Re: Compromised postgresql instances

2018-06-08 Thread Steve Atkins
> On Jun 8, 2018, at 1:47 PM, Tom Lane wrote: > > Andrew Dunstan writes: >> On 06/08/2018 04:34 PM, Steve Atkins wrote: >>> I've noticed a steady trickle of reports of postgresql servers being >>> compromised via being left available to the

Compromised postgresql instances

2018-06-08 Thread Steve Atkins
I've noticed a steady trickle of reports of postgresql servers being compromised via being left available to the internet with insecure or default configuration, or brute-forced credentials. The symptoms are randomly named binaries being uploaded to the data directory and executed with the permi