Detailedseverity: MediumDraft

CAPEC-145Checksum Spoofing

Abstraction
Detailed
Status
Draft
Severity
Medium

Description

An adversary spoofs a checksum message for the purpose of making a payload appear to have a valid corresponding checksum. Checksums are used to verify message integrity. They consist of some value based on the value of the message they are protecting. Hash codes are a common checksum mechanism. Both the sender and recipient are able to compute the checksum based on the contents of the message. If the message contents change between the sender and recipient, the sender and recipient will compute different checksum values. Since the sender's checksum value is transmitted with the message, the recipient would know that a modification occurred. In checksum spoofing an adversary modifies the message body and then modifies the corresponding checksum so that the recipient's checksum calculation will match the checksum (created by the adversary) in the message. This would prevent the recipient from realizing that a change occurred.

Related weaknesses· 1

CWE-354

Related attack patterns· 1

CAPEC-148 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Validation of Integrity Check Valuecwe-354100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Content Spoofing
CAPEC
Signature Spoof
CAPEC
Identity Spoofing
CAPEC
Signature Spoofing by Misrepresentation
CAPEC
Signature Spoofing by Improper Validation
CAPEC
Protocol Manipulation
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.