# Trojan Source Code

**URL:** <https://forum.xojo.com/t/trojan-source-code/66393>\
**Category:** General\
**Created:** [November 1, 2021, 6:02pm UTC](https://forum.xojo.com/t/trojan-source-code/66393 "2021-11-01T18:02:28Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beatrix\_Willius](https://forum.xojo.com/user_avatar/forum.xojo.com/beatrix_willius/32/282_2.png) [@Beatrix\_Willius](https://forum.xojo.com/u/Beatrix_Willius)\
**Post date:** [November 1, 2021, 6:02pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/1 "2021-11-01T18:02:28Z")

</div>

Would this affect Xojo?

[https://www.lightbluetouchpaper.org/2021/11/01/trojan-source-invisible-vulnerabilities/](https://www.lightbluetouchpaper.org/2021/11/01/trojan-source-invisible-vulnerabilities/)

> **[Trojan Source Attacks](https://trojansource.codes)**
>
> Some vulnerabilities are invisible. Rather than inserting logical bugs, adversaries can attack the encoding of source code files to inject vulnerabilities.

> We have discovered ways of manipulating the encoding of source code files so that human viewers and compilers see different logic. One particularly pernicious method uses Unicode directionality override characters to display code as an anagram of its true logic. We’ve verified that this attack works against C, C++, C#, JavaScript, Java, Rust, Go, and Python, and suspect that it will work against most other modern languages.

---

<div class="post-metadata">

**Author:** ![Kem\_Tekinay](https://forum.xojo.com/user_avatar/forum.xojo.com/kem_tekinay/32/154_2.png) [@Kem\_Tekinay](https://forum.xojo.com/u/Kem_Tekinay)\
**Post date:** [November 1, 2021, 6:38pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/2 "2021-11-01T18:38:43Z")

</div>

I’d love to see an example of this.

---

<div class="post-metadata">

**Author:** ![TimStreater](https://forum.xojo.com/user_avatar/forum.xojo.com/timstreater/32/586_2.png) [@TimStreater](https://forum.xojo.com/u/TimStreater)\
**Post date:** [November 1, 2021, 6:43pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/3 "2021-11-01T18:43:44Z")

</div>

Remember the thread from a day or so ago:

‘String.Length’ Bug?

That was caused by a string with invisible unicode characters in it.

---

<div class="post-metadata">

**Author:** ![Kem\_Tekinay](https://forum.xojo.com/user_avatar/forum.xojo.com/kem_tekinay/32/154_2.png) [@Kem\_Tekinay](https://forum.xojo.com/u/Kem_Tekinay)\
**Post date:** [November 1, 2021, 6:45pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/4 "2021-11-01T18:45:13Z")

</div>

Ah, I see. So when reading an IF statement that compares values, you might think it will do one thing when it will actually drop to the ELSE clause.

---

<div class="post-metadata">

**Author:** ![anon20074439](https://forum.xojo.com/letter_avatar_proxy/v4/letter/a/ac8455/32.png) [@anon20074439](https://forum.xojo.com/u/anon20074439)\
**Post date:** [November 1, 2021, 6:47pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/5 "2021-11-01T18:47:14Z")

</div>

Just looking through the paper and trying something simple, xojo doesn’t render the unicode correctly so instead of seeing ⁧⁦abc⁩⁦def⁩⁩ (yes there is unicode in this post, `%u2067%u2066abc%u2069%u2066def%u2069%u2069`) you see abcdef which would mean you couldn’t hide the change while using the xojo ide. That being said, if the code went downstream for checking for example to a source control system that rendered it correctly, it might be overlooked and nefarious code could be let through.

---

<div class="post-metadata">

**Author:** ![TimStreater](https://forum.xojo.com/user_avatar/forum.xojo.com/timstreater/32/586_2.png) [@TimStreater](https://forum.xojo.com/u/TimStreater)\
**Post date:** [November 1, 2021, 6:50pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/6 "2021-11-01T18:50:19Z")

</div>

I just tried the example from @GarryPettet post about the `String.Length` issue. It gives 21 as Garry said. The “Clean Invisibles” command does detect those characters, which are multi-byte UTF-8 characters.

---

<div class="post-metadata">

**Author:** ![anon20074439](https://forum.xojo.com/letter_avatar_proxy/v4/letter/a/ac8455/32.png) [@anon20074439](https://forum.xojo.com/u/anon20074439)\
**Post date:** [November 1, 2021, 6:53pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/7 "2021-11-01T18:53:54Z")

</div>

You can move stuff around so it visually renders in one way but the actual code sent to the compiler reads another way, so you can fake a change and have it push into live code.

It’s really bad for bad actors that have trusted access to source in a corporation as those checking the changes over might not even know they are letting through a new zero day exploit.

