California, Berkeley and its contributors.
.\" 4. Neither the name of the University nor the names of its contributors
.\"    may be used to endorse or promote products derived from this software
.\"    without specific prior written permission.
.\"
.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
.\"     from: @(#)fingerd.8	8.1 (Berkeley) 6/4/93
.\"	$Id: fingerd.8,v 1.8 1999/07/21 01:07:57 deraadt Exp $
.\"
.Dd June 4, 1993
.Dt FINGERD 8
.Os
.Sh NAME
.Nm fingerd
.Nd remote user information server
.Sh SYNOPSIS
.Nm fingerd
.Op Fl s
.Op Fl l
.Op Fl u
.Op Fl m
.Op Fl M
.Op Fl p
.Op Fl S
.Op Fl P Ar filename
.Sh DESCRIPTION
.Nm Fingerd
is a simple protocol based on
.%T RFC1196
that provides an interface to the
Name and Finger programs at several network sites.
The program is supposed to return a friendly,
human-oriented status report on either the system at the moment
or a particular person in depth.
There is no required format and the
protocol consists mostly of specifying a single
.Dq command line .
.Pp
.Nm Fingerd
is started by
.Xr inetd 8 ,
which listens for
.Tn TCP
requests at port 79.
Once connected it reads a single command line
terminated by a
.Aq Tn CRLF
which is passed to
.Xr finger 1 .
.Nm Fingerd
closes its connections as soon as the output is finished.
.Pp
If the line is null (i.e. just a
.Aq Tn CRLF
is sent) then
.Xr finger
returns a
.Dq default
report that lists all people logged into
the system at that moment.
.Pp
If a user name is specified (e.g.
.Pf eric Aq Tn CRLF )
then the
response lists more extended information for only that particular user,
whether logged in or not.
Allowable
.Dq names
in the command line include both
.Dq login names
and
.Dq user names .
If a name is ambiguous, all possible derivations are returned.
.Pp
The following options may be passed to
.Nm fingerd
as server program arguments in
.Pa /etc/inetd.conf :
.Bl -tag -width Ds
.It Fl s
Enable secure mode.
Forwarding of queries to other remote hosts is denied.
.It Fl l
Enable logging.
The name of the host originating the query is reported via
.Xr syslog 3
at LOG_NOTICE priority.
.It Fl u
Queries without a user name are rejected.
.It Fl m
Prevent matching of
.Ar user
names.
.Ar User
is usually a login name; however, matching will also be done on the
users' real names, unless the
.Fl m
option is supplied.
.It Fl M
Enables matching of
.Ar user
names.  This is disabled by default if the system is running YP.
.It Fl p
Prevents
.Nm finger
from displaying the contents of the
.Dq Pa .plan
and
.Dq Pa .project
files.
.It Fl S
Prints user information in short mode, one line per user.
This overrides the
.Dq Pa Whois switch
that may be passed in from the remote client.
.It Fl P Ar filename
Use an alternate program as the local information provider.
The default local program
executed by
.Nm fingerd
is
.Xr finger 1 .
By specifying a customized local server,
this option allows a system manager
to have more control over what information is
provided to remote sites.
.El
.Sh SEE ALSO
.Xr finger 1 ,
.Xr inetd 8
.Sh BUGS
Connecting directly to the server from a
.Tn TIP
or an equally narrow-minded
.Tn TELNET Ns \-protocol
user program can result
in meaningless attempts at option negotiation being sent to the
server, which will foul up the command line interpretation.
.Nm Fingerd
should be taught to filter out
.Tn IAC Ns \'s
and perhaps even respond
negatively
.Pq Tn IAC WON'T
to all option commands received.
.Sh HISTORY
The
.Nm
command appeared in
.Bx 4.3 .