{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T00:28:32Z","timestamp":1766449712774,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2013,5,13]],"date-time":"2013-05-13T00:00:00Z","timestamp":1368403200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2013,5,13]]},"DOI":"10.1145\/2488388.2488427","type":"proceedings-article","created":{"date-parts":[[2016,2,5]],"date-time":"2016-02-05T20:43:24Z","timestamp":1454705004000},"page":"435-446","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["When tolerance causes weakness"],"prefix":"10.1145","author":[{"given":"Yossi","family":"Gilad","sequence":"first","affiliation":[{"name":"Bar-Ilan University, Ramat Gan, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Herzberg","sequence":"additional","affiliation":[{"name":"Bar-Ilan University, Ramat Gan, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,5,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Advanced Network Architecture Group. Spoofer Project. http:\/\/spoofer.csail.mit.edu\/index.php 2012.  Advanced Network Architecture Group. Spoofer Project. http:\/\/spoofer.csail.mit.edu\/index.php 2012."},{"key":"e_1_3_2_1_2_1","unstructured":"Alexa Web Information Company. Top Sites. http:\/\/www.alexa.com\/topsites 2012.  Alexa Web Information Company. Top Sites. http:\/\/www.alexa.com\/topsites 2012."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455518.1455524"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"F. Baker and P. Savola. Ingress Filtering for Multihomed Networks. RFC 3704 (Best Current Practice) Mar. 2004.   F. Baker and P. Savola. Ingress Filtering for Multihomed Networks. RFC 3704 (Best Current Practice) Mar. 2004.","DOI":"10.17487\/rfc3704"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"A. Barth. The Web Origin Concept. RFC 6454 (Proposed Standard) Dec. 2011.  A. Barth. The Web Origin Concept. RFC 6454 (Proposed Standard) Dec. 2011.","DOI":"10.17487\/rfc6454"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/378444.378449"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.3"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644936"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"W. Eddy. TCP SYN Flooding Attacks and Common Mitigations. RFC 4987 (Informational) Aug. 2007.  W. Eddy. TCP SYN Flooding Attacks and Common Mitigations. RFC 4987 (Informational) Aug. 2007.","DOI":"10.17487\/rfc4987"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1516539.1516541"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"P. Ferguson and D. Senie. Network Ingress Filtering: Defeating Denial of Service Attacks which Employ IP Source Address Spoofing. RFC 2827 May 2000.   P. Ferguson and D. Senie. Network Ingress Filtering: Defeating Denial of Service Attacks which Employ IP Source Address Spoofing. RFC 2827 May 2000.","DOI":"10.17487\/rfc2827"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"R. Fielding J. Gettys J. Mogul H. Frystyk L. Masinter P. Leach and T. Berners-Lee. Hypertext Transfer Protocol -- HTTP\/1.1. RFC 2616 (Draft Standard) June 1999. Updated by RFCs 2817 5785 6266.   R. Fielding J. Gettys J. Mogul H. Frystyk L. Masinter P. Leach and T. Berners-Lee. Hypertext Transfer Protocol -- HTTP\/1.1. RFC 2616 (Draft Standard) June 1999. Updated by RFCs 2817 5785 6266.","DOI":"10.17487\/rfc2616"},{"key":"e_1_3_2_1_13_1","first-page":"41","volume-title":"Off-Path Attacking the Web. In USENIX Workshop on Offensive Technologies","author":"Gilad Y.","year":"2012"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"F. Gont and S. Bellovin. Defending against Sequence Number Attacks. RFC 6528 (Proposed Standard) Feb. 2012.  F. Gont and S. Bellovin. Defending against Sequence Number Attacks. RFC 6528 (Proposed Standard) Feb. 2012.","DOI":"10.17487\/rfc6528"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242654"},{"volume-title":"Black Ops of TCP\/IP. In Black Hat conference","year":"2011","author":"Kaminsky D.","key":"e_1_3_2_1_16_1"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"T. Killalea. Recommended Internet Service Provider Security Services and Procedures. RFC 3013 (Best Current Practice) Nov. 2000.   T. Killalea. Recommended Internet Service Provider Security Services and Procedures. RFC 3013 (Best Current Practice) Nov. 2000.","DOI":"10.17487\/rfc3013"},{"volume-title":"White Paper","year":"2004","author":"Klein A.","key":"e_1_3_2_1_18_1"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","first-page":"1373","DOI":"10.1007\/978-1-4419-5906-5_666","volume-title":"Encyclopedia of Cryptography and Security","author":"Klein A.","year":"2011","edition":"2"},{"key":"e_1_3_2_1_20_1","unstructured":"klm. Remote Blind TCP\/IP Spoofing. Phrack magazine 2007.  klm. Remote Blind TCP\/IP Spoofing. Phrack magazine 2007."