Jack of Denial of Service I
An attacker can cause the logging subsystem to stop working.
Threat |
|
Your log configuration files are not read-only, so an attacker can modify the log level being used by the system from info to fatal so that none of the logs defined in the code are triggered. |
|
CAPEC |
CAPEC-571 – Block logging to the central repository |
ASVS |
7.1.3 – Ensure the application logs security-related events 7.1.4 – Ensure log entries contain what’s necessary for forensics |
CWE |
CWE-778 – Insufficient logging |
Mitigations |
|
|