Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-40 — Manipulating Writeable Terminal Devices
CAPEC-40

Manipulating Writeable Terminal Devices

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. This attack exploits terminal devices that allow themselves to be written to by other users. The attacker sends command strings to the target terminal device hoping that the target user will hit enter and thereby execute the malicious command with their privileges. The attacker can send the results (such as copying /etc/passwd) to a known directory and collect once the attack has succeeded.

Mitigation

Design: Ensure that terminals are only writeable by named owner user and/or administrator | Design: Enforce principle of least privilege

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.