Talk About Network

Google


Register and Login
Nick
Password
Register create new account Sign up is FREE and you can post replies, new topics, bookmark posts and more!
Recover lost password


Data Bases > Pgsql Interfaces Pgadmin Support > Re: pgadmin sec...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 2 of 3 Topic 2006 of 2158
Post > Topic >>

Re: pgadmin security issue

by julius@[EMAIL PROTECTED] (Julius Tuskenis) Apr 23, 2008 at 10:11 AM

Hi, Suren,

> //
>
> */PROBLEM 1/*
>
> /Even though we can restrict a user for couple of databases , the user 
> can disconnect from the current  session and edit the connection 
> properties/
>
> /SO this means he could remove the /DB restriction field/ “ datname IN

> ('live_db', 'test_db') “  and reconnect and see all the other
databases/
>
> / /
>
> /I recommend setting up a admin account at the time of installing 
> pgadmin and only by login in to the admin account of pgadmin should be 
> able to create, edit and view connection properties/
>
I think its not pgAdmin you should set permitions on. You should not 
grant your user to connect to databases you don't want him to (in 
postgreSQL).
>
> //
>
> / /
>
> */PROBLEM 2/*
>
> /When making a connection to the DB server with pgadmin if u use a 
> valid db name and a valid user login name/
>
> /Then pgadmin will allow access to the database with out checking the 
> password/
>
> /I mean if I type a wrong password BUT if the user account and the 
> database is valid I will still be able to access the database/
>
> / /
>
> /I’m new to postgres so I’m not sure if this is a real bug or if
this 
> is a feature , Please update me ASAP/
>
> /Thanks/
>
> /Suren/
>
configure your  postgresql. In file pg_hba.conf that you have "md5" 
identification method, not "trust".

-- 
Julius Tuskenis



-- 
Sent via pgadmin-sup****t mailing list (pgadmin-sup****t@[EMAIL PROTECTED]
)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgadmin-sup****t
 




 3 Posts in Topic:
pgadmin security issue
suren@[EMAIL PROTECTED]   2008-04-23 15:56:08 
Re: pgadmin security issue
julius@[EMAIL PROTECTED]   2008-04-23 10:11:56 
Re: pgadmin security issue
dpage@[EMAIL PROTECTED]   2008-04-23 08:50:44 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
tan12V112 Mon Dec 1 17:35:26 CST 2008.