miniblog.
← Back to all posts
Wilfred Hughes
Nov 11, 2021 at 06:43
Unicode attacks creating invisible variables in JS:
https://certitude.consulting/blog/en/invisible-backdoor/
Unicode in string literals or comments seems worthwhile, but non-ASCII in variable names seems fraught.
The Invisible JavaScript Backdoor – Certitude Blog