Attack patterns (CAPEC)
558 pages, showing 201–300, ordered by identifier.
- CAPEC-32 — XSS Through HTTP Query Strings An adversary embeds malicious script code in the parameters of an HTTP query string and convinces a victim to submit...
- CAPEC-320 — TCP Timestamp Probe This OS fingerprinting probe examines the remote server's implementation of TCP timestamps. Not all operating...
- CAPEC-321 — TCP Sequence Number Probe This OS fingerprinting probe tests the target system's assignment of TCP sequence numbers. One common way to test...
- CAPEC-322 — TCP (ISN) Greatest Common Divisor Probe This OS fingerprinting probe sends a number of TCP SYN packets to an open port of a remote machine. The Initial...
- CAPEC-323 — TCP (ISN) Counter Rate Probe This OS detection probe measures the average rate of initial sequence number increments during a period of time....
- CAPEC-324 — TCP (ISN) Sequence Predictability Probe This type of operating system probe attempts to determine an estimate for how predictable the sequence number...
- CAPEC-325 — TCP Congestion Control Flag (ECN) Probe This OS fingerprinting probe checks to see if the remote host supports explicit congestion notification (ECN)...
- CAPEC-326 — TCP Initial Window Size Probe This OS fingerprinting probe checks the initial TCP Window size. TCP stacks limit the range of sequence numbers...
- CAPEC-327 — TCP Options Probe This OS fingerprinting probe analyzes the type and order of any TCP header options present within a response...
- CAPEC-328 — TCP 'RST' Flag Checksum Probe This OS fingerprinting probe performs a checksum on any ASCII data contained within the data portion or a RST...
- CAPEC-329 — ICMP Error Message Quoting Probe An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable,...
- CAPEC-33 — HTTP Request Smuggling An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages...
- CAPEC-330 — ICMP Error Message Echoing Integrity Probe An adversary uses a technique to generate an ICMP Error message (Port Unreachable, Destination Unreachable,...
- CAPEC-331 — ICMP IP Total Length Field Probe An adversary sends a UDP packet to a closed port on the target machine to solicit an IP Header's total length field...
- CAPEC-332 — ICMP IP 'ID' Field Error Message Probe An adversary sends a UDP datagram having an assigned value to its internet identification field (ID) to a closed...
- CAPEC-34 — HTTP Response Splitting An adversary manipulates and injects malicious content, in the form of secret unauthorized HTTP responses, into a...
- CAPEC-35 — Leverage Executable Code in Non-Executable Files An attack of this type exploits a system's trust in configuration and resource files. When the executable loads the...
- CAPEC-36 — Using Unpublished Interfaces or Functionality An adversary searches for and invokes interfaces or functionality that the target system designers did not intend to...
- CAPEC-37 — Retrieve Embedded Sensitive Data An attacker examines a target system to find sensitive data that has been embedded within it. This information can...
- CAPEC-38 — Leveraging/Manipulating Configuration File Search Paths This pattern of attack sees an adversary load a malicious resource into a program's standard path so that when a...
- CAPEC-383 — Harvesting Information via API Event Monitoring An adversary hosts an event within an application framework and then monitors the data exchanged during the course...
- CAPEC-384 — Application API Message Manipulation via Man-in-the-Middle An attacker manipulates either egress or ingress data from a client within an application framework in order to...
- CAPEC-385 — Transaction or Event Tampering via Application API Manipulation An attacker hosts or joins an event or transaction within an application framework in order to change the content of...
- CAPEC-386 — Application API Navigation Remapping An attacker manipulates either egress or ingress data from a client within an application framework in order to...
- CAPEC-387 — Navigation Remapping To Propagate Malicious Content An adversary manipulates either egress or ingress data from a client within an application framework in order to...
- CAPEC-388 — Application API Button Hijacking An attacker manipulates either egress or ingress data from a client within an application framework in order to...
- CAPEC-389 — Content Spoofing Via Application API Manipulation An attacker manipulates either egress or ingress data from a client within an application framework in order to...
- CAPEC-39 — Manipulating Opaque Client-based Data Tokens In circumstances where an application holds important data client-side in tokens (cookies, URLs, data files, and so...
- CAPEC-390 — Bypassing Physical Security Facilities often used layered models for physical security such as traditional locks, Electronic-based card entry...
- CAPEC-391 — Bypassing Physical Locks An attacker uses techniques and methods to bypass physical security measures of a building or facility. Physical...
- CAPEC-392 — Lock Bumping An attacker uses a bump key to force a lock on a building or facility and gain entry. Lock Bumping is the use of a...
- CAPEC-393 — Lock Picking An attacker uses lock picking tools and techniques to bypass the locks on a building or facility. Lock picking is...
- CAPEC-394 — Using a Snap Gun Lock to Force a Lock An attacker uses a Snap Gun, also known as a Pick Gun, to force the lock on a building or facility. A Pick Gun is a...
- CAPEC-395 — Bypassing Electronic Locks and Access Controls An attacker exploits security assumptions to bypass electronic locks or other forms of access controls. Most attacks...
- CAPEC-397 — Cloning Magnetic Strip Cards An attacker duplicates the data on a Magnetic strip card (i.e. 'swipe card' or 'magstripe') to gain unauthorized...
- CAPEC-398 — Magnetic Strip Card Brute Force Attacks An adversary analyzes the data on two or more magnetic strip cards and is able to generate new cards containing...
- CAPEC-399 — Cloning RFID Cards or Chips An attacker analyzes data returned by an RFID chip and uses this information to duplicate a RFID signal that...
- CAPEC-4 — Using Alternative IP Address Encodings This attack relies on the adversary using unexpected formats for representing IP addresses. Networked applications...
- CAPEC-40 — Manipulating Writeable Terminal Devices This attack exploits terminal devices that allow themselves to be written to by other users. The attacker sends...
- CAPEC-400 — RFID Chip Deactivation or Destruction An attacker uses methods to deactivate a passive RFID tag for the purpose of rendering the tag, badge, card, or...
- CAPEC-401 — Physically Hacking Hardware An adversary exploits a weakness in access control to gain access to currently installed hardware and precedes to...
- CAPEC-402 — Bypassing ATA Password Security An adversary exploits a weakness in ATA security on a drive to gain access to the information the drive contains...
- CAPEC-406 — Dumpster Diving An adversary cases an establishment and searches through trash bins, dumpsters, or areas where company information...
- CAPEC-407 — Pretexting An adversary engages in pretexting behavior to solicit information from target persons, or manipulate the target...
- CAPEC-41 — Using Meta-characters in E-mail Headers to Inject Malicious Payloads This type of attack involves an attacker leveraging meta-characters in email headers to inject improper behavior...
- CAPEC-410 — Information Elicitation An adversary engages an individual using any combination of social engineering methods for the purpose of extracting...
- CAPEC-412 — Pretexting via Customer Service An adversary engages in pretexting behavior, assuming the role of someone who works for Customer Service, to solicit...
- CAPEC-413 — Pretexting via Tech Support An adversary engages in pretexting behavior, assuming the role of a tech support worker, to solicit information from...
- CAPEC-414 — Pretexting via Delivery Person An adversary engages in pretexting behavior, assuming the role of a delivery person, to solicit information from...
- CAPEC-415 — Pretexting via Phone An adversary engages in pretexting behavior, assuming some sort of trusted role, and contacting the targeted...
- CAPEC-416 — Manipulate Human Behavior An adversary exploits inherent human psychological predisposition to influence a targeted individual or group to...
- CAPEC-417 — Influence Perception The adversary uses social engineering to exploit the target's perception of the relationship between the adversary...
- CAPEC-418 — Influence Perception of Reciprocation An adversary uses a social engineering techniques to produce a sense of obligation in the target to perform a...
- CAPEC-42 — MIME Conversion An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the...
- CAPEC-420 — Influence Perception of Scarcity The adversary leverages a perception of scarcity to persuade the target to perform an action or divulge information...
- CAPEC-421 — Influence Perception of Authority An adversary uses a social engineering technique to convey a sense of authority that motivates the target to reveal...
- CAPEC-422 — Influence Perception of Commitment and Consistency An adversary uses social engineering to convince the target to do minor tasks as opposed to larger actions. After...
- CAPEC-423 — Influence Perception of Liking The adversary influences the target's actions by building a relationship where the target has a liking to the...
- CAPEC-424 — Influence Perception of Consensus or Social Proof The adversary influences the target's actions by leveraging the inherent human nature to assume behavior of others...
- CAPEC-425 — Target Influence via Framing An adversary uses framing techniques to contextualize a conversation so that the target is more likely to be...
- CAPEC-426 — Influence via Incentives The adversary incites a behavior from the target by manipulating something of influence. This is commonly associated...
- CAPEC-427 — Influence via Psychological Principles The adversary shapes the target's actions or behavior by focusing on the ways human interact and learn, leveraging...
- CAPEC-428 — Influence via Modes of Thinking The adversary tailors their communication to the language and thought patterns of the target thereby weakening...
- CAPEC-429 — Target Influence via Eye Cues The adversary gains information via non-verbal means from the target through eye movements.
- CAPEC-43 — Exploiting Multiple Input Interpretation Layers An attacker supplies the target software with input data that contains sequences of special characters designed to...
- CAPEC-433 — Target Influence via The Human Buffer Overflow An attacker utilizes a technique to insinuate commands to the subconscious mind of the target via communication...
- CAPEC-434 — Target Influence via Interview and Interrogation
- CAPEC-435 — Target Influence via Instant Rapport
- CAPEC-438 — Modification During Manufacture An attacker modifies a technology, product, or component during a stage in its manufacture for the purpose of...
- CAPEC-439 — Manipulation During Distribution An attacker undermines the integrity of a product, software, or technology at some stage of the distribution...
- CAPEC-44 — Overflow Binary Resource File An attack of this type exploits a buffer overflow vulnerability in the handling of binary resources. Binary...
- CAPEC-440 — Hardware Integrity Attack An adversary exploits a weakness in the system maintenance process and causes a change to be made to a technology,...
- CAPEC-441 — Malicious Logic Insertion An adversary installs or adds malicious logic (also known as malware) into a seemingly benign component of a fielded...
- CAPEC-442 — Infected Software An adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic...
- CAPEC-443 — Malicious Logic Inserted Into Product by Authorized Developer An adversary uses their privileged position within an authorized development organization to inject malicious logic...
- CAPEC-444 — Development Alteration An adversary modifies a technology, product, or component during its development to acheive a negative impact once...
- CAPEC-445 — Malicious Logic Insertion into Product Software via Configuration Management Manipulation An adversary exploits a configuration management system so that malicious logic is inserted into a software products...
- CAPEC-446 — Malicious Logic Insertion into Product via Inclusion of Third-Party Component An adversary conducts supply chain attacks by the inclusion of insecure third-party components into a technology,...
- CAPEC-447 — Design Alteration An adversary modifies the design of a technology, product, or component to acheive a negative impact once the system...
- CAPEC-448 — Embed Virus into DLL An adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These...
- CAPEC-45 — Buffer Overflow via Symbolic Links This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or...
- CAPEC-452 — Infected Hardware An adversary inserts malicious logic into hardware, typically in the form of a computer virus or rootkit. This logic...
- CAPEC-456 — Infected Memory An adversary inserts malicious logic into memory enabling them to achieve a negative impact. This logic is often...
- CAPEC-457 — USB Memory Attacks An adversary loads malicious code onto a USB memory stick in order to infect any system which the device is plugged...
- CAPEC-458 — Flash Memory Attacks An adversary inserts malicious logic into a product or technology via flashing the on-board memory with a code-base...
- CAPEC-459 — Creating a Rogue Certification Authority Certificate An adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate...
- CAPEC-46 — Overflow Variables and Tags This type of attack leverages the use of tags or variables from a formatted configuration data to cause buffer...
- CAPEC-460 — HTTP Parameter Pollution (HPP) An adversary adds duplicate HTTP GET/POST parameters by injecting query string delimiters. Via HPP it may be...
- CAPEC-461 — Web Services API Signature Forgery Leveraging Hash Function Extension Weakness An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service...
- CAPEC-462 — Cross-Domain Search Timing An attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses...
- CAPEC-463 — Padding Oracle Crypto Attack An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on...
- CAPEC-464 — Evercookie An attacker creates a very persistent cookie that stays present even after the user thinks it has been removed. The...
- CAPEC-465 — Transparent Proxy Abuse A transparent proxy serves as an intermediate between the client and the internet at large. It intercepts all...
- CAPEC-466 — Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy An attacker leverages an adversary in the middle attack (CAPEC-94) in order to bypass the same origin policy...
- CAPEC-467 — Cross Site Identification An attacker harvests identifying information about a victim via an active session that the victim's browser has with...
- CAPEC-468 — Generic Cross-Browser Cross-Domain Theft An attacker makes use of Cascading Style Sheets (CSS) injection to steal data cross domain from the victim's...
- CAPEC-469 — HTTP DoS An attacker performs flooding at the HTTP level to bring down only a particular web application rather than anything...
- CAPEC-47 — Buffer Overflow via Parameter Expansion In this attack, the target software is given input that the adversary knows will be modified and expanded in size...
- CAPEC-470 — Expanding Control over the Operating System from the Database An attacker is able to leverage access gained to the database to read / write data to the file system, compromise...
- CAPEC-471 — Search Order Hijacking An adversary exploits a weakness in an application's specification of external libraries to exploit the...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.