Having_Fun_With_PostgreSQL.pdf

Having_Fun_With_PostgreSQL.pdf

ID:34163245

大小:133.52 KB

页数:11页

时间:2019-03-03

Having_Fun_With_PostgreSQL.pdf_第1页
Having_Fun_With_PostgreSQL.pdf_第2页
Having_Fun_With_PostgreSQL.pdf_第3页
Having_Fun_With_PostgreSQL.pdf_第4页
Having_Fun_With_PostgreSQL.pdf_第5页
资源描述:

《Having_Fun_With_PostgreSQL.pdf》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库

1、HavingFunWithPostgreSQLNicoLeideckernfl@portcullis-security.comJune0520071CONTENTSHavingFunWithPostgreSQLContents1Preface32dblink:TheRootOfAllEvil32.1PrivilegeEscalation...................................32.2Brute-ForcingUserAccounts..............................5

2、2.3Port-ScanningViaRemoteAccess...........................73MappingLibraryFunctions83.1GettingAShell......................................93.2UploadingFiles......................................94FromSleepingAndCopyingInPostgreSQL8.2105RecommendationAndPrevention

3、106Introducingpgshell107Contact&Copyright112HavingFunWithPostgreSQLElephantOnTheRisePostgreSQLisanopen-sourcedatabasemanagementsystem(DBMS),releasedundertheBSDlicensewiththecurrentstableversionof8.2.3.ItderivedfromthePOSTGRESprojectattheUniversityofCalifornia,Ber

4、keleystartingin19861.POSTGRES’sfinalperformanceinversion4.2dated19942whilePostgreSQLbecameoneofthemostpopularDBMStoday.Inversion8.0approximately1milliondownloadswererecordedwithinsevenmonthsofitsrelease.ThePostgreSQLprojectregistersanumberofsignificantuserslikeBASF

5、,Fujitsu,SunMicrosystemsortheU.S.CenterForDiseaseControlandPrevention3.1PrefaceThisdocumentpresentsacoupleofideasforexploitingweaknessesintypicalPostgreSQLcon-figurations.Mostoftheseideaswon’tbenewbutarestilldifficulttofindoreasytomiss,mostdocumentationaimedatdatabas

6、eadministratorsoftendonotaddressoroverlooktheseissues.ThefollowingexampleswheretestedonPostgreSQL8.1andmaydifferfrompreviousversions.Version8.2bringsfurthersignificantchangesthatarediscussedinsection4.2dblink:TheRootOfAllEvilTheDatabaseLinklibrary(dblink)hasbeenpar

7、tofthePostgreSQLprojectsinceversion7.2.Asthenamesuggestsitisusedforinterconnetionsbetweenremotedatabases.Thecontributioncomesinhandy,when,forinstance,datafromaremotedatabaseneedstobeincludedintoalocaldatabase.Typicalusageforthefunctioniscreatingaviewfromaremotely

8、executedquery:CREATEVIEWentry_statesASSELECT*FROMdblink(’host=1.2.3.4dbname=remotedbuser=dbuserpassword=secretpass’,’SELECTid,titleFROMentries’)ASremote_entrie

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
相关文章
更多
相关标签