Gea-Suan Lin<p>TAWPA (台灣公益揭弊暨吹哨者保護協會) 網站被植入木馬</p><p>新聞的部分應該蠻好搜的,這邊抓個中央社的:「揭弊者協會網站疑有惡意程式 黃國昌:沒有資安外洩」。 網站現在已經離線了,但 Internet Archive 上的資訊已經足夠判斷,看起來至少首頁就被植了? 從 <a href="https://web.archive.org/web/*/https://www.tawpa.org/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">web.archive.org/web/*/https://</span><span class="invisible">www.tawpa.org/</span></a> 可以看到首頁上最近的兩筆是這兩個 archive (以寫這篇的當下): 20250313220309 (2025/03/13) 20241206095011 (2024/12/06) 直接翻網頁 html 比較可以看到 3041 行以前的結構都一樣,但今…</p><p><a href="https://blog.gslin.org/archives/2025/03/19/12310/tawpa-%e5%8f%b0%e7%81%a3%e5%85%ac%e7%9b%8a%e6%8f%ad%e5%bc%8a%e6%9a%a8%e5%90%b9%e5%93%a8%e8%80%85%e4%bf%9d%e8%ad%b7%e5%8d%94%e6%9c%83-%e7%b6%b2%e7%ab%99%e8%a2%ab%e6%a4%8d%e5%85%a5%e6%9c%a8%e9%a6%ac/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.gslin.org/archives/2025/0</span><span class="invisible">3/19/12310/tawpa-%e5%8f%b0%e7%81%a3%e5%85%ac%e7%9b%8a%e6%8f%ad%e5%bc%8a%e6%9a%a8%e5%90%b9%e5%93%a8%e8%80%85%e4%bf%9d%e8%ad%b7%e5%8d%94%e6%9c%83-%e7%b6%b2%e7%ab%99%e8%a2%ab%e6%a4%8d%e5%85%a5%e6%9c%a8%e9%a6%ac/</span></a></p><p><a href="https://abpe.org/tags/attack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>attack</span></a> <a href="https://abpe.org/tags/fingerprint" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fingerprint</span></a> <a href="https://abpe.org/tags/fingerprintjs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fingerprintjs</span></a> <a href="https://abpe.org/tags/homepage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homepage</span></a> <a href="https://abpe.org/tags/html" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>html</span></a> <a href="https://abpe.org/tags/javascript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>javascript</span></a> <a href="https://abpe.org/tags/js" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>js</span></a> <a href="https://abpe.org/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://abpe.org/tags/recaptcha" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>recaptcha</span></a> <a href="https://abpe.org/tags/script" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>script</span></a> <a href="https://abpe.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://abpe.org/tags/tawpa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tawpa</span></a> <a href="https://abpe.org/tags/webpage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webpage</span></a></p>