Find Backdoor code with Hotspots or code smell

Hello @C0019956,

We did not receive a lot of requests to detect specific patterns that could be used to hide a backdoor but in principle, it should be possible to create rules to detect such patterns and raise Security Hotspots to be reviewed by a human.
In the past, we just added the detection of Bidirectional Characters to prevent trojan source attacks.

Do you have any ideas of patterns you would look for in your 20+ years old code?

Thanks
Alex

1 Like