Security misconfigurations are relative. In this category, a lot of possible errors are introduced, and the most simple and accurate way to detect them using Burp Suite is through the scanner.
- Open Burp Suite and when the main Dashboard is displayed, click on New scan. Here it is possible to define the URL to scan, and some options, like credentials to log in to the application, as shown in the following screenshot:
- The tests are classified by categories. When the scan finishes, we can see that some issues are detected that are related to security misconfiguration, as shown in the following screenshot: ...