Collected research
When Tolerance Causes Weakness: The Case of Injection-Friendly Browsers
An off-path attacker running only a sandboxed script recovers the randomised client port by SYN-eliminating candidates and timing the script's connection attempts. Browsers treat a malformed HTTP response as a body with a default header, leaking back the guessed server sequence number. Port prediction worked on 93% of the Alexa top 1024; full injection succeeded about 35% of the time.
Record
- Researcher
- Yossi Gilad and Amir Herzberg
- Published by
- archives.iw3c2.org
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yossi Gilad and Amir Herzberg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .