Lax Security Settings
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Improper security settings are a common cause of vulnerabilities.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Harmful
What are lax security settings?
Lax security settings are a security misconfiguration vulnerability in which servers, frameworks, databases or cloud services are deployed with insecure configuration. Examples include default passwords, open admin consoles, debug mode in production and directory listings. Attackers find them with automated scans and simple searches, and use them as an easy way into your systems.
What you'll learn
- How attackers use search engines to find misconfigured software
- Why default accounts, debug settings and open directory listings are easy ways in
- How scripted deployments and segregated environments keep configuration secure
Where this lesson counts
OWASP Top 10
Default accounts, verbose errors, unhardened parsers and permissive headers leave the door open.
Learn more about A02This lesson includes
-
Lax Security Settings lab
See how attackers use search engines to find badly configured software, then walk through the mistakes they look for: default accounts, open directory listings, debug tools left on in production, exposed test environments and admin interfaces, widely shared credentials and unclaimed CDN domains.
-
How to prevent Lax Security Settings
The prevention guide covers seven approaches:
- Automate Your Build Process
- Review New Software Components and Disable Default Credentials
- Clearly Separate Code and Configuration
- Create Dedicated Accounts with Appropriate Privileges
- Script Your Deployment Process
- Segregate Environments
- Add Extra Security for Administrative Systems
-
Lax Security Settings quiz
Two questions. Passing marks the lesson complete.
Related lessons
Browse all 45 lessons
Information Leakage
Revealing system information helps an attacker learn about your tech stack.
Password Mismanagement
Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.
XML External Entities
Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.
Cross-Origin Resource Sharing
Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.