Web Hack List

Collected research

When Tolerance Causes Weakness: The Case of Injection-Friendly Browsers

An off-path attacker running only a sandboxed script recovers the randomised client port by SYN-eliminating candidates and timing the script's connection attempts. Browsers treat a malformed HTTP response as a body with a default header, leaking back the guessed server sequence number. Port prediction worked on 93% of the Alexa top 1024; full injection succeeded about 35% of the time.

Record

Researcher
Yossi Gilad and Amir Herzberg
Published by
archives.iw3c2.org
Format
Whitepaper
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yossi Gilad and Amir Herzberg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .