What is Nostr?
daniel:// stenberg:// /
npub1cm0…enqe
2024-06-16 08:06:20
in reply to nevent1q…uut3

daniel:// stenberg:// on Nostr: closed a third. Turns out Windows sometimes do fun IDN-like unicide-to-ascii ...

closed a third. Turns out Windows sometimes do fun IDN-like unicide-to-ascii conversions for command lines that then allows users to insert unicode characters in cmdline argument when run on windows, and they are converted to their ASCII look-alike counterparts. Which can be abused to insert arguments and what not.

Not a curl security flaw. Just the weirdest Windows feature I've seen in a while. And probably a security problem in many places.
Author Public Key
npub1cm0ds9u8u42r7xeq7zwhgjcgj3p4ynv7dlj2jk4wknq8kshqzt9smpenqe