Re: Spoofing as the postmaster

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: Spoofing as the postmaster
Дата
Msg-id 200712230536.lBN5aVj19721@momjian.us
обсуждение исходный текст
Ответ на Re: Spoofing as the postmaster  ("Brendan Jurd" <direvus@gmail.com>)
Ответы Re: Spoofing as the postmaster
Список pgsql-hackers
Brendan Jurd wrote:
> On Dec 23, 2007 1:25 PM, Bruce Momjian <bruce@momjian.us> wrote:
> > I have written documentation for this item:
> >
> >         http://momjian.us/tmp/pgsql/server-shutdown.html#SERVER-SPOOFING
> >
> > Comments?
> 
> I thought the content made sense, but the location didn't.  I wouldn't
> expect to find instructions on configuring Postgres for secure
> operation under a section about how to shut the server down.
> 
> I realise that in order for the exploit to occur, the server must be
> shut down (or not yet started), but unless a user already knows about
> the way the exploit works, how will they know to look for info about
> it here?
> 
> IMO by putting this guidance under "Shutting Down" you're going to
> hurt the chances of anyone stumbling across it.  I doubt you'd get
> many users reading "Shutting Down" at all because in most cases, it's
> an easy or obvious thing to do (initscripts provided by package and
> pg_ctl are self-explanatory).

Agreed. I moved it up to its own section:
http://momjian.us/tmp/pgsql/preventing-server-spoofing.html

I improved the wording slightly too.

--  Bruce Momjian  <bruce@momjian.us>        http://momjian.us EnterpriseDB
http://postgres.enterprisedb.com
 + If your life is a hard drive, Christ can be your backup. +


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Brendan Jurd"
Дата:
Сообщение: Re: Spoofing as the postmaster
Следующее
От: Mark Mielke
Дата:
Сообщение: Re: Spoofing as the postmaster