CAPEC-497

File Discovery
Haute
Très bas
Draft
2019-09-30
00h00 +00:00
2020-12-17
00h00 +00:00
Alerte pour un CAPEC
Restez informé de toutes modifications pour un CAPEC spécifique.
Gestion des notifications

Descriptions du CAPEC

An adversary engages in probing and exploration activities to determine if common key files exists. Such files often contain configuration and security parameters of the targeted application, system or network. Using this knowledge may often pave the way for more damaging attacks.

Informations du CAPEC

Conditions préalables

The adversary must know the location of these common key files.

Atténuations

Leverage file protection mechanisms to render these files accessible only to authorized parties.

Faiblesses connexes

CWE-ID Nom de la faiblesse

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Soumission

Nom Organisation Date Date de publication
CAPEC Content Team The MITRE Corporation 2019-09-30 +00:00

Modifications

Nom Organisation Date Commentaire
CAPEC Content Team The MITRE Corporation 2020-07-30 +00:00 Updated Taxonomy_Mappings
CAPEC Content Team The MITRE Corporation 2020-12-17 +00:00 Updated Resources_Required