Monthly Archives: November 2008

Unicode attacks and test cases – Visual Spoofing, IDN homograph attacks, and the Confusables

Let’s face it, playing tricks that mess with people’s perception can be fun.  With Unicode, there’s lots of fun tricks to be had.  What’s to stop someone from believing the following is what it appears to be: www.аmazon.com Looks like … Continue reading

Posted in Unicode, security | Tagged , , , | 6 Comments

Advisory: Adobe Air 1.1 JavaScript execution security vulnerability

Adobe released a patch and bulletin for an issue I reported back in May.  The issue is really in WebKit, and many products seem to be affected. A vulnerability has been identified in Adobe AIR 1.1 and earlier that could … Continue reading

Posted in JavaScript, Unicode, advisory, cross site scripting, testing | Tagged , , | Leave a comment