Web Security / Thinking like a defender
Lesson 5 of 27
Security misconfiguration
Default passwords, debug mode left on, directory listings and verbose error pages all hand attackers information. Harden configs before going live.
Key points
- Turn debug mode off in production
- Change every default password
- Show friendly errors, log the details privately
Quiz · +10 XP
Why turn off debug mode on a live site?
Log in to save progress and earn XP.