Re: How to stop script executions

Поиск
Список
Период
Сортировка
От David G. Johnston
Тема Re: How to stop script executions
Дата
Msg-id CAKFQuwaz9+QR+tLc59RWG7a5Y8HVfwQjQaDkKq+n1WfU5n1iSA@mail.gmail.com
обсуждение исходный текст
Ответ на Re: How to stop script executions  (Sameer Kumar <sameer.kumar@ashnik.com>)
Ответы Re: How to stop script executions  (Dev Kumkar <devdas.kumkar@gmail.com>)
Список pgsql-general
On Tue, Jul 26, 2016 at 9:21 AM, Sameer Kumar <sameer.kumar@ashnik.com> wrote:

Yeah these extensions are not present, are their any chances of running OS commands from database?

What do you mean by "from database"? I think you need to lay down your requirement and goal more clearly.

 
​Typically this means that given user only having psql, or some other backend protocol only, connect to the database are they able to execute arbitrary commands as the user running the PostgreSQL process on the host system.​

Untrusted langauges are untrusted for specifically this reason.  Without untrusted languages it requires privilege escalation to interact dynamically with the host operating system.

Assuming raised privileges it is presently impossible to prevent such dynamic interaction.

David J.

В списке pgsql-general по дате отправления:

Предыдущее
От: "David G. Johnston"
Дата:
Сообщение: Re: How to stop script executions
Следующее
От: Dev Kumkar
Дата:
Сообщение: Re: How to stop script executions