CAPEC-497: File Discovery

Standard Draft 严重程度: Very Low 攻击可能性: High

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and security parameters of the targeted application, system or network. Using this knowledge may often pave the way for more damaging attacks.

前提条件

  • The adversary must know the location of these common key files.

后果影响

影响范围: Confidentiality

技术影响: Read Data

缓解措施

Leverage file protection mechanisms to render these files accessible only to authorized parties.

分类映射

分类名称 条目ID 条目名称
ATTACK 1083 File and Directory Discovery
关键信息

CAPEC ID: CAPEC-497

抽象级别: Standard

状态: Draft

典型严重程度: Very Low

攻击可能性: High

相关攻击模式
相关CWE弱点