-
Archives
- November 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- September 2007
- April 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- April 2006
- August 2005
- April 2005
- March 2005
- March 2004
-
Meta
Monthly Archives: March 2009
Advisory: Lenovo/IBM ActiveX buffer overflow
CERT released the advisory for this, which I believe is not being fixed by Lenovo/IBM. http://www.kb.cert.org/vuls/id/340420 This ActiveX control comes preinstalled on many Lenovo systems, and is also downloaded from the main page of their support site. It’s a nasty … Continue reading
Detecting ill-formed UTF-8 byte sequences in HTML content
One issue I’ve come across, pretty infrequently, is the existence of ill-formed UTF-8 byte sequences in HTML content. As far as I can tell nobody’s every really tried to find this type of bug. Huh, so what’s up? UTF-8 is … Continue reading
Watcher: a free web-app security vulnerability scanner
I announced Watcher at CanSecWest and I’m happy to say IE8 Security Program Manager and Fiddler author Eric Lawrence also announced our it at MIX09 yesterday. Check out his talk at http://videos.visitmix.com/MIX09/T54F it’s an eye opener for Web developers – … Continue reading
Unicode security attacks and test cases: character mappings and normalization for testing
Point: Normalizing strings after validation is dangerous Impact: filter evasion, enabling code execution Are you testing a Web or other application in attempt to bypass restrictions on domain names? For example, what if you were testing a phishing filter and … Continue reading
Uniview character lookup tool
Richard Ishida has an online character lookup tool which is very nice. It’s called Uniview and it’s comparable to Babelmap in some functionality but it’s available online if that’s useful to you. If you’re looking to use any of the … Continue reading
Posted in security
Leave a comment
Presenting IDN spoofing threats to ICANN’s security committee
I had the chance to present to the ICANN Security and Stability Advisory Committee during their ICANN Mexico conference. It was an opportunity to give a portion of my upcoming presentation on Exploiting Unicode-enabled Software, focusing just on IDN visual … Continue reading