Umbra Wiki attack-pattern attack-pattern/CAPEC-460
Back to wiki

CAPEC-460 — HTTP Parameter Pollution (HPP)

provenance: imported · CWE: CWE-88 CWE-147 CWE-235

CAPEC-460: HTTP Parameter Pollution (HPP)

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be possible to override existing hardcoded HTTP parameters, modify the application behaviors, access and, potentially exploit, uncontrollable variables, and bypass input validation checkpoints and WAF rules.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-88, CWE-147, CWE-235

Prerequisites

  • HTTP protocol is used with some GET/POST parameters passed

Mitigations

  • Configuration: If using a Web Application Firewall (WAF), filters should be carefully configured to detect abnormal HTTP requests
  • Design: Perform URL encoding
  • Implementation: Use strict regular expressions in URL rewriting
  • Implementation: Beware of multiple occurrences of a parameter in a Query String

Source