Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
От | Lamar Owen |
---|---|
Тема | Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL |
Дата | |
Msg-id | 200208261118.48487.lamar.owen@wgcr.org обсуждение исходный текст |
Ответ на | @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL (Sir Mordred The Traitor <mordred@s-mail.com>) |
Ответы |
Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL |
Список | pgsql-hackers |
On Monday 26 August 2002 10:46 am, Sir Mordred The Traitor wrote: > Conditions: entry in a pg_hba.conf file that matches attacker's host. > Risk: average > --[ Solution > > Disable network access for untrusted users. TCP/IP access must be enabled as well. TCP/IP accessibility is OFF by default. I for one thought that it was normal operating procedure to only allow access to trusted machines; maybe I'm odd in that regard. Hey, if I can connect to postmaster I can DoS it quite easily, but flooding it with connection requests..... But, if we can thwart this, all the better. -- Lamar Owen WGCR Internet Radio 1 Peter 4:11
В списке pgsql-hackers по дате отправления: