7. of Denial of Service
An attacker can make a client unavailable or unusable and the problem persists after the attacker goes away (client, authenticated, persistent).
Threat |
|
An attacker sends a phishing email to a user who logs in to a fake version of your site, and the attacker then logs into your site with the credentials they gathered and changes the password, locking out the legitimate user. |
|
CAPEC |
CAPEC-98 – Phishing CAPEC-163 – Spear phishing |
ASVS |
2.2.4 – Ensure the use of MFA |
CWE |
CWE-308 – Use of single-factor authentication |
Mitigations |
|
|