Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
peteatphylum
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
peteatphylum
4y ago
Another huge fan of just, here. I love that it's installable with a one-liner and I've added this as an option to my dotfile setup. I'm done trying to cast spells at Make
2.
▲
A Deep Dive into PoweRAT: A Newly Discovered Stealer/Rat Combo Polluting PyPI
(blog.phylum.io)
1 points
by
peteatphylum
4y ago
|
0 comments
3.
▲
by
peteatphylum
4y ago
This attack is particularly interesting. The attackers targeted the massively popular 'requests' package in PyPI, used bitsquatting to target typosquat candidates, and results in ransomware getting deployed. There be dragons in he
4.
▲
by
peteatphylum
4y ago
Not only great work in taking the bugs all the way, but a great writeup too
5.
▲
Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)
(blog.sonarsource.com)
1 points
by
peteatphylum
4y ago
|
1 comments
6.
▲
by
peteatphylum
4y ago
Totally agree. It feels like there is a pretty strong inverse correlation between standard library size, and average depth of a dependency tree for projects in a given language. In our world, that is pretty close to attack surface.
7.
▲
by
peteatphylum
4y ago
We've found a lot of open-source packages that are authored by (well, released by authors identified by) disposable email addresses. We were shocked to find companies doing this, too. Package Dependency land is a crazy place
8.
▲
by
peteatphylum
4y ago
This is the double-edged sword of open-source. It's awesome because anyone can contribute. It can be dangerous for the same reason, unfortunately.
9.
▲
by
peteatphylum
4y ago
I think the majority of the functionality in leap can be had in IntelliJ IDE's with the AceJump plugin
10.
▲
by
peteatphylum
4y ago
(Disclaimer: I work at Phylum, which has a very similar capability) Not all of it has to be manual. Some vulnerabilities come with enough information to deduce vulnerability reachability with a high degree of confidence with some slightly c
11.
▲
by
peteatphylum
4y ago
This is a terrific project. Write a scraper to do this! I suggest this having read another comment of yours ( https://news.ycombinator.com/item?id=31763001 ) Scrapers are fun projects and there are tons of resources online to
12.
▲
by
peteatphylum
5y ago
We're building a solution to solve exactly this at phylum. I'm not trying to be a sales shill, but if anyone is interested in discussing ideas on how to best defend open-source libraries from these types of attacks, please get in
13.
▲
by
peteatphylum
5y ago
I wish it worked that way. I just peeked into how python packages in debian-based distros work. They are most frequently PyPI packages with some debian wrapping, so we're back at the same problem.