15–25 min Updated

Lax Security Settings

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Improper security settings are a common cause of vulnerabilities.

Prevalence
Common
Exploitability
Easy
Impact
Harmful

What are lax security settings?

Lax security settings are a security misconfiguration vulnerability in which servers, frameworks, databases or cloud services are deployed with insecure configuration. Examples include default passwords, open admin consoles, debug mode in production and directory listings. Attackers find them with automated scans and simple searches, and use them as an easy way into your systems.

What you'll learn

  • How attackers use search engines to find misconfigured software
  • Why default accounts, debug settings and open directory listings are easy ways in
  • How scripted deployments and segregated environments keep configuration secure

Where this lesson counts

OWASP Top 10

  • Lax Security Settings lab

    See how attackers use search engines to find badly configured software, then walk through the mistakes they look for: default accounts, open directory listings, debug tools left on in production, exposed test environments and admin interfaces, widely shared credentials and unclaimed CDN domains.

  • How to prevent Lax Security Settings

    The prevention guide covers seven approaches:

    • Automate Your Build Process
    • Review New Software Components and Disable Default Credentials
    • Clearly Separate Code and Configuration
    • Create Dedicated Accounts with Appropriate Privileges
    • Script Your Deployment Process
    • Segregate Environments
    • Add Extra Security for Administrative Systems
  • Lax Security Settings quiz

    Two questions. Passing marks the lesson complete.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • Password Mismanagement

    Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.

  • XML External Entities

    Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.

  • Cross-Origin Resource Sharing

    Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.