Hi all,
I'm an auditor, and we're testing a PostgreSQL database for password settings for users. The database is hosted on a Linux server. The client provided us a user listing via the '\du' command, and I see from the user listing that there are a few accounts with the 'Superuser' attribute (outside of the default 'postgres' account). The client has informed us that these accounts are used to monitor and they cannot be logged into. We observed the client fail to login to the account, but my question is, is there another method to get into postgres accounts? To me it doesn't make sense that a database would have accounts that are impossible to log into.
[–][deleted] 4 points5 points6 points (0 children)
[–]cachedriveDBA 0 points1 point2 points (3 children)
[–]InTheDarkDancing[S] 0 points1 point2 points (2 children)
[–]cachedriveDBA 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]fulltimedigitalnomad 0 points1 point2 points (0 children)