Thursday, September 10, 2026

The Rise of llms.txt: What Common Crawl Discovered About AI-Friendly Websites

 

The Rise of llms.txt: What Common Crawl Discovered About AI-Friendly Websites

The web is gaining a new type of file designed specifically for the age of artificial intelligence. Known as llms.txt, the proposed convention is often compared with robots.txt, but its purpose is quite different: instead of primarily telling crawlers what they can or cannot access, llms.txt is intended to provide AI systems with a cleaner guide to a website's most important information.

A recent analysis by Common Crawl offers one of the largest looks yet at how websites are actually using the format. The organization examined 584,107 llms.txt files collected during its July 2026 crawl and discovered that many websites are generating the files automatically, while some are even attempting to use them as if they were access-control files.

What Exactly Is llms.txt?

llms.txt is a proposed web convention that places a Markdown file at a website's root, such as:

https://example.com/llms.txt

The idea is relatively simple. A website can use the file to identify important pages and provide short descriptions that are easier for AI systems and agents to understand.

A typical file may contain:

# Example Website

> A short description of the website.

## Documentation

- [Getting Started](https://example.com/start)
- [API Reference](https://example.com/api)

## Guides

- [Tutorials](https://example.com/tutorials)

This makes llms.txt more like a machine-readable table of contents than a traditional crawler-control file.

The proposal has gained attention as AI-powered search engines, coding assistants and autonomous agents increasingly need efficient ways to locate useful information on websites.

Common Crawl Examined More Than Half a Million Files

The scale of the latest Common Crawl investigation is significant.

Researchers analyzed 584,107 llms.txt files from the July 2026 crawl. Their findings suggest that adoption is growing, but much of it is being driven by website platforms and plugins rather than individual developers manually creating the files.

One of the most notable findings was that approximately 68% of the files originated from plugins or templates.

Wix alone accounted for a large share of the files examined, while other SEO and website-management tools also automatically generated llms.txt content.

This means the growing number of llms.txt files does not necessarily indicate that website owners have deliberately developed an AI-content strategy.

In many cases, the file may simply have appeared because a platform enabled the feature.

Many Files Don't Contain Links

The proposed format is intended to help AI systems find useful pages through structured links. However, Common Crawl discovered that a substantial number of files contain no links.

Around 22% of the analyzed files had no links at all.

That raises an important question: how useful is an llms.txt file if it doesn't actually point an AI system toward the website's important resources?

The answer depends on how the file is constructed.

A carefully written file can function as a concise map of a website. An automatically generated or nearly empty file may provide little practical value.

Some Websites Are Treating llms.txt Like robots.txt

Perhaps the most interesting discovery involves crawler restrictions.

Some website owners appear to believe that llms.txt can be used to allow or block AI crawlers in the same way that robots.txt is used.

Common Crawl found 1,570 files that mentioned specific crawlers, including 32 that appeared to deny access to CCBot, the crawler operated by Common Crawl.

But there is an important technical distinction.

robots.txt controls crawler access

The traditional robots.txt mechanism is designed to communicate crawling rules.

For example:

User-agent: CCBot
Disallow: /

A crawler that follows the robots exclusion protocol can use this information when deciding whether to fetch content.

llms.txt does not work that way

llms.txt is intended primarily to describe and organize information for AI systems.

It does not automatically grant or deny access.

Common Crawl checked the robots.txt files associated with sites that appeared to block CCBot through llms.txt. Of the 31 sites it could evaluate, none actually blocked CCBot outright through robots.txt.

This is an important lesson for website owners: putting "AI crawler blocked" inside llms.txt does not necessarily stop a crawler.

Why robots.txt Still Matters

The two files serve different purposes.

File Main purpose
robots.txt Communicate crawler access rules
llms.txt Provide an AI-friendly content map
sitemap.xml Help crawlers discover URLs
llms-full.txt Provide a larger AI-oriented content representation

Think of the difference this way:

robots.txt = "What may you crawl?"

llms.txt = "Here is what is important on my website."

sitemap.xml = "Here are the URLs on my website."

Keeping these roles separate can prevent significant confusion.

Templates Are Driving Adoption

Another important finding is the growing role of automated tools.

Instead of website owners manually writing llms.txt, many content-management systems and plugins are producing them automatically.

Common Crawl reported that about two-thirds of the files it analyzed were generated through plugins or templates.

This helps explain why adoption numbers can vary dramatically between studies.

For example, separate research from Ahrefs found that 28% of 137,000 domains in its Web Analytics sample published a valid llms.txt file. However, that sample is more likely to contain technically sophisticated websites than the entire internet.

Other datasets produce considerably lower figures.

The takeaway is that there is currently no single universal adoption number for llms.txt.

Does llms.txt Actually Improve AI Visibility?

This is where website owners should be cautious.

Having an llms.txt file does not automatically mean that an AI system will use it.

Research has found that major AI providers have not universally committed to treating llms.txt as a standard crawler protocol.

That means publishers should not assume that adding the file will immediately result in:

  • More AI citations
  • Higher search rankings
  • More website traffic
  • Better visibility in ChatGPT
  • Better visibility in Google AI results

The technology is still developing.

