CAPEC™ 21: Exploitation of Trusted Identifiers
Description
An adversary guesses, obtains, or "rides" a trusted identifier (e.g. session ID, resource ID, cookie, etc.) to perform authorized actions under the guise of an authenticated user or service.
Source: CAPEC™ 21
Related ASVS Requirements
ASVS (5.0): 10.1.1, 10.1.2, 10.2.1, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.2.1, 12.2.2, 12.3.1, 12.3.2, 12.3.3, 12.3.4, 12.3.5, 13.2.1, 13.2.2, 13.2.3, 16.1.1, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.3, 16.5.1, 16.5.2, 16.5.3, 16.5.4, 3.1.1, 3.3.2, 3.3.4, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.6, 3.4.7, 3.5.1, 3.5.4, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 4.4.3, 7.1.1, 7.1.2, 7.1.3, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.3.1, 7.3.2, 7.4.1, 7.4.2, 7.4.3, 7.4.4, 7.4.5, 7.5.1, 7.5.2, 7.5.3, 7.6.1, 9.1.1, 9.1.2, 9.1.3, 9.2.1, 9.2.2, 9.2.3, 9.2.4