Secure Legion Labs

OWASP Top 10

Misconfiguration Lab Navigation

Use this area for weak headers, poor defaults, exposed internals, and deployment mistakes that turn operational shortcuts into real attack paths.

Security Headers

Audit a weak response, apply safe browser headers, and harden the baseline before launch.

Default Credentials

Use vendor-supplied credentials that were never changed and reach the exposed appliance admin console.

Debug Mode Exposure

Reach an exposed debug route, trigger verbose mode, and leak production secrets through a trace response.

Directory Listing

Enumerate a browsable public directory, pivot into backup storage, and retrieve a sensitive leaked file.