Ukuonfiguraji kutokuwa salama — mipangilio ambayo sio salama, chaguo-msingi zisizolindwa, au ukuonfiguraji ambao haujakuwa sahihi — ni moja ya dhuluma za usalama zinazojitokeza sana (hatari ya OWASP Top 10). Inajumuisha chaguo-msingi zilizoonyeshwa, huduma zisizohitajika, makosa yenye maelezo mengi, na ukamataji ambao unakosa. Kuuzuia inakanya ukuonfiguraji salama na umeme.
Ukuonfiguraji kutokuwa sahihi kawaida
✗ INSECURE DEFAULTS left unchanged → default passwords, default accounts, sample content
✗ Unnecessary FEATURES/services/ports enabled → larger attack surface
✗ VERBOSE ERRORS in production → stack traces leaking internal details to attackers
✗ Missing SECURITY HEADERS; misconfigured CORS (allow-all); directory listing enabled
✗ Exposed admin/management interfaces or debug endpoints publicly
✗ Cloud misconfigs → public storage buckets, open databases, over-permissive access
✗ Outdated software / unpatched systems; overly permissive file/access permissions
