Re: The default database account can be accessed without a password

From: MUKESH PRASAD <mukeshprasad_hit(at)yahoo(dot)co(dot)in>
To: Geoff Winkless <pgsqladmin(at)geoff(dot)dj>, "pgsql-admin(at)lists(dot)postgresql(dot)org" <pgsql-admin(at)lists(dot)postgresql(dot)org>
Subject: Re: The default database account can be accessed without a password
Date: 2020-09-22 14:07:40
Message-ID: 634841077.3807388.1600783660380@mail.yahoo.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Hi Geoff, Yes it is allowed for all the hosts in same subnet. 
host all all 10.10.10.0/24 trust
Regards,Mukesh Prasad

Sent from Yahoo Mail on Android

On Tue, 22 Sep 2020 at 7:10 PM, Geoff Winkless<pgsqladmin(at)geoff(dot)dj> wrote: On Tue, 22 Sep 2020 at 14:33, MUKESH PRASAD
<mukeshprasad_hit(at)yahoo(dot)co(dot)in> wrote:
> I am getting VA with CVE I'd 1999-0508 where it says my default database is unpassword. However I checked all the dB with \l command and In none of the database I am able to login without password.
>
> It refers to the default postgres user and I have changed password too multiple times but still it complaints.

Do you have "trust" for any lines in pg_hba.conf?

Geoff

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Shrikant Bhende 2020-09-22 14:50:16 Re: Query taking seq scan on a table
Previous Message Tom Lane 2020-09-22 14:07:26 Re: Query taking seq scan on a table