Can we believe our eyes? Misleading people with Unicode.
blogs.technet.com
Can we believe our eyes? Misleading people with Unicode.
1–10 of 128 posts
Re: Can we believe our eyes? Misleading people with Unicode.
#2Re: Can we believe our eyes? Misleading people with Unicode.
#3Re: Can we believe our eyes? Misleading people with Unicode.
#4Re: Can we believe our eyes? Misleading people with Unicode.
#5I'm pretty shocked that I have never heard of the RLO unicode character before this article. Let's see if it works: ppa.emorhCelgooG => ppa.emorhCelgooG
Re: Can we believe our eyes? Misleading people with Unicode.
#6But, how does this work? Does Windows source all of the files in your %SystemRoot%\system32\drivers\etc? Why does it matter what the file is named? To hide from idiots?
Re: Can we believe our eyes? Misleading people with Unicode.
#7Re: Can we believe our eyes? Misleading people with Unicode.
#8But, how does this work? Does Windows source all of the files in your %SystemRoot%\system32\drivers\etc? Why does it matter what the file is named? To hide from idiots?
Re: Can we believe our eyes? Misleading people with Unicode.
#9But, how does this work? Does Windows source all of the files in your %SystemRoot%\system32\drivers\etc? Why does it matter what the file is named? To hide from idiots?
It seems like it would only work for hiding from people casually checking. Personally I'd open the file by typing the path myself, so I'd end up finding the trojan's file. The same would be true for any automated anti-spyware tool.
So yes, this looks like it would only affect a very limited number of people - technical enough to check the hosts file, but naive enough to do it manually and not notice the other hidden file.
Re: Can we believe our eyes? Misleading people with Unicode.
#10I guess the solution would have to be in the terminal emulator? Would a blacklist of Unicode ranges be sufficient?