TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A Cryptocurrency Miner Hidden in a Favicon.ico

3 点作者 iamkeyur超过 7 年前

1 comment

gkya超过 7 年前
Preferably there would be some explanation and example code that demonstrates this. A handful of words and two screenshots don't tell much. If favicon.ico files can be interpreted as HTML files, that means that they can probably be anything random, and as they are often cached and even saved somewhere to be shown besides bookmarks, that seems to be a dangerous thing (not that I know much about security but still, why not just whitelist a couple widely-used formats?).