Prerequisites
Targeted software is utilizing application framework APIs
Resources Required
A software program that allows the use of adversary-in-the-middle communications between the client and server, such as an adversary-in-the-middle proxy.
Related Weaknesses
CWE-ID |
Weakness Name |
|
Missing Support for Integrity Check The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum. |
References
REF-327
So Many Ways [...]: Exploiting Facebook and YoVille
Tom Stracener, Sean Barnum.
Submission
Name |
Organization |
Date |
Date release |
CAPEC Content Team |
The MITRE Corporation |
2014-06-23 +00:00 |
|
Modifications
Name |
Organization |
Date |
Comment |
CAPEC Content Team |
The MITRE Corporation |
2019-04-04 +00:00 |
Updated Related_Weaknesses |
CAPEC Content Team |
The MITRE Corporation |
2019-09-30 +00:00 |
Updated @Abstraction |
CAPEC Content Team |
The MITRE Corporation |
2021-06-24 +00:00 |
Updated Description, Resources_Required |