Lesson 10 - OWASP Top 10 2017 - A6:2017-Security Misconfiguration

AppSec Starter is a basic application security awareness training applied to onboarding new developers. It is not the purpose of this training to discuss advanced and practical topics. Conviso has customized training and practical training platforms.

Training recorded by Nicolas Schmaltz and copyright reserved to Conviso Application Security S/A.

Lesson 10 Contents:

Bad security settings are the most observed aspect of the collected data. This is usually a consequence of insecure, incomplete or ad hoc default settings, cloud storage without any access restrictions, misconfigured HTTP headers or error messages with sensitive information. Not only must all operating systems, frameworks, code libraries and applications be securely configured, but they must also be updated and security patched in a timely fashion.