Home > taxonomy > capec 3.9 > 560
An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.
Source: CAPEC™ 560
ASVS (5.0): 13.2.3, 6.2.10, 6.2.11, 6.2.12, 6.2.4, 6.3.2, 6.3.3, 6.3.8, 6.4.2, 6.5.6