This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Secure Configuration Guide"
Timo.goosen (talk | contribs) (→2. Web servers misconfiguration) |
Timo.goosen (talk | contribs) (→2. Web servers misconfiguration) |
||
Line 29: | Line 29: | ||
'''[[SCG_WS_IBM|2.5. IBM HTTP Server]]''' | '''[[SCG_WS_IBM|2.5. IBM HTTP Server]]''' | ||
− | '''[[SCG_WS_LIGHTTPD lighttpd]]''' | + | '''[[SCG_WS_LIGHTTPD|2.6 lighttpd]]''' |
− | '''[[SCG_WS_OPENBSD_HTTPD New OpenBSD HTTPD Webserver]]''' | + | '''[[SCG_WS_OPENBSD_HTTPD|2.7 New OpenBSD HTTPD Webserver]]''' |
== 3. Application servers misconfiguration == | == 3. Application servers misconfiguration == |
Revision as of 13:36, 14 January 2015
Welcome on the page of Secure Configuration Guide!
Project description is available here: https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide
When editing the page, please follow the page structure, described in Template:OWASP Secure Configuration Guide
Table of Contents
1. Introduction
1.1. The OWASP Secure Configuration Guide
1.2. Misconfiguration. Defender's point
1.3. Misconfiguration. Attacker's point
2. Web servers misconfiguration
2.7 New OpenBSD HTTPD Webserver
3. Application servers misconfiguration
3.2. Borland Enterprise Server
3.4. IBM WebSphere Application Server
3.5. JBoss Enterprise Application Platform
3.7. SAP NetWeaver Application Server
3.8. Oracle Application Server
4. Web frameworks misconfiguration
5. CMS misconfiguration
6. Crypto misconfiguration
6.1 SSL / TLS configuration
6.2 Cryptographic Password storage policy
6.3 to be complemented later
7. Services
7.1. VNC - srsly.de ;)
SSH
RDP
7.2 to be complemented later
8. Devices
8.2. Routers
8.3. Firewalls
8.4. to be complemented later