Security of ODBC debug log file leaves something to be desired

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Security of ODBC debug log file leaves something to be desired
Дата
Msg-id 24444.1112929224@sss.pgh.pa.us
обсуждение исходный текст
Ответы Re: Security of ODBC debug log file leaves something to be desired  (Mischa Sandberg <mischa.sandberg@telus.net>)
Список pgsql-odbc
I got a complaint here
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154126
pointing out that when you set debug=1, the generated log file
is world-readable by default, which doesn't seem like a good
idea when it may contain your password.  Also, since the name
of the file is pretty predictable, there is an opportunity
for a symlink redirection attack (though I doubt anything
really interesting could be accomplished that way).

Any thoughts about fixing this?  It's hard to believe no one
has pointed it out before, so I was wondering if there was some
good reason for doing it like this.

            regards, tom lane

В списке pgsql-odbc по дате отправления:

Предыдущее
От: "Philippe Lang"
Дата:
Сообщение: MS Access & ODBC driver & Postgresql 8.01
Следующее
От: Mischa Sandberg
Дата:
Сообщение: Re: Security of ODBC debug log file leaves something to be desired