Uploaded December 2025 | Updated September 2026, 2 weeks ago
As web applications evolve, so do their data processing pipelines—handling Unicode normalization, encoding, and translation before storing or executing user input. But what if these same data transformations could be weaponized by attackers? This talk exposes how Unicode normalization flaws (such as visual confusables/best-fit mappings, truncation/overflows, case-mappings and entity decodings) lead to critical security bypasses—allowing attackers to evade WAFs, input filters, and backend logic to execute Remote Code Execution (RCE), Cross-Site Scripting (XSS), Server-Side Template Injection (SSTI), Open Redirects, and HTTP Response Splitting.
Using real-world attack data from Akamai's research team, this session will showcase live exploitation demos, explore the impact of vulnerabilities like CVE-2024-4577 (PHP-CGI Argument Injection), and introduce cutting-edge Unicode fuzzing techniques. Attendees will leave with a deep understanding of Unicode security pitfalls and hands-on tools like Shazzer, recollapse, and Burp Activescan++ enhancements to detect these issues.
Ryan Barnett
Akamai
Principal Security Researcher
Metro DC
Ryan Barnett is a web application defender with over two decades of experience. He is currently a Principal Security Researcher working on the Akamai Threat Research Team, supporting the App and API Protector product. In addition to his primary work at Akamai, he is also a former Faculty Member for the SANS Institute, a WASC Board Member and OWASP Co-Project Leader for: Web Hacking Incident Database (WHID. Mr. Barnett has also authored two web security books: Preventing Web Attacks with Apache (Pearson) and The Web Application Defender's Cookbook: Battling Hackers and Defending Users (Wiley).
@ryancbarnett
linkedin.com/in/ryan-barnett-b27635
webappdefender.blogspot.com (blog)
Isabella Barnett
Databuoy
Software Engineering Intern
Isabella Barnett is a Software Engineering Intern at Databuoy and a Sophomore at George Mason Honor's College studying Cyber Security Engineering.
@4ng3lhacker
Managed by the OWASP® Foundation
owasp.org
As web applications evolve, so do their data processing pipelines—handling Unicode normalization, encoding, and translation before storing or executing user input. But what if these same data transformations could be weaponized by attackers? This talk exposes how Unicode normalization flaws (such as visual confusables/best-fit mappings, truncation/overflows, case-mappings and entity decodings) lead to critical security bypasses—allowing attackers to evade WAFs, input filters, and backend logic to execute Remote Code Execution (RCE), Cross-Site Scripting (XSS), Server-Side Template Injection (SSTI), Open Redirects, and HTTP Response Splitting.
Using real-world attack data from Akamai's research team, this session will showcase live exploitation demos, explore the impact of vulnerabilities like CVE-2024-4577 (PHP-CGI Argument Injection), and introduce cutting-edge Unicode fuzzing techniques. Attendees will leave with a deep understanding of Unicode security pitfalls and hands-on tools like Shazzer, recollapse, and Burp Activescan++ enhancements to detect these issues.
Ryan Barnett
Akamai
Principal Security Researcher
Metro DC
Ryan Barnett is a web application defender with over two decades of experience. He is currently a Principal Security Researcher working on the Akamai Threat Research Team, supporting the App and API Protector product. In addition to his primary work at Akamai, he is also a former Faculty Member for the SANS Institute, a WASC Board Member and OWASP Co-Project Leader for: Web Hacking Incident Database (WHID. Mr. Barnett has also authored two web security books: Preventing Web Attacks with Apache (Pearson) and The Web Application Defender's Cookbook: Battling Hackers and Defending Users (Wiley).
@ryancbarnett
linkedin.com/in/ryan-barnett-b27635
webappdefender.blogspot.com (blog)
Isabella Barnett
Databuoy
Software Engineering Intern
Isabella Barnett is a Software Engineering Intern at Databuoy and a Sophomore at George Mason Honor's College studying Cyber Security Engineering.
@4ng3lhacker
Managed by the OWASP® Foundation
owasp.org










