<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Casaba Security &#187; Unicode</title>
	<atom:link href="http://www.casabasecurity.com/blog/category/unicode/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.casabasecurity.com/blog</link>
	<description>Building and breaking software and robots</description>
	<lastBuildDate>Tue, 31 Aug 2010 18:27:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>IDNA2008 hits the standards track &#8211; visually confusing strings remain a threat</title>
		<link>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/</link>
		<comments>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 18:27:09 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[confusables]]></category>
		<category><![CDATA[IDN]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=216</guid>
		<description><![CDATA[After many years of engineering efforts, the Internationalizing Domain Names in Applications (IDNA) protocol had a major update released from its original 2003 standard. Although named IDNA2008, it hit the standards track in August 2010. It&#8217;s worth noting in section &#8220;4.4 Visually Confusable Characters&#8221; of RFC 5890: It is worth noting that there are no [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2010/08/idna2008-hits-the-standards-track-visually-confusing-strings-remain-a-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unicode security vulnerabilities &#8211; presentation from Internationalization and Unicode Conference 33</title>
		<link>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/</link>
		<comments>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 19:24:44 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Unicode]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#039;m attaching my slides from the Unicode conference last week in San Jose, California. I&#039;m getting much feedback for code-level action items. Providing details for code review and static analysis is in the works, with a focus on major frameworks such as ICU, .NET, and Java. You can download the presentation here.]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/10/unicode-security-vulnerabilities-presentation-from-internationalization-and-unicode-conference-33/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unibomber tool for specialized XSS testing</title>
		<link>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/</link>
		<comments>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 01:04:31 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[John Hernandez has been working hard at Casaba to build a specialized testing tool that automates some of the unique techniques we use to find cross-sites scripting bugs (XSS). At Black Hat I&#039;m planning to demo what we have so far. It automates the testing process greatly, by auto-injecting a canary and ID into each [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2009/07/unibomber-tool-for-specialized-xss-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>32nd Internationalization and Unicode Conference presentation on Exploiting Unicode-enabled Software</title>
		<link>http://www.casabasecurity.com/blog/2008/09/32nd-internationalization-and-unicode-conference-presentation-on-exploiting-unicode-enabled-software/</link>
		<comments>http://www.casabasecurity.com/blog/2008/09/32nd-internationalization-and-unicode-conference-presentation-on-exploiting-unicode-enabled-software/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 18:37:18 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Unicode]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#39;m glad to have had the chance to present at the Unicode conference yesterday, and meet all the wonderful people there. You can download the presentation slides here for Exploiting Unicode-enabled software. &#160;]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2008/09/32nd-internationalization-and-unicode-conference-presentation-on-exploiting-unicode-enabled-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generating test cases for Unicode-enabled software</title>
		<link>http://www.casabasecurity.com/blog/2008/09/generating-test-cases-for-unicode-enabled-software/</link>
		<comments>http://www.casabasecurity.com/blog/2008/09/generating-test-cases-for-unicode-enabled-software/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 07:00:00 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[test cases]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[When it comes to Unicode implementations, there’s a rich set of test cases to perform. Realizing it is the start. Automating it is the next step. At a high-level Unicode-related security bugs can be categorized into the following root-causes: Canonicalization Interpreting non-shortest form (e.g .UTF-8 encoding trickery) Other decoding issues Absorption (over-consumption) Over-consuming invalid byte [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2008/09/generating-test-cases-for-unicode-enabled-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unicode formatter characters lead to cross-site scripting in popular browsers</title>
		<link>http://www.casabasecurity.com/blog/2008/09/unicode-formatter-characters-lead-to-cross-site-scripting-in-popular-browsers/</link>
		<comments>http://www.casabasecurity.com/blog/2008/09/unicode-formatter-characters-lead-to-cross-site-scripting-in-popular-browsers/#comments</comments>
		<pubDate>Fri, 05 Sep 2008 21:25:41 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[test cases]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#039;ll be discussing some of the issues recently reported to Opera, Apple, and Mozilla at the 32nd Unicode Conference in San Jose next week. We discovered some issues with the way certain Unicode characters could be leveraged to enable cross-site scripting attacks in popular web browsers (aka User-Agents). These issues involve utilizing Unicode characters in [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2008/09/unicode-formatter-characters-lead-to-cross-site-scripting-in-popular-browsers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Handling Unicode when marshalling from .Net to a platform invoke</title>
		<link>http://www.casabasecurity.com/blog/2008/04/handling-unicode-when-marshalling-from-net-to-a-platform-invoke/</link>
		<comments>http://www.casabasecurity.com/blog/2008/04/handling-unicode-when-marshalling-from-net-to-a-platform-invoke/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 05:09:56 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Code Review]]></category>
		<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[.NET]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[By default, the .Net runtime will marshall a string (and files in a value type) as a LPStr to a platform invoke (p/invoke) function. By default the .Net framework and runtime handles strings as UTF-16. That&#39;s two bytes representing a single Unicode &#39;code point&#39;, and more familiar, a single character. An LPStr on the other [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2008/04/handling-unicode-when-marshalling-from-net-to-a-platform-invoke/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I18N input validation whitelist filter with System.Globalization and GetUnicodeCategory</title>
		<link>http://www.casabasecurity.com/blog/2007/04/i18n-input-validation-whitelist-filter-with-system-globalization-and-getunicodecategory/</link>
		<comments>http://www.casabasecurity.com/blog/2007/04/i18n-input-validation-whitelist-filter-with-system-globalization-and-getunicodecategory/#comments</comments>
		<pubDate>Tue, 24 Apr 2007 05:33:20 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Unicode]]></category>
		<category><![CDATA[whitelist]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Maybe you’re building internationalized code and wondering how to build a whitelist filter that will support all the different character sets your planning to support. If you support more than ten, especially some of the larger east Asian sets, this might seem like an unwieldy or tricky process. Well luckily it’s easier than most people [...]]]></description>
		<wfw:commentRss>http://www.casabasecurity.com/blog/2007/04/i18n-input-validation-whitelist-filter-with-system-globalization-and-getunicodecategory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
