Re: [HACKERS] Query cancel and OOB data (fwd)
От | Tom Lane |
---|---|
Тема | Re: [HACKERS] Query cancel and OOB data (fwd) |
Дата | |
Msg-id | 11838.896224491@sss.pgh.pa.us обсуждение исходный текст |
Ответ на | Re: [HACKERS] Query cancel and OOB data (fwd) (Bruce Momjian <maillist@candle.pha.pa.us>) |
Ответы |
Re: [HACKERS] Query cancel and OOB data (fwd)
Re: [HACKERS] Query cancel and OOB data (fwd) |
Список | pgsql-hackers |
Bruce Momjian <maillist@candle.pha.pa.us> writes: >> However, if they are already snooping, how much harder >> is it for them to insert their own query into the tcp stream? > Can someone answer this for me? Well, that depends entirely on what your threat model is --- for example, someone with read access on /dev/kmem on a relay machine might be able to watch packets going by, yet not be able to inject more. On the other hand, someone with root privileges on another machine on your local LAN could likely do both. My guess is that most of the plausible cases that allow one also allow the other. But it's only a guess. regards, tom lane
В списке pgsql-hackers по дате отправления: