Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Unicode Vulnerabilities That Could Byte You

NorthSec via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore Unicode vulnerabilities and their impact on modern applications in this 42-minute conference talk from NorthSec 2020. Delve into the security implications of encoding conversion, normalization, and character transformation. Learn about the HostSplit and HostBond attacks, which exploit minor character conversions to trigger open redirects and Server-Side Request Forgery (SSRF). Discover how uppercase and lowercase transformations can introduce vulnerabilities and how encoding can be used to bypass security controls like Web Application Firewalls. Examine the risks associated with Punycode representation in domain names and its potential for visual confusion. Gain a comprehensive understanding of Unicode-related security concerns, including patched issues and ongoing risks. Benefit from the expertise of Philippe Arteau, a security researcher at GoSecure, as he shares his insights on Web application security, static analysis tools, and proxy tool plugins.

Syllabus

Intro
Presentation Outline
Code points
Encoding
Security list
Example
General recommendations
Case modification
Critical signature
TLS validation
Safe function
Encoding bypass
XSS bypass
Does this work in certificates

Taught by

NorthSec

Reviews

Start your review of Unicode Vulnerabilities That Could Byte You

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.