CAPEC - Common Attack Pattern Enumeration and Classification (A Community of Knowledge Resource for Building Secure Software)
Home > CAPEC List > VIEW LIST: CAPEC-284: Detailed Abstractions (Release 1.4)  

CAPEC-284: Detailed Abstractions

 
Detailed Abstractions
Definition in a New Window Definition in a New Window
View ID: 284 (View: Implicit Slice)Status: Draft
+ View Data

View Structure: Implicit_Slice

View Objective

This view (slice) covers detailed abstraction attack patterns.

Filter Used: .//@Pattern_Abstraction='Detailed'

CAPECs in this viewTotal CAPECs
Total80out of310
Views0out of5
Categories0out of18
Attack Patterns87out of287
Attack PatternAttack Pattern Accessing/Intercepting/Modifying HTTP Cookies - (31)
Attack PatternAttack Pattern Analog In-band Switching Signals (aka Blue Boxing) - (5)
Attack PatternAttack Pattern Blind SQL Injection - (7)
Attack PatternAttack Pattern Buffer Overflow in an API Call - (8)
Attack PatternAttack Pattern Buffer Overflow in Local Command-Line Utilities - (9)
Attack PatternAttack Pattern Buffer Overflow via Environment Variables - (10)
Attack PatternAttack Pattern Buffer Overflow via Parameter Expansion - (47)
Attack PatternAttack Pattern Buffer Overflow via Symbolic Links - (45)
Attack PatternAttack Pattern Calling signed code from another language within a sandbox that allows this - (237)
Attack PatternAttack Pattern Catching exception throw/signal from privileged block - (236)
Attack PatternAttack Pattern Client Network Footprinting (using AJAX/XSS) - (85)
Attack PatternAttack Pattern Client-side Injection-induced Buffer Overflow - (14)
Attack PatternAttack Pattern Cross-Site Scripting in Attributes - (243)
Attack PatternAttack Pattern Cross-Site Scripting Using Doubled Characters, e.g. %3C%3Cscript - (245)
Attack PatternAttack Pattern Cross-Site Scripting via Encoded URI Schemes - (244)
Attack PatternAttack Pattern Cross-Site Scripting with Masking through Invalid Characters in Identifiers - (247)
Attack PatternAttack Pattern Dictionary-based Password Attack - (16)
Attack PatternAttack Pattern DNS Rebinding - (275)
Attack PatternAttack Pattern DTD Injection in a SOAP Message - (254)
Attack PatternAttack Pattern Embedding NULL Bytes - (52)
Attack PatternAttack Pattern Embedding Script (XSS ) in HTTP Headers - (86)
Attack PatternAttack Pattern Embedding Scripts in HTTP Query Strings - (32)
Attack PatternAttack Pattern Exploiting Incorrectly Configured SSL Security Levels - (217)
Attack PatternAttack Pattern Filter Failure through Buffer Overflow - (24)
Attack PatternAttack Pattern Fuzzing and observing application log data/errors for application mapping - (215)
Attack PatternAttack Pattern Fuzzing for garnering (through web or log) other adjacent user/sensitive data as an authorized system user (overly broad but valid SQL queries) - (261)
Attack PatternAttack Pattern Fuzzing for garnering J2EE/.NET-based stack traces, for application mapping - (214)
Attack PatternAttack Pattern HTTP Request Smuggling - (33)
Attack PatternAttack Pattern HTTP Response Smuggling - (273)
Attack PatternAttack Pattern HTTP Response Splitting - (34)
Attack PatternAttack Pattern HTTP Verb Tampering - (274)
Attack PatternAttack Pattern ICMP Address Mask Request - (294)
Attack PatternAttack Pattern ICMP Echo Request Ping - (285)
Attack PatternAttack Pattern ICMP Echo Request Ping - (288)
Attack PatternAttack Pattern ICMP Information Request - (296)
Attack PatternAttack Pattern ICMP Timestamp Request - (295)
Attack PatternAttack Pattern Implementing a callback to system routine (old AWT Queue) - (235)
Attack PatternAttack Pattern JSON Hijacking (aka JavaScript Hijacking) - (111)
Attack PatternAttack Pattern Leveraging Race Conditions via Symbolic Links - (27)
Attack PatternAttack Pattern Leveraging web tools (e.g. Mozilla's GreaseMonkey, Firebug) to change application behavior - (211)
Attack PatternAttack Pattern Manipulating Writeable Terminal Devices - (40)
Attack PatternAttack Pattern MIME Conversion - (42)
Attack PatternAttack Pattern Overflow Binary Resource File - (44)
Attack PatternAttack Pattern Overflow Variables and Tags - (46)
Attack PatternAttack Pattern Passing Local Filenames to Functions That Expect a URL - (48)
Attack PatternAttack Pattern Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Dynamic Update - (258)
Attack PatternAttack Pattern Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Initial Distribution - (260)
Attack PatternAttack Pattern Passively Sniffing and Capturing Application Code Bound for an Authorized Client During Patching - (259)
Attack PatternAttack Pattern Postfix, Null Terminate, and Backslash - (53)
Attack PatternAttack Pattern Read Sensitive Stings Within an Executable - (191)
Attack PatternAttack Pattern Resource Depletion through DTD Injection in a SOAP Message - (228)
Attack PatternAttack Pattern Restful Privilege Elevation - (58)
Attack PatternAttack Pattern Session Credential Falsification through Manipulation - (226)
Attack PatternAttack Pattern Session Credential Falsification through Prediction - (59)
Attack PatternAttack Pattern SOAP Array Overflow - (256)
Attack PatternAttack Pattern SOAP Parameter Tampering - (280)
Attack PatternAttack Pattern Spoofing of UDDI/ebXML Messages - (218)
Attack PatternAttack Pattern String Format Overflow in syslog() - (67)
Attack PatternAttack Pattern TCP ACK Ping - (297)
Attack PatternAttack Pattern TCP ACK Scan - (305)
Attack PatternAttack Pattern TCP Connect Scan - (301)
Attack PatternAttack Pattern TCP FIN scan - (302)
Attack PatternAttack Pattern TCP Null Scan - (304)
Attack PatternAttack Pattern TCP RPC Scan - (307)
Attack PatternAttack Pattern TCP SYN Ping - (299)
Attack PatternAttack Pattern TCP SYN Scan - (287)
Attack PatternAttack Pattern TCP Window Scan - (306)
Attack PatternAttack Pattern TCP Xmas Scan - (303)
Attack PatternAttack Pattern Traceroute Route Enumeration - (293)
Attack PatternAttack Pattern Try Common(default) Usernames and Passwords - (70)
Attack PatternAttack Pattern UDP Ping - (298)
Attack PatternAttack Pattern UDP Scan - (308)
Attack PatternAttack Pattern Using Alternative IP Address Encodings - (4)
Attack PatternAttack Pattern Using Escaped Slashes in Alternate Encoding - (78)
Attack PatternAttack Pattern Using Leading 'Ghost' Character Sequences to Bypass Input Filters - (3)
Attack PatternAttack Pattern Using Meta-characters in E-mail Headers to Inject Malicious Payloads - (41)
Attack PatternAttack Pattern Using Slashes and URL Encoding Combined to Bypass Validation Logic - (64)
Attack PatternAttack Pattern Using Slashes in Alternate Encoding - (79)
Attack PatternAttack Pattern Using Unicode Encoding to Bypass Validation Logic - (71)
Attack PatternAttack Pattern Using Unpublished Web Service APIs - (36)
Attack PatternAttack Pattern Using URL/codebase / G.A.C. (code source) to convince sandbox of privilege - (238)
Attack PatternAttack Pattern Using UTF-8 Encoding to Bypass Validation Logic - (80)
Attack PatternAttack Pattern Utilizing REST's Trust in the System Resource to Register Man in the Middle - (57)
Attack PatternAttack Pattern WSDL Scanning - (95)
Attack PatternAttack Pattern XPath Injection - (83)
Attack PatternAttack Pattern XQuery Injection - (84)
Attack PatternAttack Pattern XSS in IMG Tags - (91)
Page Last Updated: September 22, 2009