Re: contrib: auth_delay module

Поиск
Список
Период
Сортировка
От Stephen Frost
Тема Re: contrib: auth_delay module
Дата
Msg-id 20101104133516.GN26232@tamriel.snowman.net
обсуждение исходный текст
Ответ на Re: contrib: auth_delay module  (Jan Urbański <wulczer@wulczer.org>)
Ответы Re: contrib: auth_delay module  (Robert Haas <robertmhaas@gmail.com>)
Re: contrib: auth_delay module  (Jeff Janes <jeff.janes@gmail.com>)
Список pgsql-hackers
* Jan Urbański (wulczer@wulczer.org) wrote:
> On 04/11/10 14:09, Robert Haas wrote:
> > Hmm, I wonder how useful this is given that restriction.
>
> As KaiGai mentined, it's more to make bruteforcing difficult (read: tmie
> consuming), right?

Which it would still do, since the attacker would be bumping up against
max_connections.  max_connections would be a DOS point, but that's no
different from today.  Other things could be put in place to address
that (max # of connections from a given IP or range could be implemented
using iptables, as an example).

5 second delay w/ max connections at 100 would mean max of 20 attempts
per second, no?  That's alot fewer than 100*(however many attempts can
be done in a second).  Doing a stupid while true; psql -d blah; done
managed to get 50 successful ident auths+no-db-found errors done in a
second on one box here.  5000 >> 20, and I wasn't even trying.
Thanks,
    Stephen

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: Comparison with "true" in source code
Следующее
От: Tom Lane
Дата:
Сообщение: Re: why does plperl cache functions using just a bool for is_trigger