However, there may still be a practical reason to create one: it is relatively inexpensive to provide a clean, structured summary of a website's most valuable content.

A Potential Benefit for Documentation Websites

llms.txt may be particularly useful for websites containing technical documentation.

Imagine a software company with hundreds of pages covering:

  • API references
  • Installation instructions
  • Tutorials
  • SDK documentation
  • Authentication
  • Troubleshooting
  • Examples

An AI coding assistant could potentially benefit from a concise file pointing toward the most authoritative documentation.

This is one reason developer-focused companies and documentation platforms have shown considerable interest in the format.

For these websites, an llms.txt file can act as a curated entry point rather than another generic SEO document.

There Is Also a Security Concern

Common Crawl discovered a small number of files containing text that appeared to be attempts at influencing an AI model.

Ten files matched its strictest prompt-injection detection test. After manual examination, researchers identified four genuine cases, while several others were false positives or examples used for research and demonstrations.

The numbers are extremely small compared with the hundreds of thousands of files analyzed.

Nevertheless, the discovery highlights an important principle:

AI systems should not automatically trust instructions contained inside an llms.txt file.

A file intended to describe website content could potentially contain malicious or misleading instructions.

AI agents therefore need to distinguish between:

  1. Information about a website
  2. Instructions directed at the AI
  3. Actual crawler permissions
  4. Potentially malicious content

This distinction becomes increasingly important as AI agents gain the ability to browse and take actions on the web.

What Website Owners Should Do

For most website owners, the safest approach is relatively straightforward.

1. Don't treat llms.txt as a replacement for robots.txt

If you want to communicate crawler restrictions, use the appropriate robots.txt mechanism.

2. Keep llms.txt useful

If you publish one, include your most important pages and documentation rather than filling it with promotional material.

3. Keep it updated

A broken or outdated content map could be worse than having no file at all.

4. Don't expect instant SEO benefits

There is currently insufficient evidence to treat llms.txt as a guaranteed ranking or traffic strategy.

5. Use clear descriptions

Short explanations can help humans and machines understand why a particular page matters.

6. Keep security in mind

AI systems should never blindly obey instructions simply because they appear inside an llms.txt file.

The Bigger Picture

The emergence of llms.txt reflects a much larger change taking place across the internet.

For decades, websites were primarily designed for humans, search engines and traditional crawlers. The rise of generative AI introduces another consumer of web information: AI agents that need to understand content rather than simply index it.

That creates a new challenge.

A traditional search engine can crawl thousands of pages and build an index. An AI agent may instead need to identify the most authoritative page, understand its context and retrieve only the information required to answer a question or complete a task.

A structured content map could eventually become useful in that environment.

But Common Crawl's research also demonstrates why adoption alone isn't enough. If websites generate thousands of low-quality files through templates, misunderstand the purpose of the format or attempt to use llms.txt as an access-control mechanism, the value of the system becomes much less clear.

Final Thoughts

The latest Common Crawl analysis provides an important reality check on the rapidly growing llms.txt conversation.

More than half a million files were examined, and the results show a format that is gaining adoption but remains inconsistent in practice. Many files are automatically generated, a significant percentage contain no links, and some websites mistakenly treat llms.txt as an alternative to robots.txt.

For now, llms.txt should be viewed as an emerging convention rather than a universal internet standard.

Its long-term importance will ultimately depend on whether AI search engines, agents and other machine-reading systems actually use the information it provides.

One thing is already clear, though: as AI becomes a major way people discover information online, websites are beginning to create new machine-readable layers specifically for AI. llms.txt may be an early experiment in what that future web looks like.

Sunday, September 6, 2026

Malicious Sites Use JavaScript to Build Malware in Browser Memory: How Browser-Based Attacks Work

 

Malicious Sites Use JavaScript to Build Malware in Browser Memory: How Browser-Based Attacks Work

The modern web is remarkably powerful. A browser can run complex applications, process graphics, communicate with servers in real time, access device capabilities, and execute millions of lines of JavaScript without requiring users to install traditional desktop software.

That flexibility is also attractive to cybercriminals.

A malicious website can abuse JavaScript and browser features to perform harmful activities while the page is open. In some attacks, malicious code can remain primarily in the browser's memory rather than appearing immediately as a conventional executable file on the computer. This has contributed to a broader category of threats often described as fileless, in-memory, or browser-based attacks.

However, an important distinction is necessary: JavaScript running inside a normal, up-to-date browser does not automatically have unrestricted access to the operating system. Modern browsers use sandboxing and security boundaries specifically to prevent websites from freely executing native malware. Successful attacks that cross those boundaries generally require additional weaknesses, such as browser vulnerabilities, malicious extensions, social engineering, or unsafe downloads.

Understanding this distinction helps explain both the danger and the limitations of browser-based malware.

What Does “Malware in Browser Memory” Mean?

Traditional malware often follows a familiar pattern.

A victim downloads a file, executes it, and the malicious program creates files, registry entries, services, or other persistent components on the system.

Browser-based attacks can follow a different path.

