TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Detecting Malicious Unicode

40 点作者 TangerineDream9 天前

3 条评论

rurban8 天前
I also rerported that to github some years ago and pointed them to use a library of mine to catch such confusables, libu8ident. No reaction whatsoever. Compilers and binutils didn't care neither. They don't care about strings, but even not about names.
评论 #44010070 未加载
fsflover9 天前
Qubes OS protects from such attacks by running all software in isolated VMs and not passing the unicode symbols to the host by default, <a href="https:&#x2F;&#x2F;www.qubes-os.org&#x2F;news&#x2F;2024&#x2F;07&#x2F;13&#x2F;qubes-os-4-2-2-has-been-released&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.qubes-os.org&#x2F;news&#x2F;2024&#x2F;07&#x2F;13&#x2F;qubes-os-4-2-2-has-...</a>
评论 #44004149 未加载
graemep9 天前
Surely the fact that the change is in a domain name (and the diff shows this) is a red flag?
评论 #44003645 未加载