WEBVTT

0:00:03.880000 --> 0:00:09.340000
 Testing for weak lockout mechanisms
 bypassing capture.

0:00:09.340000 --> 0:00:15.880000
 So in this video we're going to be exploring
 the process of testing for

0:00:15.880000 --> 0:00:18.160000
 weak lockout mechanisms.

0:00:18.160000 --> 0:00:22.840000
 So this builds on what we covered in
 the previous video where we were

0:00:22.840000 --> 0:00:24.020000
 performing a brute force.

0:00:24.020000 --> 0:00:27.840000
 And if you remember what I covered
 in the slides in the previous video

0:00:27.840000 --> 0:00:33.040000
 as well as in the lab demonstration,
 one of the things I mentioned is

0:00:33.040000 --> 0:00:39.400000
 how performing a dictionary attack
 or a brute force attack is sort of

0:00:39.400000 --> 0:00:45.200000
 tied into testing various aspects
 of authentication security.

0:00:45.200000 --> 0:00:49.060000
 One of which are our lockout mechanisms.

0:00:49.060000 --> 0:00:51.260000
 So what are lockout mechanisms?

0:00:51.260000 --> 0:00:52.640000
 Well, we'll get into that shortly.

0:00:52.640000 --> 0:00:59.700000
 But in short, there are mechanisms
 that again work in tandem with the

0:00:59.700000 --> 0:01:04.540000
 authentication mechanism to prevent
 attacks like a dictionary attack or

0:01:04.540000 --> 0:01:07.240000
 a brute force attack.

0:01:07.240000 --> 0:01:13.240000
 And one of these mechanisms, one of
 these lockout mechanisms is capture.

0:01:13.240000 --> 0:01:15.960000
 So you should be familiar
 with the capture.

0:01:15.960000 --> 0:01:21.800000
 They're usually put on login forms
 or pages that you typically expect

0:01:21.800000 --> 0:01:26.080000
 to have or you would expect
 to see malicious activity.

0:01:26.080000 --> 0:01:28.060000
 But of course, it's not
 just limited to that.

0:01:28.060000 --> 0:01:35.660000
 They also, they also created as a way
 to sort of mitigate the amount of

0:01:35.660000 --> 0:01:40.720000
 requests that let's say bad
 bots or crawlers would make.

0:01:40.720000 --> 0:01:43.180000
 And you know, there's a
 lot of aspects to it.

0:01:43.180000 --> 0:01:47.460000
 So before we get into anything practical,
 which we will be exploring in

0:01:47.460000 --> 0:01:53.000000
 the practical section of this video,
 let's get an intro to, you know,

0:01:53.000000 --> 0:01:58.180000
 this particular test, which again, I'm
 using the same nomenclature used

0:01:58.180000 --> 0:02:06.820000
 in the OSW STG and I've listed out the
 test ID there, which is WSTG, ATH,

0:02:06.820000 --> 0:02:09.900000
 N03. So what is this test about?

0:02:09.900000 --> 0:02:14.540000
 Well, as the name suggests, this test
 focuses on evaluating whether a

0:02:14.540000 --> 0:02:19.320000
 web applications lockout mechanism,
 such as capture, effectively prevent

0:02:19.320000 --> 0:02:24.520000
 automated login attempts after multiple
 failed login attempts, which is

0:02:24.520000 --> 0:02:26.180000
 sort of the point here.

0:02:26.180000 --> 0:02:28.600000
 We don't want to block legitimate users.

0:02:28.600000 --> 0:02:34.700000
 We want the lockout mechanism to prevent
 anything that, you know, looks

0:02:34.700000 --> 0:02:36.680000
 automated or looks malicious.

0:02:36.680000 --> 0:02:40.740000
 Case in point, a dictionary attack
 or a brute force attack, right?

0:02:40.740000 --> 0:02:44.280000
 One of these lockout mechanisms that's
 very popular, as I'm sure you're

0:02:44.280000 --> 0:02:46.000000
 aware, is capture.

0:02:46.000000 --> 0:02:49.800000
 So capture is a common method that
 used to prevent automated attacks.

0:02:49.800000 --> 0:02:54.380000
 But if it is weak or improperly implemented,
 attackers can still circumvent

0:02:54.380000 --> 0:02:59.500000
 it, as we'll be seeing in the practical
 section, essentially allowing

0:02:59.500000 --> 0:03:02.640000
 them to bypass the lockout mechanism.

0:03:02.640000 --> 0:03:07.180000
 What that does is just nullifies the
 lockout mechanism and sort of defeats

0:03:07.180000 --> 0:03:11.520000
 the purpose. So the key thing to take
 from this, if you're more so on

0:03:11.520000 --> 0:03:15.400000
 the defensive side or if you're a developer,
 is that correct implementation

0:03:15.400000 --> 0:03:21.700000
 is important. And yeah, so that's
 what the test is all about.

0:03:21.700000 --> 0:03:25.460000
 What we're doing is, and you know,
 there's multiple ways we can do it,

0:03:25.460000 --> 0:03:30.280000
 but obviously, if we are to take the
 case of a brute force attack or a

0:03:30.280000 --> 0:03:36.760000
 dictionary attack on a on a web application
 with a login form that has

0:03:36.760000 --> 0:03:41.960000
 a capture or has a lockout mechanism like
 capture, it can be very difficult

0:03:41.960000 --> 0:03:44.200000
 to, again, perform a brute force attack.

0:03:44.200000 --> 0:03:47.020000
 But that's exactly what we're
 going to be exploring.

0:03:47.020000 --> 0:03:52.440000
 How do we bypass or circumvent these
 captures or weak lockout mechanisms

0:03:52.440000 --> 0:03:56.820000
 and still perform our brute force attack,
 which again, is something quite

0:03:56.820000 --> 0:04:03.400000
 common, very, very modern and relevant
 to modern day web applications

0:04:03.400000 --> 0:04:08.000000
 and consequently modern day web
 application penetration testing.

0:04:08.000000 --> 0:04:12.100000
 So, you know, I don't think I need to
 give you an introduction to capture,

0:04:12.100000 --> 0:04:14.680000
 but I still think it's quite important.

0:04:14.680000 --> 0:04:15.900000
 What is capture?

0:04:15.900000 --> 0:04:21.180000
 Well, capture is a very, it's a technology
 that's been there for a while

0:04:21.180000 --> 0:04:25.560000
 now. And as a result, it's very broad
 in terms of its definition, which

0:04:25.560000 --> 0:04:29.120000
 is why we're going to get into the types
 of captures, which is very important

0:04:29.120000 --> 0:04:31.560000
 for you as a web app and tested to know.

0:04:31.560000 --> 0:04:37.080000
 But simply put capture is a test that
 requires the user or a user to solve

0:04:37.080000 --> 0:04:43.700000
 puzzles. These puzzles can be image based,
 text based, so on and so forth,

0:04:43.700000 --> 0:04:47.860000
 right? And this is all done
 to prove they're human.

0:04:47.860000 --> 0:04:52.420000
 What that means is preventing automated
 bots from exploiting vulnerability.

