Anguish: Invisible Programming Language and Invisible Data Theft
blogs.perl.org
blogs.perl.org
I think Unicode Emoji were a great step forward but we must redouble our efforts.
This is actually related to something I'm working on at the moment and it cleared up a few misconceptions. So thanks for the link :-)
exp="\u2060|\u200b|\u2061|\u2062|\u2063|\u200c|\u200d"
git log -p --pickaxe-regex -S"$exp"Spaces, tabs, and newlines can be used to alter code in invisible way.
=print
=function()
for =1,5 do
()
end
end
((()))For example:
print("")
This is benign, but that's not an empty string. The string contains a bunch of U+200e and U+200f characters, even though it appears empty. It proves that you can have strings with invisible characters in them.Since we have two types of invisible characters, U+200e and U+200f, we can use those as binary digits -- 1 and 0. Thus, we can write a function that takes an invisible string as input, and returns a normal string as output.
So, what kind of string could we feed it? One possibility would be to convert something like "echo 'command-line injection'" into an invisible string. We'd pass that into our decoder function, and pass the result into os.execute. Since the conversion function mentioned above can be identified with an invisible variable name, it would look similar to this:
os.execute((""))
That looks very suspicious, but we can do better. In Lua, you can index into tables with strings. And we have a function which can take invisible strings and produce normal strings.The final PoC could look similar to this:
_G[(""))][(""))](("")))
That's non-working code, as I haven't put this together. But the idea is to convert the following (working) code into invisible strings: _G["os"]["execute"]("echo 'command-line injection'")
Making this work is left as an exercise for the reader. :)Another interesting approach would be to iterate through the "os" table a fixed number of times, until reaching the "execute" key. The iteration order isn't guaranteed, but given a certain version of LuaJIT, I think it's stable. That means you'd be able to do the equivalent of "os.execute" while making it look like you're "counting to 5."
* https://git-blame.blogspot.com.es/2014/12/git-1856-195-205-2...
'I passed the Turing test. No one believed me. Honest.'
passes Turing test by sounding like a petulant child
Revision: I believe I misinterpreted the intention of your post, instead wanting to expose tricks like these. I'd be fine with this.
Why try to obfuscate programs in base64-encoded strings when you have it invisibly lying around in plain light.
alert(String.fromCharCode.apply(null,String.fromCharCode.apply(null,"".split("").map(function(c){return(c.charCodeAt(0)>>2)^2098})).match(/.{8}/g).map(function(c){return parseInt(c,2)})))In other words, the programs are quines if and only if they aren't.
Androids dream of quined Anguish.
https://gist.github.com/Freaky/51086f3c97784bdd6dfbd31913cd1...
You don't need to use define_method, it just makes it more obvious what's going on.
As a random example:
titan:~ geofft$ python3 -c "$(printf "\u2063") = 1"
File "<string>", line 1
= 1
^
SyntaxError: invalid character in identifier
If you change it to e.g. 00e9 ("é"), Python 3 permits the character, so it's not just a lower-ASCII thing.And the BEL character, while non-spacing and invisible, is sometimes audible.
The language is just a cute transliteration of brainfuck to use invisible zero width characters.
Anyone who uses 'lede' correctly gets express treatment here...
is that a hint of weariness? :3