This article was posted to the Usenet group alt.hackers in 1995; any technical information is probably outdated.

Re: What is the problem with Finger?

In article <3l4nc5$> (marlowe)
>So, I'll bite. Does anyone know what the security hole is in finger? I
>can understand not wanting to have anyone be able to finger in, but why
>wouldn't the admins what me to finger out?

Beats me.  But as long as you can telnet out, you don't really need
the finger command.  Just telnet to the remote machine and talk to
the finger daemon directly.  Example:

	%telnet <host address> 79
	[bunch of telnet messages]
	<user's login followed by RETURN>


