3 ms·
Chinese-speaking security researcher fate0 found a way around the blacklisting of requirements.txt in 2017. There is a write-up in English of it here (second ha
by dubbel 6y ago
Chinese-speaking security researcher fate0 found a way around the blacklisting of requirements.txt in 2017. There is a write-up in English of it here (second half of the chapter): https://haukeluebbers.de/blog/2020-01-timeline-of-package-dependency-compromises/#may---june-2017-evil-cookie-cutters-sighted-more-requirementstxt https://haukeluebbers.de/blog/2020-01-timeline-of-package-de...
I agree, it is a different category of attack on the human side of the package manager installation process.