Compromised postgresql instances

Поиск
Список
Период
Сортировка
От Steve Atkins
Тема Compromised postgresql instances
Дата
Msg-id 3CFA575D-FFB0-401F-AF7A-385B476D9484@blighty.com
обсуждение исходный текст
Ответы Re: Compromised postgresql instances  (Andrew Dunstan <andrew.dunstan@2ndquadrant.com>)
Список pgsql-hackers
I've noticed a steady trickle of reports of postgresql servers being compromised via being left available to the
internetwith insecure or default configuration, or brute-forced credentials. The symptoms are randomly named binaries
beinguploaded to the data directory and executed with the permissions of the postgresql user, apparently via an
extensionor an untrusted PL. 

Is anyone tracking or investigating this?

Cheers,
  Steve



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Da Silva
Дата:
Сообщение: Re: pl/tcl function to detect when a request has been canceled
Следующее
От: Alvaro Herrera
Дата:
Сообщение: Re: SHOW ALL does not honor pg_read_all_settings membership