bugtraq post - Mailing list pgsql-admin

From Ray Stell
Subject bugtraq post
Date
Msg-id 20070617125606.GA17612@cns.vt.edu
Whole thread Raw
Responses Re: bugtraq post
List pgsql-admin
For the security minded:

Nico Leidecker <nicoLeidecker@web.de> posted this to bugtraq yesterday, fyi.

"I'd like to present a paper about security issues with PostgreSQL. The paper describes weaknesses in the configuration
thatmay 
+allow attackers to escalade privileges, execute shell commands and to upload arbitrary (binary) files via SQL
injections.

You can either get the TXT version from http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt
Or as PDF at at http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf

The paper comes with a tool called `pgshell' that can be downloaded at http://www.leidecker.info/pgshell"


pgsql-admin by date:

Previous
From: "Abraham, Danny"
Date:
Subject: Bug #2993 on PG 8.2.4
Next
From: Devrim GÜNDÜZ
Date:
Subject: Re: Which file to download binary, rpms or srpms?