0:04:52.420000 --> 0:04:57.040000
 So capture was created to again, mitigate
 what I said earlier about bots

0:04:57.040000 --> 0:05:02.920000
 and, you know, anything that is any
 mechanism or any piece of software

0:05:02.920000 --> 0:05:08.780000
 that's making automated requests to a particular
 web application specifically

0:05:08.780000 --> 0:05:15.380000
 to an endpoint, like a login
 form, for example, right?

0:05:15.380000 --> 0:05:19.700000
 And the testing objective here, you know,
 for this particular video, generally

0:05:19.700000 --> 0:05:24.300000
 speaking, if I'm to narrow it down,
 is to evaluate if capture or other

0:05:24.300000 --> 0:05:28.600000
 lockout mechanisms can be bypassed to
 continue automated login attempts,

0:05:28.600000 --> 0:05:32.660000
 whether they be brute force attacks or
 dictionary attacks, which you know,

0:05:32.660000 --> 0:05:33.580000
 I already mentioned.

0:05:33.580000 --> 0:05:36.360000
 So that brings us to the
 types of captures.

0:05:36.360000 --> 0:05:40.340000
 So again, if you've used the internet
 for a while, you know that there've

0:05:40.340000 --> 0:05:44.220000
 been different types of captures over
 the years, or I should say there's

0:05:44.220000 --> 0:05:48.060000
 been an evolution of captures moving
 from very basic ones like the text

0:05:48.060000 --> 0:05:52.460000
 based ones, where they would show you
 sort of a jumbled text that was

0:05:52.460000 --> 0:05:56.300000
 let's say a little bit unclear to read,
 and you had to sort of type in

0:05:56.300000 --> 0:05:59.760000
 what you saw. You know,
 those are very annoying.

0:05:59.760000 --> 0:06:04.500000
 And then we have the, there's a few
 others that will get into, but the

0:06:04.500000 --> 0:06:15.980000
 key thing to some captures will be stronger
 and more secure than others.

0:06:15.980000 --> 0:06:20.780000
 And you'll, you know, it'll become
 clear why some are stronger from a

0:06:20.780000 --> 0:06:23.420000
 security perspective and some are weaker.


0:06:23.420000 --> 0:06:26.760000
 So the next few slides that we'll go
 through will introduce you to the

0:06:26.760000 --> 0:06:32.500000
 different types or implementations of
 capture, ranked from the weakest,

0:06:32.500000 --> 0:06:42.460000
 which are easily bypassed to the strongest,
 which are more secure or actually

0:06:42.460000 --> 0:06:45.960000
 be exploring in this video and how to
 bypass it, which doesn't look, you

0:06:45.960000 --> 0:06:50.020000
 know, at first glance is not as simple
 as it looks, can actually be quite

0:06:50.020000 --> 0:06:54.960000
 confusing. But that's the arithmetic
 based capture, which as the name

0:06:54.960000 --> 0:07:03.880000
 suggests, involve you solving a mathematical
 or arithmetic question.

0:07:03.880000 --> 0:07:09.480000
 So this type of capture asks the user
 to solve a simple arithmetic problem,

0:07:09.480000 --> 0:07:11.940000
 like what's 3 plus 7.

0:07:11.940000 --> 0:07:16.140000
 I remember in the early days with these
 captures or the evolution of arithmetic

0:07:16.140000 --> 0:07:24.600000
 based captures, the obvious, the obvious
 improvement to arithmetic based

0:07:24.600000 --> 0:07:29.040000
 captures to sort of improve security
 was to make them a little bit more

0:07:29.040000 --> 0:07:33.660000
 complex than 3 plus 7, like the one
 you can see in the screenshot align

0:07:33.660000 --> 0:07:41.080000
 to the right of the slide where we
 have 59 or sorry, 5296 plus 5826.

0:07:41.080000 --> 0:07:45.980000
 Now the key thing to notice that this
 can be bypassed by brute force solving

0:07:45.980000 --> 0:07:50.360000
 or using, you know, capture solving
 services like to capture, but I'm

0:07:50.360000 --> 0:07:54.920000
 going to show you exactly how you can
 do it in a few sec in a few minutes.

0:07:54.920000 --> 0:08:03.620000
 The great thing about this one from
 a Web App Pentestus arithmetic can

0:08:03.620000 --> 0:08:10.580000
 be automated or solving these, solving
 these questions can be automated

0:08:10.580000 --> 0:08:14.040000
 sort of in tandem with the brute force
 attack, because remember, in most

0:08:14.040000 --> 0:08:17.880000
 cases, in this case, we have a log in
 form, we have a username password,

0:08:17.880000 --> 0:08:21.220000
 and then the result of the capture, they
 all have to be evaluated or they

0:08:21.220000 --> 0:08:24.100000
 all need to be sent to the server.

0:08:24.100000 --> 0:08:27.740000
 All three of these values need to be sent
 back to the server for validation.

0:08:27.740000 --> 0:08:31.740000
 And all three need to be correct, or
 I should say the capture needs to

0:08:31.740000 --> 0:08:36.960000
 be correct for the request
 to be processed, right?

0:08:36.960000 --> 0:08:42.380000
 And as I said, you know, it offers minimal
 resistance to automated attacks.

0:08:42.380000 --> 0:08:46.700000
 We then have the text based captures, which
 sort of applies to the demonstration

0:08:46.700000 --> 0:08:51.620000
 will be going through in the practical
 section of this video.

0:08:51.620000 --> 0:08:57.920000
 But this is sort of an augmentation
 of the arithmetic, the arithmetic

0:08:57.920000 --> 0:09:02.300000
 capture, but only a mine augmentation
 or improvement.

0:09:02.300000 --> 0:09:06.260000
 And you can see that the security or
 the strength is still classified

0:09:06.260000 --> 0:09:11.540000
 as basic. So this displays a distorted
 or jumbled string of text that

0:09:11.540000 --> 0:09:14.480000
 the user must type in correctly.

0:09:14.480000 --> 0:09:19.020000
 The strength is basic, while it is
 more complex than arithmetic, text

0:09:19.020000 --> 0:09:24.400000
 based captures are still vulnerable
 to bots using OCR technology.

0:09:24.400000 --> 0:09:30.520000
 And that was sort of the main turning
 point in terms of improving the

0:09:30.520000 --> 0:09:35.880000
 security. The earlier text based captures
 would actually have the text

0:09:35.880000 --> 0:09:41.220000
 that you're supposed to validate within
 the actual source code of the

0:09:41.220000 --> 0:09:46.100000
 web page. You know, the actual when you
 made a request, your browser would,

0:09:46.100000 --> 0:09:52.180000
 you know, pretty much get back the HTML
 or whatever, the capture or the

0:09:52.180000 --> 0:09:55.080000
 text within the capture
 was not in an image.

0:09:55.080000 --> 0:10:00.180000
 Instead, it was, you know, just a text
 format, which means you could actually

0:10:00.180000 --> 0:10:03.400000
 evaluate it. It was much
 easier than arithmetic.

0:10:03.400000 --> 0:10:10.500000
 It was much easier to essentially
 bypass the arithmetic captures.

0:10:10.500000 --> 0:10:14.100000
 But then, of course, they augmented
 it or they improved it and they went

0:10:14.100000 --> 0:10:16.760000
 to using images with the text.

0:10:16.760000 --> 0:10:22.120000
 So that means that you'd need to sort
 of resort to OCR technology, which

0:10:22.120000 --> 0:10:24.360000
 is a little bit more difficult.

0:10:24.360000 --> 0:10:29.440000
 And as I said, variants like distorted
 letters or background noise often

0:10:29.440000 --> 0:10:31.940000
 bypassed by advanced bots.

0:10:31.940000 --> 0:10:33.980000
 The vulnerabilities are pretty clear.

0:10:33.980000 --> 0:10:38.200000
 Bots with OCR or pre-trained machine
 learning models can easily recognize

0:10:38.200000 --> 0:10:43.820000
 distorted text. And simple distortion makes
 it easy to decipher with automated

0:10:43.820000 --> 0:10:48.040000
 tools. So text based, and then, of course,
 we have the what we have today,

0:10:48.040000 --> 0:10:52.680000
 which is the image based capture, which
 is considered to be moderate in

0:10:52.680000 --> 0:10:55.200000
 terms of security strength.

0:10:55.200000 --> 0:10:59.540000
 So in this case, you know, the users,
 as I'm sure you're aware, are asked

0:10:59.540000 --> 0:11:02.840000
 to identify or select certain
 objects from a set of images.

0:11:02.840000 --> 0:11:07.240000
 So an example of that is select all
 images with traffic lights or all

0:11:07.240000 --> 0:11:08.920000
 images with taxis.

0:11:08.920000 --> 0:11:12.640000
 I should have aligned the slide
 text and the image here.

0:11:12.640000 --> 0:11:14.520000
 But you sort of get the idea.

0:11:14.520000 --> 0:11:16.640000
 You know, this is very vague.

0:11:16.640000 --> 0:11:24.760000
 Even as a human, it can be difficult
 to decipher what a taxi is.

0:11:24.760000 --> 0:11:28.840000
 But in certain cases, as I'm sure you've
 seen yourself, usually have to

0:11:28.840000 --> 0:11:34.580000
 go through maybe one or two attempts
 if the matching is quite, let's say,

0:11:34.580000 --> 0:11:37.720000
 vague, what they are asking
 you to match is vague.

0:11:37.720000 --> 0:11:39.320000
 It gets quite annoying.

0:11:39.320000 --> 0:11:43.660000
 Now the strength for this is, of course,
 moderate for obvious reasons.

0:11:43.660000 --> 0:11:48.520000
 And this particular capture requires more
 sophisticated AI models to bypass,

0:11:48.520000 --> 0:11:53.260000
 essentially making it harder than
 simple text text based ones.

0:11:53.260000 --> 0:11:57.320000
 And the vulnerabilities are
 again listed out here.

0:11:57.320000 --> 0:12:01.680000
 Image based captures are difficult
 for bots, but still not impervious.

0:12:01.680000 --> 0:12:05.200000
 And of course, OCR and machine learning
 can still be used to identify

0:12:05.200000 --> 0:12:08.900000
 objects, though it is harder compared
 to text based captures.

0:12:08.900000 --> 0:12:13.620000
 So I just wanted to give you an intro
 or sort of rehash your memory when

0:12:13.620000 --> 0:12:14.620000
 it comes down to captures.

0:12:14.620000 --> 0:12:19.020000
 And again, the reason for this is important
 because you need to understand

0:12:19.020000 --> 0:12:21.120000
 that there's different types.

0:12:21.120000 --> 0:12:25.200000
 And in certain cases, some web applications
 end up, you know, using their

0:12:25.200000 --> 0:12:32.560000
 own form of capture, if you will, or
 let's just call it a, a week or a

0:12:32.560000 --> 0:12:36.420000
 lockout mechanism, which will also
 be exploring in the next video, in

0:12:36.420000 --> 0:12:40.400000
 terms of what other lockout mechanisms
 exist, like rate limiting and how

0:12:40.400000 --> 0:12:44.200000
 to bypass that. Going to
 be quite interesting.

0:12:44.200000 --> 0:12:48.400000
 We also have a few others, which are
 again, you know, these are sort of

0:12:48.400000 --> 0:12:52.340000
 the industry standard as of me recording
 this video where you have recapture

0:12:52.340000 --> 0:12:55.240000
 version two, which is moderate to strong.


0:12:55.240000 --> 0:13:01.260000
 This is a Google develop capture where
 users must, users often must click

0:13:01.260000 --> 0:13:03.700000
 a checkbox labeled I'm not a robot.

0:13:03.700000 --> 0:13:06.600000
 I'm sure you're, you're, you're familiar
 with that is sort of two stage,

0:13:06.600000 --> 0:13:09.940000
 if you will. And then we have
 recapture version three.

0:13:09.940000 --> 0:13:13.180000
 This is an evolution of recapture that
 works entirely in the background

0:13:13.180000 --> 0:13:15.180000
 without user interaction.

0:13:15.180000 --> 0:13:19.720000
 And it assigns a score based on user
 behavior to determine if the request

0:13:19.720000 --> 0:13:21.080000
 is legitimate or suspicious.

0:13:21.080000 --> 0:13:27.000000
 So I'm not, I'm pretty sure you've probably
 experienced this on Google.

0:13:27.000000 --> 0:13:32.720000
 For example, one of the ways I usually
 trigger this, this capture is when

0:13:32.720000 --> 0:13:39.020000
 I am using Google Docs, or I'm, you
 know, using Google keyword filters,

0:13:39.020000 --> 0:13:42.360000
 you know, part of information gathering,
 or if I'm looking for a specific

0:13:42.360000 --> 0:13:48.540000
 file or site, have you send, you know,
 a little too many of these requests,

0:13:48.540000 --> 0:13:52.360000
 recapture V3s, what runs in the background
 says, hey, this looks, you

0:13:52.360000 --> 0:13:53.700000
 know, potentially malicious.

0:13:53.700000 --> 0:13:56.700000
 And it asks you to confirm
 that you're not a robot.

0:13:56.700000 --> 0:14:01.260000
 So the objective there is just to prevent,
 again, you know, malicious

0:14:01.260000 --> 0:14:07.500000
 bots or, you know, malicious users from,
 I don't, in this case, finding,

0:14:07.500000 --> 0:14:14.300000
 finding specific information, but also
 is tied to sort of unusual activity,

0:14:14.300000 --> 0:14:18.100000
 which I'm not really a fan of one of
 the reasons why I'm not a huge fan

0:14:18.100000 --> 0:14:23.780000
 of Google, and the amount of telemetry
 they gather, you know, in with

0:14:23.780000 --> 0:14:28.820000
 regards to users, because one of the
 things, and I apologize for, for

0:14:28.820000 --> 0:14:31.880000
 going on a tangent, one of the things
 that Google does, if you're signed

0:14:31.880000 --> 0:14:36.580000
 into a Google account or a Gmail account
 and use Google search over the

0:14:36.580000 --> 0:14:39.880000
 course of, you know, the account's history,
 let's say you've had the account

0:14:39.880000 --> 0:14:44.580000
 for, you know, someone like me for about
 eight to 10 years, it actually

0:14:44.580000 --> 0:14:49.900000
 learns, you know, what your activity is
 like, or when you perform searches,

0:14:49.900000 --> 0:14:54.900000
 what you typically search about, and
 based on that, it will essentially

0:14:54.900000 --> 0:15:00.320000
 look or keep an eye out for anomalies,
 you know, in terms of your activity.

0:15:00.320000 --> 0:15:05.240000
 So let's say, you know, over the course
 of two years, you know, Google

0:15:05.240000 --> 0:15:10.620000
 is able to see that at every, at 8 p
.m., I search for news or whatever,

0:15:10.620000 --> 0:15:14.960000
 and then all of a sudden at 6 p.m., I'm,
 you know, sending multiple requests

0:15:14.960000 --> 0:15:18.920000
 for stuff outside of generally
 speaking what I search for.

0:15:18.920000 --> 0:15:25.140000
 That's another way that, you know, that
 that's another way in which recapture

0:15:25.140000 --> 0:15:28.640000
 version three is triggered, of course,
 that's not really pertinent to

0:15:28.640000 --> 0:15:30.400000
 what what we're going to be looking at.

0:15:30.400000 --> 0:15:36.540000
 But let's get into the meat and potatoes
 of this particular video by,

0:15:36.540000 --> 0:15:40.060000
 you know, sort of exploring how this
 can be done or how we can bypass

0:15:40.060000 --> 0:15:43.560000
 captures, practically speaking.

0:15:43.560000 --> 0:15:49.440000
 So in order to do that, we're going to
 be, you know, utilizing a practical

0:15:49.440000 --> 0:15:53.300000
 lab. So this video has a
 lab associated with it.

0:15:53.300000 --> 0:15:57.460000
 It's going to be the, the lab is just
 going to be below this video.

0:15:57.460000 --> 0:16:01.460000
 And, you know, you just click on it,
 just start it up as you would with

0:16:01.460000 --> 0:16:05.160000
 any other labs on the INE platform.

0:16:05.160000 --> 0:16:09.440000
 And this particular lab will provide
 you with access to a pre-configured

0:16:09.440000 --> 0:16:11.580000
 calilinic system within your browser.

0:16:11.580000 --> 0:16:15.380000
 So you know, you don't need to use
 your own or anything like that.

0:16:15.380000 --> 0:16:19.240000
 But with that being said, I'm going
 to start up my lab environment and

0:16:19.240000 --> 0:16:23.340000
 I'll switch over and I'll see you
 there in a couple of seconds.

0:16:23.340000 --> 0:16:30.160000
 All right. So I am currently
 within the lab environment.

0:16:30.160000 --> 0:16:35.940000
 And as you can see, I have, I now can
 access the pre-configured calilinic

0:16:35.940000 --> 0:16:40.640000
 system. Now in this particular lab, you
 may be asking where is the target

0:16:40.640000 --> 0:16:42.320000
 or the target web application.

0:16:42.320000 --> 0:16:49.220000
 Well, this can easily be found by opening
 up your terminal and just, you

0:16:49.220000 --> 0:16:53.620000
 know, typing in the IF config command
 to get your calilinics IP.

0:16:53.620000 --> 0:16:58.720000
 So take a look at the network interface,
 Ethernet 1, and the INET address

0:16:58.720000 --> 0:17:03.680000
 here. So in your case, your calilinics
 IP address will be different.

0:17:03.680000 --> 0:17:04.920000
 So keep that in mind.

0:17:04.920000 --> 0:17:08.900000
 But all you need to do is just copy
 this value here or your calilinics

0:17:08.900000 --> 0:17:12.680000
 IP address and change the two
 at the end to the three.

0:17:12.680000 --> 0:17:15.680000
 The target is always the third
 IP within the subnet.

0:17:15.680000 --> 0:17:20.880000
 So whatever your calilinics IP is, just,
 you know, copy it and then turn

0:17:20.880000 --> 0:17:24.240000
 the two or change the two
 at the end to a three.

0:17:24.240000 --> 0:17:27.660000
 So I'll open up my browser
 here, which is Firefox.

0:17:27.660000 --> 0:17:34.660000
 And we will let me go ahead and
 change the paste that in there.

0:17:34.660000 --> 0:17:37.620000
 Put change the two to
 a three in it, enter.

0:17:37.620000 --> 0:17:38.500000
 And there we are.

0:17:38.500000 --> 0:17:40.800000
 So this is the web application.

0:17:40.800000 --> 0:17:45.840000
 And it immediately takes us to a login
 form right over here with a, you

0:17:45.840000 --> 0:17:49.000000
 know, username, password,
 field, and look here.

0:17:49.000000 --> 0:17:49.880000
 We have a capture.

0:17:49.880000 --> 0:17:53.220000
 So in this case, this is
 an arithmetic capture.

0:17:53.220000 --> 0:17:57.520000
 And this is quite complex in, you know,
 in terms of a human being able

0:17:57.520000 --> 0:18:00.800000
 to solve it. But I guess that's the idea.


0:18:00.800000 --> 0:18:06.560000
 Firstly, to prevent any, any, any crazy
 individuals from trying to brute

0:18:06.560000 --> 0:18:08.420000
 force this manually.

0:18:08.420000 --> 0:18:09.560000
 But there we are.

0:18:09.560000 --> 0:18:10.780000
 We can see that.

0:18:10.780000 --> 0:18:15.940000
 And we also have an option to,
 you know, keep you signed in.

0:18:15.940000 --> 0:18:22.080000
 So the bottom line is, you know, we need
 to specify a username, a password,

0:18:22.080000 --> 0:18:26.620000
 and we then have the capture, which,
 you know, needs to be correct in

0:18:26.620000 --> 0:18:29.300000
 order for your request to
 be processed successfully.

0:18:29.300000 --> 0:18:31.180000
 Otherwise, it's not.

0:18:31.180000 --> 0:18:38.680000
 So first things first, I think it's
 what's important that we do is let

0:18:38.680000 --> 0:18:45.060000
 us try and test this login form, you know,
 just let's see if we can enumerate

0:18:45.060000 --> 0:18:45.480000
 any information.

0:18:45.480000 --> 0:18:50.320000
 I spoke about this in the username enumeration
 video, as well as the previous

0:18:50.320000 --> 0:18:55.400000
 video. But in this particular lab, the
 username we're testing for is admin.

0:18:55.400000 --> 0:18:57.940000
 All right. So that's already
 been provided to you.

0:18:57.940000 --> 0:19:02.340000
 And it is listed in the lab documentation
 or the documentation for this

0:19:02.340000 --> 0:19:04.840000
 lab. So we're testing admin.

0:19:04.840000 --> 0:19:09.740000
 So let's see what happens when we say,
 you know, we just specify a username,

0:19:09.740000 --> 0:19:12.640000
 no password, and no capture
 and just hit sign in.

0:19:12.640000 --> 0:19:14.520000
 Okay. So it looks like nothing happens.

0:19:14.520000 --> 0:19:16.020000
 We need to provide a value.

0:19:16.020000 --> 0:19:18.280000
 So I'll just say password 123.

0:19:18.280000 --> 0:19:20.020000
 That's not the password, obviously.

0:19:20.020000 --> 0:19:21.400000
 Let's hit sign in.

0:19:21.400000 --> 0:19:23.180000
 We still need to enter the capture.

0:19:23.180000 --> 0:19:28.740000
 So all three fields, you know, all three
 of these values, or, you know,

0:19:28.740000 --> 0:19:31.420000
 these parameters and their
 values are required.

0:19:31.420000 --> 0:19:36.480000
 So let's see if I can do this
 two, three, two, three.

0:19:36.480000 --> 0:19:40.680000
 And that's one six, zero one.

0:19:40.680000 --> 0:19:43.680000
 That should be 3924.

0:19:43.680000 --> 0:19:47.600000
 So I'll just type that in here 3924.

0:19:47.600000 --> 0:19:50.160000
 And we hit sign in.

0:19:50.160000 --> 0:19:51.640000
 Okay. All right.

0:19:51.640000 --> 0:19:56.700000
 So we know at this point, we already
 know the username exists.

0:19:56.700000 --> 0:19:58.640000
 The password entered is incorrect.

0:19:58.640000 --> 0:20:01.880000
 But the capture was correct.

0:20:01.880000 --> 0:20:03.000000
 That's the first thing.

0:20:03.000000 --> 0:20:07.460000
 So what I usually like doing when dealing
 with captures or running similar

0:20:07.460000 --> 0:20:11.380000
 types of tests on login forms or whatever
 forms that, you know, allow

0:20:11.380000 --> 0:20:16.840000
 me to, you know, either authenticate
 or whatever, or reset an account

0:20:16.840000 --> 0:20:21.860000
 password is I like taking note of the
 conditions or the tests and the

0:20:21.860000 --> 0:20:28.220000
 results, right? So in this case, correct,
 correct username, which we know

0:20:28.220000 --> 0:20:39.180000
 exists. So correct username, correct
 username, incorrect password, correct

0:20:39.180000 --> 0:20:46.060000
 capture. That gives us the following.

0:20:46.060000 --> 0:20:48.840000
 So it gives us this string over here.

0:20:48.840000 --> 0:20:50.560000
 Okay, which is actually useful.

0:20:50.560000 --> 0:20:54.360000
 We'll get back to this shortly because
 in this case, this is the type

0:20:54.360000 --> 0:20:59.940000
 of both information I was talking about
 in the username enumeration video

0:20:59.940000 --> 0:21:05.120000
 when I said that if a login form returns
 a response that's two verbals,

0:21:05.120000 --> 0:21:09.440000
 it can actually, you know, either tell
 the user that tell you the pen

0:21:09.440000 --> 0:21:11.160000
 tester that a user exists.

0:21:11.160000 --> 0:21:16.500000
 But in this case, it can also be used
 to, you know, identify, again, as

0:21:16.500000 --> 0:21:19.220000
 I said, not only whether user
 exists or doesn't exist.

0:21:19.220000 --> 0:21:22.980000
 In this case, we're able to tell that
 the user exists because it says,

0:21:22.980000 --> 0:21:27.540000
 as you can read here, this form only
 accepts five character passwords

0:21:27.540000 --> 0:21:28.840000
 from the character set.

0:21:28.840000 --> 0:21:32.020000
 Now, if you remember in the previous video,
 we're talking about a dictionary

0:21:32.020000 --> 0:21:36.660000
 attack, I mentioned when you would
 get into, or when you would perform

0:21:36.660000 --> 0:21:39.920000
 a traditional classic brute force attack.


0:21:39.920000 --> 0:21:45.360000
 And in this case, it's actually telling
 us that it, this form only accepts

0:21:45.360000 --> 0:21:46.340000
 five characters.

0:21:46.340000 --> 0:21:50.940000
 So telling us that it really doesn't
 give us an upper bound, it's giving

0:21:50.940000 --> 0:21:55.760000
 us a minimum, so five minimum,
 which password 123 was over.

0:21:55.760000 --> 0:22:01.360000
 However, because, you know, the minimum
 is not an issue, it tells us that

0:22:01.360000 --> 0:22:06.180000
 the character set for the passwords or
 the passwords must have the following

0:22:06.180000 --> 0:22:10.940000
 character set. So this looks like,
 you know, not really reject.

0:22:10.940000 --> 0:22:15.540000
 So a x for m and this closed
 bracket right over here.

0:22:15.540000 --> 0:22:22.820000
 So that means that the password will
 be, in this case, it's saying my

0:22:22.820000 --> 0:22:26.260000
 apologies, it looks like only accepts
 five character passwords.

0:22:26.260000 --> 0:22:29.560000
 So nothing over, which we
 can actually test, right?

0:22:29.560000 --> 0:22:32.580000
 And then it needs to include
 this character set.

0:22:32.580000 --> 0:22:37.040000
 So whatever permutations of this character
 set exists, which I'll actually

0:22:37.040000 --> 0:22:40.500000
 show you how to generate a word list
 or a password list for the brute

0:22:40.500000 --> 0:22:45.120000
 force attack using these parameters or,
 you know, this criteria, and you'll

0:22:45.120000 --> 0:22:48.700000
 actually see what you'll see the difference
 between a brute force attack

0:22:48.700000 --> 0:22:49.700000
 and a dictionary attack.

0:22:49.700000 --> 0:22:52.720000
 Anyway, I'm getting on
 a different tangent.

0:22:52.720000 --> 0:22:56.260000
 So, okay, let's try a different test.

0:22:56.260000 --> 0:23:03.260000
 So admin, and then now what I'm going
 to do, I'm just going to use my

0:23:03.260000 --> 0:23:05.140000
 name here of five letter passwords.

0:23:05.140000 --> 0:23:12.600000
 So we can just say, you know, Alexi,
 a l e x i, and then we'll put in

0:23:12.600000 --> 0:23:16.840000
 the correct capture will test what happens
 when the capture is incorrect.

0:23:16.840000 --> 0:23:24.160000
 So 1754 7742528.

0:23:24.160000 --> 0:23:27.980000
 Put that in there, sign in.

0:23:27.980000 --> 0:23:33.420000
 Okay, still gives us the same thing, which
 means that this is being enforced.

0:23:33.420000 --> 0:23:37.440000
 So that means that our password, you
 know, five characters, but it should

0:23:37.440000 --> 0:23:43.580000
 have up, you know, permutations of
 this, you know, the password should

0:23:43.580000 --> 0:23:47.800000
 be, you know, should contain or should
 be limited within this scope of

0:23:47.800000 --> 0:23:49.600000
 this character set anyway.

0:23:49.600000 --> 0:23:53.860000
 So now I'm just going to use the correct,
 we'll run the third test.

0:23:53.860000 --> 0:23:57.300000
 So admin, and I'll just say password
 not really important.

0:23:57.300000 --> 0:24:01.320000
 But the bottom line is that the capture
 in this time, in this case, we'll

0:24:01.320000 --> 0:24:02.940000
 just provide an incorrect value.

0:24:02.940000 --> 0:24:07.040000
 So I'll just say one, two, three, four,
 let's hit enter, and it tells

0:24:07.040000 --> 0:24:08.420000
 us incorrect capture.

