WEBVTT

0:00:03.640000 --> 0:00:06.800000
 Types of Authentication Mechanisms.

0:00:06.800000 --> 0:00:11.400000
 In this video, we're going to be building
 on our analogy that we went

0:00:11.400000 --> 0:00:16.080000
 over. We went through in the previous
 video when we got the introduction

0:00:16.080000 --> 0:00:21.840000
 or reintroduction to authentication by taking
 a look at the types of authentication

0:00:21.840000 --> 0:00:26.400000
 mechanisms. So we're now drilling
 deeper down into authentication.

0:00:26.400000 --> 0:00:31.380000
 And we know what authentication is,
 but now we need to understand what

0:00:31.380000 --> 0:00:36.200000
 authentication mechanisms exist or
 what authentication mechanisms are

0:00:36.200000 --> 0:00:42.040000
 typically utilized by modern web
 applications specifically.

0:00:42.040000 --> 0:00:47.400000
 So a bit of this will be a rehash or
 a recap of what probably stuff you

0:00:47.400000 --> 0:00:53.340000
 already know, but it'll also lay the
 groundwork or the skeleton or the

0:00:53.340000 --> 0:00:58.360000
 outline for the types of attacks that
 will be performing in this course.

0:00:58.360000 --> 0:01:03.060000
 So before we do, we know we get into
 any of that, we need to, you know,

0:01:03.060000 --> 0:01:06.520000
 what exactly is an authentication
 mechanism.

0:01:06.520000 --> 0:01:12.000000
 Well, authentication mechanisms are
 methods or processes used to verify

0:01:12.000000 --> 0:01:17.260000
 the identity of a user or system attempting
 to access a web application

0:01:17.260000 --> 0:01:25.700000
 or a service. It could be an API,
 a web application, et cetera.

0:01:25.700000 --> 0:01:29.780000
 So this is by which the web application
 verifies the identity of a user.

0:01:29.780000 --> 0:01:35.480000
 That's the key word there
 or the key set of words.

0:01:35.480000 --> 0:01:41.060000
 Now, these mechanisms ensure that only
 authorized users can gain access

0:01:41.060000 --> 0:01:45.020000
 to sensitive resources
 enhancing security.

0:01:45.020000 --> 0:01:50.480000
 So revisiting the analogy that I sort
 of introduced in the previous video,

0:01:50.480000 --> 0:01:55.380000
 where I gave you the scenario or the
 premise of having a room that has

0:01:55.380000 --> 0:01:58.720000
 data that, you know, could
 be potentially useful.

0:01:58.720000 --> 0:02:03.540000
 So for example, a room with filing
 cabinets, computers, really doesn't

0:02:03.540000 --> 0:02:08.400000
 matter. The bottom line is that whatever
 is in the room is valuable.

0:02:08.400000 --> 0:02:12.780000
 Now, the room has a door and the door
 has a locking mechanism, which allows

0:02:12.780000 --> 0:02:14.340000
 it to be opened and closed.

0:02:14.340000 --> 0:02:20.720000
 And the door is the only means through
 which you can access the room.

0:02:20.720000 --> 0:02:26.400000
 So think of the door as a login form,
 for example, or even, let's not

0:02:26.400000 --> 0:02:28.320000
 even conflate the two just yet.

0:02:28.320000 --> 0:02:34.340000
 So the door is what at a fundamental
 level controls access.

0:02:34.340000 --> 0:02:40.480000
 Now, it's very obvious, you know, if
 we sort of juxtapose this analogy

0:02:40.480000 --> 0:02:47.780000
 on top of or against web applications,
 that this is sort of what the early

0:02:47.780000 --> 0:02:51.580000
 version of the internet or
 web applications were like.

0:02:51.580000 --> 0:02:57.940000
 And what they were missing was that
 the door itself needed an additional

0:02:57.940000 --> 0:03:03.120000
 layer of security or an enhancement,
 if you will, and that, you know,

0:03:03.120000 --> 0:03:08.980000
 typically would come in the form of a
 lock, right, a lock and key mechanism.

0:03:08.980000 --> 0:03:14.120000
 And that, when I'm referring to the
 locking system, whether that be a,

0:03:14.120000 --> 0:03:21.360000
 you know, standard key lock or a padlock
 or whatever, that's what I mean

0:03:21.360000 --> 0:03:26.040000
 when I refer to authentication
 mechanisms.

0:03:26.040000 --> 0:03:31.540000
 So it's, you know, adding this layer
 of security or augmenting the door,

0:03:31.540000 --> 0:03:38.980000
 if you will, by now trying to incorporate
 a form of identity verification.

