Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
One of the goals of this gem was to have the same syntax as the twitter gem wherever possible so that it would be easy to learn and use. Download the gem and give it a try. Also, I've put together a small demo using sinatra showing how you can use the weibo gem.
To install the gem simply enter:
gem install weibo
To see an example of how it works enter the following into your terminal:
git clone git://github.com/ballantyne/weibo-example.git cd weibo-example ruby example.rb
Most of the 新浪微博 api is implemented by this gem. If I missed something, or Sina added something, please feel free to fork it and add it yourself. I will do my best to keep the gem up to date.
This gem was made in the process of creating {叽叽喳喳.de}[http://jjzz.de], please take a moment and go and check out that project. I think that it is a very useful tool for interacting with 新浪微博.
== Sites using the Weibo gem
(Please let me know if your site is using the gem so I can list you here)
== Contributors
== Note on Patches/Pull Requests
== Special Thanks This library was based upon and is an adaptation of John Nunemaker's twitter gem. It started as the twitter gem and has been adapted in the necessary ways to make it work with t.sina.com.cn's api. I'm using it with his blessing, thanks John.
== Copyright
Copyright (c) 2010 Scott Ballantyne. See LICENSE for details.
FAQs
Unknown package
We found that weibo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.