Security misconfiguration

beginnerWeb

TL;DR

Security misconfiguration is the catch-all for things left in a weak state: default credentials, verbose errors, unnecessary features switched on, missing security headers. It’s common because it’s easy to miss, and it’s often the quickest win on a test.

Only test apps you’re authorised to test.

What it is

Software ships with defaults and options, and every one is a chance to leave something open. Misconfiguration is less a single bug than a habit of shipping systems that weren’t hardened.

How it works

Typical examples: default or weak admin credentials still in place, detailed stack traces shown to users, directory listing enabled, admin panels exposed, sample apps left installed, or missing security headers. None of these needs a clever exploit — they’re just doors left open.

How to test for it

How to fix it

Reference: OWASP A05: Security Misconfiguration.

← Back to Web