Umbra Wiki attack-pattern attack-pattern/CAPEC-154
Back to wiki

CAPEC-154 — Resource Location Spoofing

provenance: imported · CWE: CWE-451

CAPEC-154: Resource Location Spoofing

MITRE CAPEC attack pattern

Status Stable
Typical severity Medium
Likelihood of attack Medium
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary deceives an application or user and convinces them to request a resource from an unintended location. By spoofing the location, the adversary can cause an alternate resource to be used, often one that the adversary controls and can be used to help them achieve their malicious goals.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-451

Prerequisites

  • None. All applications rely on file paths and therefore, in theory, they or their resources could be affected by this type of attack.

Consequences

  • Authorization: Execute Unauthorized Commands

Mitigations

  • Monitor network activity to detect any anomalous or unauthorized communication exchanges.

Source