Thread: Postgres Database Hacked

Postgres Database Hacked

From
Prashant Hunnure
Date:
Dear Team,

I am working on postgres database version 9.3 is the part of opengeo suite and now my running database become hacked by someone. In the current situation I'm able to view my database under Pgadmin III but unable to view the tables, functions and other attributes on windows environment.

Your valuable solution / suggestions are highly appreciated.

Thanks and Regards, 
Prashant Hunnure
Database Architect
S2 Infotech International Limited,Mumbai.

Re: Postgres Database Hacked

From
Imre Samu
Date:
> I am working on postgres database version 9.3
> ...and now my running database become hacked by someone.  

imho:
The 9.3 version is End of Life (EoL)  ;
Final Release:    9.3.25  (November 8, 2018)
https://www.postgresql.org/support/versioning/

Please upgrade for newer versions ( with the latest security fixes )

Best,
Imre


Prashant Hunnure <prashanthunnureulb@gmail.com> ezt írta (időpont: 2019. máj. 8., Sze, 12:50):
Dear Team,

I am working on postgres database version 9.3 is the part of opengeo suite and now my running database become hacked by someone. In the current situation I'm able to view my database under Pgadmin III but unable to view the tables, functions and other attributes on windows environment.

Your valuable solution / suggestions are highly appreciated.

Thanks and Regards, 
Prashant Hunnure
Database Architect
S2 Infotech International Limited,Mumbai.

Re: Postgres Database Hacked

From
Ron
Date:
On 5/8/19 5:42 AM, Prashant Hunnure wrote:
> Dear Team,
>
> I am working on postgres database version 9.3 is the part of opengeo suite 
> and now my running database become hacked by someone. In the current 
> situation I'm able to view my database under Pgadmin III but unable to 
> view the tables, functions and other attributes on windows environment.
>
> Your valuable solution / suggestions are highly appreciated.

Wipe the system, secure your infrastructure and restore from backup.


-- 
Angular momentum makes the world go 'round.



Re: Postgres Database Hacked

From
Adrian Klaver
Date:
On 5/8/19 3:42 AM, Prashant Hunnure wrote:
> Dear Team,
> 
> I am working on postgres database version 9.3 is the part of opengeo 
> suite and now my running database become hacked by someone. In the 

What makes you think it was hacked?

> current situation I'm able to view my database under Pgadmin III but 

Can you be more specific about being able to view the database, but not 
being able to view the objects in it?

Why do you mention Windows environment?

Is the server running on Windows or some other OS?


> unable to view the tables, functions and other attributes on windows 
> environment.
> 
> Your valuable solution / suggestions are highly appreciated.
> 
> Thanks and Regards,
> Prashant Hunnure
> Database Architect
> S2 Infotech International Limited,Mumbai.
> 


-- 
Adrian Klaver
adrian.klaver@aklaver.com



Re: Postgres Database Hacked

From
Adrian Klaver
Date:
On 5/8/19 9:04 AM, Prashant Hunnure wrote:
Please reply to list also.
Ccing list.

> Hi Adrian,
> 
> Thanks for the reply.
> 
> As my public schema under the said database has been renamed by public 
> bla bla bla.....and the .map file from the global folder is in encrypted 
> format.

At this point I would say your are going to need to go back to the last 
clean backup and restore from there into a clean instance of Postgres on 
a clean version of whatever OS you are running on.

> 
> Thanks,
> Prashant
> 
> On Wed, 8 May 2019, 19:19 Adrian Klaver, <adrian.klaver@aklaver.com 
> <mailto:adrian.klaver@aklaver.com>> wrote:
> 
>     On 5/8/19 3:42 AM, Prashant Hunnure wrote:
>      > Dear Team,
>      >
>      > I am working on postgres database version 9.3 is the part of opengeo
>      > suite and now my running database become hacked by someone. In the
> 
>     What makes you think it was hacked?
> 
>      > current situation I'm able to view my database under Pgadmin III but
> 
>     Can you be more specific about being able to view the database, but not
>     being able to view the objects in it?
> 
>     Why do you mention Windows environment?
> 
>     Is the server running on Windows or some other OS?
> 
> 
>      > unable to view the tables, functions and other attributes on windows
>      > environment.
>      >
>      > Your valuable solution / suggestions are highly appreciated.
>      >
>      > Thanks and Regards,
>      > Prashant Hunnure
>      > Database Architect
>      > S2 Infotech International Limited,Mumbai.
>      >
> 
> 
>     -- 
>     Adrian Klaver
>     adrian.klaver@aklaver.com <mailto:adrian.klaver@aklaver.com>
> 


-- 
Adrian Klaver
adrian.klaver@aklaver.com



Re: Postgres Database Hacked

From
Laurenz Albe
Date:
On Wed, 2019-05-08 at 12:42 -0700, Adrian Klaver wrote:
> At this point I would say your are going to need to go back to the last 
> clean backup and restore from there into a clean instance of Postgres on 
> a clean version of whatever OS you are running on.

... and of course, plug the hole through which the attacker crept in.

Yours,
Laurenz Albe
-- 
Cybertec | https://www.cybertec-postgresql.com