Instead of immediately dropping a conventional executable onto disk, malicious JavaScript may be downloaded by a webpage and executed by the browser's JavaScript engine. The code can manipulate the page, communicate with remote servers, collect information that the browser legitimately exposes, or attempt to exploit vulnerabilities.

Some malicious activity can therefore exist temporarily in RAM and browser-managed memory while the website or browser process is active.

This is one reason memory-based attacks can be difficult to investigate using techniques designed primarily to find suspicious files.

But “fileless” does not mean “invisible.”

Network connections, browser history, process activity, JavaScript resources, security logs, cached content, extension activity, and other traces may still exist.

Why JavaScript Is Attractive to Attackers

JavaScript is one of the fundamental technologies of the modern web.

Almost every major website uses it in some form. It powers:

  • Interactive websites
  • Online banking interfaces
  • Web applications
  • Video players
  • Browser games
  • Authentication systems
  • Web-based productivity tools
  • Real-time communication
  • Cloud applications

Because JavaScript is so common, security software cannot simply block JavaScript everywhere.

Attackers can exploit this ubiquity.

A malicious website may contain JavaScript designed to perform actions such as fingerprinting the browser environment, redirecting users, communicating with command-and-control infrastructure, manipulating content, or exploiting vulnerable software.

The code may also be heavily obfuscated, making its original purpose difficult to understand.

The Browser Sandbox Is the First Line of Defense

Modern browsers are designed around an important security principle: a website should not automatically be trusted with access to the user's computer.

Chrome, Edge, Firefox, Safari, and other browsers use sandboxing and permission controls to isolate webpage content from sensitive operating-system resources.

For example, ordinary JavaScript cannot simply say:

“Open the user's password database and copy everything.”

The browser should prevent such behavior.

Similarly, a webpage generally cannot arbitrarily read files from your computer without user interaction or an appropriate browser permission.

This makes modern browser-based attacks considerably more complicated than simply writing malicious JavaScript.

Attackers therefore look for ways around these boundaries.

How a Malicious Website Can Become Dangerous

A browser attack can be understood as a chain of events rather than a single piece of JavaScript.

1. The victim visits a website

The user may intentionally visit a malicious domain, click a deceptive advertisement, follow a compromised link, or be redirected from another website.

Sometimes the site looks completely legitimate.

2. The page loads JavaScript

The browser downloads JavaScript from the website or from third-party resources embedded into the page.

The script may perform ordinary functions, malicious activities, or both.

3. The script examines the environment

Some malicious websites perform browser and device fingerprinting.

They may examine information such as:

  • Browser type
  • Operating system
  • Screen characteristics
  • Language
  • Time zone
  • Available browser features
  • Rendering behavior
  • Other exposed environment information

This can help attackers decide whether a visitor is worth targeting.

4. The attack attempts to abuse available capabilities

The malicious code may exploit browser functionality, trick the user into granting permissions, abuse a vulnerable extension, or attempt to exploit a browser vulnerability.

5. Malicious activity occurs in memory

If successful, some components may execute inside browser processes or other processes without initially producing a conventional malware file on disk.

This is where the term in-memory execution becomes relevant.

Browser Vulnerabilities Change the Security Equation

The biggest difference between ordinary JavaScript and a successful browser exploit is usually the presence of a vulnerability.

Browsers contain extremely complicated components, including:

  • JavaScript engines
  • HTML parsers
  • CSS engines
  • Image decoders
  • Video codecs
  • PDF viewers
  • Graphics components
  • Networking components

Each complex component creates opportunities for programming errors.

A vulnerability may allow specially crafted webpage content to cause behavior that developers did not intend.

In severe cases, an attacker may attempt to move from normal webpage execution toward more privileged browser processes or eventually the operating system.

This is commonly described as an exploit chain.

What Is a Browser Exploit Chain?

A sophisticated browser attack may involve multiple vulnerabilities.

A simplified conceptual chain looks like this:

Malicious website → browser vulnerability → sandbox escape → operating-system access

The first vulnerability might allow an attacker to execute unintended code within a browser process.

But the browser sandbox may still contain the attacker.

Therefore, another vulnerability may be required to escape the sandbox.

This layered security model is one of the reasons modern browsers are significantly harder to compromise than older web browsers.

Fileless Malware and Browser Attacks

The term fileless malware is sometimes used broadly to describe malicious activity that avoids traditional executable files.

However, it can be misleading.

Fileless does not necessarily mean that absolutely nothing touches storage.

For example, an attack could:

  • Download scripts
  • Store data temporarily
  • Execute code in memory
  • Abuse legitimate system tools
  • Communicate with remote infrastructure
  • Leave browser caches or logs behind

The important characteristic is that the attacker attempts to minimize reliance on conventional malware files.

This can reduce the effectiveness of traditional file-scanning approaches.

Why Memory-Based Activity Can Be Difficult to Detect

Traditional antivirus software historically relied heavily on signatures and filesystem scanning.

Memory-based attacks challenge that model.

Suppose malicious code is executed dynamically and disappears when the browser process terminates.

A disk scan performed later might not find the original code.

Security teams therefore increasingly use behavioral detection.

Instead of asking only:

“Is this file malicious?”

Modern security systems can ask:

“Why is this browser behaving this way?”

For example, unusual process creation, unexpected network connections, suspicious browser extensions, exploit-like behavior, or abnormal access patterns can all become detection signals.

Obfuscated JavaScript Makes Analysis Harder

Attackers frequently hide malicious JavaScript through obfuscation.

Obfuscation changes the appearance of code without necessarily changing what it does.

A script might contain:

  • Difficult variable names
  • Encoded strings
  • Unnecessary mathematical operations
  • Dynamically constructed functions
  • Split-up strings
  • Multiple layers of encoding
  • Compressed code

The objective is to make analysis harder for humans and automated systems.

Security researchers can use JavaScript beautifiers, static analysis, browser developer tools, sandbox environments, and threat-intelligence systems to investigate suspicious code.

Malvertising: A Major Delivery Method

Users do not always visit a malicious website deliberately.

Attackers can sometimes abuse online advertising ecosystems through malvertising.

A legitimate website may display an advertisement supplied through an external advertising network. If that advertising infrastructure is compromised or abused, users could be redirected to malicious content.

This creates an interesting security problem:

The user may trust the website, while the dangerous content comes from somewhere else.

Malvertising campaigns may also use filtering to show malicious content only to particular visitors.

Drive-By Attacks

A drive-by attack traditionally refers to a situation where visiting a website can expose the visitor to malicious content without requiring an obvious download.

Modern browsers make classic drive-by compromise much harder through sandboxing, automatic updates, security restrictions, and exploit mitigations.

Nevertheless, malicious websites can still use techniques such as:

  • Fake security warnings
  • Deceptive download buttons
  • Credential phishing
  • Permission abuse
  • Malicious advertisements
  • Browser vulnerability exploitation

Consequently, users should not assume that a website is safe simply because they did not download a file manually.

Browser Cryptojacking

Another example of malicious JavaScript is cryptojacking.

A website can execute JavaScript that uses the visitor's CPU resources for cryptocurrency mining.

The result may include:

  • High CPU usage
  • Increased fan activity
  • Reduced battery life
  • Slower system performance
  • Increased power consumption

Unlike a conventional malware infection, the activity can stop when the malicious webpage is closed.

Although browser-based mining has declined from its earlier peak, the example demonstrates how JavaScript can misuse a user's computing resources without installing a traditional executable.

Web Workers and Background Processing

JavaScript can perform computational work through browser mechanisms such as Web Workers.

These features are legitimate and useful.

For example, a sophisticated web application can move expensive calculations away from the main interface so that the webpage remains responsive.

The same capabilities can potentially be abused for unwanted computation.

This illustrates an important cybersecurity principle:

A legitimate feature can become dangerous when an attacker finds a way to misuse it.

WebAssembly Adds Another Layer

Modern browsers also support WebAssembly (Wasm).

WebAssembly allows high-performance code to run inside browser environments.

It is widely used for legitimate purposes such as:

  • Gaming
  • Image processing
  • Video applications
  • Scientific computing
  • Developer tools
  • High-performance web applications

Because WebAssembly can execute efficiently, security researchers also pay attention to its potential misuse.

However, WebAssembly is not equivalent to unrestricted native code. Browser security boundaries still apply.

The danger arises when legitimate high-performance technologies are combined with vulnerabilities, deception, or other attack techniques.

The Role of Malicious Browser Extensions

Extensions deserve special attention.

A normal webpage is heavily restricted, but a browser extension can receive considerably more privileges depending on the permissions it requests.

A malicious or compromised extension may potentially access:

  • Web pages
  • Browsing information
  • Cookies
  • User-provided content
  • Network requests
  • Other browser data

The exact capabilities depend on the browser's extension architecture and permissions.

This means users should treat browser extensions almost like software installations.

Installing an extension from an unknown source can introduce risks that ordinary JavaScript on a webpage would not have.

Phishing Remains One of the Biggest Risks

Sophisticated technical attacks receive considerable attention, but attackers often achieve better results through simple deception.

A malicious website can imitate:

  • Banking portals
  • Email services
  • Social networks
  • Cloud storage
  • Online shopping websites
  • Cryptocurrency services
  • Government websites

The goal may be to convince users to voluntarily enter sensitive information.

In these cases, the JavaScript may simply support the fake interface.

The attacker does not necessarily need to exploit the browser if the user willingly provides the information.

How Security Researchers Investigate Browser-Based Threats

Professionals investigating suspicious websites commonly examine multiple layers.

Static analysis

Researchers inspect JavaScript and other webpage resources without executing them.

They look for suspicious patterns, unusual URLs, encoded content, and potentially dangerous behavior.

Dynamic analysis

The website is executed inside a controlled environment.

Researchers observe:

  • Network requests
  • Browser behavior
  • JavaScript execution
  • Process activity
  • Resource consumption
  • Unexpected redirects

Network monitoring

Security teams can examine connections made by a browser.

Unexpected communication with suspicious domains can become an important indicator.

