CAPEC 78 Using Escaped Slashes in Alternate Encoding

Draft Detailed High Risk
Severity High

Description

This attack targets the use of the backslash in alternate encoding. An adversary can provide a backslash as a leading character and causes a parser to believe that the next character is special. This is called an escape. By using that trick, the adversary tries to exploit alternate ways to encode the same character which leads to filter problems and opens avenues to attack.

Attack Execution Flow

3

Mitigations

7

Consequences

Indicators

1

Relationships