Metaseverity: HighDraft

CAPEC-161Infrastructure Manipulation

Abstraction
Meta
Status
Draft
Severity
High

Description

An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Most often, this involves manipulation of the routing of network messages so, instead of arriving at their proper destination, they are directed towards an entity of the attackers' choosing, usually a server controlled by the attacker. The victim is often unaware that their messages are not being processed correctly. For example, a targeted client may believe they are connecting to their own bank but, in fact, be connecting to a Pharming site controlled by the attacker which then collects the user's login information in order to hijack the actual bank account.

Related weaknesses· 1

CWE-923

Related attack patterns· 1

CAPEC-664 (CanPrecede)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Communication Channel to Intended Endpointscwe-923100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Protocol Manipulation
CAPEC
Pharming
CAPEC
Client-Server Protocol Manipulation
CAPEC
Configuration/Environment Manipulation
CAPEC
Application API Message Manipulation via Man-in-the-Middle
CAPEC
Interface Manipulation
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.