Memory analysis

For advanced incidents, investigators may capture and analyze memory from affected processes.

This can help identify malicious code or artifacts that are not obvious on disk.

How Users Can Protect Themselves

The good news is that ordinary users can significantly reduce their exposure.

Keep the browser updated

Browser vendors regularly patch security vulnerabilities.

Enable automatic updates whenever possible.

An outdated browser can expose users to vulnerabilities that have already been publicly addressed.

Update the operating system

Browser security depends partly on operating-system security mechanisms.

Install security updates for Windows, macOS, Linux, Android, or other platforms promptly.

Be careful with extensions

Install only extensions you genuinely need.

Review permissions carefully.

Remove extensions that you no longer use.

Avoid suspicious downloads

A webpage claiming:

“Your browser is infected! Download this cleaner immediately!”

should immediately raise suspicion.

Real browser security warnings generally do not require users to install random executables from unfamiliar websites.

Use reputable security software

Modern endpoint-security products increasingly monitor behavior rather than relying exclusively on file signatures.

Keep security tools updated.

Be cautious with unexpected links

A link received through email, messaging applications, social networks, or advertisements can lead to a malicious webpage.

Check the destination before entering sensitive information.

Use strong account security

Even if attackers manage to steal a password through phishing, multi-factor authentication can provide another layer of protection.

Passkeys and hardware-backed authentication can offer even stronger resistance to many phishing scenarios.

What Website Owners Should Do

Website administrators also have an important role.

Security measures include:

  • Keeping web servers updated
  • Removing unnecessary third-party scripts
  • Monitoring JavaScript dependencies
  • Using Content Security Policy
  • Implementing appropriate security headers
  • Monitoring unexpected file changes
  • Protecting administrator accounts
  • Using HTTPS correctly
  • Reviewing advertising integrations
  • Scanning dependencies for vulnerabilities

Third-party JavaScript deserves particular attention.

A website might be secure while an external script included on the page becomes compromised.

This creates a supply-chain security problem.

Content Security Policy Can Help

Content Security Policy (CSP) allows website operators to specify which resources a webpage is permitted to load or execute.

A carefully designed CSP can reduce the impact of certain attacks, including some forms of cross-site scripting.

It is not a universal solution.

However, it can create another defensive layer between an attacker and a vulnerable application.

Why JavaScript Is Not the Enemy

It is important not to misunderstand the issue.

JavaScript itself is not malware.

It is one of the technologies that made the modern web possible.

Without JavaScript, many applications that people use every day would be significantly less capable.

The security problem comes from how code is written, delivered, and abused.

The same browser capability can power a video conferencing application or become part of a malicious campaign.

Cybersecurity is therefore less about eliminating technology and more about controlling trust, permissions, vulnerabilities, and behavior.

The Future of Browser Security

Browsers are becoming increasingly sophisticated security platforms.

Modern defenses include:

  • Sandboxing
  • Site isolation
  • Memory protections
  • Exploit mitigations
  • Permission controls
  • Automatic security updates
  • Phishing protection
  • Extension security
  • Process isolation
  • Secure coding practices

At the same time, attackers are developing more sophisticated techniques.

Artificial intelligence may also influence both sides of the security equation. Attackers can potentially use AI to generate and modify malicious code, while defenders can use AI for malware analysis, anomaly detection, threat hunting, and automated incident response.

This creates a continuing technological race.

Final Thoughts

Malicious websites can use JavaScript to perform unwanted activities inside the browser, and sophisticated attacks may attempt to execute code in memory or exploit vulnerabilities without relying immediately on conventional malware files.

However, simply visiting a page containing JavaScript does not mean that the website automatically gains unrestricted control of the computer. Modern browser sandboxing creates significant barriers, and successful compromise often requires additional vulnerabilities, permissions, deception, or user interaction.

The most effective defense is therefore layered security.

Keep browsers and operating systems updated, minimize unnecessary extensions, avoid suspicious downloads, use strong authentication, and remain cautious when websites make unexpected security claims.

For organizations, behavioral monitoring, network visibility, endpoint detection, browser isolation where appropriate, secure web development, and careful management of third-party scripts can provide additional protection.

The browser has evolved from a simple document viewer into a powerful application platform. That power brings enormous benefits—but it also creates a larger security surface. Understanding how malicious websites attempt to abuse browser memory, JavaScript, extensions, and vulnerabilities is an important step toward using the modern web more safely.

List Programs in Python: A Beginner-Friendly Guide with Examples

 

List Programs in Python: A Beginner-Friendly Guide with Examples

https://technologiesinternetz.blogspot.com


Python is known for its simple syntax and powerful built-in data structures. Among these, the list is one of the most commonly used. Whether you are storing student names, calculating marks, managing products, or processing large amounts of data, Python lists provide a flexible way to keep multiple values together.

In this guide, we will understand what a Python list is, learn the most useful list operations, and explore practical programs that beginners can try.

What Is a List in Python?

A list is a collection that can store multiple items in a single variable.

For example:

fruits = ["Apple", "Banana", "Mango", "Orange"]

print(fruits)

Output:

['Apple', 'Banana', 'Mango', 'Orange']

A Python list can contain numbers, strings, or even different types of data:

data = ["Dhanraj", 25, 85.5, True]

Lists are:

  • Ordered
  • Changeable
  • Indexed
  • Able to contain duplicate values
  • Able to store different data types

1. Creating a Simple List

The easiest way to create a list is with square brackets [].

numbers = [10, 20, 30, 40, 50]

print(numbers)

Output:

[10, 20, 30, 40, 50]

2. Accessing List Elements

Each element has an index. Python starts indexing from 0.

fruits = ["Apple", "Banana", "Mango", "Orange"]

print(fruits[0])
print(fruits[2])

Output:

Apple
Mango

The index positions are:

Apple   → 0
Banana  → 1
Mango   → 2
Orange  → 3

3. Taking List Input from the User

We can ask the user to enter several values and convert them into a list.

numbers = input("Enter numbers separated by spaces: ").split()

print(numbers)

If the user enters:

10 20 30 40

the output will be:

['10', '20', '30', '40']

If you want actual integers:

numbers = list(map(int, input("Enter numbers: ").split()))

print(numbers)

Now the values are stored as integers.

4. Adding an Element with append()

The append() method adds an item to the end of a list.

fruits = ["Apple", "Banana"]

fruits.append("Mango")

print(fruits)

Output:

['Apple', 'Banana', 'Mango']

This is one of the most frequently used list operations.

5. Adding Multiple Elements with extend()

The extend() method adds multiple items.

numbers = [1, 2, 3]

numbers.extend([4, 5, 6])

print(numbers)

Output:

[1, 2, 3, 4, 5, 6]

6. Inserting an Element

The insert() method allows us to add an item at a specific position.

fruits = ["Apple", "Mango"]

fruits.insert(1, "Banana")

print(fruits)

Output:

['Apple', 'Banana', 'Mango']

The first argument specifies the position, while the second specifies the value.

7. Removing an Element

The remove() method removes a specific value.

fruits = ["Apple", "Banana", "Mango"]

fruits.remove("Banana")

print(fruits)

Output:

['Apple', 'Mango']

Be careful: if the requested value doesn't exist, remove() raises a ValueError.

8. Removing an Element Using pop()

pop() removes an item using its index.

numbers = [10, 20, 30, 40]

removed = numbers.pop(1)

print("Removed:", removed)
print(numbers)

Output:

Removed: 20
[10, 30, 40]

Calling pop() without an index removes the last element.

9. Finding the Length of a List

The len() function tells us how many elements a list contains.

students = ["Amit", "Riya", "Rahul", "Sneha"]

print(len(students))

Output:

4

10. Finding the Largest and Smallest Number

Python provides max() and min() for numerical lists.

numbers = [25, 10, 75, 40, 5]

print("Largest:", max(numbers))
print("Smallest:", min(numbers))

Output:

Largest: 75
Smallest: 5

11. Calculating the Sum of List Elements

The sum() function calculates the total.

numbers = [10, 20, 30, 40]

total = sum(numbers)

print("Total:", total)

Output:

Total: 100

This is particularly useful when working with marks, expenses, sales figures, or other numerical data.

12. Sorting a List

The sort() method arranges list elements.

numbers = [50, 10, 40, 20, 30]

numbers.sort()

print(numbers)

Output:

[10, 20, 30, 40, 50]

For descending order:

numbers.sort(reverse=True)

print(numbers)

Output:

[50, 40, 30, 20, 10]

13. Reversing a List

Use reverse() to reverse the existing list.

numbers = [1, 2, 3, 4, 5]

numbers.reverse()

print(numbers)

Output:

[5, 4, 3, 2, 1]

14. Checking Whether an Item Exists

The in operator can determine whether a value exists in a list.

fruits = ["Apple", "Banana", "Mango"]

if "Mango" in fruits:
    print("Mango is available")
else:
    print("Mango is not available")

Output:

Mango is available

This is useful for searching lists.

15. Counting Duplicate Values

The count() method tells us how many times a value occurs.

numbers = [10, 20, 10, 30, 10, 40]

print(numbers.count(10))

Output:

3

16. Finding the Position of an Element

The index() method returns the position of the first matching element.

fruits = ["Apple", "Banana", "Mango"]

print(fruits.index("Mango"))

Output:

2

17. List Slicing

List slicing allows us to extract a portion of a list.

numbers = [10, 20, 30, 40, 50]

print(numbers[1:4])

Output:

[20, 30, 40]

The general syntax is:

list[start:stop]

The stop position is not included.

18. Using a for Loop with a List

Loops make it easy to process every item.

fruits = ["Apple", "Banana", "Mango"]

for fruit in fruits:
    print(fruit)

Output:

Apple
Banana
Mango

This technique is extremely common in Python programming.

