Top 10 winner
Lost in Translation: Exploiting Unicode Normalization
How Unicode handling diverges between a front-end proxy or CDN and the back-end application. Decoding errors, overlong encodings, byte truncation, confusables, case mapping and combining diacritics all let input that passes validation normalize later into a different, dangerous string, defeating filters and enabling injection or account takeover.
Record
- Researcher
- Ryan Barnett and Isabella Barnett
- Published by
- Black Hat
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Ryan Barnett and Isabella Barnett, first published at the original source. Preserved copies are kept so the citation survives its host.