Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL

From: Sir Mordred The Traitor <mordred(at)s-mail(dot)com>
To: lamar(dot)owen(at)wgcr(dot)org
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Date: 2002-08-26 15:31:26
Message-ID: 3d6a49ce.4b9ea323@s-mail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

>Hey, if I can connect to postmaster I can DoS it quite easily, but
flooding it
>with connection requests.....

Hm, that's true of course, but now i will do this with a couple of
connections.
Lets say, bot on a owned machine, connects to a database,
send a crafted packet,
postgresql will allocate a huge amount of memory, and will be
happy to read anything it recvs from my bot.

________________________________________________________________________
This letter has been delivered unencrypted. We'd like to remind you that
the full protection of e-mail correspondence is provided by S-mail
encryption mechanisms if only both, Sender and Recipient use S-mail.
Register at S-mail.com: http://www.s-mail.com/inf/en

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Stephan Szabo 2002-08-26 15:33:25 Re: Deadlock situation using foreign keys (reproduceable)
Previous Message Mario Weilguni 2002-08-26 15:30:28 Re: Deadlock situation using foreign keys (reproduceable)