Re: [HACKERS] Query cancel and OOB data (fwd)

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: [HACKERS] Query cancel and OOB data (fwd)
Дата
Msg-id 11838.896224491@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: [HACKERS] Query cancel and OOB data (fwd)  (Bruce Momjian <maillist@candle.pha.pa.us>)
Ответы Re: [HACKERS] Query cancel and OOB data (fwd)
Re: [HACKERS] Query cancel and OOB data (fwd)
Список pgsql-hackers
Bruce Momjian <maillist@candle.pha.pa.us> writes:
>> However, if they are already snooping, how much harder
>> is it for them to insert their own query into the tcp stream?

> Can someone answer this for me?

Well, that depends entirely on what your threat model is --- for
example, someone with read access on /dev/kmem on a relay machine
might be able to watch packets going by, yet not be able to inject
more.  On the other hand, someone with root privileges on another
machine on your local LAN could likely do both.

My guess is that most of the plausible cases that allow one also
allow the other.  But it's only a guess.

            regards, tom lane

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Massimo Dal Zotto
Дата:
Сообщение: Re: [HACKERS] Time to fix libpgtcl for async NOTIFY
Следующее
От: Tom Lane
Дата:
Сообщение: Re: [HACKERS] Time to fix libpgtcl for async NOTIFY