0:24:08.420000 --> 0:24:11.780000
 So when the capture is incorrect, and
 that's what I wanted to demonstrate,

0:24:11.780000 --> 0:24:17.660000
 when the capture is incorrect, your
 request is disregarded completely.

0:24:17.660000 --> 0:24:21.360000
 So let me go ahead and write that down.

0:24:21.360000 --> 0:24:29.820000
 So in this case, we'll say correct username,
 incorrect password, incorrect

0:24:29.820000 --> 0:24:36.800000
 capture. And I'm just going
 to copy that there.

0:24:36.800000 --> 0:24:40.020000
 So error incorrect, incorrect capture.

0:24:40.020000 --> 0:24:43.300000
 This will be important to
 you in a few seconds.

0:24:43.300000 --> 0:24:45.760000
 So, and I can actually verify this.

0:24:45.760000 --> 0:24:54.180000
 So if I say, you know, John, John, H,
 and password is just Alexis is bad

0:24:54.180000 --> 0:25:00.400000
 at typing. And I say an incorrect, you
 know, incorrect result here, actually,

0:25:00.400000 --> 0:25:01.920000
 that might be correct.

0:25:01.920000 --> 0:25:05.640000
 5100 sign in, there we are.

0:25:05.640000 --> 0:25:09.880000
 So it doesn't really matter whether
 your info is correct or incorrect.

0:25:09.880000 --> 0:25:13.640000
 If your capture is incorrect, it's not
 going to be passed to the server.

0:25:13.640000 --> 0:25:19.000000
 So very, very important, which also, you
 know, makes me believe that there's

0:25:19.000000 --> 0:25:21.100000
 something interesting going on here.

0:25:21.100000 --> 0:25:28.220000
 So if I go into inspect element,
 it looks like the arithmetic.

0:25:28.220000 --> 0:25:30.560000
 This is all client side, right?

0:25:30.560000 --> 0:25:32.220000
 So this is within the browser.

0:25:32.220000 --> 0:25:35.920000
 So, you know, let me just expand this.

0:25:35.920000 --> 0:25:41.600000
 If I go into just hold on a
 second, so inspect element.

0:25:41.600000 --> 0:25:47.540000
 And if we go to not the style editor,
 we just go to the inspector right

0:25:47.540000 --> 0:25:51.880000
 over here. And I want to
 click on this right here.

0:25:51.880000 --> 0:25:55.380000
 Okay, so we can see this in here.

0:25:55.380000 --> 0:25:59.520000
 I don't know whether it
 is clear to everyone.

0:25:59.520000 --> 0:26:00.120000
 So there we are.

0:26:00.120000 --> 0:26:05.680000
 It looks like it is encapsulated in
 an H4 under a div, where yes, we can

0:26:05.680000 --> 0:26:09.280000
 see that it is being sent.

0:26:09.280000 --> 0:26:13.000000
 The capture is being included in the
 response for every GET request we

0:26:13.000000 --> 0:26:18.200000
 make. So that means that if I refresh
 this, you know, it's going it's

0:26:18.200000 --> 0:26:19.480000
 part of the source code.

0:26:19.480000 --> 0:26:23.000000
 So if I save view page source, and
 let me just zoom in so you can see

0:26:23.000000 --> 0:26:28.180000
 this here. If we go to where we have
 the form, there we are form, we can

0:26:28.180000 --> 0:26:30.060000
 see the classes of form.

0:26:30.060000 --> 0:26:38.060000
 We have the username whose name is user,
 password, and then capture right

0:26:38.060000 --> 0:26:42.420000
 over here. So, sorry, right over here.

0:26:42.420000 --> 0:26:50.140000
 So there we go. We can see it's H4, and
 we then have the actual arithmetic

0:26:50.140000 --> 0:26:53.160000
 operation passed in here.

0:26:53.160000 --> 0:26:57.840000
 So this actually makes it quite easy
 for us because if the capture is

0:26:57.840000 --> 0:27:03.280000
 unique or the arithmetic operation is
 unique for every request, then we

0:27:03.280000 --> 0:27:07.040000
 can write a script, you know, Python
 script, and actually use rejects

0:27:07.040000 --> 0:27:10.560000
 to filter for the arithmetic operation.

0:27:10.560000 --> 0:27:16.320000
 And then we can improve upon the script
 to actually perform or automate

0:27:16.320000 --> 0:27:19.540000
 the brute force attack for us.

0:27:19.540000 --> 0:27:27.260000
 And secondly, we can also use JavaScript
 or not JavaScript, we can use

0:27:27.260000 --> 0:27:37.660000
 Python or the request library to actually,
 to actually, you know, evaluate

0:27:37.660000 --> 0:27:42.780000
 this for us. So or to perform the
 calculation for each request.

0:27:42.780000 --> 0:27:46.020000
 And you know, the great thing about modern
 computers is they're very fast.

0:27:46.020000 --> 0:27:48.220000
 So this shouldn't take any time at all.

0:27:48.220000 --> 0:27:52.500000
 We also have the very, very useful
 information, which is the character

0:27:52.500000 --> 0:27:57.300000
 set here, which we'll use to generate
 our word list or password list for

0:27:57.300000 --> 0:27:59.060000
 the brute force attack.

0:27:59.060000 --> 0:28:02.400000
 So it looks like in this
 case, my tab crashed.

0:28:02.400000 --> 0:28:03.680000
 I'm not really sure why.

0:28:03.680000 --> 0:28:09.640000
 Let me probably need
 to reload this again.

0:28:09.640000 --> 0:28:10.880000
 Firefox all is crashing.

0:28:10.880000 --> 0:28:13.520000
 Let me restart it again.

0:28:13.520000 --> 0:28:16.600000
 And then we'll create the script.

0:28:16.600000 --> 0:28:19.020000
 So there we go. Sign in looper.

0:28:19.020000 --> 0:28:20.340000
 There we go. All right, cool.

0:28:20.340000 --> 0:28:27.140000
 So one more thing I'd like to point
 out in this lab, it's not going to

0:28:27.140000 --> 0:28:31.400000
 be the case, but in certain cases, very
 old websites, the captures were

0:28:31.400000 --> 0:28:35.140000
 again, not randomized or the arithmetic
 operations were not randomized.

0:28:35.140000 --> 0:28:37.540000
 They were part of a library or an array.

0:28:37.540000 --> 0:28:41.300000
 So you may see captures repeated in
 that case, it'll be even easier to

0:28:41.300000 --> 0:28:42.280000
 brute force attack.

0:28:42.280000 --> 0:28:46.900000
 So I'm going to open up my terminal
 and I'm going to navigate onto my

0:28:46.900000 --> 0:28:54.280000
 desktop here. And I am going to create
 a script to check something.

0:28:54.280000 --> 0:28:57.360000
 Firstly, there obviously is a session ID.


0:28:57.360000 --> 0:29:00.180000
 And I know we haven't covered session
 IDs, but you should be familiar

0:29:00.180000 --> 0:29:01.620000
 with them by this point.

0:29:01.620000 --> 0:29:02.880000
 We will revisit them.

0:29:02.880000 --> 0:29:06.840000
 Actually, the next section of the course,
 but I'll just call this request

0:29:06.840000 --> 0:29:10.460000
 dot pi. Let's use Python.

0:29:10.460000 --> 0:29:14.080000
 And I'll increase my font size
 so you can see what's going on.

0:29:14.080000 --> 0:29:19.500000
 So first things first, we need a few
 libraries in here, we're going to

0:29:19.500000 --> 0:29:23.040000
 work. So we'll just say import.

0:29:23.040000 --> 0:29:25.560000
 Sorry, I'm using them.

0:29:25.560000 --> 0:29:27.780000
 You can use whatever text
 that it works for you.

0:29:27.780000 --> 0:29:29.680000
 So I'll say import re.

0:29:29.680000 --> 0:29:31.260000
 That's the rejects library.

0:29:31.260000 --> 0:29:34.540000
 And then we'll say import requests,
 because we need to be able to make

0:29:34.540000 --> 0:29:37.360000
 requests or import requests.

0:29:37.360000 --> 0:29:40.840000
 And then now we need to
 create a session object.

0:29:40.840000 --> 0:29:43.960000
 So if you're familiar with Python and
 the request library, so we'll say

0:29:43.960000 --> 0:29:52.080000
 session, that's going to be requests
 dot session over here.

0:29:52.080000 --> 0:29:58.900000
 Okay. We then need to create
 a rejects variable here.

0:29:58.900000 --> 0:30:03.300000
 And we need to actually specify our what
 we're checking for, right, which

0:30:03.300000 --> 0:30:08.680000
 is the h4 tag. But more specifically,
 the value included or in between

0:30:08.680000 --> 0:30:16.240000
 the h4 tag. So we'll get
 to that in a second.

0:30:16.240000 --> 0:30:22.820000
 And then we need to we need to send
 a get request to the server and then

0:30:22.820000 --> 0:30:24.980000
 save it in a variable.

0:30:24.980000 --> 0:30:28.900000
 So in this case, we'll just create
 a new variable called response.

0:30:28.900000 --> 0:30:32.900000
 And we'll say session dot get.

0:30:32.900000 --> 0:30:38.800000
 And then in here, we need to put in
 the IP address of the web server.

0:30:38.800000 --> 0:30:40.680000
 In your case, the IP will be different.

0:30:40.680000 --> 0:30:45.600000
 So do remember that in every lab instantiation,
 it's going to be different.

0:30:45.600000 --> 0:30:46.700000
 So I'll copy that in there.

0:30:46.700000 --> 0:30:49.940000
 There's no spec, there's no specific IPO.


0:30:49.940000 --> 0:30:54.120000
 Sorry, there's no specific port is
 just port 80, because it's HTTP.

0:30:54.120000 --> 0:30:56.580000
 That makes it even easier.

0:30:56.580000 --> 0:30:59.720000
 And we'll close that there.

0:30:59.720000 --> 0:31:02.600000
 So sending a get request.

0:31:02.600000 --> 0:31:08.120000
 Now, we need to get some
 info from the response.

0:31:08.120000 --> 0:31:09.900000
 So what do we want from the response?

0:31:09.900000 --> 0:31:12.780000
 At least what do we want displayed to us?


0:31:12.780000 --> 0:31:22.020000
 I obviously want the, we want to search,
 you know, the response for the

0:31:22.020000 --> 0:31:24.600000
 arithmetic operation.

0:31:24.600000 --> 0:31:26.760000
 And we'll do that using rejects.

0:31:26.760000 --> 0:31:31.520000
 So we'll just say output is going to
 be equal to variable output is going

0:31:31.520000 --> 0:31:35.500000
 to be equal to or use the rejects
 library re dot search.

0:31:35.500000 --> 0:31:39.280000
 And then we're going to pass in the
 rejects variable, which we created.

0:31:39.280000 --> 0:31:41.800000
 We haven't added in our value yet.

0:31:41.800000 --> 0:31:43.160000
 So just keep that in mind.

0:31:43.160000 --> 0:31:49.700000
 And then the response is usually
 in response dot text.

0:31:49.700000 --> 0:31:53.880000
 So we wanted, you know,
 text format there.

0:31:53.880000 --> 0:31:58.680000
 And then we need to get the cookie,
 because I want that just to show you

0:31:58.680000 --> 0:32:03.560000
 that again, the cookie
 sort of infers the.

0:32:03.560000 --> 0:32:08.780000
 Well, in this case, it would be the
 session ID that, you know, for every

0:32:08.780000 --> 0:32:11.760000
 new request you make, you
 get a new session ID.

0:32:11.760000 --> 0:32:14.140000
 Remember, we're unauthenticated.

0:32:14.140000 --> 0:32:18.120000
 If you go back to the earlier videos
 in this course, you'll remember what

0:32:18.120000 --> 0:32:21.760000
 I mentioned that cookies or session IDs
 or session management can be used,

0:32:21.760000 --> 0:32:30.680000
 not just for authentication, but also
 this at or at least having a unique

0:32:30.680000 --> 0:32:33.260000
 capture for every request or every user.

0:32:33.260000 --> 0:32:38.120000
 Anyway, to do this, we can just, you
 know, go ahead and print it out and

0:32:38.120000 --> 0:32:41.540000
 say print session dot cookies.

0:32:41.540000 --> 0:32:47.700000
 Session dot cookies dot get.

0:32:47.700000 --> 0:32:53.440000
 And then we'll just say, gets the
 yeah, we just want to print it.

0:32:53.440000 --> 0:32:58.140000
 So, we'll just say, yeah, get dictionary.


0:32:58.140000 --> 0:33:06.000000
 And then we want to group output.

0:33:06.000000 --> 0:33:12.940000
 So we'll then say print, we'll
 say output dot group.

0:33:12.940000 --> 0:33:17.800000
 And we'll pass in that there.

0:33:17.800000 --> 0:33:22.400000
 Okay, so now we need the rejects
 is what is key now.

0:33:22.400000 --> 0:33:27.540000
 So firstly, let's see, you know, what
 exactly we need to filter for what

0:33:27.540000 --> 0:33:30.440000
 we're, you know, we want
 the script to search for.

0:33:30.440000 --> 0:33:34.620000
 We wanted to search for
 anything between this.

0:33:34.620000 --> 0:33:40.440000
 So the opening of the h4 tag
 and the closing just the h4.

0:33:40.440000 --> 0:33:46.160000
 So anything in the middle here, this
 pretty much what appears to be a

0:33:46.160000 --> 0:33:53.000000
 number, then a space, a plus number,
 and then a space equals to, and then

0:33:53.000000 --> 0:33:54.780000
 yeah, that really doesn't matter.

0:33:54.780000 --> 0:33:58.100000
 So we are going to copy this here.

0:33:58.100000 --> 0:34:01.480000
 So it's h4, and we need
 to make a few changes.

0:34:01.480000 --> 0:34:03.760000
 So I'll just copy directly
 into the script here.

0:34:03.760000 --> 0:34:06.340000
 So on the rejects, single quote.

