This course highlights configuration errors—from leftover sample endpoints and directory listing to detailed error messages —that can expose the pastebin application to attackers.
Overview
Syllabus
- Unit 1: Introduction to Security Misconfiguration
- Unit 2: Sample Endpoints with Default Admin Credentials
- Exploiting Default Credentials
- Secure Admin User Initialization
- Secure Admin Credentials with Bcrypt
- Implement JWT Authentication for Admin Panel
- Secure Admin Access with Middleware
- Unit 3: Directory Listing Enabled
- Exploiting Directory Listing Vulnerability
- Disable Directory Listing Vulnerability
- Secure File Access Implementation
- Handle Unauthorized Directory Access
- Unit 4: Detailed Error Messages Exposed
- Exploiting Vulnerable Error Handlers
- Secure Error Logging Practices
- Switching Environments