php - OWASP 2010 - Security Misconfiguration example -


i working php , owasp 2010 top 10 , need :)

i need example of how use security misconfiguration, think need know how bug can know how prevent. i've tried find via google got concept of it. need actual example can understand clearlier :)

so there's 1 example of a6 - security misconfiguration in php. well, there 1 until 5.4.0. called register_globals. if had register_globals on, opened several potential doors vulnerabilities.

another misconfiguration if have display_errors on in production. problem, because errors disclosed user (potentially giving them clues filesystem structure , potential vulnerable error-producing parts of application.


Comments

Popular posts from this blog

monitor web browser programmatically in Android? -

Shrink a YouTube video to responsive width -

wpf - PdfWriter.GetInstance throws System.NullReferenceException -