Jack of Tampering
An attacker can write to some resource because permissions are granted to the world or there are no ACLs:
Threat |
|
You have a file stored on a Unix-based operating system that has the permissions set to |
|
CAPEC |
CAPEC-576: Group Permission Footprinting CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels |
ASVS |
4.1.3: Ensure users or services only have the necessary privileges to perform the actions they need to do |
CWE |
CWE-552: Files or Directories Accessible to External Parties CWE-285: Improper Authorization CWE-668: Exposure... |