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"M. Larsen and F. Gont. Recommendations for Transport-Protocol Port Randomization. RFC 6056 (Best Current Practice) Jan. 2011.  M. Larsen and F. Gont. Recommendations for Transport-Protocol Port Randomization. RFC 6056 (Best Current Practice) Jan. 2011.","DOI":"10.17487\/rfc6056"},{"key":"e_1_3_2_1_22_1","first-page":"89","volume-title":"BSDCon","author":"Lemon J.","year":"2002"},{"key":"e_1_3_2_1_23_1","unstructured":"R. T. Morris. A Weakness in the 4.2BSD Unix TCP\/IP Software. Technical report AT&T Bell Laboratories Feb. 1985.  R. T. Morris. A Weakness in the 4.2BSD Unix TCP\/IP Software. Technical report AT&T Bell Laboratories Feb. 1985."},{"key":"e_1_3_2_1_24_1","unstructured":"Paul Petefish Eric Sheridan and Dave Wichers. Cross-Site Request Forgery Prevention Cheat Sheet. https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet 2011.  Paul Petefish Eric Sheridan and Dave Wichers. Cross-Site Request Forgery Prevention Cheat Sheet. https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet 2011."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"J. Postel. Transmission Control Protocol. RFC 793 (Standard) Sept. 1981.  J. Postel. Transmission Control Protocol. RFC 793 (Standard) Sept. 1981.","DOI":"10.17487\/rfc0793"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.29"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382258"},{"key":"e_1_3_2_1_28_1","unstructured":"J. Ruderman. Same Origin Policy for JavaScript.https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript 2001.  J. Ruderman. Same Origin Policy for JavaScript.https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript 2001."},{"key":"e_1_3_2_1_29_1","unstructured":"T. Shimomura and J. Markoff. Takedown: The Pursuit and Capture of Kevin Mitnick America's Most Wanted Computer Outlaw - by the Man Who Did It. Hyperion Press 1st edition 1995.   T. Shimomura and J. Markoff. Takedown: The Pursuit and Capture of Kevin Mitnick America's Most Wanted Computer Outlaw - by the Man Who Did It. Hyperion Press 1st edition 1995."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772784"},{"key":"e_1_3_2_1_31_1","unstructured":"The Open Web Application Security Project. Cache Poisoning. www.owasp.org\/index.php\/Cache_Poisoning 2009.  The Open Web Application Security Project. Cache Poisoning. www.owasp.org\/index.php\/Cache_Poisoning 2009."},{"key":"e_1_3_2_1_32_1","unstructured":"The Open Web Application Security Project. Cross-Site Request Forgery. https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2010.  The Open Web Application Security Project. Cross-Site Request Forgery. https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2010."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"J. Touch. Defending TCP Against Spoofing Attacks. RFC 4953 (Informational) July 2007.  J. Touch. Defending TCP Against Spoofing Attacks. RFC 4953 (Informational) July 2007.","DOI":"10.17487\/rfc4953"},{"volume-title":"CanSecWest","year":"2004","author":"Watson P.","key":"e_1_3_2_1_34_1"},{"key":"e_1_3_2_1_35_1","unstructured":"M. Zalewski. Strange Attractors and TCP\/IP Sequence Number Analysis.http:\/\/lcamtuf.coredump.cx\/newtcp\/ 2001.  M. Zalewski. Strange Attractors and TCP\/IP Sequence Number Analysis.http:\/\/lcamtuf.coredump.cx\/newtcp\/ 2001."},{"key":"e_1_3_2_1_36_1","unstructured":"M. Zalewski. The Tangled Web: A Guide to Securing Modern Web Applications. No Starch Press San Francisco CA USA 1st edition 2011.   M. Zalewski. The Tangled Web: A Guide to Securing Modern Web Applications. No Starch Press San Francisco CA USA 1st edition 2011."}],"event":{"name":"WWW '13: 22nd International World Wide Web Conference","sponsor":["NICBR Nucleo de Informatcao e Coordenacao do Ponto BR","CGIBR Comite Gestor da Internet no Brazil","SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"],"location":"Rio de Janeiro Brazil","acronym":"WWW '13"},"container-title":["Proceedings of the 22nd international conference on World Wide Web"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2488388.2488427","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2488388.2488427","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:48:41Z","timestamp":1750236521000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2488388.2488427"}},"subtitle":["the case of injection-friendly browsers"],"short-title":[],"issued":{"date-parts":[[2013,5,13]]},"references-count":36,"alternative-id":["10.1145\/2488388.2488427","10.1145\/2488388"],"URL":"https:\/\/doi.org\/10.1145\/2488388.2488427","relation":{},"subject":[],"published":{"date-parts":[[2013,5,13]]},"assertion":[{"value":"2013-05-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}