Security misconfiguration
TL;DR
Security misconfiguration is the catch-all for things left in a weak state: default credentials, verbose errors, unnecessary features switched on, missing security headers. It’s common because it’s easy to miss, and it’s often the quickest win on a test.
Only test apps you’re authorised to test.
What it is
Software ships with defaults and options, and every one is a chance to leave something open. Misconfiguration is less a single bug than a habit of shipping systems that weren’t hardened.
How it works
Typical examples: default or weak admin credentials still in place, detailed stack traces shown to users, directory listing enabled, admin panels exposed, sample apps left installed, or missing security headers. None of these needs a clever exploit — they’re just doors left open.
How to test for it
- Try default credentials on anything with a login.
- Trigger errors and see whether they leak stack traces, versions or paths.
- Look for exposed admin interfaces, directory listings, and left-over sample content.
- Check the response headers for the usual security ones.
How to fix it
- Harden from a baseline: change defaults, turn off what you don’t need, keep errors generic.
- Automate configuration so environments are consistent and repeatable.
- Set the standard security headers and review them.
Reference: OWASP A05: Security Misconfiguration.