CAPEC-161: Infrastructure Manipulation

ID CAPEC-161
Typical Severity High
Status Draft

An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Most often, this involves manipulation of the routing of network messages so, instead of arriving at their proper destination, they are directed towards an entity of the attackers' choosing, usually a server controlled by the attacker. The victim is often unaware that their messages are not being processed correctly. For example, a targeted client may believe they are connecting to their own bank but, in fact, be connecting to a Pharming site controlled by the attacker which then collects the user's login information in order to hijack the actual bank account.

https://capec.mitre.org/data/definitions/161.html

Weaknesses

# ID Name Type
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints weakness
Loading...