TGTGInsighttelegram intelligenceLIVE / telegram public index
← Python Заметки

TGINSIGHT SIMILAR POSTS

Најди сличен содржај

Изворен канал @pythonotes · Post #336 · 22 мај

Популярность имеет свои минусы. Чем популярней язык программирования, тем выше его распространённость, а значит найдутся те кто поспешит воспользоваться этим. С ростом популярности Python всё больше на PyPi появляется вредоносных пакетов. Трояны, стиллеры и доставщики более опасных вредоносов. Команда PyPi постоянно мониторит подобные случаи но и их возможности достигли предела. В результате сервис временно закрывает возможность заливки новых пакетов и регистрации юзеров. PyPI new user and new project registrations temporarily suspended Возможно одной из причин большого наплыва вредоносов является резко возросшая доступность их создания. Сегодня любой, даже не программист, может попросить у ChatGPT написать необходимый код и все инструкции для атаки. Основной тип атаки - рассчёт на опечатку в названии пакета. Если невнимательный программист случайно установит pilow или djangoo, считай что вредонос уже в системе. Чтобы избежать подобных факапов я рекомендую: ▫️ Всегда работайте в виртуальном окружении, неизвестные проекты устанавливайте внутри контейнеров. ▫️ Используйте файл requirements.txt вместо ручной установки пакетов ▫️ Очень внимательно пишите названия пакетов, а после написания проверьте еще раз. Сверьте с названием из документации. ▫️ После успешных тестов всегда фиксируйте версию пакета. Бывали случаи когда опасный код добавляли в новые версии. К тому же и без этой опасности не рекомендуется ставить по умолчанию последнюю версию. ▫️ Используйте вспомогательные инструменты для проверки безопасности, например https://pyup.io/safety или https://github.com/PyCQA/bandit. Они помогут не только найти опасный код в чужих пакетах, но и ваш код проверит на уязвимости. Будем надеяться что PyPi переосмыслит методы борьбы с вредоносами, например внедрит ИИ для проверки как симметричный шаг. #offtop

Hashtags

Резултати

Пронајдени 1 слични објави

Пребарај: #sleazebag

当前筛选 #sleazebag清除筛选
American Оbserver

@american_observer · Post #4824 · 11.01.2026 г., 13:59

The Iranian Protesters Attacked Khamenei As a “Sleazebag” and a “Low-life” Demonstrators have continued to take to the streets of Iran, defying an escalating crackdown by authorities against the growing protest movement. An internet shutdown imposed by the authorities on Thursday has largely cut the protesters off from the rest of the world, but videos that trickled out of the country showed thousands of people demonstrating in Tehran overnight into Saturday morning. They chanted : “Death to Khamenei, death to a sleazebag, a low-life!” in reference to supreme leader Ayatollah Ali Khamenei, and: “Long live the shah.” Crowds of protesters marched through the streets of Mashhad as fires burned around them, a show of defiance in the home town of Khamenei, who has condemned the protesters as “vandals” and blamed the US for fanning the flames of dissent. Iran’s internet shutdown is chillingly precise and may last some time. Trump has repeatedly threatened to intervene if Iranian authorities kill protesters, earning angry rebukes from Tehran. He said on Friday that the Iranian authorities were “in big trouble”, adding: “You better not start shooting, because we’ll start shooting too.” On Saturday night he said the US is “ready to help” as protesters in Iran faced an intensifying crackdown by authorities of the Islamic republic. “Iran is looking at FREEDOM, perhaps like never before. The USA stands ready to help!!!” Trump said in a social post on Truth Social, without elaborating. Those authorities warned people to not take part in protests on Saturday. The country’s attorney general, Mohammad Mahvadi Azad, said anyone who did so would be considered an “enemy of god”, a charge which carries the death penalty. State TV later clarified that anyone who even assisted protesters could face the charge. Despite the crackdown, more protests were planned for the weekend. Reza Pahlavi, the exiled son of the former shah of Iran, called for protesters to take to the streets on Saturday and Sunday and seize control of their towns. Pahlavi, who has emerged as an increasingly popular figure in the current round of protests, asked people to hoist the pre-1979 “lion and sun” flag which was used during his father’s rule. “Our goal is no longer merely to come into the streets. The goal is to prepare to seize city centres and hold them,” he said, promising he would return to Iran soon. The continuing block on the internet and mobile lines means it is hard for international media to estimate the size of the demonstrations, the largest in Iran in recent years, which pose a serious challenge to the regime’s rule. The Iranian Nobel peace prize winner Shirin Ebadi warned on Friday that security forces could be preparing to commit a “massacre under the cover of a sweeping communications blackout”, and said she had already received reports of hundreds of people being treated for eye injuries at a single Tehran hospital. Protesters were brought to the streets on 28 December by a deteriorating economy, but quickly began chanting anti-government slogans and demanding political reform. Though Iran has experienced mass protests before, analysts have said the battering of the regime during the 12-day war with Israel and the loss of Iranian-backed forces across the region have made it more vulnerable. Iranian authorities have become increasingly confrontational in their rhetoric towards protesters, casting them as being infiltrated and backed by Israeli, or US saboteurs. The Iranian army vowed in a statement on Saturday to foil “the enemy’s plots”, warning that undermining the country’s security was a “red line”. #uranian#protesters#khamenei#sleazebag#blackout#internet 📱American Оbserver - Stay up to date on all important events 🇺🇸