Questions tagged [unicode]

39 questions
5
votes
2 answers

What applications are at risk from "Backwards Unicode Names" and what are the mitigations?

There is a vulnerability where some applications (such as explorer.exe) respond to Unicode characters that change the direction of the text (right-to-left vs left-to-right). This may be used to mask an EXE file into one that looks like a text…
makerofthings7
  • 50,090
  • 54
  • 250
  • 536
4
votes
4 answers

SQL Injection via Unicode

My team currently uses ASP.NET with MS SQL Server for our software. Security has only become important since I started, in which there is injection vulnerabilities everywhere. Due to current integration with Oracle and MS SQL the business decision…
Cyassin
  • 503
  • 2
  • 6
  • 12
4
votes
0 answers

Whatsapp Unicode Phishing Link

I have been receiving messages from relatives that goes like this: AirAsia is rewarding everyone with 2 free plane tickets to celebrate 24 Years of quality service. Get your free ticket at: http://airasîa.com/free-tickets/ . which is a unicode…
Liren Yeo
  • 141
  • 5
3
votes
1 answer

XSS via Unicode

Reading about XSS and its countermeasures from http://www.xssed.com/xssinfo#Avoiding_XSS_vulnerabilities , it says (in the 2nd last paragraph of the link) that: […] support for Unicode character sets by browsers could leave an application open to…
Karan
  • 467
  • 5
  • 14
3
votes
2 answers

How to defend against invalid UTF7/8 that hides a