Hacker found bug in Postgres ?

From: Matthias Schmitt <freak001(at)mmp(dot)lu>
To: pgsql-hackers(at)postgresql(dot)org
Subject: Hacker found bug in Postgres ?
Date: 1999-04-27 16:22:33
Message-ID: v04020a03b34b9040da56@[192.168.129.13]
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Hello,

this night we discovered here a strange behaviour on our servers. Somebody
managed to get access to the UNIX shell using the 'postgres' db
administrator account. He logged in some machines with a single try ! The
password was not part of any dictionary. He tried some other accounts,
without success. Under the user postgres he installed an 'eggdrop' program
on the machine, implementing an IRC server.

If you want to look on your servers, look for an ".elm/..." directory in
the postgres home directory. You may discover too some processes named
"./..." or "../ -m" running under the postgres user.

Is there any chanche, that the postgres database contains a bug giving
shell access ? Is there any chance to trace what happens on the postgres
port ?

Matthias Schmitt
------------------------------------------------------------------
Matthias Schmitt
magic moving pixel s.a. Phone: +352 54 75 75 - 0
Technoport Schlassgoart Fax : +352 54 75 75 - 54
66, rue de Luxembourg URL : http://www.mmp.lu
L-4221 Esch-sur-Alzette Email: info(at)mmp(dot)lu

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Jan Wieck 1999-04-27 16:24:23 Re: [HACKERS] views and group by (formerly: create view as selec
Previous Message Bruce Momjian 1999-04-27 16:21:55 Re: [HACKERS] numeric & decimal