WEBVTT

0:00:06.600000 --> 0:00:12.000000
 So, now that we have an understanding of
 what authentication is, authorization

0:00:12.000000 --> 0:00:19.760000
 is, and session management is, we can
 begin exploring the authentication

0:00:19.760000 --> 0:00:33.980000
 testing methodology that we know a
 guide as to firstly, you know, how

0:00:33.980000 --> 0:00:42.500000
 to test web applications for authentication,
 session management vulnerabilities.

0:00:42.500000 --> 0:00:48.280000
 And more importantly, the reason why I
 am actually recording this particular

0:00:48.280000 --> 0:00:51.920000
 video is to provide you
 with this methodology.

0:00:51.920000 --> 0:00:59.680000
 Now, if you have taken the EWT certification,
 you should be familiar with

0:00:59.680000 --> 0:01:05.580000
 this because I introduced, you know,
 the OASP web security testing guide

0:01:05.580000 --> 0:01:12.320000
 in that particular certification or within
 the courses within that certification.

0:01:12.320000 --> 0:01:18.200000
 And the reason why I really like the
 web security testing guide is, you

0:01:18.200000 --> 0:01:22.620000
 know, not because it's something that
 I like to adhere to, you know, very

0:01:22.620000 --> 0:01:26.700000
 strictly, but it sort of always ensures
 that I'm performing checks for

0:01:26.700000 --> 0:01:31.720000
 things that, you know, I would
 typically not test for.

0:01:31.720000 --> 0:01:36.820000
 And given that this course is really
 focused on, you know, authentication

0:01:36.820000 --> 0:01:42.140000
 attacks, widely speaking or broadly speaking,
 I think it's important that

0:01:42.140000 --> 0:01:47.240000
 we actually approach this methodologically
 before we get into any attacks

0:01:47.240000 --> 0:01:49.980000
 or performing any attacks practically.

0:01:49.980000 --> 0:01:55.820000
 So with that being said, I think we need
 to understand what authentication

0:01:55.820000 --> 0:02:00.980000
 testing is. You know, if you're a web
 app and test what authentication

0:02:00.980000 --> 0:02:08.140000
 testing means is essentially testing for
 authentication specific vulnerabilities

0:02:08.140000 --> 0:02:12.620000
 or vulnerabilities specific to
 the authentication mechanisms.

0:02:12.620000 --> 0:02:18.360000
 So formally speaking, authentication
 testing is the process of probing

0:02:18.360000 --> 0:02:23.100000
 and exploiting weaknesses in a web
 application's identity verification

0:02:23.100000 --> 0:02:27.740000
 mechanisms or the authentication mechanisms,
 whether that be a login form

0:02:27.740000 --> 0:02:33.240000
 using the standard username and password
 combo, or one that has two fact

0:02:33.240000 --> 0:02:35.980000
 authentication tokens, etc.

0:02:35.980000 --> 0:02:41.000000
 So the bottom line is that this involves
 testing various authentication

0:02:41.000000 --> 0:02:46.960000
 controls like login forms, the password
 reset functionality, multifactor

0:02:46.960000 --> 0:02:51.620000
 authentication and account lockouts
 to discover any vulnerabilities that

0:02:51.620000 --> 0:02:56.740000
 could allow unauthorized access
 or account compromise.

0:02:56.740000 --> 0:03:00.260000
 So the objective here is you're testing
 the authentication functionality

0:03:00.260000 --> 0:03:04.540000
 of the web application that you're targeting,
 whether you're performing

0:03:04.540000 --> 0:03:10.720000
 a bug bounty, whether you're doing bug
 bounty hunting or this is a standard

0:03:10.720000 --> 0:03:14.420000
 web app, pen test that you've
 been hired to perform.

0:03:14.420000 --> 0:03:20.080000
 So authentication testing targets flaws
 that may permit bypassing of login

0:03:20.080000 --> 0:03:25.880000
 controls. And you know, these would
 include weak password policies, so

0:03:25.880000 --> 0:03:34.320000
 not the login form or authentication
 mechanism, not enforcing stronger

0:03:34.320000 --> 0:03:39.500000
 passwords, essentially meaning that
 users would most likely be tempted

0:03:39.500000 --> 0:03:43.540000
 to use very basic passwords that they
 remember, which can be susceptible

0:03:43.540000 --> 0:03:46.900000
 to brute force attacks
 or dictionary attacks.

