From 582fa970a39d8aa5abbed714371f57a8aa3a4dbc Mon Sep 17 00:00:00 2001 From: feng Date: Mon, 6 Apr 2026 08:02:40 +0800 Subject: [PATCH] fix: anonymize researcher reference per issue #10 request MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Remove named references to cxxsheng across 4 locations in index.html, replacing with anonymous attribution ("独立安全研究者" / "An independent security researcher"). Respects contributor's request to not be cited. Closes #10 Co-Authored-By: Claude --- index.html | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/index.html b/index.html index 3718943..49445ed 100644 --- a/index.html +++ b/index.html @@ -2565,7 +2565,7 @@ Language/zh-Hant Region/CN
  • 支付宝的预填是攻击者通过 URL 参数指定收款账号和金额 — 性质完全不同
  • 结合 UI 欺骗能力(setTitle/showToast),攻击者可以伪造合法转账理由,降低用户警惕
  • -

    参与讨论的 cxxsheng 独立编写了 PoC,结论:「还是认为这个功能是漏洞,但是危害性会低一些」。他还引用了 CVE-2024-40676(Android 先例):减少用户交互步骤本身可以构成漏洞。

    +

    一位参与讨论的独立安全研究者编写了 PoC,结论:「还是认为这个功能是漏洞,但是危害性会低一些」。该研究者还引用了 CVE-2024-40676(Android 先例):减少用户交互步骤本身可以构成漏洞。

    Source: GitHub Issue #4 (sevck, rama2910****10)

    @@ -2576,7 +2576,7 @@ Language/zh-Hant Region/CN
  • Alipay's pre-fill is specified by the attacker via URL parameters for recipient account and amount — fundamentally different
  • Combined with UI spoofing (setTitle/showToast), attackers can fabricate legitimate-looking transfer reasons, reducing user vigilance
  • -

    cxxsheng independently wrote a PoC and concluded: "I still consider this a vulnerability, but with lower severity." He also cited CVE-2024-40676 (Android precedent): reducing user interaction steps itself can constitute a vulnerability.

    +

    An independent security researcher wrote a PoC and concluded: "I still consider this a vulnerability, but with lower severity." The researcher also cited CVE-2024-40676 (Android precedent): reducing user interaction steps itself can constitute a vulnerability.

    @@ -2667,7 +2667,7 @@ Language/zh-Hant Region/CN
  • PDPC 新加坡 — 启动正式数据保护调查 (#006****24)
  • CIRCL 卢森堡 CERT — 事件处理人员主动代为联系 Alibaba SRC
  • HKMA 香港金管局 — 立案调查 (Case CE2026****5412)
  • -
  • cxxsheng(GitHub 安全研究者)— 独立编写 PoC 后确认漏洞存在
  • +
  • 独立安全研究者(GitHub)— 独立编写 PoC 后确认漏洞存在
  • freshnn(GitHub 用户)— 独立确认 Android 无感 GPS 复现成功
  • @@ -2682,7 +2682,7 @@ Language/zh-Hant Region/CN
  • PDPC Singapore — Formal data protection investigation (#006****24)
  • CIRCL Luxembourg CERT — Incident handler proactively contacted Alibaba SRC on our behalf
  • HKMA Hong Kong — Case filed (CE2026****5412)
  • -
  • cxxsheng (GitHub researcher) — Independently wrote PoC and confirmed vulnerability exists
  • +
  • Independent researcher (GitHub) — Independently wrote PoC and confirmed vulnerability exists
  • freshnn (GitHub user) — Independently confirmed silent GPS reproduction on Android
  • @@ -2864,7 +2864,8 @@ if (saved === 'zh') setLang('zh'); GitHub · Zenodo · IACR · -Packet Storm +Packet Storm · +Mastodon