Lazo Lab Sign up

Web Security / Thinking like a defender

Lesson 5 of 27

Security misconfiguration

Default passwords, debug mode left on, directory listings and verbose error pages all hand attackers information. Harden configs before going live.

Key points

  • Turn debug mode off in production
  • Change every default password
  • Show friendly errors, log the details privately
Watch a video on thisOpens YouTube search results for “Security misconfiguration” in a new tab

Quiz · +10 XP

Why turn off debug mode on a live site?

Log in to save progress and earn XP.