Dark Mode

Settings

Capec-75 Detail

Manipulating Writeable Configuration Files

Standard Software Likelihood: High Typical Severity: Very High

Parents: 176

Threats: T62 T68 T269 T270 T271 T272 T273 T274 T297 T393

Description

Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.

Not present

External ID Source Link Description
CAPEC-75 capec https://capec.mitre.org/data/definitions/75.html
CWE-349 cwe http://cwe.mitre.org/data/definitions/349.html
CWE-99 cwe http://cwe.mitre.org/data/definitions/99.html
CWE-77 cwe http://cwe.mitre.org/data/definitions/77.html
CWE-346 cwe http://cwe.mitre.org/data/definitions/346.html
CWE-353 cwe http://cwe.mitre.org/data/definitions/353.html
CWE-354 cwe http://cwe.mitre.org/data/definitions/354.html
REF-1 reference_from_CAPEC G. Hoglund, G. McGraw, Exploiting Software: How to Break Code, 2004--02, Addison-Wesley

Not present

  1. Configuration files must be modifiable by the attacker

Not present

Medium
To identify vulnerable configuration files, and understand how to manipulate servers and erase forensic evidence
Authorization Access Control Confidentiality
Gain Privileges Gain Privileges Gain Privileges
  1. The BEA Weblogic server uses a config.xml file to store configuration data. If this file is not properly protected by the system access control, an attacker can write configuration information to redirect server output through system logs, database connections, malicious URLs and so on. Access to the Weblogic server may be from a so-called Custom realm which manages authentication and authorization privileges on behalf of user principals. Given write access, the attacker can insert a pointer to a custom realm jar file in the config.xml < CustomRealmConfigurationData="java.util.Properties"Name="CustomRealm"RealmClassName="Maliciousrealm.jar"/> The main issue with configuration files is that the attacker can leverage all the same functionality the server has, but for malicious means. Given the complexity of server configuration, these changes may be very hard for administrators to detect.