hack0r.net


Ynnuf Ffuts

Posted in Webapp Security by n00k on the March 14th, 2007

I just played around with some special characters as I stumbled across this. If you insert ‮ into some text, from that point the order of the following characters will be reversed. As far as I can see this has no security implication, since tags are still interpreted in the “right” direction, but this can be very annoying whatsoever and depending on the way the page is written might even kind of deface it. The effect applies on all characters after the this “special character”, that are in the same DOM text element. Well this is not really accurate, because the Source Code gets all converted from that point on, at least in Firefox.

‮So here is a small example what this looks like…

Popularity: unranked [?]

Leave a Reply