> For the complete documentation index, see [llms.txt](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/learning-paths/comptia-pentest+/application-based-vulnerabilites/owasp-top-10/severity-6-security-misconfiguration.md).

# \[Severity 6] Security Misconfiguration

Notes about Security Misconfiguration.

Security Misconfiguration occurs when security was configured, but not properly.

They can include poorly configured permissions on cloud services such as S3, having unnecessary features enabled like services, pages, or accounts, default accounts with unchanged passwords, error messages that are overly detailed, not using HTTP security headers.

Practical

To hack into the pensive notes web app, I used the hint to start looking for the webapp's source code on GitHub.
