Re: Compromised postgresql instances

Поиск
Список
Период
Сортировка
От Andrew Dunstan
Тема Re: Compromised postgresql instances
Дата
Msg-id 4d6d8208-8b56-0308-d271-fe3d465b2f36@2ndQuadrant.com
обсуждение исходный текст
Ответ на Compromised postgresql instances  (Steve Atkins <steve@blighty.com>)
Ответы Re: Compromised postgresql instances  (Tom Lane <tgl@sss.pgh.pa.us>)
Re: Compromised postgresql instances  (Thomas Kellerer <spam_eater@gmx.net>)
Список pgsql-hackers

On 06/08/2018 04:34 PM, Steve Atkins wrote:
> I've noticed a steady trickle of reports of postgresql servers being compromised via being left available to the
internetwith insecure or default configuration, or brute-forced credentials. The symptoms are randomly named binaries
beinguploaded to the data directory and executed with the permissions of the postgresql user, apparently via an
extensionor an untrusted PL.
 
>
> Is anyone tracking or investigating this?
>



Please cite actual instances of such reports. Vague queries like this 
help nobody.

Furthermore, security concerns are best addressed to the security 
mailing list.

cheers

andrew

-- 
Andrew Dunstan                https://www.2ndQuadrant.com
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Alvaro Herrera
Дата:
Сообщение: Re: SHOW ALL does not honor pg_read_all_settings membership
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Compromised postgresql instances