Thread: Security problem with Postgres sql

Security problem with Postgres sql

From
DEEPANSHU GARG
Date:
Hi,
We have a problem when logging in postgresql.
We are setting the user id and password using Create User command.
Now when we login the postgresql using
$psql -U username databasename
it does'nt prompt for the password but connects to the database.
The password is correctly set and we examined the pg_shadow table also
where it has been stored in the encrypted format. Please help us with
this.

Also when we log in the Psql with the small -u option it shows the option
is deprecated , use -U option , prompts for the user id and passsword but
never validates the password.

If someone else has faced this problem please help us out. This is very
ugently required.

Regards,
Deeps

Re: Security problem with Postgres sql

From
Bruno Wolff III
Date:
On Fri, Mar 21, 2003 at 16:44:07 +0530,
  DEEPANSHU GARG <deepanshu.garg@tatainfotech.com> wrote:
> Hi,
> We have a problem when logging in postgresql.
> We are setting the user id and password using Create User command.
> Now when we login the postgresql using
> $psql -U username databasename
> it does'nt prompt for the password but connects to the database.
> The password is correctly set and we examined the pg_shadow table also
> where it has been stored in the encrypted format. Please help us with
> this.
>
> Also when we log in the Psql with the small -u option it shows the option
> is deprecated , use -U option , prompts for the user id and passsword but
> never validates the password.
>
> If someone else has faced this problem please help us out. This is very
> ugently required.

Can you show us pg_hba.conf?

Most likely you are using trust as the authentication method.