615 indexed

CAPECCAPEC attack patterns

615 MITRE CAPEC entries — attack patterns at meta, standard, and detailed abstraction levels. Filter by abstraction. Authored by Adam Lundqvist.

Showing 551–600 of 615 · page 12 of 13

IDTitleSummary
CAPEC-667Bluetooth Impersonation AttackS (BIAS)An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and trusted connection and authenticates succe…
CAPEC-668Key Negotiation of Bluetooth Attack (KNOB)An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two devices communicating via Bluetooth. The adv…
CAPEC-669Alteration of a Software UpdateMetadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC patterns: [object Obj…
CAPEC-67String Format Overflow in syslog()This attack targets applications and software that uses the syslog() function insecurely. If an application does not explicitely use a format string parameter …
CAPEC-670Software Development Tools Maliciously AlteredAn adversary with the ability to alter tools used in a development environment causes software to be developed with maliciously modified tools. Such tools incl…
CAPEC-671Requirements for ASIC Functionality Maliciously AlteredAn adversary with access to functional requirements for an application specific integrated circuit (ASIC), a chip designed/customized for a singular particular…
CAPEC-672Malicious Code Implanted During Chip ProgrammingMetadata: detailed CAPEC pattern, status draft, likelihood low, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object]…
CAPEC-673Developer Signing Maliciously Altered SoftwareMetadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obje…
CAPEC-674Design for FPGA Maliciously AlteredMetadata: detailed CAPEC pattern, status stable, likelihood low, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object…
CAPEC-675Retrieve Data from Decommissioned DevicesMetadata: standard CAPEC pattern, status stable, likelihood medium, severity medium. Underlying weakness: CWE-1266. Mapped ATT&CK technique: [object Object]. R…
CAPEC-676NoSQL InjectionMetadata: standard CAPEC pattern, status stable, likelihood high, severity high. Underlying weaknesses: CWE-943, CWE-1286. Related CAPEC pattern: [object Objec…
CAPEC-677Server Motherboard CompromiseMetadata: detailed CAPEC pattern, status draft, likelihood low, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object]…
CAPEC-678System Build Data Maliciously AlteredMetadata: detailed CAPEC pattern, status draft, likelihood low, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object]…
CAPEC-679Exploitation of Improperly Configured or Implemented Memory ProtectionsMetadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1222, CWE-1252, CWE-1257, CWE-1260, CWE-1274 …
CAPEC-68Subvert Code-signing FacilitiesMany languages use code signing facilities to vouch for code's identity and to thus tie code to its assigned privileges within an environment. Subverting this …
CAPEC-680Exploitation of Improperly Controlled RegistersMetadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-1224, CWE-1231, CWE-1233, CWE-1262, CWE-1283. Rela…
CAPEC-681Exploitation of Improperly Controlled Hardware Security IdentifiersMetadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1259, CWE-1267, CWE-1270, CWE-1294, CWE-1302.…
CAPEC-682Exploitation of Firmware or ROM Code with Unpatchable VulnerabilitiesAn adversary may exploit vulnerable code (i.e., firmware or ROM) that is unpatchable. Unpatchable devices exist due to manufacturers intentionally or inadverte…
CAPEC-69Target Programs with Elevated PrivilegesThis attack targets programs running with elevated privileges. The adversary tries to leverage a vulnerability in the running program and get arbitrary code to…
CAPEC-690Metadata SpoofingMetadata: meta CAPEC pattern, status stable, likelihood medium, severity high. Metadata: meta CAPEC pattern, status stable, likelihood medium, severity high.
CAPEC-691Spoof Open-Source Software MetadataMetadata: standard CAPEC pattern, status stable, likelihood medium, severity high. Underlying weakness: CWE-494. Mapped ATT&CK techniques: [object Object], [ob…
CAPEC-692Spoof Version Control System Commit MetadataMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Underlying weakness: CWE-494. Related CAPEC pattern: [object Object]. Metad…
CAPEC-693StarJackingMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Underlying weakness: CWE-494. Related CAPEC pattern: [object Object]. Metad…
CAPEC-694System Location DiscoveryMetadata: standard CAPEC pattern, status stable, likelihood high, severity very low. Underlying weakness: CWE-497. Mapped ATT&CK technique: [object Object]. Re…
CAPEC-695Repo JackingMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Underlying weaknesses: CWE-494, CWE-829. Mapped ATT&CK technique: [object Ob…
