Executive brief
The rusers service is an obsolete network protocol that reveals a list of currently logged-in users to anyone on the network. While not a direct software bug, this information disclosure helps attackers perform reconnaissance and identify valid targets for further attacks. Organizations should disable this service as it provides no modern business value and compromises privacy.
Technical details
This entry describes a security weakness in the rusers protocol, which is used to identify users logged into remote machines. By design, the service responds to unauthenticated network queries with a list of active usernames and session details. This constitutes an information disclosure vulnerability that facilitates user enumeration and reconnaissance. Because this is a protocol-level design issue rather than a specific coding error, it is often classified as a configuration or architectural weakness. The recommended remediation is to disable the rusers daemon (rusersd) entirely.
Affected products
- unknown rusers
Timeline
- 1997-01-01: disclosed: NVD Published Date