Microsoft backward compatibility helpfulness helps hackers

https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/

Easy-to-read explanation of how ‘just-trying-to-be-helpful’ Best-Fit Unicode equivalents in MS code pages are an attack surface for injection of naughty characters in code-page-handling apps.

Eg, Yen (¥), and Won (₩) map to ‘\’ on JK code pages.

(" U+FF02) maps to ‘“’.

The map of (√π⁷≤∞) to ‘vp7=8’ makes sense, is nice, but what were they thinking!?

Me at

Back to HomePage