CAPEC Definitions

    CAPEC Definitions / CAPEC-383

    CAPEC-383: Harvesting Information via API Event Monitoring

    An adversary hosts an event within an application framework and then monitors the data exchanged during the course of the event for the purpose of harvesting any important data leaked during the transactions. One example could be harvesting lists of usernames or userIDs for the purpose of sending spam messages to those users. One example of this type of attack involves the adversary creating an event within the sub-application. Assume the adversary hosts a virtual sale of rare items. As other users enter the event, the attacker records via AiTM (CAPEC-94) proxy the user_ids and usernames of everyone who attends. The adversary would then be able to spam those users within the application using an automated script.

    Severity:Low
    Possibility:

    Extended Description

    No Extended Description.

    Mitigations

    Leverage encryption techniques during information transactions so as to protect them from attack patterns of this kind.

    Relationships with other CAPECs

    CAPEC-407: Pretexting

    CAPEC-94: Adversary in the Middle (AiTM)

    Prerequisites

    The target software is utilizing application framework APIs

    Related Weaknesses

    CWE-311: Missing Encryption of Sensitive Data

    CWE-319: Cleartext Transmission of Sensitive Information

    CWE-419: Unprotected Primary Channel

    CWE-602: Client-Side Enforcement of Server-Side Security