Dark Mode

Settings

Capec-161 Detail

Infrastructure Manipulation

Meta Communications Software Hardware Typical Severity: High

Children: 141 166 268 481 571 700

Threats: T46 T68 T274 T276 T297 T339 T382 T393 T395

Description

An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Most often, this involves manipulation of the routing of network messages so, instead of arriving at their proper destination, they are directed towards an entity of the attackers' choosing, usually a server controlled by the attacker. The victim is often unaware that their messages are not being processed correctly. For example, a targeted client may believe they are connecting to their own bank but, in fact, be connecting to a Pharming site controlled by the attacker which then collects the user's login information in order to hijack the actual bank account.

Not present

External ID Source Link Description
CAPEC-161 capec https://capec.mitre.org/data/definitions/161.html
CWE-923 cwe http://cwe.mitre.org/data/definitions/923.html

Not present

  1. The targeted client must access the site via infrastructure that the attacker has co-opted and must fail to adequately verify that the communication channel is operating correctly (e.g. by verifying that they are, in fact, connected to the site they intended.)
  1. The attacker must be able to corrupt the infrastructure used by the client. For some variants of this attack, the attacker must be able to stand up their own services that mimic the services the targeted client intends to use.

Not present

Not present

Not present