Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-461 — Web Services API Signature Forgery Leveraging Hash Function Extension Weakness
CAPEC-461

Web Services API Signature Forgery Leveraging Hash Function Extension Weakness

TLP:CLEAR

Description

Typical severity: High. An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service.

Mitigation

Design: Use a secure message authentication code (MAC) function such as an HMAC-SHA1

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.