Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes.
In this episode:
Hardcoded Active Directory credentials and API keys discovered in a public GitHub repo during a healthcare pen test
Default credentials (admin/1234) found on a clinical research app storing PHI
A rogue Apache basic auth panel that survived from dev into production
How verbose error handling and stack traces hand attackers a roadmap to your app
Why dev-to-production is the most dangerous transition in your app's lifecycle
The shift-left mindset and DevSecOps — empowering devs to ship secure code
How CIS lockdown guides can dramatically improve your security posture overnight
Podden och tillhörande omslagsbild på den här sidan tillhör
SecurIT360. Innehållet i podden är skapat av SecurIT360 och inte av,
eller tillsammans med, Poddtoppen.