10. of Tampering I
An attacker can alter information in a data store because it has weak ACLs or includes a group that is equivalent to everyone (all Live ID holders).
The alternative text is that an attacker can alter information in a data store because it has weak/open permissions or includes a group that is equivalent to everyone (anyone with a Facebook account):
Threat |
|
You have given everyone full permissions on your database schema and now they can create, read, update, and delete data, or maybe they can modify the schema itself. |
|
CAPEC |
CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs |
ASVS |
4.1.3: Ensure users or services only have the necessary privileges to perform... |