What problem does it solve? Web servers and deployment infrastructure often ship with misconfigurations, default credentials, exposed backup files, and missing security headers that attackers exploit. This Skill provides a structured methodology to systematically test all 11 OWASP WSTG configuration and deployment management test cases during a penetration test or security assessment. ## Core Features & Use Cases - Complete WSTG-CONF Coverage: Step-by-step testing procedures for all 11 test cases, from network infrastructure configuration (WSTG-CONF-01) through cloud storage access control (WSTG-CONF-11). - Detection and Remediation Guidance: Each test case includes objectives, how-to-test procedures, what to look for, and concrete remediation steps. - Common Vulnerability Patterns: A prioritized list of high-impact misconfigurations (backup files in webroot, default credentials, directory listing, missing HSTS) plus bug-finding efficiency tips. - Use Case: During a web application penetration test, use this Skill to enumerate admin interfaces, test HTTP methods for access control bypass, validate HSTS headers, hunt for subdomain takeover via dangling DNS records, and audit S3 bucket permissions. ## Quick Start Use the wstg-configuration-management skill to test the target web server for configuration weaknesses, exposed backup files, dangerous HTTP methods, and missing HSTS headers.