Compromised postgresql instances - Mailing list pgsql-hackers

From Steve Atkins
Subject Compromised postgresql instances
Date
Msg-id 3CFA575D-FFB0-401F-AF7A-385B476D9484@blighty.com
Whole thread Raw
Responses Re: Compromised postgresql instances
List pgsql-hackers
I've noticed a steady trickle of reports of postgresql servers being compromised via being left available to the
internetwith insecure or default configuration, or brute-forced credentials. The symptoms are randomly named binaries
beinguploaded to the data directory and executed with the permissions of the postgresql user, apparently via an
extensionor an untrusted PL. 

Is anyone tracking or investigating this?

Cheers,
  Steve



pgsql-hackers by date:

Previous
From: Peter Da Silva
Date:
Subject: Re: pl/tcl function to detect when a request has been canceled
Next
From: Alvaro Herrera
Date:
Subject: Re: SHOW ALL does not honor pg_read_all_settings membership