2. of Denial of Service II
An attacker can make your authentication system unusable or unavailable.
Threat |
|
You use single sign-on and can no longer reach your identity provider (IdP) because an attacker is using Address Resolution Protocol (ARP) or Domain Name System (DNS) poisoning to make your IdP, or login server. By forcing your ARP cache for a given IP to point to a different medium access control address (MAC), a unique value given to each network interface, they can stop you from being able to reach your identity provider IdP because your system no longer knows how to get to its destination. |
|
CAPEC |
CAPEC-589 – DNS Blocking CAPEC-590 – IP address blocking CAPEC-603 – Blockage CAPEC-607 – Obstruction |
ASVS |
N/A |
...