Locale vector

Talk about internet security, computer security, personal security, your social security number...
Post Reply
morganism
Senior Member
Posts: 136
Joined: Tue Nov 26, 2013 9:44 pm

Locale vector

Post by morganism »

looks like the big Red October attack required a change to the crylic alphabet to execute.

Windows since XP don't allow users to change language fonts, they hav to create a "locale".
This could easily be a backdoor injection route. If a person got a "you need to install a language pack" message.

Prob want to make sure that a site isn't going to try to change display font.


Red October
https://www.securelist.com/en/analysis/ ... estigation


and locale and font vector

http://www.microsoft.com/typography/unicode/cscp.htm

http://msdn.microsoft.com/en-us/magazine/cc440752.aspx

http://docs.oracle.com/javase/7/docs/ap ... ilder.html
Mozilla/5.0 (Windows NT 6.0; rv:24.0) Gecko/20100101 Firefox/24.0
Post Reply