Skip to content

Remote hacking of PostgREST ?? #3671

Answered by wolfgangwalther
JLacal asked this question in Q&A
Discussion options

You must be logged in to vote

I opened port 5432 on the router and forwarded the port to the mac Mini's port 5432. Friday July 26 at 13:00 hr. UTC.
[...]
The PostgresApp has this setting "Ask for permission when apps connect without password." I believe the problem starts here.
[...]
Over the weekend I received several pop-up messages from the PostgresApp along the lines of "something wants to connect with app." I mindlessly accepted a couple of times, thinking it was my team members requesting remote access.

So you opened the PostgreSQL port to the public and allowed connections without password. This is neither a problem with PostgreSQL nor PostgREST - it's a problem with your configuration.

The email you received…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by wolfgangwalther
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants