Re: [GENERAL] Worst case scenario of a compromised non super-user PostgreSQL user account

2011-02-21 Thread Craig Ringer
On 21/02/2011 3:44 PM, Allan Kamau wrote: Are there other problems we may expect. Can they run any OS programs or install any such tools, induce buffer overflows and so on.? So long as your webapp user and database owner is a regular user (non-superuser) without CREATE ROLE or CREATE

Re: [GENERAL] Worst case scenario of a compromised non super-user PostgreSQL user account

2011-02-21 Thread Andrew Sullivan
On Mon, Feb 21, 2011 at 10:44:05AM +0300, Allan Kamau wrote: A web application requires a dedicated PostgreSQL database in which to create tables and other database objects and manipulate data within this single database. Why does the web application need to create tables? I usually prefer

[GENERAL] Worst case scenario of a compromised non super-user PostgreSQL user account

2011-02-20 Thread Allan Kamau
We are trying to determine the possible side effects of a rouge user account. A web application requires a dedicated PostgreSQL database in which to create tables and other database objects and manipulate data within this single database. So I have created a database and made the application's