OWASP Top 10 Vulnerabilities: #5 Security Misconfiguration

This video by IBM’s ethical hacking team outlines how bugs can be found in applications when tools used for debugging and testing applications remain in the application post-go-live. From leaving debugging enabled to not setting directory permissions correctly and leaving default passwords enabled, each is considered a security misconfiguration that can lead to application compromise.  This short 2 minute video outlines each of these in sequence and offers a checklist of steps to eliminate them from your development efforts.

