Skip to main content

Invisible Backdoor Detector

Invisible Backdoor Detector is a little Python script that allows you to spot and remove Bidi characters that could lead to an invisible backdoor. If you don't know what that is you should check the related paragraph.

Table of Contents

What is an Invisbile Backdoor

An Invisible Backdoor is exactly what you think: a backdoor that you cannot see! It was described by Wolfgang Ettlinger at Certitude in this blog post. It leverages the presence of Unicode characters (Bidi characters) which behaves like normal spaces. In conjunction with the Javascript object destructuring those characters may allow an attacker to introduce a backdoor into an open-source project without anyone noticing it. Check out the blog post for more info.

Install

You can easily install it by running:

pip install invisible-backdoor-detector

Usage

invisible-backdoor-detector -h
 Usage: invisible-backdoor-detector [OPTIONS] PATH                                                                          
                                                                                                                            
╭─ Arguments ──────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ *    path      TEXT  Path of the folder to check [default: None] [required]                                              │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ --remove  -r        Remove the Bidi characters found                                                                     │
│ --help    -h        Show this message and exit.                                                                          │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯

Example

The example folder provides a working example of an invisible backdoor in Node.js, you may test the script on that folder. If you want to try out the backdoor you can add the following parameter to the query string:

%E3%85%A4=<any command>

Contributions

Everyone is invited to contribute! If you are a user of the tool and have a suggestion for a new feature or a bug to report, please do so through the issue tracker.

Credits

Developed by Angelo Delicato @SecSI

License

invisible-backdoor-detector is released under the MIT LICENSE

Release files for invisible-backdoor-detector 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for invisible-backdoor-detector 0.1.0
File Size Uploaded
invisible_backdoor_detector-0.1.0.tar.gz 5.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for invisible-backdoor-detector 0.1.0
File Interpreter ABI Platform
invisible_backdoor_detector-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 10.9 kB

Release files / invisible_backdoor_detector-0.1.0.tar.gz

Download URL invisible_backdoor_detector-0.1.0.tar.gz
Size 5.0 kB
Tags Source
SHA-256 checksum
How to use checksums
2887d101f678587b91013f6d4f8ed92126b38fc91ad9a21ced92f295ad7f6556
BLAKE2b-256 checksum
How to use checksums
914203b696af6ab072aed4afe5a1e46972d91e36bc328a53dab0b3ec3b5650ee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.1 CPython/3.11.0

Release files / invisible_backdoor_detector-0.1.0-py3-none-any.whl

Download URL invisible_backdoor_detector-0.1.0-py3-none-any.whl
Size 5.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
22037fa7e229c3ac73ab91dc148eeef3d209bee994302041e770a9718d4e9c2c
BLAKE2b-256 checksum
How to use checksums
d7d45f20646032a999cd34dc6afc302147d836d05c056d2a82ab2565a8cb201e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.1 CPython/3.11.0

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page