19. Program to Find Even Numbers

Here's a practical list program that extracts even numbers.

numbers = [10, 15, 22, 31, 40, 55]

even_numbers = []

for number in numbers:
    if number % 2 == 0:
        even_numbers.append(number)

print("Even numbers:", even_numbers)

Output:

Even numbers: [10, 22, 40]

20. Program to Calculate the Average

We can calculate the average of numbers stored in a list.

marks = [75, 82, 68, 90, 85]

average = sum(marks) / len(marks)

print("Average marks:", average)

Output:

Average marks: 80.0

21. Removing Duplicate Values

A simple way to remove duplicates is to use set().

numbers = [10, 20, 10, 30, 20, 40]

unique_numbers = list(set(numbers))

print(unique_numbers)

However, converting to a set does not guarantee preservation of the original order in the general case.

If maintaining order matters, a useful approach is:

numbers = [10, 20, 10, 30, 20, 40]

unique_numbers = list(dict.fromkeys(numbers))

print(unique_numbers)

Output:

[10, 20, 30, 40]

22. List Comprehension

Python provides a concise way to create lists called list comprehension.

For example:

numbers = [1, 2, 3, 4, 5]

squares = [number ** 2 for number in numbers]

print(squares)

Output:

[1, 4, 9, 16, 25]

A list comprehension can make many simple list-processing operations shorter and easier to read.

A Small Real-World List Project

Let's create a simple shopping-list program.

shopping_list = []

while True:
    item = input("Enter an item (or type 'done' to finish): ")

    if item.lower() == "done":
        break

    shopping_list.append(item)

print("\nYour Shopping List:")

for item in shopping_list:
    print("-", item)

The user can continuously enter products until typing done.

Common Python List Methods

Method Purpose
append() Adds an item at the end
extend() Adds multiple items
insert() Adds an item at a specific position
remove() Removes a specified value
pop() Removes an item by position
clear() Removes all items
sort() Sorts the list
reverse() Reverses the list
count() Counts occurrences
index() Finds an item's position
copy() Creates a shallow copy

Why Are Lists Important in Python?

Lists are used everywhere in Python programming. They can represent:

  • Student records
  • Product inventories
  • Shopping items
  • Employee names
  • Examination marks
  • Sensor readings
  • Financial transactions
  • Search results
  • API responses
  • Collections of files

They are also frequently used together with loops, functions, dictionaries, classes, NumPy, Pandas, and other Python technologies.

Conclusion

Python lists are one of the first data structures beginners should master. Their straightforward syntax makes it easy to store, access, modify, search, and process collections of data.

Start with simple operations such as append(), remove(), sort(), and len(). Once you are comfortable with these, move on to loops, slicing, list comprehensions, and small projects.

A good way to learn is to experiment with your own examples. Try creating a student marks program, shopping-list application, expense tracker, or contact manager using Python lists. These small projects can turn basic syntax into practical programming skills.

How to Generate an OTP Using Python: A Simple Beginner-Friendly Guide

 

How to Generate an OTP Using Python: A Simple Beginner-Friendly Guide

One-Time Passwords, commonly called OTPs, have become a familiar part of modern digital life. Whether you are logging into an account, confirming a transaction, resetting a password, or verifying a phone number, an OTP provides an additional layer of security.

Python makes it surprisingly easy to create a basic OTP generator. In this tutorial, we will build one from scratch and understand how the code works.

What Is an OTP?

An OTP is a temporary password that is generally valid for only one authentication attempt or for a short period.

A typical OTP might look like:

583214

Unlike a permanent password, an OTP is designed to be short-lived. This makes it useful for identity verification and multi-factor authentication.

There are several types of OTPs, including:

  • Numeric OTPs — such as 583214
  • Alphanumeric OTPs — such as A7K92P
  • Time-based OTPs (TOTP) — codes that change automatically after a fixed interval
  • Event-based OTPs (HOTP) — codes generated based on an event or counter

For learning purposes, let's start with a simple six-digit numeric OTP.

Why Use Python for OTP Generation?

Python includes a number of useful modules for generating random values.

For security-sensitive applications, the secrets module is particularly important. Unlike ordinary pseudo-random functions intended for simulations or general programming, secrets is designed for generating values suitable for security-related purposes.

We can therefore create an OTP generator with only a few lines of code.

Method 1: Generate a Six-Digit OTP

Here is a simple example:

import secrets

otp = ''.join(str(secrets.randbelow(10)) for _ in range(6))

print("Your OTP is:", otp)

Example output

Your OTP is: 583214

Every time you run the program, a different OTP should normally be produced.

Understanding the Code

Let's break it down.

Import the secrets module

import secrets

The secrets module provides functions for generating cryptographically stronger random values.

Generate a random digit

secrets.randbelow(10)

This produces a random integer from 0 through 9.

For example:

7

Generate six digits

for _ in range(6)

This repeats the operation six times.

Convert the digits to strings

str(secrets.randbelow(10))

The generated number is converted into text so that the digits can be joined together.

Join everything together

''.join(...)

This combines the six individual digits into a single OTP.

Method 2: Using secrets.choice()

Another clean approach is to create a collection of digits and randomly select from it.

import secrets
import string

digits = string.digits

otp = ''.join(secrets.choice(digits) for _ in range(6))

print("Generated OTP:", otp)

Here, string.digits contains:

0123456789

The program randomly selects six digits from that collection.

