5. of Spoofing
An attacker can confuse a client because there are too many ways to identify a server.
Threat |
|
Here are some examples of addressing the same host, which can become confusing:
Not to mention Domain Name Service (DNS) aliases, IPv6 addresses, additional IPs, and so on. |
|
CAPEC |
CAPEC-4 - Using Alternative IP Address Encodings |
ASVS |
N/A |
CWE |
CWE-173 - Improper Handling of Alternate Encoding CWE-647 - Use of Non-Canonical URL Paths for Authorization Decisions |
Mitigations... |