DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 5th September 2022
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,128
Default Warning: PyPI Feature Executes Code Automatically After Python Package Download

From https://thehackernews.com/2022/09/wa...utes-code.html
Quote:
In another finding that could expose developers to increased risk of a supply chain attack, it has emerged that nearly one-third of the packages in PyPI, the Python Package Index, trigger automatic code execution upon downloading them.

"A worrying feature in pip/PyPI allows code to automatically run when developers are merely downloading a package," Checkmarx researcher Yehuda Gelb said in a technical report published this week.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenBSD In -current, dhclient(8) now just logs warnings and executes ifconfig(8) J65nko News 0 4th July 2022 12:15 AM
DragonFlyBSD Package download statistics shep News 0 11th May 2013 01:11 AM
Best place to download Apache package for OBSD 5.1 dbach OpenBSD Packages and Ports 2 5th June 2012 06:53 PM
[Solved] VIM without Python feature ? sw2wolf OpenBSD Packages and Ports 3 14th May 2012 01:14 AM
Disappearing firefox feature.. BSDfan666 OpenBSD Packages and Ports 7 2nd November 2008 03:47 PM


All times are GMT. The time now is 07:45 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick