WebApp Sec mailing list archives

Canonicalization


From: <tom.rogers () hushmail com>
Date: Wed, 18 Feb 2004 06:10:49 -0800

I am confused with what I need to deal with regarding cononicalization
and wonder if anyone can help. 

I understand that inout can be represented in many different character
sets and therefore I need to convert it all to a standard set before
applying any rules to it but.

1. How do I know the initial format ?
2. I understodd the webserver and app server can do conversion of HTTP
streams. What does it convert and when does this happen in the data flow.
3. Don't languages like Java operate in Unicode so its done for you ?

Thanks



Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427


Current thread: