पाठ 14 / 25

Security Misconfiguration

Defaults, debug modes and exposed services.

Harden every layer

Misconfiguration includes debug mode or verbose stack traces in production, default or shared admin credentials, unnecessary features and ports enabled, directory listing, publicly readable cloud storage buckets, overly permissive IAM roles and missing security headers. Prevent it with a repeatable hardened baseline applied by infrastructure as code, minimal images and services, separate configuration per environment, automated configuration scanning, and regular reviews of cloud permissions.

Production settings that matter

Examples across frameworks.

Django      DEBUG = False; ALLOWED_HOSTS set; SECRET_KEY from environment; check --deploy clean
Spring      management endpoints restricted; no stack traces in error responses
Express     app.disable("x-powered-by"); NODE_ENV=production; helmet middleware for headers
Cloud       storage buckets private by default; block public access settings enabled
Containers  non-root user; read-only filesystem where possible; no package managers in final image

Scan infrastructure code

Tools such as Checkov, tfsec/Trivy or cloud security posture management catch public buckets and open security groups before deployment.

त्वरित जाँच: Which is a security misconfiguration?

  • Hashing passwords with Argon2id
  • Using parameterised queries
  • Enabling HSTS
  • Running production with debug mode and detailed stack traces enabled
Answer

Running production with debug mode and detailed stack traces enabled — Debug output leaks internals.