CAPEC 461 Web Services API Signature Forgery Leveraging Hash Function Extension Weakness

Draft Standard Unknown Risk
Severity High

Description

An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service.

Attack Execution Flow

3

Mitigations

1

Consequences

Relationships

Resources Required

1