Empty Password in Configuration

The attacker can access confidential resources without using any password



Configuration files are the one of the most popular storage areas to place resource credentials, such as database passwords, ldap connectivity passwords, etc.

Below snippet shows such a configuration piece including using empty password that may be used for authentication.

<add key="password" value="" />
<add key="secret" value="" />

This will enable brute force or dictionary attacks more practical and easy to employ by attackers.

