I still haven’t been compromised. Have I done something wrong?
I still haven’t been compromised. Have I done something wrong?
In my case I was only made aware of the compromised VM because my hosting provider sent me very stern email about my server's IP netscanning their entire fricking address range.
Then see if it got compromised.
This means that your data either goes in plain text over the network, or might be vulnerable to a MITM attack (if you don't manage your certs correctly).
I also guess that you don't use SCRAM as the password hashing method, but rather MD5. That means that if someone is able to listen to the connection, they can do a replay attack using the password hash, as there is only 32 bits of entropy added to the hash from the server side. And once you have managed to do the replay attack you can issue arbitrary sql commands as that user.
Which is ok until about 5 seconds after you open the port to the world.