Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL

Поиск
Список
Период
Сортировка
От Pavel Borisov
Тема Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL
Дата
Msg-id CALT9ZEGG6DPg=ahRSMBOEMg6OuRJx3Tsrfnw8DtVQ4HHybyWPQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL  (Jeffrey Walton <noloader@gmail.com>)
Ответы Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL
Список pgsql-bugs
On Tue, 10 Jan 2023 at 17:54, Jeffrey Walton <noloader@gmail.com> wrote:
>
> On Tue, Jan 10, 2023 at 9:46 AM Magnus Hagander <magnus@hagander.net> wrote:
> >
> > On Tue, Jan 10, 2023, 15:42 Jeffrey Walton <noloader@gmail.com> wrote:
> >>
> >>
https://www.bleepingcomputer.com/news/security/microsoft-kubernetes-clusters-hacked-in-malware-campaign-via-postgresql/
> >
> > I think the most impressive part in that article is that they found and linked to the postgresql 7
documentation...
>
> It looks like the article used an older version of the docs because
> the link is broken for the newer version. When following the link to
> the latest version of the docs, its results in a "Page not found".

I wonder what was the vulnerability in Postgres that enabled "hackers"
to run malware? I've read the article and the linked ones and found no
causative link between Postgres and malware inside. Sorry, it seems
like baseless warnings, not a description of vulnerability. Maybe I
haven't got something?

Regards,
Pavel Borisov,
Supabase



В списке pgsql-bugs по дате отправления:

Предыдущее
От: Jeffrey Walton
Дата:
Сообщение: Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: [OT] Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL