PostgreSQL (port 5432) is a frequent target because, as a superuser, it will run operating-system commands and read or write arbitrary files on the host, all through documented features. Even as a non-superuser there are file and function primitives worth reaching for, and several well-known paths promote an ordinary role to superuser.
What to reach for#
- Access: default and weak credentials,
trustauthentication, and reaching a login. - Command execution:
COPY ... FROM PROGRAM, untrusted languages (plpythonu,plperlu), and C extensions. - File access:
COPY, large objects, andpg_read_fileto read and write host files.