Detailedlikelihood: Highseverity: HighDraft

CAPEC-60Reusing Session IDs (aka Session Replay)

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High

Description

This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay. Metadata: detailed CAPEC pattern, status draft, likelihood high, severity high. Underlying weaknesses: CWE-294, CWE-290, CWE-346, CWE-384, CWE-488 (and 5 more). Mapped ATT&CK techniques: [object Object], [object Object]. Related CAPEC pattern: [object Object].

Related weaknesses· 10

CWE-294CWE-290CWE-346CWE-384CWE-488CWE-539CWE-200CWE-285CWE-664CWE-732

MITRE ATT&CK crosswalk· 2

T1134.001: Access Token Manipulation:Token Impersonation/TheftT1550.004: Use Alternate Authentication Material:Web Session Cookie

Related attack patterns· 1

CAPEC-593 (ChildOf)

Exploits10

TypeTargetConfidenceTier
WeaknessImproper Control of a Resource Through its Lifetimecwe-664100%live
WeaknessImproper Authorizationcwe-285100%live
WeaknessAuthentication Bypass by Spoofingcwe-290100%live
WeaknessUse of Persistent Cookies Containing Sensitive Informationcwe-539100%live
WeaknessSession Fixationcwe-384100%live
WeaknessIncorrect Permission Assignment for Critical Resourcecwe-732100%live
WeaknessOrigin Validation Errorcwe-346100%live
WeaknessAuthentication Bypass by Capture-replaycwe-294100%live
WeaknessExposure of Data Element to Wrong Sessioncwe-488100%live
WeaknessExposure of Sensitive Information to an Unauthorized Actorcwe-200100%live

Related to2

TypeTargetConfidenceTier
SubTechniqueToken Impersonation/Theftt1134.001100%live
SubTechniqueWeb Session Cookiet1550.004100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Session Credential Falsification through Prediction
CAPEC
Session Fixation
CAPEC
Session Hijacking
CAPEC
Session Credential Falsification through Forging
CAPEC
Session Credential Falsification through Manipulation
CAPEC
Session Sidejacking
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.