ZCode 开源后,开发者又从代码里发现一个安全问题。
This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.
ZCode 开源后,开发者又从代码里发现一个安全问题。 ZCode 会把用户的登录凭据加密保存在本地,但默认情况下,解密密钥可以根据操作系统、用户名和用户目录直接算出来。 这些信息通常并不难获得。攻击者一旦拿到 ZCode 保存凭据的文件,就可以按照公开源码重新生成密钥,不需要破解加密算法。 ZCode 官方文档称这些登录凭据「按设备加密,换机后无法解密」。但公开源码里的默认方案并没有使用设备 ID 或硬件信息。官方说法和开源代码对不上。 不过,这不是一个可以远程凭空盗取凭据的漏洞。攻击者仍需先拿到本地凭据文件;用户如果自行设置了 ZCODE_CREDENTIAL_SECRET,也不会走上述默认密钥。 文件一旦泄露,最多可能导致登录态被冒用、Coding Plan 额度被消耗,但不会导致电脑被黑。
Posted by 思维怪怪 (7.9k followers) 1 days ago · 26 likes · 5.6k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Gist.
More dev work like this
- 🚨SlowMist TI Alert🚨 — @SlowMist_Team
- Yep — @thorstenball
- 🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨 — @SlowMist_Team
- AI Agent 会写代码、会搜资料,但遇到真实安全事件,很多时候还是不知道该从哪里下手。 — @bkdgiffug
- Here's an API security question I wish every developer would ask: — @shehackspurple
- Theorem co-founder @diagram_chaser reveals the one-line change that took verifying… — @MTSlive
- 80–90% of modern applications rely on open-source code you didn't write - making… — @jfrog
- One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. — @shehackspurple
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 09:16 UTC. Full method.