Перейти к содержимому

OWASP Security misconfiguration explained

thehackerish

0:00 / 0:00

OWASP Security misconfiguration explained

3 856 просмотров · 6 лет назад
thehackerish
47,8 тыс. подписчиков
3 856 просмотров · 6 лет назад
Download your own Web hacking LAB: https://thehackerish.com/owasp-top-10... Blog post: https://thehackerish.com/owasp-securi... Follow us on Twitter:   / thehackerish   Facebook Page:   / thehackerish   Nahamsec's stream:    • @Th3G3nt3lman Shares His Recon Methodology...   Patrik's blog post: https://blog.it-securityguard.com/bug... Geluchat blog post: https://www.dailysecurity.fr/comment-... Hello dear readers and welcome to this new OWASP Top 10 vulnerabilities episode. Today’s video is about Security misconfiguration. You will learn one of the most impactful vulnerabilities which some bug bounty hunters specialize in. Yet, many security testers overlook it. We will explore the following points: Define Security misconfiguration: First, we need to start from a common base. Some flaws related to Security misconfiguration: We will discover how a security researcher got hacked, and how a bug bounty hunter accessed multiple admin portals. Real-world examples: Here, we will see breaches, reports of bug bounty hunters. But most importantly, we will explore a great stream talking about how a security researcher found more than 90K by exploiting security misconfigurations. Security misconfiguration impact. How to prevent it. You might find the name a bit vague, that’s because Security misconfiguration can be found in many contexts. But in general, Security misconfiguration happens when the responsible party fails to follow best practices when configuring an asset. This asset can be an operating system, a web server, software running on a machine, etc. Security misconfigurations don’t affect web assets only. Any component which requires a configuration is subject to this vulnerability. This means that network devices, hardware, email services, etc. can suffer from this vulnerability.