PDF4PRO ⚡AMP

Modern search engine that looking for books and documents around the web

Example: confidence

PostgreSQL Pass­The­Hash protocol design weakness

PostgreSQL pass The hash protocol design weakness Date: Monday, 2nd March 2015 Version tested: PostgreSQL , older ones are affected as well Credits: Jens Steube: __AT__ Philipp Schmidt: __AT__ ThePostgreSQLC hallenge ResponseAuthenticationusingtheAUTH_REQ_M D5methodor simplyconfiguring"md5"astheHostBasedAuth entication(HBA) defaultsettingonmanylinuxdistributionsas wellasrecommendedinthedefault configuration on github: METHOD can be "trust", "reject", "md5", "password", "gss", "sspi", "ident", "peer", "pam", "ldap", "radius" or "cert". Note that "password" sends passwords in clear text "md5" is preferred since it sends encrypted passwords. ,andthatwe candemonstratewithaproofofconcept(POC)co de,isalsoknownasapass the hash (PTH) vulnerability [1].

The PostgreSQL Challenge­Response Authentication using the AUTH_REQ_MD5 method or simply configuring "md5" as the Host Based Authentication (HBA) in pg_hba.conf is the default setting on many linux distributions as well as recommended in the default

Loading..

Tags:

  Design, Protocol, Pass, Weakness, Hash, 173 the, Postgresql, Postgresql pass, 173 hash protocol design weakness

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Spam in document Broken preview Other abuse

Transcription of PostgreSQL Pass­The­Hash protocol design weakness

Related search queries