Collected research
Off-Path Attacking the Web
A spoofing-only attacker with a puppet script in the victim's browser can learn both TCP sequence numbers of an existing connection by abusing the global IP-ID counter used by Windows as a side channel. With the sequence numbers known, injected packets yield XSS, CSRF and site spoofing without any browser or server bug. Firewall-level defences are proposed.
Record
- Researcher
- Yossi Gilad and Amir Herzberg
- Published by
- usenix.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yossi Gilad and Amir Herzberg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .