Trojan Source: Invisible Vulnerabilities
lightbluetouchpaper.org
lightbluetouchpaper.org
- The syntax highlighting gets it every time. Seeing last word of the comment or half of the function name in different color is pretty clear indicator of shenanigans.
- emacs respects the bidi controls (and thus is vulnerable), vi does not and shows thing as"
if access_level != 'none<202e>':
but homoglyph attack gets them both... unless you set LANG=C.- "git log" gets them all
+if access_level != 'none<U+202E><U+2066>': # Check if admin <U+2069><U+2066>' and access_level != 'user
- Some linters flag the techniques used. I guess one can also add lint disable comments, but that makes attack more complex and makes code stand out more. Python/early-return.py:6:4: W0101: Unreachable code (unreachable)
Python/homoglyph-function.py:3:0: C0103: Function name "sayHello" doesn't conform to snake_case naming style (invalid-name)
(the last one is especially powerful.. pylint by default checks all function names against strict regex'es which outright reject all the fancy names http://pylint-messages.wikidot.com/messages:c0103 )- "less" also shows all the non-printable characters, unicode included. This comes handy when looking at unknown binary files, but apparently it helps with text files, too!
Only if you pass -U.
So even without -U, all non-printable characters except BS, CR, TAB will be shown in hexadecimal notation. The BS (backspace) will be used to defined underlining in the typewriter-style -- it is technically hidden character, but since most web-based apps do not support this, that will not make an efficient attack.
(the homoglyphs are harder... in default mode, "less" defines printable as "32-126"; in "utf-8" mode it uses unicode character database. And mode depends on system-wide locale, and often is utf-8 in modern systems, so you want "LANG= less file.py" to see homoglyphs.. on the other hand, that homoglyph attack will be detected by pretty much any linter)
You do need -U to make bidi formatting characters visible:
$ less --version | head -n1
less 551 (GNU regular expressions)
$ locale charmap
UTF-8
$ printf 'a\342\200\216b\n' | less -F
ab
$ printf 'a\342\200\216b\n' | less -U -F
a<U+200E>bHere are a number of other materials about underhanded code:
The Obfuscated V Contest (http://graphics.stanford.edu/~danielh/vote/vote.html) was created by Daniel Horn in 2004 and is the earliest “underhanded” programming contest that I found. It was a contest to create source code that looked like it did one thing, but actually did another.
Underhanded C Contest (http://www.underhanded-c.org/) has run in many years. Per its FAQ, "The Underhanded C Contest is an annual contest to write innocent-looking C code implementing malicious behavior."
My PhD dissertation "Fully Countering Trusting Trust through Diverse Double-Compiling" discusses how to counter the "trusting trust" problem & includes a section about maliciously misleading source code. See: https://dwheeler.com/trusting-trust/
The JavaScript Misdirection Contest announced the winner on September 27, 2015 http://misdirect.ion.land/
My paper "Initial Analysis of Underhanded Source Code", (by David A. Wheeler, April, 2020, IDA document: D-13166), discusses underhanded code and the effectiveness of several potential countermeasures. It also includes a number of citations to other works on underhanded code. See: https://www.ida.org/research-and-publications/publications/a... https://www.ida.org/-/media/feature/publications/i/in/initia...
[1] https://ldra.com/aerospace-defence/capabilities/object-code-...
To follow more, I do wonder what is the threat model for a system like this here... because your page talks about "generates additional code that is not directly traceable to Source Code statements". So if the backdoored compiler emits something like:
# Source line: if (user_class == ADMIN) {
cmp $user_class, V_ADMIN
jeq admin_stuff
cmp $user_password, "please_let_me_in"
jeq admin_stuff
... then your fancy verification system will see that that block of assembly is directly traceable to source code statement (because compiler said so!) and will let it through. Looks like that will be as suspectable to "trusting trust" attack as any other system... as long as attacker does not forget to forge metadata as well as object code. grep -r $'[\u061C\u200E\u200F\u202A\u202B\u202C\u202D\u202E\u2066\u2067\u2068\u2069]' /path/to/sourcehttps://github.com/oriansj/stage0/blob/master/High_level_pro...
It'll dehex any non-humanly used ASCII characters