Under the sea - Attacking vulnerable C creatures in Snakes-land

Fri, 09. Sep. 2022, 14:15 - 15:00

I'd like to share the findings from my research where I looked into python packages that wrap vulnerable C code and ship vulnerabilities to the unaware developers.
Attackers aware of such libs may abuse these components without the developers knowing and can continue to do so while completely flying under the radar.

ps - while the research was conducted mostly on the Python ecosystem, the results are correct for all ecosystems