Re: The default database account can be accessed without a password - Mailing list pgsql-admin

From Ganesh Korde
Subject Re: The default database account can be accessed without a password
Date
Msg-id CAPNyb0V9ZZMp8wL6vE1yKSGL2ozP9uNDTSWh4n0HbWjg+JMN3A@mail.gmail.com
Whole thread Raw
In response to Re: The default database account can be accessed without a password  (MUKESH PRASAD <mukeshprasad_hit@yahoo.co.in>)
List pgsql-admin
You need to change it to md5.

On Tue, 22 Sep 2020, 7:38 pm MUKESH PRASAD, <mukeshprasad_hit@yahoo.co.in> wrote:
Hi Geoff, 
Yes it is allowed for all the hosts in same subnet. 

host all all 10.10.10.0/24 trust

Regards,
Mukesh Prasad


On Tue, 22 Sep 2020 at 7:10 PM, Geoff Winkless
On Tue, 22 Sep 2020 at 14:33, MUKESH PRASAD

<mukeshprasad_hit@yahoo.co.in> wrote:
> I am getting VA with CVE I'd 1999-0508 where it says my default database is unpassword. However I checked all the dB with \l command and In none of the database I am able to login without password.
>
> It refers to the default postgres user and I have changed password too multiple times but still it complaints.


Do you have "trust" for any lines in pg_hba.conf?

Geoff

pgsql-admin by date:

Previous
From: Jim Geurts
Date:
Subject: Re: HIPAA Business Associate Agreement (BAA)
Next
From: "JOIGNY Michael @Neteven"
Date:
Subject: Re: Cannot allocate memory