The Slovak National Security Office (NBU) has identified ten malicious Python libraries uploaded on PyPI â Python Package Index â the official third-party software repository for the Python programming language. NBU experts say attackers used a technique known as typosquatting to upload Python libraries with names similar to legitimate packages â e.g.: "urlib" instead of "urllib." The PyPI reposit
The Slovakian National Security Authority on Thursday warned that PyPI, the repository for Python software packages, has been hosting malicious software libraries. The group's cybersecurity division, SK-CSIRT, identified 10 fake libraries designed to dupe developers through typosquatting. The names of the malicious libraries are almost identical to legitimate libraries, in the hope that fat-finger
The official repository for the widely used Python programming language has been tainted with modified code packages, a computer security authority in Slovakia warned. The authority also said the packages have been downloaded by unwitting developers who incorporated them into software over the past three months. Multiple code packages were uploaded to the Python Package Index, often abbreviated as
ã¹ãããã¢æ¿åºã®ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çãã¼ã SK-CSIRTã¯ãPythonããã±ã¼ã¸ã®å ¬å¼ãªãã¸ã㪠PyPI ã«æªæããã³ã¼ããå«ã10åã®å½ã©ã¤ãã©ãªããã±ã¼ã¸ãã¢ãããã¼ãããã¦ãããã¨ãçºè¡¨ãã(SK-CSIRTã¢ããã¤ã¶ãªã¼: skcsirt-sa-20170909-pypiã Ars Technicaã®è¨äºã The Registerã®è¨äºã Bleeping Computerã®è¨äº)ã å½ããã±ã¼ã¸ã¯ããããæåããã±ã¼ã¸ã®ã³ãã¼ã§ããªãªã¸ãã«ã®ããã±ã¼ã¸åãä¸é¨å¤ããååãä»ãããã¦ãããã³ã¼ãèªä½ã¯ãªãªã¸ãã«ã¨å ¨ãåããã®ã ããã¤ã³ã¹ãã¼ã«æã«å®è¡ãããã¹ã¯ãªãããæªæã®ããã³ã¼ããå«ããã®ã«å¤ãããã¦ããã¨ã®ãã¨ã SK-CSIRTã®éå ±ã«ããæ¢ã«åé¡ã®ããã±ã¼ã¸ã¯å ¨ã¦ãªãã¸ããªããåé¤ãããããå ¬éããã¦ãã6æãã9æã®éã«è¤æ°åã®ãã¦ã³ãã¼ãã確èªããã¦ãã
Unverified details These details have not been verified by PyPI Project links Homepage Download Meta License: GNU Lesser General Public License v2 (LGPLv2) (GNU Lesser General Public License version 2.1) Author: Miquel Torres Tags benchmarking, visualization # Codespeed [![Build Status](https://travis-ci.org/tobami/codespeed.png?branch=master)](https://travis-ci.org/tobami/codespeed) [![PyPI versi
Unverified details These details have not been verified by PyPI Project links Homepage Meta License: Apache Software License (Apache License 2.0) Author: AWS Elastic Beanstalk Classifiers Development Status 5 - Production/Stable Intended Audience Developers System Administrators License OSI Approved :: Apache Software License Natural Language English Programming Language Python Python :: 3.7 Pytho
Unverified details These details have not been verified by PyPI Project links Homepage Meta License: Python Software Foundation License (PSF) Author: Ilan Schnell Classifiers Development Status 6 - Mature Intended Audience Developers License OSI Approved :: Python Software Foundation License Operating System OS Independent Programming Language C Python :: 3 Python :: 3.5 Python :: 3.6 Python :: 3.
Cython implementation of Toolz: High performance functional utilities Unverified details These details have not been verified by PyPI Project links Homepage Meta License: BSD License (BSD) Author: https://raw.github.com/pytoolz/cytoolz/master/AUTHORS.md Maintainer: Erik Welch Tags functional, utility, itertools, functools, iterator, generator, curry, memoize, lazy, streaming, bigdata, cython, tool
Perlã§ããã¨ããã®Test::TCPç¸å½ã®ãã¨ãPythonã§ããã©ã¤ãã©ãªãPyPIã«ä¸ãã¾ãããããããPyPIããã¥ã¼ã§ãã https://github.com/nekoya/python-tcptest https://pypi.python.org/pypi/tcptest Test::TCPã¯Perlã§ãã¹ãæã«ä¸æçã«ãµã¼ããèµ·åãããããå¦çã®åºç¤ã¨ãªãã©ã¤ãã©ãªã§ããåçã®ãã¨ãPythonã§ããã®ã«é©å½ãªãã®ãè¦å½ãããªãã£ãã®ã§èªåã§æ¸ããã¨ããçµç·¯ã§ãã 社å ã§ã¯ä»¥åãããã®ä»çµã¿ã使ã£ã¦ãã¹ããæ¸ãã¦ããã®ã§ãããèªç¤¾ã®configç³»ã®ã©ã¤ãã©ãªã¨ã®çµåãæé¤ãã¦ãåæ§æãããã®ã«ãªãã¾ããä»åãããã¦å ¬éããã«ããã£ã¦ãé¢æ°åããªãªã¸ãã«ã®Perlçã«è¿ä»ããããTestServerã®å®è£ ãå ¨é¢çã«è¦ç´ããããã¾ããã tcptestããã±ã¼ã¸ã«ã¯Test
pip ã easy_install ãçªç¶éããªããããããªã ã§ç´¹ä»ãã pypi ããã®ã¤ã³ã¹ãã¼ã«é«éåã®ç¬¬ä¸å¼¾ãå§ã¾ãã¾ããã ã¨ãã£ã¦ãããããªãåæã« pypi å´ã§ã¹ã¯ã¬ã¤ãã³ã°ããURLãå¤æ´ããã®ã§ã¯ãªãã¦ãããã±ã¼ã¸ç®¡çè ãæ示çã«æå®ããæ¹æ³ã«ãªãã¾ãã pypi ã«ããã±ã¼ã¸ãã¢ãããã¼ããã¦ãã人ã¯è¨å®å¤æ´ãã¾ãããã ããã±ã¼ã¸ã®ç®¡çç»é¢ã®ãã¡ url ã®ç»é¢ãéãã¨ããã®ç»åã®ãããªãã¼ã¸ã表示ããã¾ãã ã¾ãã Hosting Mode ã®ã¨ããã§ã "As above but also..." ã«ãªã£ã¦ããã®ã "Do not extract..." ã«å¤ãã¾ããããã§ãã¢ãããã¼ããããã¡ã¤ã«ä»¥å¤ãæ¢ãã«è¡ããã¨ããªããªãã¾ãã (pypi ã«ããã±ã¼ã¸ãã¢ãããã¼ããã¦ããªã人ã¯ã download_url ãæå®ã㦠"Present URLs..
PyPI ãå®å ¨ã«å©ç¨ããããã«ãå æ¥ããã©ã«ã㧠https ãå©ç¨ãã pip ããªãªã¼ã¹ããã¾ããã ã§ããããã§çµããã§ã¯ããã¾ããã pip ã easy_install 㯠PyPI ã®ãã¼ã¸ãããªã³ã¯ã辿ã£ã¦ã¹ã¯ã¬ã¤ãã³ã°ãã¦ããã±ã¼ã¸ãæ¢ãã¦ãã¾ãããªã³ã¯å ãhttpsã§ãªãã£ãããã£ã±ãå®å ¨ã§ã¯ããã¾ããã å®ã¯ã 90% ã®ããã±ã¼ã¸ã¯ PyPI ã«ç´æ¥é å¸ãã¡ã¤ã«ãã¢ãããã¼ããã¦ãããããã§ãã ç¾å¨ããããã®ããã±ã¼ã¸ã§å¤é¨ã®URLã /simple ãã¼ã¸ã«è¡¨ç¤ºããªãããã«ãããã¨ããè°è«ãé²è¡ä¸ã§ãã ãããå®æ½ãããã¨å®å¿ãªã ãã§ãªããä½è¨ãªã¹ã¯ã¬ã¤ãã³ã°ãçºçããªããªã£ã¦ pip ãé«éã«ãªãã¨æããã¾ãã wktk ã§ãã èå³ã®æããã㯠Catalog-SIG ã® ML ãåç §ãã¦ãã ããã
æãããã¨ã¯ãã£ã¦ããPerlãéå»2å¹´ã§7000ãããæ°ãå¢ããã¦ãã¦ããããã ããã¾ã ã¾ã ã¢ã¯ãã£ãã§ããåããä¸è©±ã«ãªãã¾ããããã¢ãããã¼ãããã¦ããã½ã¼ã¹ã³ã¼ããèªãã§ã¢ã«ã´ãªãºã ã®åå¼·ãããã¦ããã£ããã価å¤ã®é«ãã¯å¥å¨ã§ããæ´å²ãããåãããã«ã¼ãªäººãå¤ãã¦ã¬ãã«ãé«ãã¤ã¡ã¼ã¸ã§ããã¡ãã£ã¨åã«ãã¨ã³ã¸ãã¢ãªãgithubã®ã¢ã«ã¦ã³ãã§ã½ã¼ã·ã£ã«ã³ã¼ãã£ã³ã°ã§ãã¿ãããªããºã¯ã¼ããæµè¡ã£ã¦ã¾ãããã20ä¸ç´ããsourceforge.netã®ã¢ã«ã¦ã³ãæã£ã¦ãã人ã®æ¹ãæç¶ãªã¼ã©ãæããããçãªã ããã¦ãPythonãPerlãæããã¨ã¯ããããã®ç«å ´ãã§ã«è ãããã¦ãã¾ããnode.jsã®ããã±ã¼ã¸ã®npmã§ããGoogle Trendsã§è¦ãã¨ã2010å¹´8æãããã«ã§ããã°ããããªãã¨ããã¨ããã§ããããã§ã«23300ããã1ã¶æã§ã1500ãããæ°ã伸ã°ãã¦ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}