DEF CON 33 - Rusty pearls: Postgres RCE on cloud databases - Tal 'TLP' Peleg, Coby Abrams

DEF CON 33 - Rusty pearls: Postgres RCE on cloud databases - Tal 'TLP' Peleg, Coby Abrams

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 18:28

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The researchers discovered a PostgreSQL vulnerability allowing privilege escalation and remote code execution using PL/Perl and PL/Rust extensions, which they successfully demonstrated in cloud environments 1:21-1:2310:03-10:07.

Key Takeaways:
• The vulnerability exploits PL/Perl's ability to modify environment variables despite being a "trusted" language, bypassing PostgreSQL's security model 3:20-3:243:34-3:36
• They leveraged the cargo_build_rust_wrapper environment variable in PL/Rust to execute arbitrary shell commands 6:33-6:357:45-7:56
• The team successfully tested the exploit on AWS RDS, triggering a rapid response from the AWS security team 10:19-10:2213:10-13:12
• Database administrators should keep PostgreSQL updated (patched in versions 12+), limit privileges, and restrict extensions 14:32-14:4014:54-15:05

Their research highlights that vulnerabilities in managed cloud services exist and can lead to serious security implications 15:44-15:4716:31-16:33.

Sources:

  • 1:21-1:23 Researchers introduce finding PostgreSQL RCE vulnerability
  • 3:20-3:24 Breaking PostgreSQL's trusted language assumption with PL/Perl
  • 6:33-6:35 Using cargo_build_rust_wrapper to change binary execution
  • 10:03-10:07 Objective of running shell commands as non-superuser
  • 13:10-13:12 AWS's quick incident response to the exploit
  • 14:32-14:40 Recommendations for keeping databases updated
  • 15:44-15:47 Existence of vulnerabilities in cloud environments
  • 16:31-16:33 Importance of cross-tenant access prevention

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay. So, let's get started. >> Oh, yeah. Okay. So, hi, I'm Tall Pelg. Uh, I'm a security research team lead at Veronus. Um, I specialize on security currently, so AWS, Azure, things like that. Um, and I really like breaking things and fixing them. Again, I like making music and astrophysics. And I'm Kobe Abrams. So I work with Tal at Veronis as a cloud security researcher as well. I also do is research and I'm really passionate about teaching. So I like teaching a lot and specifically, you know, teaching cyber security. Um, so yeah, that's us. Um, let's talk about what's about to happen, what we're going to talk about. So we're going to start by talking just a little bit about how the vulnerability that we found uh works. Uh, just kind of the basic details. And then later on in the talk, …