पाठ 14 / 25
Security Misconfiguration
Defaults, debug modes and exposed services.
Harden every layer
Misconfiguration includes debug mode or verbose stack traces in production, default or shared admin credentials, unnecessary features and ports enabled, directory listing, publicly readable cloud storage buckets, overly permissive IAM roles and missing security headers. Prevent it with a repeatable hardened baseline applied by infrastructure as code, minimal images and services, separate configuration per environment, automated configuration scanning, and regular reviews of cloud permissions.
Production settings that matter
Examples across frameworks.
Django DEBUG = False; ALLOWED_HOSTS set; SECRET_KEY from environment; check --deploy clean
Spring management endpoints restricted; no stack traces in error responses
Express app.disable("x-powered-by"); NODE_ENV=production; helmet middleware for headers
Cloud storage buckets private by default; block public access settings enabled
Containers non-root user; read-only filesystem where possible; no package managers in final imageScan infrastructure code
Tools such as Checkov, tfsec/Trivy or cloud security posture management catch public buckets and open security groups before deployment.
त्वरित जाँच: Which is a security misconfiguration?
- Hashing passwords with Argon2id
- Using parameterised queries
- Enabling HSTS
- Running production with debug mode and detailed stack traces enabled
Answer
Running production with debug mode and detailed stack traces enabled — Debug output leaks internals.