Ace of Spoofing II
You’ve invented a new spoofing attack.
Threat |
|
Another type of spoofing not in the other cards is DNS spoofing to trick the user or service into talking to a host on a different IP. |
|
CAPEC |
CAPEC-142 - DNS Cache Poisoning CAPEC-598 - DNS Spoofing |
ASVS |
10.3.3 - Ensure good DNS hygiene practices |
CWE |
CWE-350 - Reliance on Reverse DNS Resolution for a Security-Critical Action CWE-290 - Authentication Bypass by Spoofing CWE-295 - Improper Certificate Validation CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints |
Mitigations |
|
... |