0:03:38.980000 --> 0:03:44.440000
 What that means is that presumably,
 the only people who will be allowed

0:03:44.440000 --> 0:03:48.960000
 to access that room or can access that
 room are people who are authorized

0:03:48.960000 --> 0:03:50.800000
 to access that room.

0:03:50.800000 --> 0:03:56.960000
 And the authorized personnel have keys
 that essentially grant them that

0:03:56.960000 --> 0:04:03.640000
 access. So revisiting what I have listed
 out in the slides, these mechanisms

0:04:03.640000 --> 0:04:09.160000
 ensure that only authorized users can
 gain access to sensitive resources.

0:04:09.160000 --> 0:04:18.260000
 So previously, the secure or the room
 with all the data only had a door.

0:04:18.260000 --> 0:04:24.800000
 The door didn't have a locking mechanism
 or a way to essentially prevent

0:04:24.800000 --> 0:04:27.040000
 unauthorized personnel from accessing it.


0:04:27.040000 --> 0:04:31.660000
 And what that means or what that meant
 is that, well, yes, a closed door

0:04:31.660000 --> 0:04:35.440000
 would prevent some people
 from not accessing it.

0:04:35.440000 --> 0:04:40.720000
 However, pretty much anyone with the
 intent or the will to find out what's

0:04:40.720000 --> 0:04:45.600000
 in the room would easily be able to
 twist the handle and open the door,

0:04:45.600000 --> 0:04:50.380000
 get in and, you know, do whatever they
 wanted to or with the data that's

0:04:50.380000 --> 0:04:51.700000
 stored in that room.

0:04:51.700000 --> 0:04:58.280000
 When you introduce a locking mechanism
 or a security mechanism, so it

0:04:58.280000 --> 0:05:05.040000
 could be a standard, you know, key lock
 mechanism or, for example, biometric

0:05:05.040000 --> 0:05:07.080000
 lock or whatever.

0:05:07.080000 --> 0:05:12.860000
 Now, only the individuals who have
 the key or who have been provided,

0:05:12.860000 --> 0:05:23.240000
 whose fingerprints or will be
 able to access that room.

0:05:23.240000 --> 0:05:28.220000
 So I know I'm using a very convoluted
 analogy here, but I think it's very

0:05:28.220000 --> 0:05:32.880000
 important that you understand what, when
 I refer to mechanisms, what exactly

0:05:32.880000 --> 0:05:37.620000
 I mean. And this is very important
 because the mechanisms that you'll

0:05:37.620000 --> 0:05:41.280000
 find out in the wild or in the
 real world are going to differ.

0:05:41.280000 --> 0:05:44.100000
 So you're going to have your
 standard login forms, right?

0:05:44.100000 --> 0:05:45.480000
 So that's username and password.

0:05:45.480000 --> 0:05:50.480000
 That's essentially your door with a
 key lock, for example, where, you

0:05:50.480000 --> 0:05:55.480000
 know, you put in your username, which is
 really not secure, but your password

0:05:55.480000 --> 0:06:00.260000
 is what actually allows you in or, you
 know, prevents you from accessing

0:06:00.260000 --> 0:06:07.620000
 the room or a particular website or a resource
 on a website or web application.

0:06:07.620000 --> 0:06:13.220000
 And you'll see that there've been augmentations
 made or you'll find these

0:06:13.220000 --> 0:06:19.260000
 variations in authentication mechanisms in
 the form of two-factor authentication,

0:06:19.260000 --> 0:06:23.560000
 where, you know, they're adding this
 additional layer of security to the

0:06:23.560000 --> 0:06:28.900000
 door to essentially ensure the same
 thing that only authorized personnel

0:06:28.900000 --> 0:06:31.320000
 can access what's behind the door.

0:06:31.320000 --> 0:06:36.220000
 So in the next couple of slides, we'll
 explore some of the key types of

0:06:36.220000 --> 0:06:40.980000
 authentication mechanisms used
 in modern web applications.

0:06:40.980000 --> 0:06:45.340000
 And to kick things off, we have the
 most basic, which I mentioned.

0:06:45.340000 --> 0:06:50.540000
 This is the password-based authentication
 mechanism where users provide

0:06:50.540000 --> 0:06:54.300000
 a username and a password
 to verify their identity.

0:06:54.300000 --> 0:06:58.800000
 Fairly simple. The most basic, you know,
 implemented everywhere, not just

0:06:58.800000 --> 0:07:03.100000
 on web applications or websites,
 but your own computer.

0:07:03.100000 --> 0:07:04.960000
 When you start it up, you need to log in.


0:07:04.960000 --> 0:07:08.680000
 Typically, you're going to, you know,
 use a password and you can start

0:07:08.680000 --> 0:07:12.560000
 to understand that, for example, on Windows,
 you now have different authentication

0:07:12.560000 --> 0:07:18.260000
 mechanisms where you can use a PIN code
 or you can use facial recognition

0:07:18.260000 --> 0:07:22.440000
 or if you have a fingerprint scanner,
 you know, if you're on a Mac, a

0:07:22.440000 --> 0:07:27.280000
 Mac OS system, you still, when you start
 up your Mac OS system, you still

0:07:27.280000 --> 0:07:30.560000
 need to provide your password before,
 you know, biometric authentication

0:07:30.560000 --> 0:07:36.380000
 can be enabled, you know, on system
 wakeups or, you know, whatever.

0:07:36.380000 --> 0:07:38.880000
 But that's the most basic one.

0:07:38.880000 --> 0:07:43.880000
 You then have an augmented version of that,
 which is multi-factor authentication,

0:07:43.880000 --> 0:07:49.040000
 where you're combining two or more independent
 credentials and the keyword

0:07:49.040000 --> 0:07:50.740000
 there is independent.

0:07:50.740000 --> 0:07:52.140000
 So they're not linked to each other.

0:07:52.140000 --> 0:07:56.080000
 So it's not like, you know, providing
 another password, although that

0:07:56.080000 --> 0:07:59.380000
 is generally considered multi-factor
 authentication, but you're trying

0:07:59.380000 --> 0:08:01.540000
 to keep them as distinct as possible.

0:08:01.540000 --> 0:08:09.140000
 So, you know, this could be something like
 a password and or a PIN, something

0:08:09.140000 --> 0:08:12.940000
 that you have. So something that you
 know, something that you have, what

0:08:12.940000 --> 0:08:19.760000
 would you would a person or an individual
 or an identity typically have

0:08:19.760000 --> 0:08:22.280000
 besides a password.

0:08:22.280000 --> 0:08:26.720000
 So, you know, something like a smartphone
 that only you have access to

0:08:26.720000 --> 0:08:30.720000
 and that's where you have your two
-factor authentication codes.

0:08:30.720000 --> 0:08:33.780000
 So, you know, security tokens, etc.

0:08:33.780000 --> 0:08:38.560000
 And then something that you are, and this
 is where we have biometric verification,

0:08:38.560000 --> 0:08:41.280000
 like, you know, fingerprint
 or facial recognition.

0:08:41.280000 --> 0:08:46.080000
 So you can probably already start to
 understand that they're all trying

0:08:46.080000 --> 0:08:49.140000
 to do all of these mechanisms are
 trying to do the same thing.

0:08:49.140000 --> 0:08:53.000000
 They're just, you know, some are much
 more secure than the others, but

0:08:53.000000 --> 0:08:58.460000
 we couldn't have gotten this far without
 the initial password-based authentication

0:08:58.460000 --> 0:09:05.380000
 mechanism. You then have two-factor
 authentication classic or what we

0:09:05.380000 --> 0:09:08.040000
 now refer to as two-factor
 authentication.

0:09:08.040000 --> 0:09:13.780000
 So this is a type or a subset of multi
-factor authentication, but you

0:09:13.780000 --> 0:09:17.240000
 know, that requires exactly two
 factors for authentication.

0:09:17.240000 --> 0:09:23.180000
 Often a password and a one-time code
 that's sent typically via SMS or

0:09:23.180000 --> 0:09:27.660000
 an authenticate app where you configure
 two-factor authentication on a

0:09:27.660000 --> 0:09:30.600000
 device that only you have access to.

0:09:30.600000 --> 0:09:34.400000
 And when you log in with a username
 and password, you'll be prompted to

0:09:34.400000 --> 0:09:38.540000
 enter the two-factor authentication code,
 either through your authenticator

0:09:38.540000 --> 0:09:42.100000
 app on your phone, or you'll
 be sent in a message.

0:09:42.100000 --> 0:09:45.920000
 Again, a message will be sent to your
 number that only you will have access

0:09:45.920000 --> 0:09:53.320000
 to. But as you probably know, with
 these SIM swap attacks, and attack

0:09:53.320000 --> 0:10:00.360000
 is being able to essentially clone your
 phone number, the safest option

0:10:00.360000 --> 0:10:03.120000
 at this point is the authenticator app.

0:10:03.120000 --> 0:10:07.360000
 You then have token-based authentication,
 something that will be covering

0:10:07.360000 --> 0:10:11.640000
 quite a bit in this course, and
 that's essentially uses tokens.

