Re: PostgreSQL Password Cracker - Mailing list pgsql-hackers

From Tom Lane
Subject Re: PostgreSQL Password Cracker
Date
Msg-id 1148.1041356309@sss.pgh.pa.us
Whole thread Raw
In response to PostgreSQL Password Cracker  (Devrim GUNDUZ <devrim@tr.net>)
Responses Re: PostgreSQL Password Cracker
Re: PostgreSQL Password Cracker
List pgsql-hackers
Devrim GUNDUZ <devrim@tr.net> writes:
> Some guys from Turkey claim that they have a code to crack PostgreSQL
> passwords, defined in pg_hba.conf .

> http://www.core.gen.tr/pgcrack/

This is not a cracker, this is just a brute-force "try all possible
passwords" search program (and a pretty simplistic one at that).
I'd say all this proves is the importance of choosing a good password.
Using only lowercase letters is a *bad* idea, especially if you're only
going to use five of 'em...
        regards, tom lane


pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: Bug in Dependencies Code in 7.3.x?
Next
From: Tom Lane
Date:
Subject: Re: Bug in Dependencies Code in 7.3.x?