---

<div class="post-metadata">

**Author:** ![anon20074439](https://forum.xojo.com/letter_avatar_proxy/v4/letter/a/ac8455/32.png) [@anon20074439](https://forum.xojo.com/u/anon20074439)\
**Post date:** [November 1, 2021, 7:07pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/8 "2021-11-01T19:07:50Z")

</div>

Copy this line into the Xojo IDE

`If accessLevel <> "user‮⁦ //check if admin⁩⁦" Then`

---

<div class="post-metadata">

**Author:** ![Tim\_Parnell](https://forum.xojo.com/user_avatar/forum.xojo.com/tim_parnell/32/161_2.png) [@Tim\_Parnell](https://forum.xojo.com/u/Tim_Parnell)\
**Post date:** [November 1, 2021, 7:10pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/9 "2021-11-01T19:10:51Z")

</div>

Hah nifty

---

<div class="post-metadata">

**Author:** ![Kem\_Tekinay](https://forum.xojo.com/user_avatar/forum.xojo.com/kem_tekinay/32/154_2.png) [@Kem\_Tekinay](https://forum.xojo.com/u/Kem_Tekinay)\
**Post date:** [November 1, 2021, 7:13pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/10 "2021-11-01T19:13:21Z")

</div>

That doesn’t look valid on casual inspection though, but still quite nifty.

---

<div class="post-metadata">

**Author:** ![anon20074439](https://forum.xojo.com/letter_avatar_proxy/v4/letter/a/ac8455/32.png) [@anon20074439](https://forum.xojo.com/u/anon20074439)\
**Post date:** [November 1, 2021, 7:14pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/11 "2021-11-01T19:14:18Z")

</div>

It’s not, its just showing the concept

---

<div class="post-metadata">

**Author:** ![anon20074439](https://forum.xojo.com/letter_avatar_proxy/v4/letter/a/ac8455/32.png) [@anon20074439](https://forum.xojo.com/u/anon20074439)\
**Post date:** [November 1, 2021, 8:39pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/12 "2021-11-01T20:39:27Z")

</div>

Here’s some valid xojo to show the problem.

```auto
Dim user as string = "user‮ ⁦ 'not admin⁩⁦"
if user="user‮ ⁦ 'not admin⁩⁦" Then
  system.DebugLog("uh oh, this was meant to be a user")
End If

```

If user was passed in, the user could now log in as `user‮ ⁦ 'not admin⁩⁦`  
and the person that checked in the change would be none the wiser.

Obviously this would show in the IDE, but might now show in the source control system.

There is also the issue of replacing ascii character with their unicode lookalikes which could allow for another function to be called

```auto
Public Sub Abс()
  system.DebugLog("Fake Abc")
End Sub

Public Sub Abc()
  system.DebugLog("Abc")
End Sub

```

Plenty of fun 😉

---

<div class="post-metadata">

**Author:** ![dave\_duke](https://forum.xojo.com/letter_avatar_proxy/v4/letter/d/c77e96/32.png) [@dave\_duke](https://forum.xojo.com/u/dave_duke)\
**Post date:** [November 5, 2021, 10:18pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/13 "2021-11-05T22:18:12Z")

</div>

I remeber many years ago finding a Trojan on the windows install cd, they were pressed in Europe, so even if your produce a good product you have to secure end to end delivery. Don’t expect hashes will help, they won’t.

---

<div class="post-metadata">

**Author:** ![Markus\_Winter](https://forum.xojo.com/user_avatar/forum.xojo.com/markus_winter/32/144_2.png) [@Markus\_Winter](https://forum.xojo.com/u/Markus_Winter)\
**Post date:** [November 6, 2021, 12:39am UTC](https://forum.xojo.com/t/trojan-source-code/66393/14 "2021-11-06T00:39:58Z")

</div>

> [@anon20074439](#):
>
> ```auto
> Dim user as string = "user<U+202E> <U+2066> 'not admin<U+2069><U+2066>"
> if user="user<U+202E> <U+2066> 'not admin<U+2069><U+2066>" Then
> system.DebugLog("uh oh, this was meant to be a user")
> End If
> 
> ```

I get

The keyword ‘Then’ is expected after this if statement’s condition

And I had to type it in as copy paste changed it round

---

<div class="post-metadata">

**Author:** ![Michel\_Bujardet](https://forum.xojo.com/user_avatar/forum.xojo.com/michel_bujardet/32/252_2.png) [@Michel\_Bujardet](https://forum.xojo.com/u/Michel_Bujardet)\
**Post date:** [November 6, 2021, 9:55am UTC](https://forum.xojo.com/t/trojan-source-code/66393/15 "2021-11-06T09:55:10Z")

</div>

> [@Beatrix\_Willius](#):
>
> One particularly pernicious method uses Unicode directionality override characters to display code as an anagram of its true logic.

It would need to be verified, but I suspect TextInputCanvas is not able to display that kind of Unicode.

---

<div class="post-metadata">

**Author:** ![GarryPettet](https://forum.xojo.com/user_avatar/forum.xojo.com/garrypettet/32/31_2.png) [@GarryPettet](https://forum.xojo.com/u/GarryPettet)\
**Post date:** [November 6, 2021, 4:13pm UTC](https://forum.xojo.com/t/trojan-source-code/66393/16 "2021-11-06T16:13:15Z")

</div>

I found another “neat” Xojo issue with non-visible characters yesterday. Turns out that you can name a property of a class with text with non-visible characters (did this by mistake, pasting the property name into the IDE). You then can’t access said property by typing it’s visible name.

---

<div class="post-metadata">

**Author:** ![Emile\_Schwarz](https://forum.xojo.com/letter_avatar_proxy/v4/letter/e/90ced4/32.png) [@Emile\_Schwarz](https://forum.xojo.com/u/Emile_Schwarz)\
**Post date:** [November 7, 2021, 10:20am UTC](https://forum.xojo.com/t/trojan-source-code/66393/17 "2021-11-07T10:20:31Z")

</div>

If you can Save As XML the project, were-you able to delete the Property ?
