Re: Black Hat: New database attack revealed

Поиск
Список
Период
Сортировка
От Dave Page
Тема Re: Black Hat: New database attack revealed
Дата
Msg-id 46B1CDAA.8050902@postgresql.org
обсуждение исходный текст
Ответ на Re: Black Hat: New database attack revealed  (Peter Eisentraut <peter_e@gmx.net>)
Ответы Re: Black Hat: New database attack revealed  (Magnus Hagander <magnus@hagander.net>)
Re: Black Hat: New database attack revealed  (Lukas Kahwe Smith <smith@pooteeweet.org>)
Список pgsql-advocacy
Peter Eisentraut wrote:
> Am Donnerstag, 2. August 2007 13:31 schrieb Robert Bernier:
>> New timing attack doesn't need application bugs to work
>>
>> http://www.computerworlduk.com/management/security/cybercrime/news/index.cf
>> m?RSS&newsid=4344
>
> This is complete BS, as evidenced by this statement:
>
> """
> their attack involves performing record insertion operations, typically
> available to all database users - including anonymous users of front-end web
> applications - and analysing the time it takes to perform different kinds of
> insertions.
> """
>
> In principle, attacks of this kind would be possible, but it's not quite as
> simple as they make it appear.
>

That was roughly my thought as well.

In our case, would it even be possible given WAL?

Regards, Dave.

В списке pgsql-advocacy по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Black Hat: New database attack revealed
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: Black Hat: New database attack revealed