Schedule - PostgreSQL Development Conference 2025

Crafting exploits for historical CVEs

Level: Beginner

Bring your laptops, we will try to hack Postgres. Literally. I'll explain some old CVEs and together we will try to build exploits for them. Also, I'll explain how these vulnerabilities were introduced and fixed. Probably, for an experienced CTF player or Postgres hacker there won't be much new. But others might get to know some basics of Postgres red-teaming.

To participate you need a computer with Docker, Postgres-compatible SQL client and internet connection to download sources and dependencies.

Speaker

Andrey Borodin