Tag Archives: IDN

Advisory: Certain domain names could allow execution of arbitrary code in Opera

Opera released 10.01 recently, which fixed a memory corruption issue found with Casaba’s IDN/URI fuzzer. http://www.opera.com/support/kb/view/938/

Posted in advisory | Tagged , , | Leave a comment

Presenting IDN spoofing threats to ICANN’s security committee

I had the chance to present to the ICANN Security and Stability Advisory Committee during their ICANN Mexico conference. It was an opportunity to give a portion of my upcoming presentation on Exploiting Unicode-enabled Software, focusing just on IDN visual … Continue reading

Posted in Unicode, Web | Tagged , | Leave a comment

The current state of IDN homograph spoofing in 2009 – you don’t need a .CN to do it

Aside from the frightening SSL stuff, Moxie Marlinspike stirred up some good interest in Internationalized Domain Names at Black Hat in DC with his domain lookalike attack. Since I’ve been studying the topic for a while, I wanted to point … Continue reading

Posted in Unicode, Web | Tagged , | Leave a comment