1.1 PSQL Large Object Shell -linux
PostgreSQL large objects: server-side file write validation
Use this only on an authorized lab or assessment target. PostgreSQL's
lo_import and lo_export functions read and write files on the database
server, using the database service account's operating-system permissions.
They do not read from a client shell's standard input.
Safe validation with a marker file
The following creates a large object from known bytes, verifies it in the
database, exports a harmless marker, and removes the object. Server-side file
functions normally require a superuser or an explicitly granted predefined
server-file role.
-- Create a large object containing a harmless marker and retain its OID.
SELECT lo_from_bytea(0, convert_to('authorized PostgreSQL file-write test\n', 'UTF8')) AS oid;
-- Substitute the returned OID below.
SELECT oid, lomowner, lomacl
FROM pg_largeobject_metadata
WHERE oid = 12345;
SELECT convert_from(lo_get(12345), 'UTF8') AS marker;
-- This path is on the database server, not the client.
SELECT lo_export(12345, '/tmp/postgresql-authorized-test.txt');
-- Remove the large object after validation.
SELECT lo_unlink(12345);
Confirm the exported marker through the approved host-access path, record the
database role and file ownership, then remove the marker. Do not use executable
payloads for this validation.
Importing an existing server file
lo_import('/path') reads a file that already exists on the database server.
Use it only when that specific server path is in scope.
SELECT lo_import('/tmp/approved-input.txt') AS oid;