Denial of service is absolutely a security problem, so I don't think whoever gave this advice is correct. Sounds like a frustrating experience.
Denial of service is absolutely a security problem, so I don't think whoever gave this advice is correct. Sounds like a frustrating experience.
Any user could likely cause issues for Redshift by running completely nuts queries that exhaust all the servers resources. Is “shit SQL” a bounty worthy issue
Yes, having the power to crash your own instance might not be a security issue per se.
The problem I know of is a bit different, in that it is a direct and immediate server crash. It's not a denial of service by making the cluster slow. It's run-query, crash-server.
You are right of course that any normal user can issue crazy queries which hog resources, and hammer performance.
They have a direct email and are responsive. If the issue meets their criteria then you get a payout.
I found nothing.
Do you have a URL of any kind, for more information about this, including contacts?
I wouldn’t expect a bounty for something like this, but I believe the above is the correct avenue for reporting it.
- You have raw access to the DB
- You don't have enough privileges to get something more valuable than crashing the DB
- You don't care to get noticed/caught
Does sound pretty unlikely
I've not actually checked, so I don't know, but knowing how logging works on RS, I think the cluster crashing will mean your killer query is not logged.
Your session will have been logged by the time the cluster crashes. OTOH, maybe you were logged in for some time first, or there's connection pooling, or you slipped the query into an existing connection's query stream, and so on.
Actually, thinking about it, I think you could reduce the problem to a single query, rather than two, which would help cover tracks.
First yes for this.
> If it's the latter, it should obviously be rewarded with big $.
Second yes for this.
:-)
"Security problem" isn't a binary. DoS can be an issue, but often it is acceptable risk. Especially if your DoS is minor. E.g. i can crash the server by sending 50 Gbps of data to it, is not usually a security issue in context.
In the parent post they implied they needed privleged access to exploit. That probably makes it not a security issue as it can only be triggered by a trusted user.
Additionally most bug bounty programs disallow DoS, due to some combination of reports being low value, and testers being idiots, so it might be out of scope right from the bat.
These people don't even know about CIA triad and are gatekeeping four-figure bounty payouts while earning five figures or more every month. I'm extremely salty about this.