CAPEC™ 37: Retrieve Embedded Sensitive Data
Description
An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confidential contents, such as account numbers or individual keys/credentials that can be used as an intermediate step in a larger attack.
Source: CAPEC™ 37
Related ASVS Requirements
ASVS (5.0): 10.1.1, 10.4.16, 11.1.1, 11.1.2, 11.1.3, 11.1.4, 11.2.1, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 13.1.4, 13.2.1, 13.2.2, 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 13.4.1, 13.4.7, 14.1.1, 14.1.2, 14.2.1, 14.2.2, 14.3.1, 14.3.2, 14.3.3, 16.2.5, 16.3.3, 16.5.1