Full Disclosure mailing list archives
Re: noise about full-width encoding bypass?
From: "Brian Eaton" <eaton.lists () gmail com>
Date: Mon, 21 May 2007 14:36:59 -0400
On 5/21/07, Brian Eaton <eaton.lists () gmail com> wrote:
Has anyone had a look at the full-width unicode encoding trick discussed here? http://www.kb.cert.org/vuls/id/739224 AFAICT, this technique could be useful for a homograph attack. I don't think it's useful for much else. However, a few vendors have reacted already, so I may be missing something important.
To summarize what I've heard from various sources: I am missing something important. =) Both PHP and ASP.NET will decode these characters into their ASCII equivalents. I don't think J2EE apps are vulnerable, but this is definitely useful for more more than just homograph attacks. Thanks to the various people who have tested this out! Regards, Brian _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- noise about full-width encoding bypass? Brian Eaton (May 21)
- Re: noise about full-width encoding bypass? 3APA3A (May 21)
- Re: noise about full-width encoding bypass? Brian Eaton (May 21)
- Re: noise about full-width encoding bypass? 3APA3A (May 22)
- Re: noise about full-width encoding bypass? Brian Eaton (May 21)
- Re: noise about full-width encoding bypass? Brian Eaton (May 21)
- Re: noise about full-width encoding bypass? ascii (May 21)
- Re: noise about full-width encoding bypass? Brian Eaton (May 21)
- Re: noise about full-width encoding bypass? Steven Adair (May 21)
- Re: noise about full-width encoding bypass? Valdis . Kletnieks (May 21)
- Re: noise about full-width encoding bypass? 3APA3A (May 22)
- Re: noise about full-width encoding bypass? ascii (May 21)
- Re: [WEB SECURITY] Re: noise about full-width encoding bypass? Chris Weber (May 21)
- Re: [WEB SECURITY] Re: noise about full-width encoding bypass? ascii (May 21)
- Re: noise about full-width encoding bypass? 3APA3A (May 21)
- Re: [WEB SECURITY] Re: noise about full-width encoding bypass? Brian Eaton (May 22)
- Re: [WEB SECURITY] Re: noise about full-width encoding bypass? Arian J. Evans (May 22)