严重:pg_hba.conf拒绝连接主机“ 127.0.0.1”,用户“ postgres”,数据库“ prod”,关闭SSL

Pra*_*ant 10 postgresql

最近几个月一直运行良好;突然开始注意到应用程序中的错误,

FATAL: pg_hba.conf rejects connection for host "127.0.0.1", user "postgres", database "prod", SSL off
Run Code Online (Sandbox Code Playgroud)

pg_hba.conf有,

# IPv4 local connections:
host    all             all             127.0.0.1/32            md5
host    all             all             0.0.0.0/0               md5
Run Code Online (Sandbox Code Playgroud)

postgresql.conf有,

listen_addresses = '*'
Run Code Online (Sandbox Code Playgroud)

两个月都没有触摸/更改过这两个文件。

在运行环境中有人遇到过类似的问题吗?

我已经处理了有关stoackoverflow的几个与连接有关的问题;但是它们都指向配置错误的两个文件之一。那不是在这种情况下的问题。


找到根本原因并解决。

这就是发生的情况(为了那些可能遇到如此奇怪问题的人的利益)

  • 在文件顶部的pg_hba.conf中发现了三个神秘的整体
  • 这些已经为用户postgres,pgsql和pgdbadm配置了拒绝方法
  • 我们的团队成员均未添加他们
  • 因为这些在顶部,所以即使在“#PostgreSQL客户端身份验证配置文件......”注释开始之前,我们也没有注意到它。
  • 我仍然不确定这些如何出现
  • 可能是一些升级问题-但我们尚未更新Postgres
  • 这可能是部分成功的黑客尝试-仍在调查中
  • 但是为了安全起见,我们更改了服务器凭据,并研究了其他强化方法。

如果发生此问题,那么在运行良好的环境中,它可能会节省一个人不眠之夜。

Boy*_*nev 7

我有同样的问题。这是一个hack。此处描述了相同的内容:

https://dba.stackexchange.com/questions/215834/postgres-9-6-10-pg-hba-conf-altered

我有一个新的admin postgres用户“ pgdbadm”,由于template1数据库中的3个对象依赖于此,因此无法删除。从template0恢复template1 db之后,我设法删除了该用户。

pg_hba.conf文件的顶部有两个新规则:

host all postgres 0.0.0.0/0 reject
host all pgdbadm 0.0.0.0/0 md5
Run Code Online (Sandbox Code Playgroud)

文件的其余部分相同。

通过在pgAdmin 4中执行以下操作,我设法复制了完全没有外壳访问权限的hack:

-- creating a new table
create table test(a text);

-- inserting the contents of pg_hba.conf into the table
copy test from '/var/lib/pgsql/data/pg_hba.conf';

-- overwriting the pg_hba.conf file with the contents from the table prepended with one random rule (just to test it)
copy (select 'host    all             all             127.0.0.1/32            md5' union all select * from test) TO '/var/lib/pgsql/data/pg_hba.conf';

-- cleanup
drop table a;

-- reloading the server config
select pg_reload_conf();
Run Code Online (Sandbox Code Playgroud)

当然,这仅是可能的,因为postgres是在AWS EC2实例上设置的,其中所有端口均打开,默认postgres用户,默认端口,一个愚蠢的超级容易猜到的密码:“ asd123”。实例中的安全日志充满了尝试通过各种端口,各种用户名等进行连接的尝试,因此很可能是随机攻击。