Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
A Cryptocurrency Miner Hidden in a Favicon.ico (twitter.com/xbs)
3 points by iamkeyur on Feb 17, 2018 | hide | past | favorite | 1 comment



Preferably there would be some explanation and example code that demonstrates this. A handful of words and two screenshots don't tell much. If favicon.ico files can be interpreted as HTML files, that means that they can probably be anything random, and as they are often cached and even saved somewhere to be shown besides bookmarks, that seems to be a dangerous thing (not that I know much about security but still, why not just whitelist a couple widely-used formats?).




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: