What is Security Misconfiguration?

Untitled

I believe this name was chosen to be as ambiguous as possible for one of the Top 10 OWASP vulnerabilities. It can encompass anything and everything related to configurations but if we do some effort it is possible to define a general testing guide for security misconfigurations by looking at the common properties of all the issues we can find in write ups and activities.

How to identify Security Misconfiguration

The following properties of a system will indicate a likely vulnerability though some of these properties are a bit more ambiguous and harder to test.

To prevent these kinds of vulnerabilities, we can implement some mitigations.

All of these best practices serve to cover a particular goal but we also need to know what these goals are so we can test with precision.

Test network infrastructure configuration