Superuser without pg_hba could drop database

From: Mudy Situmorang <mudy(at)astasolusi(dot)com>
To: pgadmin-support(at)postgresql(dot)org
Subject: Superuser without pg_hba could drop database
Date: 2010-07-29 05:34:56
Message-ID: AANLkTikhq7YUXx0ex8eSZ59Y_+M0atJFTUJqcmUw8wAA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgadmin-support

Superuser without pg_hba could drop database from client at pgAdminIII
Object browser by left click & Delete/Drop.

User has superuser rights, but no pg_hba connection entry for the host.

There are warnings on left click, twice:
An error has occured:
FATAL: no pg_hba.conf entry for host "172.17.0.8", user "tempuser", database
"testdatabase", SSL on
FATAL: no pg_hba.conf entry for host "172.17.0.8", user "tempuser", database
"testdatabase", SSL off

Then context menu appear, click Delete/Drop, Yes on confirmation.

The database is gone.

pgAdminIII at client:
Windows XP
pgAdminIII 1.10.3 (from PostgreSQL 8.4 windows package)

PostgreSQL 8.4 server:
Ubuntu 10.04

I think it is very dangerous.

Regards,
Mudy

Responses

Browse pgadmin-support by date

  From Date Subject
Next Message Samokhin Viktor 2010-07-29 06:06:29 pgAdmin 1.10.2 issue
Previous Message Michael Shapiro 2010-07-28 14:04:32 Re: Bug with exceptionally long values.