Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-75 — Manipulating Writeable Configuration Files
CAPEC-75

Manipulating Writeable Configuration Files

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. Generally these are manually edited files that are not in the preview of the system administrators, any ability on the attackers' behalf to modify these files, for example in a CVS repository, gives unauthorized access directly to the application, the same as authorized users.

Mitigation

Design: Enforce principle of least privilege | Design: Backup copies of all configuration files | Implementation: Integrity monitoring for configuration files | Implementation: Enforce audit logging on code and configuration promotion procedures. | Implementation: Load configuration from separate process and memory space, for example a separate physical device like a CD

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.