SECURITY MISCONFIGURATION — MERIDIAN HEALTH
HARD ⭐⭐⭐⭐ — OWASP A05 — WEB APPLICATION ASSESSMENT
DEFAULT CREDS · DIR LISTING · VERBOSE ERRORS · HEADERS · EXPOSED FILES
Loading target: portal.meridian-health.com...

OBJECTIVES

Discover the exposed admin panel
Access admin panel with default credentials
Find directory listing enabled
Trigger verbose error with stack trace
Identify dangerous HTTP methods
Inspect response headers for missing controls
Find the exposed backup/config file
Submit the full findings report
🌐
Browser
📡
Response Headers
🔍
Findings Tracker
📋
Report
SECMISCONFIG
Browser
Headers
Findings
Report
--:--:--
PHASE 1 — RECONNAISSANCE
MISSION BRIEF
HARD ⭐⭐⭐⭐ — OWASP A05

SECURITY MISCONFIGURATION

TARGET: portal.meridian-health.com (simulated)

SCENARIO

You are conducting a black-box external web application penetration test against Meridian Health, a regional healthcare provider. The client suspects their patient portal has configuration issues but does not know the extent. Find and document all security misconfigurations.

METHODOLOGY

Security Misconfiguration findings are discovered through exploration and observation — not exploitation of application logic. Browse the application carefully. Think about what should not be accessible from the outside. Try common paths. Inspect what the server reveals about itself.

WHAT TO LOOK FOR

  • Administrative interfaces accessible without strong authentication
  • Default or weak credentials on any login
  • Directory listings revealing file structure
  • Verbose error messages leaking internal details
  • Unnecessary or dangerous HTTP methods enabled
  • Missing or misconfigured security response headers
  • Sensitive files accessible without authorisation

DELIVERABLE

A complete findings report documenting all misconfigurations discovered, their individual risk ratings, chained impact, and specific remediation steps for each. The report is scored on coverage and quality.

Display Mode
BROWSER — Meridian Health Portal
🔒 Go
RESPONSE HEADERS — Current Page
Navigate to a page to inspect its response headers.
FINDINGS TRACKER
PENTEST REPORT — Meridian Health Misconfigurations
SECURITY MISCONFIGURATION — FINDINGS
OVERALL ASSESSMENT
FINDING 1 — Admin Panel / Default Credentials
FINDING 2 — Directory Listing + Exposed Files
FINDING 3 — Verbose Errors + Server Disclosure
FINDING 4 — Dangerous HTTP Methods
FINDING 5 — Missing Security Headers
REMEDIATION PRIORITY
Score: 0 / 10