phpPgAdmin Security hole - Mailing list pgsql-novice

From Frank Hilliard
Subject phpPgAdmin Security hole
Date
Msg-id 3C23ADFA.2080504@shaw.ca
Whole thread Raw
In response to Re: Import DB from DOS- dbase4  ("Josh Berkus" <josh@agliodbs.com>)
List pgsql-novice
I've just discovered that password protection for phpPgAdmin may not be
functioning if the postgres config file isn't set to require passwords.
It's sure easy to check, just type in postgres as a username and  a
bogus password and it still works! The quick, but dirty, fix is to
change the default directory to some other name.

Frank Hilliard
http://frankhilliard.com/


pgsql-novice by date:

Previous
From: Tom Lane
Date:
Subject: Re: appropriate sort_mem & shared buffers
Next
From: Francisco Reyes
Date:
Subject: Variable + string concatenation?