aura icon indicating copy to clipboard operation
aura copied to clipboard

Add analyzer to report non-ascii character

Open RootLUG opened this issue 4 years ago • 0 comments

With the recent news on attacks leveraging the non-ascii characters, implement a new analyzer that would flag such characters as suspicious, namely:

  • strings containing non-ascii characters
  • variable names and attribute names containing non-ascii characters

This should be preferably configurable in a config file as it can produce a lot of false-positives or uninteresting results in some codebases, for example to turn it off/on completely as well as setting a trigger for min and max occurence of non-ascii characters

RootLUG avatar Nov 08 '21 15:11 RootLUG