full-disclosure-uk May 2007 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: Re: [Full-disclosure] noise about full-width

Re: [Full-disclosure] noise about full-width encoding bypass?

From: Brian Eaton <eaton.lists_at_nospam>
Date: Mon May 21 2007 - 18:36:59 GMT
To: "Web Security" <websecurity@webappsec.org>, Full-Disclosure <full-disclosure@lists.grok.org.uk>


On 5/21/07, Brian Eaton <eaton.lists@gmail.com> wrote:
> Has anyone had a look at the full-width unicode encoding trick discussed here?
>
> http://www.kb.cert.org/vuls/id/739224
>
> AFAICT, this technique could be useful for a homograph attack. I
> don't think it's useful for much else. However, a few vendors have
> reacted already, so I may be missing something important.

To summarize what I've heard from various sources: I am missing something important. =) Both PHP and ASP.NET will decode these characters into their ASCII equivalents. I don't think J2EE apps are vulnerable, but this is definitely useful for more more than just homograph attacks.

Thanks to the various people who have tested this out!

Regards,
Brian



Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/