Re: [HACKERS] security flaw

2003-06-15 Thread Christopher Kings-Lynne
Since schemas provide a simple way to limit your own view, they provide for that function. Can phppgadmin be programmed to only use certain search paths in the schema? Not at the moment. The only control you have is 'show only owned databases'. 'Show only owned schemas' is also quite easy.

Re: [HACKERS] security flaw

2003-06-13 Thread ohp
On Tue, 10 Jun 2003, scott.marlowe wrote: Date: Tue, 10 Jun 2003 08:15:06 -0600 (MDT) From: scott.marlowe [EMAIL PROTECTED] To: [EMAIL PROTECTED] Cc: pgsql-hackers list [EMAIL PROTECTED] Subject: Re: [HACKERS] security flaw On Sat, 7 Jun 2003 [EMAIL PROTECTED] wrote: Hi all, I

Re: [HACKERS] security flaw

2003-06-10 Thread scott.marlowe
On Sat, 7 Jun 2003 [EMAIL PROTECTED] wrote: Hi all, I wonder if it's a security problem: One of my customer noticed that he could see all databases on the system with phppgadmin. not only he sees databases but tables, views, fonctions... Fortunatly he can't see any row. This customer has

Re: [HACKERS] security flaw

2003-06-09 Thread Robert Treat
On Sat, 2003-06-07 at 14:04, [EMAIL PROTECTED] wrote: Hi all, I wonder if it's a security problem: One of my customer noticed that he could see all databases on the system with phppgadmin. not only he sees databases but tables, views, fonctions... Fortunatly he can't see any row. This

[HACKERS] security flaw

2003-06-08 Thread ohp
Hi all, I wonder if it's a security problem: One of my customer noticed that he could see all databases on the system with phppgadmin. not only he sees databases but tables, views, fonctions... Fortunatly he can't see any row. This customer has the ability to create databases but not users. I