bugtraq post

Поиск
Список
Период
Сортировка
От Ray Stell
Тема bugtraq post
Дата
Msg-id 20070617125606.GA17612@cns.vt.edu
обсуждение исходный текст
Ответы Re: bugtraq post  ("Dawid Kuroczko" <qnex42@gmail.com>)
Список pgsql-admin
For the security minded:

Nico Leidecker <nicoLeidecker@web.de> posted this to bugtraq yesterday, fyi.

"I'd like to present a paper about security issues with PostgreSQL. The paper describes weaknesses in the configuration
thatmay 
+allow attackers to escalade privileges, execute shell commands and to upload arbitrary (binary) files via SQL
injections.

You can either get the TXT version from http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt
Or as PDF at at http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf

The paper comes with a tool called `pgshell' that can be downloaded at http://www.leidecker.info/pgshell"


В списке pgsql-admin по дате отправления:

Предыдущее
От: "Abraham, Danny"
Дата:
Сообщение: Bug #2993 on PG 8.2.4
Следующее
От: Devrim GÜNDÜZ
Дата:
Сообщение: Re: Which file to download binary, rpms or srpms?