CAPEC-696Load Value InjectionAn adversary exploits a hardware design flaw in a CPU implementation of transient instruction execution in which a faulting or assisted load instruction transi…
CAPEC-697DHCP SpoofingMetadata: standard CAPEC pattern, status stable, likelihood low, severity high. Underlying weakness: CWE-923. Mapped ATT&CK technique: [object Object]. Related…
CAPEC-698Install Malicious ExtensionMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Underlying weaknesses: CWE-507, CWE-829. Mapped ATT&CK techniques: [object O…
CAPEC-699Eavesdropping on a MonitorAn Adversary can eavesdrop on the content of an external monitor through the air without modifying any cable or installing software, just capturing this signal…
CAPEC-7Blind SQL InjectionBlind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered best practice, the s…
CAPEC-70Try Common or Default Usernames and PasswordsAn adversary may try certain common or default usernames and passwords to gain access into the system and perform unauthorized actions. An adversary may try an…
CAPEC-700Network Boundary BridgingAn adversary which has gained elevated access to network boundary devices may use these devices to create a channel to bridge trusted and untrusted networks. B…
CAPEC-701Browser in the Middle (BiTM)An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection in the victim's browser to th…
CAPEC-702Exploiting Incorrect Chaining or Granularity of Hardware Debug ComponentsMetadata: detailed CAPEC pattern, status draft, likelihood low, severity medium. Underlying weakness: CWE-1296. Related CAPEC pattern: [object Object]. Metada…
CAPEC-71Using Unicode Encoding to Bypass Validation LogicAn attacker may provide a Unicode string to a system component that is not Unicode aware and use that to circumvent the filter or cause the classifying mechani…
CAPEC-72URL EncodingThis attack targets the encoding of the URL. An adversary can take advantage of the multiple way of encoding an URL and abuse the interpretation of the URL. M…
CAPEC-73User-Controlled FilenameAn attack of this type involves an adversary inserting malicious characters (such as a XSS redirection) into a filename, directly or indirectly that is then us…
CAPEC-74Manipulating StateMetadata: meta CAPEC pattern, status stable, likelihood medium, severity high. Underlying weaknesses: CWE-372, CWE-315, CWE-353, CWE-693, CWE-1245 (and 3 more)…
CAPEC-75Manipulating Writeable Configuration FilesGenerally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files,…
CAPEC-76Manipulating Web Input to File System CallsAn attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perha…
CAPEC-77Manipulating User-Controlled VariablesThis attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An adversary can override variables leveraging user-supplied, untrusted que…
CAPEC-78Using Escaped Slashes in Alternate EncodingThis attack targets the use of the backslash in alternate encoding. An adversary can provide a backslash as a leading character and causes a parser to believe …
CAPEC-79Using Slashes in Alternate EncodingThis attack targets the encoding of the Slash characters. An adversary would try to exploit common filtering problems related to the use of the slashes charact…
CAPEC-8Buffer Overflow in an API CallThis attack targets libraries or shared code modules which are vulnerable to buffer overflow attacks. An adversary who has knowledge of known vulnerable librar…
CAPEC-80Using UTF-8 Encoding to Bypass Validation LogicThis attack is a specific variation on leveraging alternate encodings to bypass validation logic. This attack leverages the possibility to encode potentially h…
CAPEC-81Web Server Logs TamperingWeb Logs Tampering attacks involve an attacker injecting, deleting or otherwise tampering with the contents of web logs typically for the purposes of masking o…
CAPEC-82DEPRECATED: Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Service (XDoS))This attack pattern has been deprecated as it a generalization of CAPEC-230: XML Nested Payloads, CAPEC-231: XML Oversized Payloads, and CAPEC-147: XML Ping of…
CAPEC-83XPath InjectionAn attacker can craft special user-controllable input consisting of XPath expressions to inject the XML database and bypass authentication or glean information…
CAPEC-84XQuery InjectionThis attack utilizes XQuery to probe and attack server systems; in a similar manner that SQL Injection allows an attacker to exploit SQL calls to RDBMS, XQuery…
CAPEC-85AJAX FootprintingThis attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it do…
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, Founder at SQUR.