Any user could likely cause issues for Redshift by running completely nuts queries that exhaust all the servers resources. Is “shit SQL” a bounty worthy issue
Yes, having the power to crash your own instance might not be a security issue per se.
The problem I know of is a bit different, in that it is a direct and immediate server crash. It's not a denial of service by making the cluster slow. It's run-query, crash-server.
You are right of course that any normal user can issue crazy queries which hog resources, and hammer performance.
They have a direct email and are responsive. If the issue meets their criteria then you get a payout.
I found nothing.
Do you have a URL of any kind, for more information about this, including contacts?
I wouldn’t expect a bounty for something like this, but I believe the above is the correct avenue for reporting it.
- You have raw access to the DB
- You don't have enough privileges to get something more valuable than crashing the DB
- You don't care to get noticed/caught
Does sound pretty unlikely
I've not actually checked, so I don't know, but knowing how logging works on RS, I think the cluster crashing will mean your killer query is not logged.
Your session will have been logged by the time the cluster crashes. OTOH, maybe you were logged in for some time first, or there's connection pooling, or you slipped the query into an existing connection's query stream, and so on.
Actually, thinking about it, I think you could reduce the problem to a single query, rather than two, which would help cover tracks.
First yes for this.
> If it's the latter, it should obviously be rewarded with big $.
Second yes for this.
:-)