Re: logfile subprocess and Fancy File Functions

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: logfile subprocess and Fancy File Functions
Дата
Msg-id 200407241655.i6OGtEp13717@candle.pha.pa.us
обсуждение исходный текст
Ответ на Re: logfile subprocess and Fancy File Functions  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-patches
Andrew Dunstan wrote:
>
>
> Bruce Momjian wrote:
>
> >As a super-user, could an attacker load a server-side language and
> >access the backend environment variable PGDATA.
> >
> >
>
> plperl won't do it, but plperlu will (as expected I guess). But the
> superuser will have to jump through some explicit hoops in order to get
> there, which is different from providing such facilities out of the box.

I am thinking they could easily use pgtcl.  I don't think the hoops are
very high.

--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 359-1001
  +  If your life is a hard drive,     |  13 Roberts Road
  +  Christ can be your backup.        |  Newtown Square, Pennsylvania 19073

В списке pgsql-patches по дате отправления:

Предыдущее
От: Andrew Dunstan
Дата:
Сообщение: Re: logfile subprocess and Fancy File Functions
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: logfile subprocess and Fancy File Functions