Detailedlikelihood: Lowseverity: MediumDraft

CAPEC-611BitSquatting

Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
Medium

Description

An adversary registers a domain name one bit different than a trusted domain. A BitSquatting attack leverages random errors in memory to direct Internet traffic to adversary-controlled destinations. BitSquatting requires no exploitation or complicated reverse engineering, and is operating system and architecture agnostic. Experimental observations show that BitSquatting popular websites could redirect non-trivial amounts of Internet traffic to a malicious entity.

Related attack patterns· 3

CAPEC-616 (ChildOf)CAPEC-89 (CanPrecede)CAPEC-543 (CanPrecede)

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
SoundSquatting
CAPEC
TypoSquatting
CAPEC
DNS Cache Poisoning
CAPEC
DNS Spoofing
CAPEC
Scheme Squatting
CAPEC
DNS Rebinding
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.