there are plenty of other potentially nasty things (like
generate_series and the ! operator).  why are advisory_locks handled
specially?   the way it stands right now is a user with command access
can DoS a server after five minutes of research on the web.

You don't even have to do any research, just fire off ab.

Using a DOS to attack *any* database server via the web is a 3 second command.

Joshua D. Drake


