3 ms·
Wow thats a rough read. Could something similar be done to django sites ?
by MollyR 9y ago
Wow thats a rough read.
Could something similar be done to django sites ?
- rollcat 9y agoYes. There are basically three steps here... 1. Use social engineering to get your package included as a dependency; 2. Use obfuscation techniques to hide the real intent of the package; 3. Capture data and send it off to a remote server. First can be pulled off, but really depends on the community / maintainers doing their job right. In case of Django, I imagine that would be pretty hard - while the codebase is giant, by itself it has no other dependencies (except stdlib and pytz). Then 3 could be either much easier or much harder on the backend, depending on how well the box is secured (e.g. outgoing firewall rules). However the impact could be much more severe, since you're executing code on the server - at the very least you can inject any malicious JS you like, rewrite the CSP headers (if present), just dump the entire DB right away, and a lot of other bad things. This basic recipe has a chance to work regardless of the target language/package manager. It's all up to your dev process and security regime to catch it.