0:03:46.900000 --> 0:03:52.320000
 Credential stuffing also as they're called
 session fixation and inadequate

0:03:52.320000 --> 0:03:57.000000
 token handling. So don't worry, you know,
 I've mentioned quite a few vulnerabilities

0:03:57.000000 --> 0:04:01.660000
 or attacks here and we'll be exploring
 them to various degrees, I'll be

0:04:01.660000 --> 0:04:06.280000
 in this course, I'm going to be focusing
 on some of the more modern, or

0:04:06.280000 --> 0:04:12.600000
 I should say targeting some of the more
 modern authentication mechanisms.

0:04:12.600000 --> 0:04:16.960000
 So going beyond the standard brute
 forcing a login form, but taking a

0:04:16.960000 --> 0:04:22.080000
 look at vulnerabilities like authentication
 bypasses, let's see if I can

0:04:22.080000 --> 0:04:26.800000
 remember any other bypassing,
 any rate limiting.

0:04:26.800000 --> 0:04:32.160000
 So if there's a capture, how do you
 brute force that particular login

0:04:32.160000 --> 0:04:34.300000
 form or how do you automate it?

0:04:34.300000 --> 0:04:36.660000
 Because again, that can be quite complex.


0:04:36.660000 --> 0:04:38.040000
 So stuff like that.

0:04:38.040000 --> 0:04:41.480000
 Now the objective really, you know,
 simply port, which is why there's

0:04:41.480000 --> 0:04:46.700000
 only one paragraph on this slide is
 that you're so within this phase,

0:04:46.700000 --> 0:04:51.260000
 you're trying to identify and of course
 exploit your if you're a pen tester,

0:04:51.260000 --> 0:04:56.660000
 weaknesses in authentication
 to gain unauthorized access.

0:04:56.660000 --> 0:04:59.780000
 In addition to that, you're also trying
 to see whether you can elevate

0:04:59.780000 --> 0:05:00.520000
 your privileges.

0:05:00.520000 --> 0:05:05.100000
 So moving from a standard user account
 to maybe getting the privileges

0:05:05.100000 --> 0:05:07.420000
 of an admin user, that
 would be pretty cool.

0:05:07.420000 --> 0:05:13.440000
 Or even hijack legitimate user sessions,
 therefore, or thus demonstrating

0:05:13.440000 --> 0:05:17.280000
 the real world impact of compromised
 authentication security.

0:05:17.280000 --> 0:05:21.240000
 And I'm approaching this from, you know,
 more so a bug bounty perspective

0:05:21.240000 --> 0:05:27.240000
 because, you know, this particular
 methodological approach and the use

0:05:27.240000 --> 0:05:35.900000
 of the OSWSDG guide, as it were, essentially
 provide you with ways of

0:05:35.900000 --> 0:05:41.540000
 not only testing for specific vulnerabilities,
 but the the proper way

0:05:41.540000 --> 0:05:46.320000
 of categorizing or documenting them so
 that when you're writing your report,

0:05:46.320000 --> 0:05:51.240000
 they are as accurate as possible in terms
 of describing exactly what vulnerability

0:05:51.240000 --> 0:05:56.720000
 you've found, but also replicating
 it and demonstrating the potential

0:05:56.720000 --> 0:06:00.300000
 impact, which I think is quite important.


0:06:00.300000 --> 0:06:04.100000
 Now, of course, this will also apply
 to a professional web app pen test,

0:06:04.100000 --> 0:06:08.560000
 but this also applies to bug bounty
 hunting, I would say quite a bit.

0:06:08.560000 --> 0:06:15.600000
 So that's where we have the WSDG
 or the OSWSDG testing guide.

0:06:15.600000 --> 0:06:21.240000
 And for web application penetration
 testers, the OSWSDG service, both

0:06:21.240000 --> 0:06:26.140000
 a training resource and a methodological
 guide, particularly in the critical

0:06:26.140000 --> 0:06:31.460000
 area of authentication testing, particularly,
 but not limited to, as you'll

0:06:31.460000 --> 0:06:34.920000
 see in a few seconds, if you're
 not familiar with it.

0:06:34.920000 --> 0:06:39.980000
 The WSDG is not to be confused with
 the OASP top 10, which is sort of

0:06:39.980000 --> 0:06:45.700000
 a catalog or list of vulnerabilities,
 you know, that are categorized by

0:06:45.700000 --> 0:06:48.560000
 rank by OASP. That's something different.


0:06:48.560000 --> 0:06:55.620000
 This is more so a resource or a guide
 that sort of gives you an idea of,

0:06:55.620000 --> 0:07:01.540000
 you know, what to test, when to
 test it, how to test it, etc.

0:07:01.540000 --> 0:07:07.180000
 So by providing standardized comprehensive
 guidance on testing steps,

0:07:07.180000 --> 0:07:12.500000
 it enables testers like yourself to
 conduct effective, consistent, and

0:07:12.500000 --> 0:07:17.740000
 impactful assessments of, in this case,
 authentication controls and other

0:07:17.740000 --> 0:07:23.360000
 security areas, like session security
 or session management, that will

0:07:23.360000 --> 0:07:26.480000
 be exploring later on within
 this very course.

0:07:26.480000 --> 0:07:30.040000
 So for now, we're just sticking to
 the authentication testing section

0:07:30.040000 --> 0:07:33.340000
 of the OASP web security testing guide.

0:07:33.340000 --> 0:07:37.660000
 A link to the guide has been added to
 this slide, or you can just search

0:07:37.660000 --> 0:07:40.060000
 for OASP WSDG on Google.

0:07:40.060000 --> 0:07:43.980000
 I'll show you what the website
 looks like in a few seconds.

0:07:43.980000 --> 0:07:48.560000
 There's also a PDF, which I, you know,
 personally have on my iPad, pretty

0:07:48.560000 --> 0:07:51.180000
 much for quick reference
 whenever I need to.

0:07:51.180000 --> 0:07:56.820000
 But it's a, it's been an invaluable
 resource to me specifically for, you

0:07:56.820000 --> 0:08:01.660000
 know, these two points here, effective
 and consistent, because we use

0:08:01.660000 --> 0:08:06.060000
 a methodology. Again, you don't have
 to rigorously adhere to one, but

0:08:06.060000 --> 0:08:11.840000
 it also, it always ensures that you're
 performing checks and the WSDG

0:08:11.840000 --> 0:08:15.600000
 or the OASP web security testing guide
 is not something that OASP developed

0:08:15.600000 --> 0:08:21.040000
 in isolation. It's actually a project
 that a lot of, you know, people

0:08:21.040000 --> 0:08:22.880000
 on the defensive side.

0:08:22.880000 --> 0:08:28.440000
 So dev, DevOps, appsec, DevSecOps contribute
 to as well as the offensive

0:08:28.440000 --> 0:08:36.440000
 side. So they actually contribute to making
 it as still, you know, providing

0:08:36.440000 --> 0:08:40.500000
 you with the flexibility to incorporate,
 you know, additional tests if

0:08:40.500000 --> 0:08:48.620000
 you so want. So I've listed out the
 tests that are in the OASP WSDG, the

0:08:48.620000 --> 0:08:55.300000
 latest version, hence the IDs here, and
 what they're used for, or generally

0:08:55.300000 --> 0:09:06.880000
 speaking, and this will make much more
 sense in these are the tests that

0:09:06.880000 --> 0:09:11.200000
 are essentially recommended that, you
 know, you perform if you're testing

0:09:11.200000 --> 0:09:15.560000
 the security of a web application, or
 even an API, but that's something

0:09:15.560000 --> 0:09:17.100000
 that we're not covering right now.

0:09:17.100000 --> 0:09:21.120000
 So the first one is testing for credentials
 transported over an encrypted

0:09:21.120000 --> 0:09:28.200000
 channel. So that's essentially verifying
 that credentials or data being

0:09:28.200000 --> 0:09:33.080000
 transferred from a browser or your browser
 to the web application or the

0:09:33.080000 --> 0:09:40.620000
 web server are transmitted using HTTPS
 or via HTTPS to ensure that they're

0:09:40.620000 --> 0:09:44.780000
 encrypted and they cannot be intercepted
 and, you know, deciphered.

0:09:44.780000 --> 0:09:48.820000
 So man in the middle attacks testing
 for default credentials.

0:09:48.820000 --> 0:09:52.540000
 So checking if any default credentials
 are still in use, especially when

0:09:52.540000 --> 0:09:57.360000
 you're using or you're testing a third
 party web application like a CMS

0:09:57.360000 --> 0:10:02.000000
 or something like that, where you check
 for you essentially check to see

0:10:02.000000 --> 0:10:05.200000
 if there's use of any
 default credentials.

0:10:05.200000 --> 0:10:07.920000
 You then have testing for
 weak lockout mechanisms.

0:10:07.920000 --> 0:10:11.800000
 This is very, very relevant to what you're
 going to deal with in the modern

0:10:11.800000 --> 0:10:16.800000
 day, at least as of me recording this
 course, where you're assessing the

0:10:16.800000 --> 0:10:20.640000
 application's lockout mechanisms to
 prevent brute force attacks on user

0:10:20.640000 --> 0:10:32.720000
 accounts. This, you are limited to let's
 say 10 for every hour and you're

0:10:32.720000 --> 0:10:36.280000
 essentially locked out or an account
 is locked out after three failed

0:10:36.280000 --> 0:10:38.640000
 attempts and you have
 to reset the password.

0:10:38.640000 --> 0:10:44.440000
 So that's one of the security mechanisms
 that you typically see used in

0:10:44.440000 --> 0:10:45.940000
 web applications.

0:10:45.940000 --> 0:10:51.280000
 Another one on login forms is the captures,
 which I'll actually show you

0:10:51.280000 --> 0:10:57.820000
 how to bypass or how you can still
 essentially not bypass, but include

0:10:57.820000 --> 0:11:00.180000
 in your brute force attacks successfully.


0:11:00.180000 --> 0:11:04.380000
 So you can actually brute force perform
 a standard, you know, username

0:11:04.380000 --> 0:11:09.060000
 password brute force on a login form
 that has a capture and not bypass

0:11:09.060000 --> 0:11:17.400000
 it, but also, you know, perform the
 essentially ensure that your capture

0:11:17.400000 --> 0:11:20.240000
 entries per request are correct.

0:11:20.240000 --> 0:11:23.980000
 Then you have testing for bypassing
 authentication schema.

0:11:23.980000 --> 0:11:26.740000
 This again is also very relevant.

0:11:26.740000 --> 0:11:30.940000
 What this is referring to for some of
 you experienced web app pentas out

0:11:30.940000 --> 0:11:35.960000
 there, pentasters out there is authentication
 bypass vulnerabilities.

0:11:35.960000 --> 0:11:41.380000
 So, you know, this is where you identify
 flaws in the authentication process,

0:11:41.380000 --> 0:11:47.000000
 which again is quite wide in terms
 of, you know, but this essentially

0:11:47.000000 --> 0:11:51.620000
 allows attackers or will allow
 you to bypass authentication.

0:11:51.620000 --> 0:11:55.220000
 So, you know, I used a very
 basic example there.

0:11:55.220000 --> 0:11:59.780000
 The standard nomenclature or, you know,
 this is colloquially known as

0:11:59.780000 --> 0:12:04.080000
 authentication bypass where if you have
 a login form through some magic,

0:12:04.080000 --> 0:12:09.340000
 which I'll show you, you're able to
 bypass the login form altogether,

0:12:09.340000 --> 0:12:14.100000
 no brute force just bypass it and somehow
 magically you're logged in.

0:12:14.100000 --> 0:12:17.960000
 You then have testing for vulnerable
 remember password function.

0:12:17.960000 --> 0:12:22.800000
 So, this evaluates if the remember me functionalities
 implement is implemented

0:12:22.800000 --> 0:12:27.160000
 securely without exposing sensitive
 data that could aid in unauthorized

0:12:27.160000 --> 0:12:32.320000
 access. A good an example of how this
 is done well is if you are on a

0:12:32.320000 --> 0:12:40.080000
 web application or let's say a SaaS service
 and it has the forgot password

0:12:40.080000 --> 0:12:45.960000
 functionality. If you enter an email,
 again, let's just say it's real

0:12:45.960000 --> 0:12:49.940000
 or it's not real, you know, you're
 essentially performing a test, the

0:12:49.940000 --> 0:12:53.840000
 web application will not tell you whether
 that email actually belongs

0:12:53.840000 --> 0:12:58.660000
 to an account. So, there's no information
 that it's that's being exposed.

0:12:58.660000 --> 0:13:02.320000
 So, the attacker will not be able to
 tell that, hey, there is an account

0:13:02.320000 --> 0:13:11.260000
 with this email that if this account
 is registered with us, we will send

0:13:11.260000 --> 0:13:14.840000
 a password reset email to the email.

0:13:14.840000 --> 0:13:16.660000
 So, it doesn't reveal
 anything beyond that.

0:13:16.660000 --> 0:13:21.640000
 It doesn't even say that, hey, this
 email doesn't belong to any user or

0:13:21.640000 --> 0:13:24.880000
 anything like that because that can
 be very useful for attackers.

0:13:24.880000 --> 0:13:29.020000
 So, another test that's quite important.

0:13:29.020000 --> 0:13:32.940000
 Then we have a couple of others like
 testing for browser cache weaknesses.

0:13:32.940000 --> 0:13:38.640000
 So, this ensures sensitive information
 is not only stored, is not stored,

0:13:38.640000 --> 0:13:42.280000
 sorry, insecurely in the browser cache
 where attackers could retrieve

0:13:42.280000 --> 0:13:46.940000
 it. Testing for weak password policy,
 that's your brute force attack where

0:13:46.940000 --> 0:13:50.740000
 you examine the application's password
 policy to determine if it enforces

0:13:50.740000 --> 0:13:55.580000
 sufficient password complexity
 and expiration requirements.

0:13:55.580000 --> 0:14:02.780000
 So, you know, to the latter point there,
 it's always good for web application

0:14:02.780000 --> 0:14:08.160000
 to continually prompt the user to reset
 their password, not mandatory,

0:14:08.160000 --> 0:14:11.540000
 but something that's quite important
 in certain industries.

0:14:11.540000 --> 0:14:16.140000
 For example, banking and then testing
 for weak authentication in alternative

0:14:16.140000 --> 0:14:21.700000
 channels. So, this involves testing
 alternative authentication channels.

0:14:21.700000 --> 0:14:25.260000
 For example, API is mobile
 applications, etc.

0:14:25.260000 --> 0:14:29.860000
 For weaker or inconsistent security practices
 that could lead to an account

0:14:29.860000 --> 0:14:34.200000
 compromise. So, what this means, this
 is again, I'll use the example of

0:14:34.200000 --> 0:14:39.100000
 online banking, at least in certain
 regions or countries, you have, you

0:14:39.100000 --> 0:14:43.500000
 know, the ability to access your account
 online through a web application,

0:14:43.500000 --> 0:14:48.040000
 or you can use your mobile application.

0:14:48.040000 --> 0:14:52.160000
 And what you're doing here is what
 you're trying to assess whether the

0:14:52.160000 --> 0:14:57.820000
 web application uses, let's say a specific
 API, does the mobile application

0:14:57.820000 --> 0:15:01.980000
 use the same API in the same standard,
 or is it using something weaker

0:15:01.980000 --> 0:15:05.560000
 that could be, you know,
 potentially targeted.

0:15:05.560000 --> 0:15:11.520000
 And instead of targeting the login form
 on, you know, the web application

0:15:11.520000 --> 0:15:16.040000
 that you access in your browser, you
 may be, you may have more success

0:15:16.040000 --> 0:15:22.040000
 in performing an attack, an authentication
 based attack on, you know,

0:15:22.040000 --> 0:15:25.540000
 the mobile application, either through
 intercepting traffic, you know,

0:15:25.540000 --> 0:15:27.540000
 there's many examples
 that I can give you.

0:15:27.540000 --> 0:15:32.300000
 But these are the tests that are outlined
 in the latest version as of

0:15:32.300000 --> 0:15:38.100000
 recording this video of the OSW SDG, more
 specifically under authentication.

0:15:38.100000 --> 0:15:43.020000
 Remember, this is just a small subset
 of tests that deal or are pertinent

0:15:43.020000 --> 0:15:49.300000
 to authentication testing or testing authentication
 within a web application.

0:15:49.300000 --> 0:15:54.280000
 So before I leave you, before I end
 this video, I'm going to switch over

0:15:54.280000 --> 0:15:58.720000
 to my browser and show you what
 the OSW SDG looks like.

0:15:58.720000 --> 0:16:03.180000
 It's completely free, you know, it's released
 or it's maintained, developed

0:16:03.180000 --> 0:16:04.880000
 and maintained by OSP.

0:16:04.880000 --> 0:16:09.960000
 So, you know, really, really
 awesome resource.

0:16:09.960000 --> 0:16:12.740000
 So I'm just going to switch over into
 my browser really quickly and I'll

0:16:12.740000 --> 0:16:15.880000
 see you, I'll see you there
 in a few seconds.

0:16:15.880000 --> 0:16:22.020000
 All right. So I'm currently in my browser
 and I've just opened up the

0:16:22.020000 --> 0:16:24.260000
 link that I added to the slides.

0:16:24.260000 --> 0:16:29.360000
 Or you can just search for the OSW
 SDG or web security testing guide.

0:16:29.360000 --> 0:16:32.220000
 So here's the project
 page, as you can see.

0:16:32.220000 --> 0:16:36.420000
 And I'll just introduce you to it,
 of course, you can see it says over

0:16:36.420000 --> 0:16:42.440000
 here, the web security testing guide,
 abbreviated as WSDG project produces

0:16:42.440000 --> 0:16:46.700000
 the premier cybersecurity testing resource
 for web application developers

0:16:46.700000 --> 0:16:49.020000
 and security professionals.

0:16:49.020000 --> 0:16:53.500000
 The WSDG is a comprehensive guide to testing
 the security of web applications

0:16:53.500000 --> 0:16:55.160000
 and web services.

0:16:55.160000 --> 0:16:59.400000
 Created by the collaborative efforts
 of cybersecurity professionals and

0:16:59.400000 --> 0:17:04.880000
 dedicated volunteers, the WSDG provides
 a framework of use by penetration

0:17:04.880000 --> 0:17:08.460000
 testers and organizations
 all over the world.

0:17:08.460000 --> 0:17:12.440000
 Enough said that, you know, I mean,
 this is, you know, I'm telling you

0:17:12.440000 --> 0:17:19.980000
 to use it, but it really has been an
 invaluable resource to me, you know,

0:17:19.980000 --> 0:17:23.440000
 over the years. And it's something that
 I always go back to whenever I,

0:17:23.440000 --> 0:17:28.680000
 you know, I'm sort of feeling whenever
 I feel that I'm not on, you know,

0:17:28.680000 --> 0:17:32.380000
 firm footing or I don't have a firm
 footing or I feel that I've missed

0:17:32.380000 --> 0:17:36.580000
 something. The key thing to note is
 that there are different versions

0:17:36.580000 --> 0:17:41.620000
 of the WSDG. There's this stable version,
 which is what you'd consider

0:17:41.620000 --> 0:17:45.960000
 a, a production release, if you will.

0:17:45.960000 --> 0:17:50.300000
 And there's also new versions coming out
 that, you know, update the framework.

0:17:50.300000 --> 0:17:53.180000
 So it's not like a completely
 new framework with new IDs.

0:17:53.180000 --> 0:17:59.420000
 It's sort of an update to the existing,
 uh, to the existing guide, if

0:17:59.420000 --> 0:18:03.500000
 you will. So you can take a
 look at the stable version.

0:18:03.500000 --> 0:18:06.300000
 Or you can always go back to.

0:18:06.300000 --> 0:18:10.160000
 So if you go to the stable version
 here, I believe that's 4.2, you can

0:18:10.160000 --> 0:18:17.500000
 read it online or alternatively, you can
 actually, if you go to the project

0:18:17.500000 --> 0:18:19.820000
 link here, know that
 takes you back there.

0:18:19.820000 --> 0:18:25.880000
 Let me see if you go here, main and the
 other stable release there, there

0:18:25.880000 --> 0:18:28.340000
 should be a way to get the PDF.

0:18:28.340000 --> 0:18:32.580000
 So if I go into the release versions,
 there we are, download the PDF,

0:18:32.580000 --> 0:18:34.580000
 which I already have open here.

0:18:34.580000 --> 0:18:38.940000
 So this is the web security
 testing guide version 4.2.

0:18:38.940000 --> 0:18:49.840000
 And, uh, you know, you can see
 the actual table of contents.

0:18:49.840000 --> 0:18:53.580000
 You can see it breaks down various tests
 or phases of a web app pen test,

0:18:53.580000 --> 0:18:55.440000
 generally speaking.

0:18:55.440000 --> 0:18:59.360000
 Um, so over here you have your
 information gathering phase.

0:18:59.360000 --> 0:19:04.040000
 Uh, you have, um, configuration and deployment
 management testing, identity

0:19:04.040000 --> 0:19:08.220000
 management testing, and what we are
 going to be focusing on, at least

0:19:08.220000 --> 0:19:10.920000
 in this section before we get
 into session management.

0:19:10.920000 --> 0:19:22.460000
 And that is where the, uh, the tests
 that I listed out, uh, in the slides,

0:19:22.460000 --> 0:19:28.200000
 as they are, I didn't put in, uh, their
 subsection header, uh, numbering,

0:19:28.200000 --> 0:19:29.640000
 because that's not really important.

0:19:29.640000 --> 0:19:34.780000
 As you'll see, each test has its own
 unique ID, uh, right over here, which

0:19:34.780000 --> 0:19:39.540000
 corresponds to what's in the slide,
 as I said, as of version 4.2.

0:19:39.540000 --> 0:19:43.960000
 Um, so you can go through each of the
 tests and it'll give you a bit more

0:19:43.960000 --> 0:19:47.180000
 of a description than what
 I gave you in the slides.

0:19:47.180000 --> 0:19:51.880000
 Um, so for example, if I went to, let's
 say, the one we, I was particularly

0:19:51.880000 --> 0:19:58.040000
 interested in, which was, um, you know,
 testing for default credentials.

0:19:58.040000 --> 0:20:02.360000
 So it actually gives you the
 root cause of the problem.

0:20:02.360000 --> 0:20:04.880000
 Um, and the test objective.

0:20:04.880000 --> 0:20:08.620000
 So the test objectives are to enumerate
 the applications for default credentials

0:20:08.620000 --> 0:20:13.900000
 and validate if they still exist, review
 and assess new user accounts.

0:20:13.900000 --> 0:20:18.060000
 And if they are created with any defaults
 or identifiable patterns, so

0:20:18.060000 --> 0:20:18.840000
 very, very nice.

0:20:18.840000 --> 0:20:22.920000
 It tells you what to look out for, what
 the objectives are and then how

0:20:22.920000 --> 0:20:27.220000
 to test it. So in a black box testing,
 the tester knows nothing about

0:20:27.220000 --> 0:20:29.180000
 the application and its underlying
 infrastructure.

0:20:29.180000 --> 0:20:31.760000
 In reality, this is often not true.

0:20:31.760000 --> 0:20:34.280000
 And some information about
 the application is known.

0:20:34.280000 --> 0:20:37.380000
 We suppose that you have identified
 through the use of the techniques

0:20:37.380000 --> 0:20:41.020000
 described in this testing guide under
 the chapter information gathering,

0:20:41.020000 --> 0:20:45.700000
 at least one or more common applications that
 may contain accessible administrative

0:20:45.700000 --> 0:20:50.560000
 interfaces. So, you know, it gives you
 a description there and it gives

0:20:50.560000 --> 0:20:53.080000
 you more, um, information
 about the procedure.

0:20:53.080000 --> 0:20:56.860000
 So, you know, testing for user enumeration,
 testing for weak password

0:20:56.860000 --> 0:21:00.660000
 policy, and, you know,
 what to look out for.

0:21:00.660000 --> 0:21:06.340000
 Um, and also how to modify your approach
 if you're performing a gray box

0:21:06.340000 --> 0:21:08.600000
 pen test as opposed to a black box test.

0:21:08.600000 --> 0:21:12.340000
 And then the really great, uh, you
 know, an additional great thing is

0:21:12.340000 --> 0:21:17.960000
 that it tells you the tools, uh, that
 again, you should use, but I get

0:21:17.960000 --> 0:21:22.320000
 remember this is something that a lot
 of people have collaborated on the

0:21:22.320000 --> 0:21:27.140000
 WSDG. And this is, um, sort of a generalization
 of the most popular tools

0:21:27.140000 --> 0:21:29.220000
 used for this type of testing.

0:21:29.220000 --> 0:21:40.040000
 I'll use one more, that, um, uh, let
 me go into the test objectives here.

0:21:40.040000 --> 0:21:43.280000
 So evaluate the account, lockout mechanisms
 ability to mitigate brute

0:21:43.280000 --> 0:21:48.120000
 force password guessing, evaluate the
 unlock mechanisms resistance to

0:21:48.120000 --> 0:21:50.060000
 unauthorized account locking.

0:21:50.060000 --> 0:21:51.280000
 And it tells you how to do it.

0:21:51.280000 --> 0:21:54.200000
 So attempt to log in with an incorrect
 password three times.

0:21:54.200000 --> 0:21:59.360000
 So essentially how to taste, uh, how
 to test for, um, you know, a weak

0:21:59.360000 --> 0:22:03.660000
 lockout mechanism or, you know, if
 you're testing a well built or well

0:22:03.660000 --> 0:22:09.320000
 secured web, web application, how to
 test a secure or a strong lockout,

0:22:09.320000 --> 0:22:14.460000
 um, a strong lockout mechanism,
 or at least a secure one.

0:22:14.460000 --> 0:22:18.700000
 And then it gives you different,
 um, different considerations.

0:22:18.700000 --> 0:22:22.600000
 So for example, a capture may hinder
 brute force attacks, but they can

0:22:22.600000 --> 0:22:24.040000
 come with their own set of weaknesses.

0:22:24.040000 --> 0:22:26.180000
 And this is what I really love.

0:22:26.180000 --> 0:22:29.640000
 So it sort of gives you the augmentations
 or what to expect.

0:22:29.640000 --> 0:22:33.500000
 And also the, uh, the weaknesses that
 you should test for within these

0:22:33.500000 --> 0:22:38.320000
 augmentation. So something like capture,
 which can be there to again protect

0:22:38.320000 --> 0:22:39.560000
 against brute force attacks.

0:22:39.560000 --> 0:22:44.400000
 It also shows you how you can defeat
 it, uh, depending on what type of

0:22:44.400000 --> 0:22:45.680000
 capture you're dealing with.

0:22:45.680000 --> 0:22:50.720000
 So to evaluate a capture's effectiveness,
 it tells you how to do that

0:22:50.720000 --> 0:22:55.520000
 as well. Um, and then some remi, uh,
 some remediation instructions, which

0:22:55.520000 --> 0:22:59.140000
 can be very useful if you're
 writing a report, right?

0:22:59.140000 --> 0:23:02.920000
 And also gives you references
 to attacks linked to this.

0:23:02.920000 --> 0:23:04.580000
 So brute force attacks.

0:23:04.580000 --> 0:23:07.060000
 And then again, you can
 proceed on anyway.

0:23:07.060000 --> 0:23:11.580000
 The bottom line is I just wanted to give
 you a feel for the OASP web security

0:23:11.580000 --> 0:23:15.060000
 testing guide and how we're
 going to be using it.

0:23:15.060000 --> 0:23:19.620000
 All right. So that brings us
 to the end of this video.

0:23:19.620000 --> 0:23:23.600000
 Um, fairly comfortable and quite happy
 with how I've laid out everything.

0:23:23.600000 --> 0:23:29.640000
 And now that we have the fundamentals
 covered, um, specifically in relation

0:23:29.640000 --> 0:23:34.500000
 to authentication, we can start exploring
 some of the attacks or tests

0:23:34.500000 --> 0:23:42.260000
 outlined in the, um, WSDG, uh, testing
 guide, uh, you know, more specific

0:23:42.260000 --> 0:23:46.460000
 or specifically the, um, authentication
 tests and we'll be looking, as

0:23:46.460000 --> 0:23:51.660000
 I said, not all of them, but some of
 the more common ones, uh, that, um,

0:23:51.660000 --> 0:23:56.280000
 you know, are what you're likely to encounter
 in the real world, uh, regardless

0:23:56.280000 --> 0:24:00.040000
 as to whether you're on the defensive
 side or on the offensive side.

0:24:00.040000 --> 0:24:03.060000
 But with that being said, I don't want
 to take too much of your time.

0:24:03.060000 --> 0:24:05.300000
 That's going to be it for this video.

0:24:05.300000 --> 0:24:07.680000
 And I will be seeing you
 in the next video.

