CAPEC 93 Log Injection-Tampering-Forging

Draft Detailed High Risk
Severity High

Description

This attack targets the log files of the target host. The attacker injects, manipulates or forges malicious log entries in the log file, allowing them to mislead a log audit, cover traces of attack, or perform other malicious actions. The target host is not properly controlling log access. As a result tainted data is resulting in the log files leading to a failure in accountability, non-repudiation and incident forensics capability.

Attack Execution Flow

2

Mitigations

5

Consequences

Relationships