615 indexed

CAPECCAPEC attack patterns

615 MITRE CAPEC entries — attack patterns at meta, standard, and detailed abstraction levels. Filter by abstraction. Authored by Adam Lundqvist.

Showing 301–350 of 615 · page 7 of 13

IDTitleSummary
CAPEC-43Exploiting Multiple Input Interpretation LayersAn attacker supplies the target software with input data that contains sequences of special characters designed to bypass input validation logic. This exploit …
CAPEC-430DEPRECATED: Target Influence via Micro-ExpressionsThis attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-431DEPRECATED: Target Influence via Neuro-Linguistic Programming (NLP)This attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-432DEPRECATED: Target Influence via Voice in NLPThis attack pattern has been deprecated. Metadata: detailed CAPEC pattern, status deprecated. Metadata: detailed CAPEC pattern, status deprecated.
CAPEC-433Target Influence via The Human Buffer OverflowAn attacker utilizes a technique to insinuate commands to the subconscious mind of the target via communication patterns. The human buffer overflow methodology…
CAPEC-434Target Influence via Interview and InterrogationMetadata: detailed CAPEC pattern, status draft, severity low. Related CAPEC pattern: [object Object]. Metadata: detailed CAPEC pattern, status draft, severity…
CAPEC-435Target Influence via Instant RapportMetadata: detailed CAPEC pattern, status draft, severity low. Related CAPEC pattern: [object Object]. Metadata: detailed CAPEC pattern, status draft, severity…
CAPEC-438Modification During ManufactureAn attacker modifies a technology, product, or component during a stage in its manufacture for the purpose of carrying out an attack against some entity involv…
CAPEC-439Manipulation During DistributionAn attacker undermines the integrity of a product, software, or technology at some stage of the distribution channel. The core threat of modification or manipu…
CAPEC-44Overflow Binary Resource FileAn attack of this type exploits a buffer overflow vulnerability in the handling of binary resources. Binary resources may include music files like MP3, image f…
CAPEC-440Hardware Integrity AttackAn adversary exploits a weakness in the system maintenance process and causes a change to be made to a technology, product, component, or sub-component or a ne…
CAPEC-441Malicious Logic InsertionAn adversary installs or adds malicious logic (also known as malware) into a seemingly benign component of a fielded system. This logic is often hidden from th…
CAPEC-442Infected SoftwareAn adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic is often hidden from the user of the softwar…
CAPEC-443Malicious Logic Inserted Into Product by Authorized DeveloperAn adversary uses their privileged position within an authorized development organization to inject malicious logic into a codebase or product. Metadata: deta…
CAPEC-444Development AlterationAn adversary modifies a technology, product, or component during its development to acheive a negative impact once the system is deployed. The goal of the adve…
CAPEC-445Malicious Logic Insertion into Product Software via Configuration Management ManipulationMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obj…
CAPEC-446Malicious Logic Insertion into Product via Inclusion of Third-Party ComponentMetadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Obj…
CAPEC-447Design AlterationAn adversary modifies the design of a technology, product, or component to acheive a negative impact once the system is deployed. In this type of attack, the g…
CAPEC-448Embed Virus into DLLAn adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result of compiler optimiz…
CAPEC-449DEPRECATED: Malware Propagation via USB StickThis attack pattern has been deprecated as it is a duplicate of CAPEC-448 : Malware Infection into Product Software. Please refer to this other pattern going f…
CAPEC-45Buffer Overflow via Symbolic LinksThis type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that …
CAPEC-450DEPRECATED: Malware Propagation via USB U3 AutorunThis attack pattern has been deprecated as it is a duplicate of CAPEC-448 : Embed Virus into DLL. Please refer to this other pattern going forward. Metadata: …
CAPEC-451DEPRECATED: Malware Propagation via Infected Peripheral DeviceThis attack pattern has been deprecated as it is a duplicate of CAPEC-448 : Malware Infection into Product Software. Please refer to this other pattern going f…
CAPEC-452Infected HardwareAn adversary inserts malicious logic into hardware, typically in the form of a computer virus or rootkit. This logic is often hidden from the user of the hardw…
CAPEC-453DEPRECATED: Malicious Logic Insertion via Counterfeit HardwareThis attack pattern has been deprecated as it is a duplicate of CAPEC-452 : Malicious Logic Insertion into Product Hardware. Please refer to this other pattern…
CAPEC-454DEPRECATED: Modification of Existing Components with Counterfeit HardwareThis attack pattern has been deprecated as it is a duplicate of CAPEC-452 : Malicious Logic Insertion into Product Hardware. Please refer to this other pattern…
CAPEC-455DEPRECATED: Malicious Logic Insertion via Inclusion of Counterfeit Hardware ComponentsThis attack pattern has been deprecated as it is a duplicate of CAPEC-457 : Malicious Logic Insertion into Product Hardware. Please refer to this other pattern…
CAPEC-456Infected MemoryAn adversary inserts malicious logic into memory enabling them to achieve a negative impact. This logic is often hidden from the user of the system and works b…
CAPEC-457USB Memory AttacksAn adversary loads malicious code onto a USB memory stick in order to infect any system which the device is plugged in to. USB drives present a significant sec…
CAPEC-458Flash Memory AttacksAn adversary inserts malicious logic into a product or technology via flashing the on-board memory with a code-base that contains malicious logic. Various atta…
CAPEC-459Creating a Rogue Certification Authority CertificateAn adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate certificate signing requests (CSR) that co…
CAPEC-46Overflow Variables and TagsThis type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer overflow. The adversary crafts a malicious HTML …
CAPEC-460HTTP Parameter Pollution (HPP)An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP param…
CAPEC-461Web Services API Signature Forgery Leveraging Hash Function Extension WeaknessAn adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating th…
CAPEC-462Cross-Domain Search TimingAn attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses may leak important information on what is …
CAPEC-463Padding Oracle Crypto AttackAn adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened wh…
CAPEC-464EvercookieAn attacker creates a very persistent cookie that stays present even after the user thinks it has been removed. The cookie is stored on the victim's machine in…
CAPEC-465Transparent Proxy AbuseA transparent proxy serves as an intermediate between the client and the internet at large. It intercepts all requests originating from the client and forwards…
CAPEC-466Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin PolicyAn attacker leverages an adversary in the middle attack (CAPEC-94) in order to bypass the same origin policy protection in the victim's browser. This active ad…
CAPEC-467Cross Site IdentificationAn attacker harvests identifying information about a victim via an active session that the victim's browser has with a social networking site. A victim may hav…
CAPEC-468Generic Cross-Browser Cross-Domain TheftAn attacker makes use of Cascading Style Sheets (CSS) injection to steal data cross domain from the victim's browser. The attack works by abusing the standards…
CAPEC-469HTTP DoSAn attacker performs flooding at the HTTP level to bring down only a particular web application rather than anything listening on a TCP/IP connection. This den…
CAPEC-47Buffer Overflow via Parameter ExpansionIn this attack, the target software is given input that the adversary knows will be modified and expanded in size during processing. This attack relies on the …
CAPEC-470Expanding Control over the Operating System from the DatabaseAn attacker is able to leverage access gained to the database to read / write data to the file system, compromise the operating system, create a tunnel for acc…
CAPEC-471Search Order HijackingAn adversary exploits a weakness in an application's specification of external libraries to exploit the functionality of the loader where the process loading t…
CAPEC-472Browser FingerprintingAn attacker carefully crafts small snippets of Java Script to efficiently detect the type of browser the potential victim is using. Many web-based attacks need…
CAPEC-473Signature SpoofAn attacker generates a message or datablock that causes the recipient to believe that the message or datablock was generated and cryptographically signed by a…
CAPEC-474Signature Spoofing by Key TheftAn attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer t…
CAPEC-475Signature Spoofing by Improper ValidationAn adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key. M…
CAPEC-476Signature Spoofing by MisrepresentationAn attacker exploits a weakness in the parsing or display code of the recipient software to generate a data blob containing a supposedly valid signature, but t…
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, Founder at SQUR.