September 2025
Intermediate to advanced
640 pages
19h 47m
English
| Threat scenario (TS) | CWE | Attack scenario | Attack-simulation test | Controls to be applied | Retest verification after controls applied |
|---|---|---|---|---|---|
| TS1: mobile or browser client/UI | CWE-287 (improper authentication) | An attacker uses stolen session tokens obtained through phishing to impersonate legitimate users, allowing unauthorized access and fraudulent transactions. | Simulate the attack by replaying a valid session token obtained from a phishing simulation. | Implement multifactor authentication (MFA), secure session token management, and periodic token rotation. | Replay the same session token and verify that it is invalidated by token rotation. |
| TS2: digital wallet/smart contracts | CWE-326 (inadequate encryption Strength) | The attacker intercepts and replays previously signed wallet transactions due to weak encryption, leading to duplicate payments or withdrawals. | Intercept a signed transaction during its transmission and replay it to check for duplicate payments. | Use stronger encryption for wallet transactions and enforce nonce-based transaction validation. | Replay intercepted transactions to ensure they are rejected due to nonce mismatches. |
| TS3: distributed digital identity system | CWE-345 (insufficient verification of data authenticity) | The attacker tampers with transmitted identity payloads, corrupting user data or enabling fraudulent access by impersonating a legitimate user. | Modify identity payloads in transit using a proxy tool like Burp Suite and check if altered ... |
Read now
Unlock full access