{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T23:46:41Z","timestamp":1768520801977,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,10,17]],"date-time":"2011-10-17T00:00:00Z","timestamp":1318809600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,10,17]]},"DOI":"10.1145\/2046707.2046736","type":"proceedings-article","created":{"date-parts":[[2011,10,18]],"date-time":"2011-10-18T13:02:00Z","timestamp":1318942920000},"page":"251-262","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":29,"title":["Fear the EAR"],"prefix":"10.1145","author":[{"given":"Adam","family":"Doup\u00e9","sequence":"first","affiliation":[{"name":"University of California, Santa Barbara, Santa Barbara, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bryce","family":"Boe","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Santa Barbara, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Santa Barbara, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Santa Barbara, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,10,17]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ASP.NET MVC. http:\/\/www.asp.net\/mvc.  ASP.NET MVC. http:\/\/www.asp.net\/mvc."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755688.1755706"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 18th Network and Distributed System Security Symposium","author":"Balduzzi M.","year":"2011"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315250"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455782"},{"key":"e_1_3_2_1_6_1","unstructured":"Boe B. UCSB's International Capture The Flag Competition 2010 Challenge 6: Fear The EAR. http:\/\/cs.ucsb.edu\/ bboe\/r\/ictf10 December 2010.  Boe B. UCSB's International Capture The Flag Competition 2010 Challenge 6: Fear The EAR. http:\/\/cs.ucsb.edu\/ bboe\/r\/ictf10 December 2010."},{"key":"e_1_3_2_1_7_1","unstructured":"Boe B. Using StackOverflow's API to Find the Top Web Frameworks. http:\/\/cs.ucsb.edu\/ bboe\/r\/top-web-frameworks February 2011.  Boe B. Using StackOverflow's API to Find the Top Web Frameworks. http:\/\/cs.ucsb.edu\/ bboe\/r\/top-web-frameworks February 2011."},{"key":"e_1_3_2_1_8_1","volume-title":"USA","author":"Boehm B. W.","year":"1981"},{"key":"e_1_3_2_1_9_1","unstructured":"Include exit with a redirect call. http:\/\/replay.web.archive.org\/20061011152124\/https:\/\/trac.cakephp.org\/t%icket\/1076 August 2006.  Include exit with a redirect call. http:\/\/replay.web.archive.org\/20061011152124\/https:\/\/trac.cakephp.org\/t%icket\/1076 August 2006."},{"key":"e_1_3_2_1_10_1","unstructured":"docs should mention redirect does not \"exit\" a script. http:\/\/replay.web.archive.org\/20061011180440\/https:\/\/trac.cakephp.org\/t%icket\/1358 August 2006.  docs should mention redirect does not \"exit\" a script. http:\/\/replay.web.archive.org\/20061011180440\/https:\/\/trac.cakephp.org\/t%icket\/1358 August 2006."},{"key":"e_1_3_2_1_11_1","unstructured":"Cake Software Foundation Inc. The CakePHP 1.3 Book. http:\/\/book.cakephp.org\/view\/982\/redirect 2011.  Cake Software Foundation Inc. The CakePHP 1.3 Book. http:\/\/book.cakephp.org\/view\/982\/redirect 2011."},{"key":"e_1_3_2_1_12_1","volume-title":"OWASP AppSec Europe 2009","author":"Carettoni L.","year":"2009"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866373"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/1884848.1884859"},{"key":"e_1_3_2_1_15_1","unstructured":"Django Software Foundation. Django shortcut functions. http:\/\/docs.djangoproject.com\/en\/dev\/topics\/http\/shortcuts\/#django.shor%tcuts.redirect 2011.  Django Software Foundation. Django shortcut functions. http:\/\/docs.djangoproject.com\/en\/dev\/topics\/http\/shortcuts\/#django.shor%tcuts.redirect 2011."},{"key":"e_1_3_2_1_16_1","unstructured":"EllisLab Inc. CodeIgniter User Guide Version 2.0.2. http:\/\/codeigniter.com\/user_guide\/helpers\/url_helper.html 2011.  EllisLab Inc. CodeIgniter User Guide Version 2.0.2. http:\/\/codeigniter.com\/user_guide\/helpers\/url_helper.html 2011."},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Felmetsger V.","year":"2010"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1640134.1640148"},{"key":"e_1_3_2_1_19_1","unstructured":"GitHub. http:\/\/github.com.  GitHub. http:\/\/github.com."},{"key":"e_1_3_2_1_20_1","unstructured":"Indictment in U.S. v. Albert Gonzalez. http:\/\/www.justice.gov\/usao\/ma\/news\/IDTheft\/Gonzalez %20Albert%20-%2%0Indictment%20080508.pdf August 2008.  Indictment in U.S. v. Albert Gonzalez. http:\/\/www.justice.gov\/usao\/ma\/news\/IDTheft\/Gonzalez %20Albert%20-%2%0Indictment%20080508.pdf August 2008."},{"key":"e_1_3_2_1_21_1","unstructured":"Hansen R. Clickjacking. http:\/\/ha.ckers.org\/blog\/20080915\/clickjacking\/ September 2008.  Hansen R. Clickjacking. http:\/\/ha.ckers.org\/blog\/20080915\/clickjacking\/ September 2008."},{"key":"e_1_3_2_1_22_1","unstructured":"Hofstetter D. Don't forget to exit after a redirect. http:\/\/cakebaker.wordpress.com\/2006\/08\/28\/dont-forget-to-exit-after-a-redirect\/ August 2006.  Hofstetter D. Don't forget to exit after a redirect. http:\/\/cakebaker.wordpress.com\/2006\/08\/28\/dont-forget-to-exit-after-a-redirect\/ August 2006."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2009.80"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988679"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134744.1134751"},{"key":"e_1_3_2_1_27_1","unstructured":"Klein A. Divide and conquer: HTTP response splitting Web cache poisoning attacks and related topics. http:\/\/www.packetstormsecurity.org\/papers\/general\/whitepaper\/httprespon%se.pdf 2004.  Klein A. Divide and conquer: HTTP response splitting Web cache poisoning attacks and related topics. http:\/\/www.packetstormsecurity.org\/papers\/general\/whitepaper\/httprespon%se.pdf 2004."},{"key":"e_1_3_2_1_28_1","first-page":"18","volume-title":"Proceedings of the 14th conference on USENIX Security Symposium -","volume":"14","author":"Livshits V. B.","year":"2005"},{"key":"e_1_3_2_1_29_1","unstructured":"Open Web Application Security Project (OWASP). OWASP Top Ten Project. http:\/\/www.owasp.org\/index.php\/Top_10 2010.  Open Web Application Security Project (OWASP). OWASP Top Ten Project. http:\/\/www.owasp.org\/index.php\/Top_10 2010."},{"key":"e_1_3_2_1_30_1","unstructured":"Ortiz C. Outcome of sentencing in U.S. v. Albert Gonzalez. http:\/\/www.justice.gov\/usao\/ma\/news\/IDTheft\/09-CR-10382\/GONZALEZ%20web%site%20info%205--11--10.pdf March 2010.  Ortiz C. Outcome of sentencing in U.S. v. Albert Gonzalez. http:\/\/www.justice.gov\/usao\/ma\/news\/IDTheft\/09-CR-10382\/GONZALEZ%20web%site%20info%205--11--10.pdf March 2010."},{"key":"e_1_3_2_1_31_1","unstructured":"R. Fielding J. Gettys J. M. H. F. L. M. P. L. T. B.-L. RFC 2616: Hypertext Transfer Protocol -- HTTP\/1.1 Header Field Definitions. http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec14.html#sec14.30 June 1999.   R. Fielding J. Gettys J. M. H. F. L. M. P. L. T. B.-L. RFC 2616: Hypertext Transfer Protocol -- HTTP\/1.1 Header Field Definitions. http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec14.html#sec14.30 June 1999."},{"key":"e_1_3_2_1_32_1","unstructured":"R. Fielding J. Gettys J. M. H. F. L. M. P. L. T. B.-L. RFC 2616: Hypertext Transfer Protocol -- HTTP\/1.1 Status Code Definitions. http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec10.html June 1999.   R. Fielding J. Gettys J. M. H. F. L. M. P. L. T. B.-L. RFC 2616: Hypertext Transfer Protocol -- HTTP\/1.1 Status Code Definitions. http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec10.html June 1999."},{"key":"e_1_3_2_1_33_1","unstructured":"Reenskaug T. Models - views - controllers. Tech. rep. Xerox Parc 1979.  Reenskaug T. Models - views - controllers. Tech. rep. Xerox Parc 1979."},{"key":"e_1_3_2_1_34_1","unstructured":"SpringSource. Contollers - Redirects. http:\/\/www.grails.org\/Controllers-Redirects 2010.  SpringSource. Contollers - Redirects. http:\/\/www.grails.org\/Controllers-Redirects 2010."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.26"},{"key":"e_1_3_2_1_36_1","unstructured":"Zend Technologies Ltd. Zend Framework: Documentation: Action Helpers - Zend Framework Manual. http:\/\/framework.zend.com\/manual\/en\/zend.controller.actionhelpers.html zend.controller.actionhelpers.redirector 2011.  Zend Technologies Ltd. Zend Framework: Documentation: Action Helpers - Zend Framework Manual. http:\/\/framework.zend.com\/manual\/en\/zend.controller.actionhelpers.html zend.controller.actionhelpers.redirector 2011."}],"event":{"name":"CCS'11: the ACM Conference on Computer and Communications Security","location":"Chicago Illinois USA","acronym":"CCS'11","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 18th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2046707.2046736","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2046707.2046736","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:48:42Z","timestamp":1750240122000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2046707.2046736"}},"subtitle":["discovering and mitigating execution after redirect vulnerabilities"],"short-title":[],"issued":{"date-parts":[[2011,10,17]]},"references-count":36,"alternative-id":["10.1145\/2046707.2046736","10.1145\/2046707"],"URL":"https:\/\/doi.org\/10.1145\/2046707.2046736","relation":{},"subject":[],"published":{"date-parts":[[2011,10,17]]},"assertion":[{"value":"2011-10-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}