0:10:11.640000 --> 0:10:15.500000
 Now, we'll dive deeper into these authentication
 mechanisms, you know,

0:10:15.500000 --> 0:10:17.920000
 in terms of how they work, etc.

0:10:17.920000 --> 0:10:25.380000
 But some examples of these are your
 standard JSON web tokens or JWTs,

0:10:25.380000 --> 0:10:28.400000
 as they're called, or OAuth tokens.

0:10:28.400000 --> 0:10:33.700000
 These are issued upon successful logins
 and are used for subsequent requests,

0:10:33.700000 --> 0:10:37.680000
 reducing the need to repeatedly
 enter credentials.

0:10:37.680000 --> 0:10:41.980000
 Now, you know, you're probably already
 guessing that as we now start to

0:10:41.980000 --> 0:10:47.700000
 get into authentication mechanisms like
 token-based authentication, that,

0:10:47.700000 --> 0:10:54.820000
 you know, these authentication mechanisms
 are not are really suited in

0:10:54.820000 --> 0:10:59.880000
 some cases for certain types of environments
 over the others, or over

0:10:59.880000 --> 0:11:03.720000
 others, right? And again, I'm not going
 to dive too deep into this, but

0:11:03.720000 --> 0:11:06.580000
 the important thing is that
 you get this overview.

0:11:06.580000 --> 0:11:10.940000
 You then have your single
 sign-on or SSO, right?

0:11:10.940000 --> 0:11:15.980000
 And this authentication mechanism allows
 users to log in once, and gain

0:11:15.980000 --> 0:11:20.820000
 access to multiple applications or
 services without needing to reenter

0:11:20.820000 --> 0:11:26.040000
 credentials, often using protocols
 like SAML or OAuth.

0:11:26.040000 --> 0:11:31.400000
 Again, we'll dive into that at a later
 stage, but moving on, we also have

0:11:31.400000 --> 0:11:34.580000
 the classic one-time passwords or OTP.

0:11:34.580000 --> 0:11:39.580000
 So this is a temporary password that
 is sent to the user via SMS or email

0:11:39.580000 --> 0:11:41.200000
 for a single login session.

0:11:41.200000 --> 0:11:45.840000
 So you've typically seen this with some
 online websites or services that

0:11:45.840000 --> 0:11:52.820000
 you may use. They typically use OTP
 codes in addition to your password.

0:11:52.820000 --> 0:11:57.000000
 So if you try to do, you know, if you
 try to log in, you'll typically

0:11:57.000000 --> 0:12:01.120000
 get an email with a code, you know,
 that you need to essentially, you

0:12:01.120000 --> 0:12:06.100000
 know, copy and paste, or you need to
 use to essentially verify identity.

0:12:06.100000 --> 0:12:10.420000
 And this is a bit different than two
-factor authentication because you're

0:12:10.420000 --> 0:12:14.740000
 also, an additional medium is now being
 added, and that, of course, is

0:12:14.740000 --> 0:12:20.100000
 email, whereby, you know, instead of
 your authenticator app and your phone

0:12:20.100000 --> 0:12:22.340000
 number, you can also use emails.

0:12:22.340000 --> 0:12:24.420000
 All the codes can be sent
 to you via email.

0:12:24.420000 --> 0:12:30.980000
 This is very, very common with
 a lot of SAS services online.

0:12:30.980000 --> 0:12:32.180000
 But there you go.

0:12:32.180000 --> 0:12:37.040000
 So that's OTP. And with that being said,
 that's going to be it for this

0:12:37.040000 --> 0:12:40.800000
 video. I just wanted to give you
 an overview of what to expect.

0:12:40.800000 --> 0:12:45.420000
 I'm sure a lot of you have already come
 across these, not just, you know,

0:12:45.420000 --> 0:12:49.820000
 at a personal level, you know, when
 using the internet, but also as a

0:12:49.820000 --> 0:12:51.260000
 penetration tester.

0:12:51.260000 --> 0:12:55.340000
 And as we progress within this section,
 you'll sort of get an understanding

0:12:55.340000 --> 0:13:00.120000
 of exactly what we'll be doing in terms of,
 you know, which of these authentication

0:13:00.120000 --> 0:13:04.240000
 mechanisms we're going to be testing,
 what types of vulnerabilities we're

0:13:04.240000 --> 0:13:07.080000
 going to be looking for, and of
 course, how to exploit them.

0:13:07.080000 --> 0:13:10.960000
 But with that being said, that's
 going to be it for this video.

0:13:10.960000 --> 0:13:13.380000
 And I will be seeing you
 in the next video.

