Any user could likely cause issues for Redshift by running completely nuts queries that exhaust all the servers resources. Is “shit SQL” a bounty worthy issue
Any user could likely cause issues for Redshift by running completely nuts queries that exhaust all the servers resources. Is “shit SQL” a bounty worthy issue
Yes, having the power to crash your own instance might not be a security issue per se.
The problem I know of is a bit different, in that it is a direct and immediate server crash. It's not a denial of service by making the cluster slow. It's run-query, crash-server.
You are right of course that any normal user can issue crazy queries which hog resources, and hammer performance.
They have a direct email and are responsive. If the issue meets their criteria then you get a payout.
I found nothing.
Do you have a URL of any kind, for more information about this, including contacts?
I wouldn’t expect a bounty for something like this, but I believe the above is the correct avenue for reporting it.