Jack of Spoofing
An attacker could steal credentials stored on the client and reuse them.
Threat |
|
An attacker could steal your session cookies or use something such as a key logger to capture your credentials when logging in. |
|
CAPEC |
CAPEC-568 - Capture Credentials via Keylogger CAPEC-31 - Accessing/Intercepting/Modifying HTTP Cookies |
ASVS |
3.4 and 3.5 - Ensure Cookies are secured properly and only accessible from the source host 2.2.6 - Ensure replay attack protections are in place and working correctly 2.2.7 - Ensure user-in-the-loop with automation protection controls 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.5.1 - Ensure Cookies are secured properly and only accessible from the source host 2.2.6 - Ensure replay attack protections are in place and working... |