Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL

Поиск
Список
Период
Сортировка
От Lamar Owen
Тема Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Дата
Msg-id 200208261118.48487.lamar.owen@wgcr.org
обсуждение исходный текст
Ответ на @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL  (Sir Mordred The Traitor <mordred@s-mail.com>)
Ответы Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Список pgsql-hackers
On Monday 26 August 2002 10:46 am, Sir Mordred The Traitor wrote:
> Conditions: entry in a pg_hba.conf file that matches attacker's host.
> Risk: average

> --[ Solution
>
> Disable network access for untrusted users.

TCP/IP access must be enabled as well.  TCP/IP accessibility is OFF by 
default.

I for one thought that it was normal operating procedure to only allow access 
to trusted machines; maybe I'm odd in that regard.

Hey, if I can connect to postmaster I can DoS it quite easily, but flooding it 
with connection requests.....

But, if we can thwart this, all the better.
-- 
Lamar Owen
WGCR Internet Radio
1 Peter 4:11


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Следующее
От: Sir Mordred The Traitor
Дата:
Сообщение: Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL