CAPEC - Common Attack Pattern Enumeration and Classification (A Community of Knowledge Resource for Building Secure Software)
Home > CAPEC List > VIEW LIST: CAPEC-283: Standard Abstractions (Release 1.4)  

CAPEC-283: Standard Abstractions

 
Standard Abstractions
Definition in a New Window Definition in a New Window
View ID: 283 (View: Implicit Slice)Status: Draft
+ View Data

View Structure: Implicit_Slice

View Objective

This view (slice) covers standard abstraction attack patterns.

Filter Used: .//@Pattern_Abstraction='Standard'

CAPECs in this viewTotal CAPECs
Total164out of310
Views0out of5
Categories0out of18
Attack Patterns171out of287
Attack PatternAttack Pattern Accessing Functionality Not Properly Constrained by ACLs - (1)
Attack PatternAttack Pattern Accessing, Modifying or Executing Executable Files - (17)
Attack PatternAttack Pattern Action Spoofing - (173)
Attack PatternAttack Pattern API Abuse/Misuse - (113)
Attack PatternAttack Pattern Argument Injection - (6)
Attack PatternAttack Pattern Attack through Shared Data - (124)
Attack PatternAttack Pattern Authentication Abuse - (114)
Attack PatternAttack Pattern Authentication Bypass - (115)
Attack PatternAttack Pattern Block Access to Libraries - (96)
Attack PatternAttack Pattern Brute Force - (112)
Attack PatternAttack Pattern Buffer Attacks - (123)
Attack PatternAttack Pattern Bypassing of Intermediate Forms in Multiple-Form Sets - (140)
Attack PatternAttack Pattern Cache Poisoning - (141)
Attack PatternAttack Pattern Cause Web Server Misclassification - (11)
Attack PatternAttack Pattern Checksum Spoofing - (145)
Attack PatternAttack Pattern Choosing a Message/Channel Identifier on a Public/Multicast Channel - (12)
Attack PatternAttack Pattern Clickjacking - (103)
Attack PatternAttack Pattern Code Inclusion - (175)
Attack PatternAttack Pattern Command Delimiters - (15)
Attack PatternAttack Pattern Command Line Execution through SQL Injection - (108)
Attack PatternAttack Pattern Common resource location exploration - (150)
Attack PatternAttack Pattern Configuration/Environment manipulation - (176)
Attack PatternAttack Pattern Content Spoofing - (148)
Attack PatternAttack Pattern Craft a Maliciously Misconfigured Registry - (270)
Attack PatternAttack Pattern Create files with the same name as files protected with a higher classification - (177)
Attack PatternAttack Pattern Create Malicious Client - (202)
Attack PatternAttack Pattern Cross Site Request Forgery (aka Session Riding) - (62)
Attack PatternAttack Pattern Cross Site Scripting through Log Files - (106)
Attack PatternAttack Pattern Cross Site Tracing - (107)
Attack PatternAttack Pattern Cross Zone Scripting - (104)
Attack PatternAttack Pattern Cross-Site Flashing - (178)
Attack PatternAttack Pattern Cross-Site Scripting in Error Pages - (198)
Attack PatternAttack Pattern Cross-Site Scripting Using Alternate Syntax - (199)
Attack PatternAttack Pattern Cross-Site Scripting Using MIME Type Mismatch - (209)
Attack PatternAttack Pattern Cryptanalysis - (97)
Attack PatternAttack Pattern Data Excavation Attacks - (116)
Attack PatternAttack Pattern Data Interception Attacks - (117)
Attack PatternAttack Pattern Data Interchange Protocol Manipulation - (277)
Attack PatternAttack Pattern Denial of Service through Resource Depletion - (227)
Attack PatternAttack Pattern Detect Unpublicised Web Pages - (143)
Attack PatternAttack Pattern Detect Unpublicised Web Services - (144)
Attack PatternAttack Pattern Directory Indexing - (127)
Attack PatternAttack Pattern Directory Traversal - (213)
Attack PatternAttack Pattern Discovering, querying, and finally calling micro-services, such as w/ AJAX - (179)
Attack PatternAttack Pattern DNS Cache Poisoning - (142)
Attack PatternAttack Pattern DNS Zone Transfers - (291)
Attack PatternAttack Pattern Double Encoding - (120)
Attack PatternAttack Pattern Email Injection - (134)
Attack PatternAttack Pattern Embedding Scripts in Nonscript Elements - (18)
Attack PatternAttack Pattern Embedding Scripts within Scripts - (19)
Attack PatternAttack Pattern Encryption Brute Forcing - (20)
Attack PatternAttack Pattern Enumerate Mail Exchange (MX) Records - (290)
Attack PatternAttack Pattern Exploitation of Authorization - (122)
Attack PatternAttack Pattern Exploitation of Session Variables, Resource IDs and other Trusted Credentials - (21)
Attack PatternAttack Pattern Exploiting Incorrectly Configured Access Control Security Levels - (180)
Attack PatternAttack Pattern Exploiting Multiple Input Interpretation Layers - (43)
Attack PatternAttack Pattern Explore for predictable temporary file names - (149)
Attack PatternAttack Pattern External Entity Attack - (201)
Attack PatternAttack Pattern External Entity Attack - (221)
Attack PatternAttack Pattern Fake the Source of Data - (194)
Attack PatternAttack Pattern File Manipulation - (165)
Attack PatternAttack Pattern File System Function Injection, Content Based - (23)
Attack PatternAttack Pattern Flash File Overlay - (181)
Attack PatternAttack Pattern Flash Injection - (182)
Attack PatternAttack Pattern Flash Parameter Injection - (174)
Attack PatternAttack Pattern Footprinting - (169)
Attack PatternAttack Pattern Force the System to Reset Values - (166)
Attack PatternAttack Pattern Force Use of Corruped Files - (263)
Attack PatternAttack Pattern Forced Deadlock - (25)
Attack PatternAttack Pattern Forced Integer Overflow - (92)
Attack PatternAttack Pattern Forceful Browsing - (87)
Attack PatternAttack Pattern Format String Injection - (135)
Attack PatternAttack Pattern Fuzzing - (28)
Attack PatternAttack Pattern Hijacking a privileged process - (234)
Attack PatternAttack Pattern Hijacking a Privileged Thread of Execution - (30)
Attack PatternAttack Pattern Host Discovery - (292)
Attack PatternAttack Pattern HTTP Request Splitting - (105)
Attack PatternAttack Pattern Identity Spoofing (Impersonation) - (151)
Attack PatternAttack Pattern IMAP/SMTP Command Injection - (183)
Attack PatternAttack Pattern Inducing Account Lockout - (2)
Attack PatternAttack Pattern Infrastructure Manipulation - (161)
Attack PatternAttack Pattern Input Data Manipulation - (153)
Attack PatternAttack Pattern Integer Attacks - (128)
Attack PatternAttack Pattern Inter-component Protocol Manipulation - (276)
Attack PatternAttack Pattern LDAP Injection - (136)
Attack PatternAttack Pattern Leverage Executable Code in Nonexecutable Files - (35)
Attack PatternAttack Pattern Leveraging Race Conditions - (26)
Attack PatternAttack Pattern Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions - (29)
Attack PatternAttack Pattern Leveraging/Manipulating Configuration File Search Paths - (38)
Attack PatternAttack Pattern Lifting cached, sensitive data embedded in client distributions (thick or thin) - (204)
Attack PatternAttack Pattern Lifting credential(s)/key material embedded in client distributions (thick or thin) - (205)
Attack PatternAttack Pattern Lifting Data Embedded in Client Distributions - (37)
Attack PatternAttack Pattern Lifting Sensitive Data from the Client - (167)
Attack PatternAttack Pattern Lifting signing key and signing malicious code from a production environment - (206)
Attack PatternAttack Pattern Locate and Exploit Test APIs - (121)
Attack PatternAttack Pattern Log Injection-Tampering-Forging - (93)
Attack PatternAttack Pattern Malicious Automated Software Update - (187)
Attack PatternAttack Pattern Malicious Software Update - (186)
Attack PatternAttack Pattern Man in the Middle Attack - (94)
Attack PatternAttack Pattern Manipulate Application Registry Values - (203)
Attack PatternAttack Pattern Manipulating hidden fields to change the normal flow of transactions (eShoplifting) - (162)
Attack PatternAttack Pattern Manipulating Input to File System Calls - (76)
Attack PatternAttack Pattern Manipulating Opaque Client-based Data Tokens - (39)
Attack PatternAttack Pattern Manipulating User State - (74)
Attack PatternAttack Pattern Manipulating User-Controlled Variables - (77)
Attack PatternAttack Pattern Manipulating Writeable Configuration Files - (75)
Attack PatternAttack Pattern Mobile Phishing (aka MobPhishing) - (164)
Attack PatternAttack Pattern Object Relational Mapping Injection - (109)
Attack PatternAttack Pattern OS Command Injection - (88)
Attack PatternAttack Pattern Overflow Buffers - (100)
Attack PatternAttack Pattern Oversized Payloads Sent to XML Parsers - (231)
Attack PatternAttack Pattern Parameter Injection - (137)
Attack PatternAttack Pattern Passively Sniff and Capture Application Code Bound for Authorized Client - (65)
Attack PatternAttack Pattern Password Brute Forcing - (49)
Attack PatternAttack Pattern Password Recovery Exploitation - (50)
Attack PatternAttack Pattern Pharming - (89)
Attack PatternAttack Pattern Phishing - (98)
Attack PatternAttack Pattern PHP Remote File Inclusion - (193)
Attack PatternAttack Pattern Pointer Attack - (129)
Attack PatternAttack Pattern Poison Web Service Registry - (51)
Attack PatternAttack Pattern Port Scanning - (300)
Attack PatternAttack Pattern Principal Spoofing - (195)
Attack PatternAttack Pattern Probing an Application Through Targeting its Error Reporting - (54)
Attack PatternAttack Pattern Programming to included script-based APIs - (160)
Attack PatternAttack Pattern Protocol Reverse Engineering - (192)
Attack PatternAttack Pattern Rainbow Table Password Cracking - (55)
Attack PatternAttack Pattern Recursive Payloads Sent to XML Parsers - (230)
Attack PatternAttack Pattern Redirect Access to Libraries - (159)
Attack PatternAttack Pattern Reflection Attack in Authentication Protocol - (90)
Attack PatternAttack Pattern Reflection Injection - (138)
Attack PatternAttack Pattern Relative Path Traversal - (139)
Attack PatternAttack Pattern Removal of filters: Input filters, output filters, data masking - (200)
Attack PatternAttack Pattern Removing Important Functionality from the Client - (207)
Attack PatternAttack Pattern Removing/short-circuiting 'guard logic' - (56)
Attack PatternAttack Pattern Removing/short-circuiting 'Purse' logic: removing/mutating 'cash' decrements - (208)
Attack PatternAttack Pattern Resource Depletion through Allocation - (130)
Attack PatternAttack Pattern Resource Depletion through Flooding - (125)
Attack PatternAttack Pattern Resource Depletion through Leak - (131)
Attack PatternAttack Pattern Resource Location Attacks - (154)
Attack PatternAttack Pattern Reusing Session IDs (aka Session Replay) - (60)
Attack PatternAttack Pattern Reverse Engineer an Executable to Expose Assumed Hidden Functionality or Content - (190)
Attack PatternAttack Pattern Screen Temporary Files for Sensitive Information - (155)
Attack PatternAttack Pattern Server Side Include (SSI) Injection - (101)
Attack PatternAttack Pattern Session Credential Falsification through Forging - (196)
Attack PatternAttack Pattern Session Fixation - (61)
Attack PatternAttack Pattern Session Sidejacking - (102)
Attack PatternAttack Pattern Simple Script Injection - (63)
Attack PatternAttack Pattern Sniffing Attacks - (157)
Attack PatternAttack Pattern Sniffing Information Sent Over Public/multicast Networks - (158)
Attack PatternAttack Pattern Soap Manipulation - (279)
Attack PatternAttack Pattern Spear Phishing - (163)
Attack PatternAttack Pattern SQL Injection - (66)
Attack PatternAttack Pattern SQL Injection through SOAP Parameter Tampering - (110)
Attack PatternAttack Pattern Subversion of authorization checks: cache filtering, programmatic security, etc. - (239)
Attack PatternAttack Pattern Subvert Code-signing Facilities - (68)
Attack PatternAttack Pattern Subverting Environment Variable Values - (13)
Attack PatternAttack Pattern Symlink Attacks - (132)
Attack PatternAttack Pattern Target Programs with Elevated Privileges - (69)
Attack PatternAttack Pattern Try All Common Application Switches and Options - (133)
Attack PatternAttack Pattern URL Encoding - (72)
Attack PatternAttack Pattern User-Controlled Filename - (73)
Attack PatternAttack Pattern Variable Manipulation - (171)
Attack PatternAttack Pattern Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Service (XDoS)) - (82)
Attack PatternAttack Pattern Web Logs Tampering - (81)
Attack PatternAttack Pattern Web Server/Application Fingerprinting - (170)
Attack PatternAttack Pattern Windows ::DATA Alternate Data Stream - (168)
Attack PatternAttack Pattern XEE (XML Entity Expansion) - (197)
Attack PatternAttack Pattern XML Parser Attack - (99)
Attack PatternAttack Pattern XML Ping of Death - (147)
Attack PatternAttack Pattern XML Routing Detour Attacks - (219)
Attack PatternAttack Pattern XML Schema Poisoning - (146)
Page Last Updated: September 22, 2009