Collected research
Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit
Extends the single-packet attack past its roughly 1,500-byte ceiling by splitting a large TCP segment across IP fragments and sending them out of order, withholding the one carrying the first sequence number. The server queues everything until it arrives, so about 10,000 requests land in 166 milliseconds, making limit-overrun races exploitable.
Record
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
- Topic
- Other
In the archive
Related sources
- Smashing the state machine: the true potential of web race conditions
- First-sequence-sync benchmark code
- First-sequence-sync demonstration code
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .