Overview
This covers everything that is insecure because nobody changed the default: sample apps left in production, directory listing enabled, stack traces shown to visitors, debug ports exposed, permissive CORS, and cloud storage set to public read.\nIt is the easiest class to exploit and the cheapest to fix through hardened baselines and repeated configuration review.
Indicators of Compromise
Signals that suggest this is present on a system.
- Default admin/admin logins
- Full stack traces in HTTP 500 pages
- Public S3 or blob containers
Controls that stop it
-
Patch Promptly and Continuously
Maintain an inventory of every framework, plugin and library you run, subscribe to their advisories, and apply fixes on a defined SLA measured in days rather than months. Prioritise anything reachable from the internet or already exploited in the wild. Automate the process so patching does not depend on someone remembering to do it.