postgresql - Downloading and using a database from an untrusted source? -


If I had to obtain a database (in this case for postgrescale) from an untrusted source, Danger and asks it?

There are very possible attack vectors, if you are asking this, here are some of those Perhaps the link from the database is actually linked to a hacked PDF file that exploits some vulnerabilities in your Acrobat plugin (your PDF plugin Patch is okay? It's a recent actually popular attack vector)

  • If it zipped it If so, then this is actually a zip bomb.

  • If this is a binary dump, then it is probably trying to take advantage of some bugs in the restoration process.

  • Perhaps it is maliciously stored procedures that will leave your database or gather your password.

  • It may be just a text dump that contains a bunch of drop statements.

  • Speaking practically, this is actually not the result of low hanging. Postgrass is a niche product with limited listeners (developers who prefer postgrasses) I think It is not quite likely that a database dump will be used to distribute any kind of malware.

    "Untrusted" in this case depends on what is "safe". If you are really worried, stop networking to limit it to potential losses.


    Comments

    Popular posts from this blog

    Eclipse CDT variable colors in editor -

    AJAX doesn't send POST query -

    wpf - Custom Message Box Advice -