Re: contrib: auth_delay module
От | Stephen Frost |
---|---|
Тема | Re: contrib: auth_delay module |
Дата | |
Msg-id | 20101104133516.GN26232@tamriel.snowman.net обсуждение исходный текст |
Ответ на | Re: contrib: auth_delay module (Jan Urbański <wulczer@wulczer.org>) |
Ответы |
Re: contrib: auth_delay module
Re: contrib: auth_delay module |
Список | pgsql-hackers |
* Jan Urbański (wulczer@wulczer.org) wrote: > On 04/11/10 14:09, Robert Haas wrote: > > Hmm, I wonder how useful this is given that restriction. > > As KaiGai mentined, it's more to make bruteforcing difficult (read: tmie > consuming), right? Which it would still do, since the attacker would be bumping up against max_connections. max_connections would be a DOS point, but that's no different from today. Other things could be put in place to address that (max # of connections from a given IP or range could be implemented using iptables, as an example). 5 second delay w/ max connections at 100 would mean max of 20 attempts per second, no? That's alot fewer than 100*(however many attempts can be done in a second). Doing a stupid while true; psql -d blah; done managed to get 50 successful ident auths+no-db-found errors done in a second on one box here. 5000 >> 20, and I wasn't even trying. Thanks, Stephen
В списке pgsql-hackers по дате отправления: