CAPEC Definitions

    CAPEC Definitions / CAPEC-694

    CAPEC-694: System Location Discovery

    An adversary collects information about the target system in an attempt to identify the system's geographical location. Information gathered could include keyboard layout, system language, and timezone. This information may benefit an adversary in confirming the desired target and/or tailoring further attacks.

    Severity:Very Low
    Possibility:High

    Extended Description

    No Extended Description.

    Mitigations

    To reduce the amount of information gathered, one could disable various geolocation features of the operating system not required for system operation.

    Relationships with other CAPECs

    CAPEC-169: Footprinting

    Prerequisites

    The adversary must have some level of access to the system and have a basic understanding of the operating system in order to query the appropriate sources for relevant information.

    Related Weaknesses

    CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere