# 我们使用一个基于vibecode的模糊测试工具，在FFmpeg中发现了一个除以零的漏洞

- 来源：Hacker News 热门（buzzing.cc 中文翻译）
- 作者：dclavijo
- 发布时间：2026-08-28 05:25
- AIHOT 分数：11
- AIHOT 链接：https://aihot.virxact.com/items/cmtc2agsu024jrop2c2nqqrbf
- 原文链接：https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/24290

## AI 摘要

开发者通过一个基于vibecode的模糊测试工具，在FFmpeg中发现了除以零漏洞。该工具利用Anubis的Proof-of-Work机制（类似Hashcash）应对AI公司的大规模爬取，在个体规模下额外负载可忽略，但在大规模爬取时成本显著增加。目前该方案为临时措施，后续将转向通过字体渲染等方式识别无头浏览器。

## 正文

Making sure you're not a bot!

Anubis could not load its JavaScript. The server may be overloaded. Please reload the page to try again.

You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.

Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.

Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.

Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
