Re: [GENERAL] Security implications of untrusted triggers

2006-01-12 Thread Tom Lane
Joshua Kramer <[EMAIL PROTECTED]> writes: > I am writing a couple of Perl modules that talk to the outside world: one > talks to a database (via DBI), and one talks to a Jabber/XMPP server. I > want to use these from within a Trigger. This is most likely a bad idea for reasons that have nothing

[GENERAL] Security implications of untrusted triggers

2006-01-12 Thread Joshua Kramer
Or more specifically, what are the security implications of a trigger written in an untrusted language - PL/PerlU? With a standard stored procedure, you have the possibility of an SQL-injection attack. Is this possible with a trigger function, if it is defined as a trigger? I am writing a