3 ms·
I really really like this creation of yours, and I've already learned a couple things from it. However, you really really need to be careful about SQL injectio
by pzxc 9y ago
I really really like this creation of yours, and I've already learned a couple things from it.
However, you really really need to be careful about SQL injection. I can see that you tried to lock it down as much as possible, as far as I can tell the account the queries are running under only has SELECT permission (no update/delete/etc). However I was still able to get some data you probably don't want me to have...
This query returns a list of all tables in your database:
SELECT c.relname||'' FROM pg_catalog.pg_class c LEFT JOIN pg_catalog.pg_namespace n ON n.oid = c.relnamespace
And this query returns a list of users and their privileges:
SELECT usename||'', usecreatedb||'', usesuper||'', usecatupd||'' FROM pg_user
I guess your name is Andy based on your HN username, but who is Rusty? :) And that's just what I've been able to get in 5 minutes of trying, let alone a determined attacker.
- andy_boot 9y agoNoted, I am currently running on the assumption that there is nothing interesting in that PG (There isn't). But yes I would like to lock that user down further it really shouldn't be able to access those things.
- andy_boot 9y agoIt is now more locked down (at least "pg_catalog, public, information_schema" are no longer available). Thanks.
- postila 9y ago||'' is another way to do ::text ? :-)