rusersd vulnerability
Summary
rusersd lists the users on a machine, what machine they are logged in from,
idle and login time information, and the device they are using.
Impact
rusersd can be used to create a table of usage and provide a list of
accounts and machine names.
Background
rusersd is normally used to see who is on a machine.
The problem
A Bad Guy(tm) could use this information to try to attack accounts and
other machines.
Fix
- Disable rusersd in the /etc/inetd.conf file and signal inetd.