Restructure repository: Remove OWASP categorization, organize by vulnerability type

Co-authored-by: Stalin-143 <161853795+Stalin-143@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-01-04 19:01:04 +00:00
parent 274734e91a
commit ba72efbc5e
46 changed files with 341 additions and 323 deletions
+26
View File
@@ -0,0 +1,26 @@
# Security Misconfiguration
## Description
Security misconfiguration vulnerabilities arise from insecure default configurations, incomplete or ad-hoc configurations, open cloud storage, misconfigured HTTP headers, and verbose error messages containing sensitive information. These are among the most common security issues.
## Common Issues
- Default credentials
- Unnecessary features enabled
- Directory listing enabled
- Detailed error messages
- Outdated software
- Misconfigured security headers
- Open cloud storage buckets
## Common Attack Vectors
- Default admin interfaces
- Configuration files exposed
- Backup files accessible
- Development/debug modes enabled
- Unnecessary services running
## Testing Approach
Test for common misconfigurations, default credentials, exposed configuration files, and security header weaknesses.
## Payloads
See `default-credentials-payloads.txt` and `misconfiguration-paths-payloads.txt` for comprehensive lists of security misconfiguration tests.