Re: Serious problem within authentication subsystem in 7.0

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Matt Sullivan <matt(at)sullivan(dot)gen(dot)nz>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Serious problem within authentication subsystem in 7.0
Date: 2000-05-23 01:39:44
Message-ID: 26774.959045984@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Matt Sullivan <matt(at)sullivan(dot)gen(dot)nz> writes:
> Essentially, in our environment, we require password authentication as
> a defacto. However it appears that once a user has authenticated with
> the backend it is possible for that user to trivially assume root dba
> privileges or privileges of any other dba user.

It appears that psql will auto-supply the previously entered password,
so if you were using the same password for all your accounts then this
might happen. Otherwise it's pretty hard to believe. That new
connection is to a new backend; there's no way for it to know that you
were previously connected.

Offhand I think it would be a good idea for psql to insist on a new
password if the \connect command gives a new user name...

regards, tom lane

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message The Hermit Hacker 2000-05-23 01:41:49 Re: OO Patch
Previous Message Tom Lane 2000-05-23 01:11:25 Re: [BUGS] port v7.0 to SGI-IRIX-6.5.7/64