Creating an OTP Generator Function

Instead of writing the code repeatedly, we can put it inside a function.

import secrets

def generate_otp(length=6):
    return ''.join(str(secrets.randbelow(10)) for _ in range(length))

otp = generate_otp()

print("Your OTP is:", otp)

The advantage is that we can easily change the OTP length.

For example:

print(generate_otp(4))
print(generate_otp(6))
print(generate_otp(8))

Possible output:

4821
735914
19384726

Building a Simple OTP Verification System

Generating an OTP is only one part of authentication. We also need to verify whether the user entered the correct code.

Here's a simple example:

import secrets

def generate_otp():
    return ''.join(str(secrets.randbelow(10)) for _ in range(6))

otp = generate_otp()

print("OTP generated successfully.")

user_input = input("Enter the OTP: ")

if user_input == otp:
    print("OTP verified successfully!")
else:
    print("Invalid OTP.")

The program generates an OTP and asks the user to enter it.

If the entered value matches the generated value, verification succeeds.

Adding an Expiration Time

Real-world OTP systems generally don't allow a code to remain valid forever.

We can demonstrate expiration using Python's time module.

import secrets
import time

otp = ''.join(str(secrets.randbelow(10)) for _ in range(6))

created_at = time.time()

print("Your OTP is:", otp)

user_input = input("Enter OTP: ")

if time.time() - created_at > 30:
    print("OTP expired.")
elif user_input == otp:
    print("OTP verified successfully!")
else:
    print("Invalid OTP.")

In this example, the OTP is considered valid for 30 seconds.

This is only a demonstration. Production authentication systems require additional safeguards.

Creating a Complete Mini OTP Program

We can combine generation, expiration, and verification into a small application.

import secrets
import time

def generate_otp():
    return ''.join(str(secrets.randbelow(10)) for _ in range(6))

otp = generate_otp()
created_at = time.time()

print("OTP generated successfully.")
print("For demonstration:", otp)

user_input = input("Enter your OTP: ")

if time.time() - created_at > 30:
    print("The OTP has expired.")
elif secrets.compare_digest(user_input, otp):
    print("OTP verification successful.")
else:
    print("Incorrect OTP.")

secrets.compare_digest() can be useful when comparing security-sensitive strings because it is designed to reduce timing-attack risks.

Generating an Alphanumeric OTP

Sometimes an OTP doesn't have to contain only numbers.

We can create an alphanumeric code like:

K7P2XA

Example:

import secrets
import string

characters = string.ascii_uppercase + string.digits

otp = ''.join(secrets.choice(characters) for _ in range(6))

print("Your OTP is:", otp)

Possible output:

Your OTP is: Q8M2KP

random vs secrets in Python

Beginners often encounter the random module and may wonder why we use secrets for OTPs.

For example:

import random

otp = random.randint(100000, 999999)

This can be useful for demonstrations and non-security-related applications, but authentication codes should generally use a security-oriented random source.

For OTP generation, prefer:

import secrets

rather than relying on:

import random

The distinction is important because security systems need unpredictable values.

Important Security Considerations

A simple Python OTP generator is excellent for learning, but a real authentication system needs considerably more protection.

1. Don't print OTPs in production

The examples above print the OTP to the terminal for demonstration.

A real application would normally deliver the OTP through an appropriate verification channel instead.

2. Set an expiration time

An OTP should normally have a limited lifetime.

3. Limit verification attempts

An attacker should not be able to try thousands of codes against an account.

4. Avoid storing OTPs unnecessarily

If an application needs to store OTP-related information, it should use an appropriate secure design rather than keeping sensitive values in plain text indefinitely.

5. Protect the delivery mechanism

Sending an OTP through an insecure channel can undermine the security of the entire system.

6. Don't use predictable codes

Avoid algorithms such as:

otp = "123456"

or codes derived from predictable information such as birthdays.

Where Can Python OTPs Be Used?

OTP systems can be incorporated into many applications, including:

  • User registration
  • Login verification
  • Password recovery
  • Email verification
  • Mobile-number verification
  • Transaction confirmation
  • Account recovery
  • Multi-factor authentication
  • Temporary access codes

Python frameworks such as Django, Flask, and FastAPI can be used to integrate OTP functionality into larger web applications.

Final Thoughts

Generating an OTP with Python is a small project that teaches several useful programming concepts, including functions, loops, random generation, string manipulation, user input, and time-based validation.

For a basic project, Python's secrets module provides a straightforward way to generate unpredictable OTP values:

import secrets

otp = ''.join(str(secrets.randbelow(10)) for _ in range(6))

print(otp)

The important lesson is that generating an OTP and building a secure OTP authentication system are two different things. A production application also needs expiration, rate limiting, secure storage practices, protected delivery, monitoring, and careful handling of authentication attempts.

For beginners, however, an OTP generator is an excellent Python project—and a natural stepping stone toward building more sophisticated authentication systems.

Organize Your Files Automatically with Python

  Organize Your Files Automatically with Python A messy downloads folder can become surprisingly difficult to manage. Images, PDFs, documen...