CAPEC 226 Session Credential Falsification through Manipulation

Draft Detailed Unknown Risk
Severity Medium

Description

An attacker manipulates an existing credential in order to gain access to a target application. Session credentials allow users to identify themselves to a service after an initial authentication without needing to resend the authentication information (usually a username and password) with every message. An attacker may be able to manipulate a credential sniffed from an existing connection in order to gain access to a target server.

Consequences

Relationships

Resources Required

1