Security implications of untrusted triggers

Поиск
Список
Период
Сортировка
От Joshua Kramer
Тема Security implications of untrusted triggers
Дата
Msg-id Pine.LNX.4.63.0601121325030.24101@localhost.localdomain
обсуждение исходный текст
Ответы Re: Security implications of untrusted triggers  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-general
Or more specifically, what are the security implications of a trigger
written in an untrusted language - PL/PerlU?

With a standard stored procedure, you have the possibility of an
SQL-injection attack.  Is this possible with a trigger function, if it is
defined as a trigger?

I am writing a couple of Perl modules that talk to the outside world: one
talks to a database (via DBI), and one talks to a Jabber/XMPP server.  I
want to use these from within a Trigger.  Do I have to taint-check the
input provided by the trigger mechanism - or does PG do this?

Thanks,
-Josh


В списке pgsql-general по дате отправления:

Предыдущее
От: Claire McLister
Дата:
Сообщение: Re: Large object restore problem w/triggers
Следующее
От: "Joshua D. Drake"
Дата:
Сообщение: Re: Plans for 8.2?