« September 2007 | Main | November 2007 »

October 2007 Archives

If you like it here, please consider subscribing to the RSS feed or spreading the news among your friends who also care about security.

October 9, 2007

Technical risk management for web applications — a case study

Are you interested in controlling the risk you are taking when it comes to technology? Do you want to know how to manage technology risk of your web start-up? Come to the next Grill IT (October 12, 6pm, in Hotel Tumski, Wrocław) where I hope to cast some light on the subject.

See you there!

October 20, 2007

Visual spoofing in modern browsers. Again

A URL, if it contains any non-ASCII characters, should always be presented to a user in an ACE (ASCII Compatible Encoding) form (looking something like this: xn--t-zfa.com) in sake of preventing any visual spoofing (a situation, when two different URLs happen to look so alike, using given font, that one might be mistaken for the other — for examples see Unicode Security Considerations).

It appears though, that certain Unicode-encoded diacritics, when appended to certain ASCII characters, still tend to escape this rule in the latest versions of some mainstream web browsers.

Continue reading "Visual spoofing in modern browsers. Again" »

October 22, 2007

After SecureCON 2007

It was a great experience! Hope you all enjoyed it just as I did. While waiting for the slides and videos to show up officially on the SecureCON website, feel free to check out the slides to the presentation I gave on the first day.

See you on the next SecureCON!

October 24, 2007

A follow-up on visual spoofing. It’s even worse, it’s on purpose

You are not going to believe this! It appears that IE7 implements the IDN support and the Unicode to ASCII conversion following the spec (thanks to Michel Suignard for pointing this out). Yeah, I was surprised too. Apparently Firefox approaches the problem creatively and gets... well... over-secured (is that even a word?). How so?

Continue reading "A follow-up on visual spoofing. It’s even worse, it’s on purpose" »

October 27, 2007

Review of the 10/2007 Hakin9 issue

Lately I've been asked to take a look at the latest (by then ;-) Hagin9 issue and to share my thoughts on a blog. Well, I thought why not — after all it may save you guys some cash or maybe get you running to the nearest newsstand. Literally running, because it took me some time to get into this. But hey, you still have like four days to the end of the month...

OK. Before we start, the important thing is that you shouldn't treat all this as me telling you what's worth reading and what's not — I think it really depends on what you are into. Instead try to think of it as of a short and unbiased *cough* *cough* glance between the covers. Honestly, I have no idea if it'll work for you or not. So, if you care, just give me a shout.

And, as a final note before we get to the meat — unfortunately, this short review concerns the Polish edition of the magazine, so it's best if you actually read Polish.

Continue reading "Review of the 10/2007 Hakin9 issue" »

© 2006-2007 Michał Sobiegraj. All rights reserved. The views expressed here are my own, and not necessarily endorsed by any former or current employer.

About October 2007

This page contains all entries posted to Michal Sobiegraj | Security Consultant and Evangelist in October 2007. They are listed from oldest to newest.

September 2007 is the previous archive.

November 2007 is the next archive.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.34