Thanks to everyone for the ideas, the information you provided me with
was much needed.  it's much appreciated.




C O N F I D E N T I A L I T Y   N O T I C E
The contents of and attachments to this e-mail are intended for the
addressee only, and may contain the confidential information of Argility
(Proprietary) Limited and/or its subsidiaries. Any review, use or
dissemination thereof by anyone other than the intended addressee is
prohibited. If you are not the intended addressee please notify the writer
immediately and destroy the e-mail. Argility (Proprietary) Limited and its
subsidiaries distance themselves from and accept no liability for
unauthorised use of their e-mail facilities or e-mails sent other than
strictly for business purposes.

-----Original Message-----
From: Scott Ribe [mailto:scott_r...@elevated-dev.com]
Sent: Wednesday, March 14, 2012 5:47 PM
To: David Ondrejik
Cc: Khangelani Gama; pgsql-admin@postgresql.org
Subject: Re: [ADMIN] Update actions (with user name) inside PostgreSQL DB
- any version on postgreSQL

On Mar 14, 2012, at 9:28 AM, David Ondrejik wrote:

> So there is some trail to track back to the original user.

Yes, but once he has root shell, the trail ends there, and impersonation
of anyone is once again trivial. Also, sudo su root, does work on some
unices, and the option you don't want to advertise is, in my opinion,
trivially obvious--but I'll respect the idea and not advertise it.

-- 
Scott Ribe
scott_r...@elevated-dev.com
http://www.elevated-dev.com/
(303) 722-0567 voice




CONFIDENTIALITY NOTICE
The contents of and attachments to this e-mail are intended for the addressee 
only, and may contain the confidential information of Argility (Proprietary) 
Limited and/or its subsidiaries. Any review, use or dissemination thereof by 
anyone other than the intended addressee is prohibited.
If you are not the intended addressee please notify the writer immediately and 
destroy the e-mail. Argility (Proprietary) Limited and its subsidiaries 
distance themselves from and accept no liability for unauthorised use of their 
e-mail facilities or e-mails sent other than strictly for business purposes.


-- 
Sent via pgsql-admin mailing list (pgsql-admin@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-admin

Reply via email to