Hacker found bug in Postgres ? - Mailing list pgsql-hackers

From Matthias Schmitt
Subject Hacker found bug in Postgres ?
Date
Msg-id v04020a03b34b9040da56@[192.168.129.13]
Whole thread Raw
Responses Re: [HACKERS] Hacker found bug in Postgres ?  (Bruce Momjian <maillist@candle.pha.pa.us>)
Re: [HACKERS] Hacker found bug in Postgres ?  (Vince Vielhaber <vev@michvhf.com>)
Re: [HACKERS] Hacker found bug in Postgres ?  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Hello,

this night we discovered here a strange behaviour on our servers. Somebody
managed to get access to the UNIX shell using the 'postgres' db
administrator account. He logged in some machines with a single try ! The
password was not part of any dictionary. He tried some other accounts,
without success. Under the user postgres he installed an 'eggdrop' program
on the machine, implementing an IRC server.

If you want to look on your servers, look for an ".elm/..." directory in
the postgres home directory. You may discover too some processes named
"./..." or "../ -m" running under the postgres user.

Is there any chanche, that the postgres database contains a bug giving
shell access ? Is there any chance to trace what happens on the postgres
port ?

Matthias Schmitt
------------------------------------------------------------------
Matthias Schmitt
magic moving pixel s.a.    Phone: +352 54 75 75 - 0
Technoport Schlassgoart    Fax  : +352 54 75 75 - 54
66, rue de Luxembourg      URL  : http://www.mmp.lu
L-4221 Esch-sur-Alzette    Email: info@mmp.lu


pgsql-hackers by date:

Previous
From: jwieck@debis.com (Jan Wieck)
Date:
Subject: Re: [HACKERS] views and group by (formerly: create view as selec
Next
From: Bruce Momjian
Date:
Subject: Re: [HACKERS] numeric & decimal