OWASP A05:2021 - Security Misconfiguration
Overview
Risk Rating
Common Scenarios
1. Default Configurations
2. Incomplete or Improper Configurations
3. Missing Security Headers
4. Outdated Software Components
Penetration Testing Methodology
1. Information Gathering
2. Configuration Analysis
3. HTTP Security Headers Testing
4. Server Configuration Testing
Common Misconfigurations by Technology
Web Servers
Databases
Application Frameworks
Detection Techniques
1. Automated Scanning
2. Manual Testing Checklist
3. Security Headers Assessment
Exploitation Examples
1. Directory Traversal via Misconfigured Web Server
2. Admin Panel with Default Credentials
3. Information Disclosure via Error Messages
Remediation Guidelines
1. Secure Configuration Management
2. Hardening Checklist
3. Security Headers Implementation
4. Error Handling
Tools and Resources
Automated Scanners
Configuration Auditing
Custom Scripts
Reporting Template
Finding Description
Common Bypasses and Advanced Techniques
1. WAF Bypass for Configuration Discovery
2. Cloud Metadata Service Access
Prevention Best Practices
References and Further Reading
Last updated