Backdooring Rust crates for fun and profit

This page summarizes the projects mentioned and recommended in the original post on dev.to

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • black-hat-rust

    Applied offensive security with Rust - https://kerkour.com/black-hat-rust

  • It's actually possible to inspect build.rs files on docs.rs by using the source view: https://docs.rs/crate/[CRATE]/[VERSION]/source/. Thanks Joshua 🙏

  • startup

    Discontinued Life before `main()` (by thomcc)

  • Here is an example extracted from the startup crate:

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • openvscode-server

    Run upstream VS Code on a remote machine with access through a modern web browser from any device, anywhere.

  • Thirdly, using cloud developer environments such as GitHub Codespaces or Gitpod. By working in sandboxed environments for each project, one can significantly reduce the impact of a compromise.

  • docs.rs

    crates.io documentation generator

  • While it's possible to audit the code of a crate on https://docs.rs on clicking on a [src] button, it turns that I couldn't find a way to inspect build.rs files. Thus, combined with a malicious update, it's the almost perfect backdoor.

  • crates.io

    The Rust package registry

  • In Rust, packages are called crates and are (most of the time) hosted on a central repository: https://crates.io for better discoverability.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Backdooring Rust crates for fun and profit

    5 projects | dev.to | 9 Nov 2022
  • Cloudflare for Speed and Security

    2 projects | /r/CloudFlare | 20 Oct 2023
  • Show HN: I'm writing a book – Cloudflare for Speed and Security

    1 project | news.ycombinator.com | 18 Oct 2023
  • Black Hat Rust

    1 project | /r/savedForMS | 1 May 2023
  • The EU Suppressed a 300-Page Study That Found Piracy Doesn’t Harm Sales

    1 project | news.ycombinator.com | 25 Apr 2023