CRYPTOGRAPHY (CR3)

Axel can modify transient or permanent data (stored or in transit), or source code, or updates/patches, or configuration data, because it is not subject to integrity checking

CRYPTOGRAPHY
3

Axel can modify transient or permanent data (stored or in transit), or source code, or updates/patches, or configuration data, because it is not subject to integrity checking

OWASP SCP

92,205,212

OWASP ASVS

10.2.3,10.2.4,10.2.5,10.2.6,10.3.1,10.3.2,14.1.1,14.1.4,14.1.5

OWASP AppSensor

SE1,IE4

CAPEC

-

SAFECODE

12,14

How to play?

Tampering with state, source code, interpreted code, libraries, executables, updates, patches, configuration data, logs, etc undermines any trust in the application. Consider the file system, database content, information in memory, in page code, and data in transit.

Mappings

OWASP ASVS (4.0): 10.2.3 ,10.2.4 ,10.2.5 ,10.2.6 ,10.3.1 ,10.3.2 ,14.1.1 ,14.1.4 ,14.1.5

Capec: 31 ,39 ,68 ,75 ,133 ,145 ,162 ,203 ,438 ,439 ,442

OWASP SCP: 92,205,212

OWASP Appsensor: SE1,IE4

Safecode: 12,14

ASVS (4.0) Cheatsheetseries Index

ASVS V10.2 - Malicious Code Search

ASVS V10.3 - Deployed Application Integrity Controls

ASVS V14.1 - Build

No suitable mappings were found.

Attacks

(Session) Data tampering

Session Hijacking (Man-in-the-Middle)

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.