0:34:06.340000 --> 0:34:11.360000
 So h4 text align will keep that as is,
 however, what we want to get rid

0:34:11.360000 --> 0:34:14.860000
 of is the arithmetic operation
 and just get what's in there.

0:34:14.860000 --> 0:34:17.840000
 Because remember, it's different
 for every request.

0:34:17.840000 --> 0:34:23.040000
 So in order to do this, we can actually
 say include everything with rejects

0:34:23.040000 --> 0:34:33.200000
 except we can actually use, you know,
 sort of a non strict capture group.

0:34:33.200000 --> 0:34:39.940000
 So in this case, numbers, the only thing
 we don't want included is, you

0:34:39.940000 --> 0:34:45.080000
 know, any delimiters or
 anything like that.

0:34:45.080000 --> 0:34:53.120000
 So we can just say in here, let's see,
 we can just say, let me just go

0:34:53.120000 --> 0:35:01.860000
 back in here. We'll obviously say space,
 and just we need the equals sign.

0:35:01.860000 --> 0:35:08.000000
 So before we do that, because we don't
 really need the equals, but we

0:35:08.000000 --> 0:35:09.940000
 need to capture that so it matches.

0:35:09.940000 --> 0:35:16.460000
 So we'll just use, you know,
 we'll just say anything.

0:35:16.460000 --> 0:35:22.600000
 Yeah, I think we can just limit it to
 these ones, because again, whatever

0:35:22.600000 --> 0:35:25.120000
 we're looking for doesn't
 have that anyway.

0:35:25.120000 --> 0:35:37.820000
 So in this particular case, it'll capture
 any text between the opening

0:35:37.820000 --> 0:35:40.480000
 to crazy in here.

0:35:40.480000 --> 0:35:43.080000
 And that should work.

0:35:43.080000 --> 0:35:47.360000
 Hopefully, we'll be able
 to test it out shortly.

0:35:47.360000 --> 0:35:52.440000
 So yeah, so whatever is in here, except
 these characters, that's what

0:35:52.440000 --> 0:35:53.320000
 we're essentially saying.

0:35:53.320000 --> 0:36:00.060000
 So print whatever is in between the opening
 of the h4 tag and the closing.

0:36:00.060000 --> 0:36:08.220000
 And just make sure it doesn't work.

0:36:08.220000 --> 0:36:09.700000
 So we're not likely to encounter that.

0:36:09.700000 --> 0:36:14.140000
 So this is a bit wide, or you know,
 a bit too permissive, but it should

0:36:14.140000 --> 0:36:18.260000
 work just fine. Anyway, we're
 taking a bit longer here.

0:36:18.260000 --> 0:36:21.020000
 But you know, it's always good
 to go through these sessions.

0:36:21.020000 --> 0:36:25.720000
 So what do we need to do
 now is save this script.

0:36:25.720000 --> 0:36:28.420000
 And I'm on my desktop.

0:36:28.420000 --> 0:36:34.260000
 So yeah, I'd save that as request.

0:36:34.260000 --> 0:36:39.000000
 So we'll say Python request
 dot pie hit enter.

0:36:39.000000 --> 0:36:45.560000
 And it worked. So it gets our session and
 it gives us the arithmetic operation.

0:36:45.560000 --> 0:36:46.200000
 So pay attention.

0:36:46.200000 --> 0:36:50.660000
 If I run it again, you can see there
 is every time a new request is made,

0:36:50.660000 --> 0:36:55.340000
 the session ID changes and the
 arithmetic operation changes.

0:36:55.340000 --> 0:36:59.000000
 And this is very important, because
 I wanted to see or wanted to show

0:36:59.000000 --> 0:37:01.520000
 you that it is indeed random.

0:37:01.520000 --> 0:37:03.520000
 And that makes it even easier.

0:37:03.520000 --> 0:37:08.580000
 So hopefully that makes sense.

0:37:08.580000 --> 0:37:16.220000
 Now, at this point, if you remember,
 I'll go back to the web app here.

0:37:16.220000 --> 0:37:20.500000
 It looks like Firefox
 keeps crashing on me.

0:37:20.500000 --> 0:37:23.980000
 And I think it's because of viewing
 it in a zoomed in form.

0:37:23.980000 --> 0:37:29.300000
 If you remember the test we ran here,
 that gave us the character set of

0:37:29.300000 --> 0:37:34.860000
 the password, we can actually generate
 a word list or, you know, yeah,

0:37:34.860000 --> 0:37:37.180000
 a word list for the brute force attack.

0:37:37.180000 --> 0:37:40.840000
 And this is a traditional
 brute force attack now.

0:37:40.840000 --> 0:37:44.740000
 So again, remember what I said in the
 previous video about generating,

0:37:44.740000 --> 0:37:51.580000
 you know, password lit a password list
 that either aligns to a password

0:37:51.580000 --> 0:37:56.240000
 policy that has been configured
 on a word list.

0:37:56.240000 --> 0:37:56.820000
 And that's what we're doing here.

0:37:56.820000 --> 0:38:01.900000
 So in this case, we're still
 working on my desktop.

0:38:01.900000 --> 0:38:05.060000
 I'm going to need a we're
 going to use crunch.

0:38:05.060000 --> 0:38:08.600000
 Crunch is a tool that allows you to create
 a word list as it says, you're

0:38:08.600000 --> 0:38:11.060000
 based on the criteria you specify.

0:38:11.060000 --> 0:38:15.480000
 The output from crunch can be sent
 to the screen file or to any other

0:38:15.480000 --> 0:38:17.660000
 program. It's fairly easy to use.

0:38:17.660000 --> 0:38:20.820000
 So we're going to say crunch, right?

0:38:20.820000 --> 0:38:25.220000
 And the minimum is five, remember,
 and the maximum is five.

0:38:25.220000 --> 0:38:31.500000
 That's what appears to be the bounds
 here or the, the, you know, the,

0:38:31.500000 --> 0:38:33.960000
 the password policy.

0:38:33.960000 --> 0:38:39.460000
 So five character passwords from
 the character set ax for M.

0:38:39.460000 --> 0:38:41.600000
 So it actually gives
 us the character set.

0:38:41.600000 --> 0:38:52.860000
 So we can just say the character max
 and then a X for, I believe the M

0:38:52.860000 --> 0:38:58.800000
 was. Upper case, it is upper case.

0:38:58.800000 --> 0:39:03.200000
 And you don't need to use the commas,
 because in this case, it's just

0:39:03.200000 --> 0:39:04.860000
 these characters.

0:39:04.860000 --> 0:39:08.000000
 And I also remember the
 square bracket, sorry.

0:39:08.000000 --> 0:39:13.440000
 Like so. So what crunch is going to
 do is it's going to generate a word

0:39:13.440000 --> 0:39:19.020000
 list of passwords with a minimum length
 of five characters and a maximum

0:39:19.020000 --> 0:39:23.180000
 length of five characters that all that
 are, you know, essentially going

0:39:23.180000 --> 0:39:26.600000
 to be variations or permutations
 of this character set.

0:39:26.600000 --> 0:39:31.460000
 So it's going to be fairly, you know,
 you're going to see it start from,

0:39:31.460000 --> 0:39:34.800000
 you know, you'll see it is
 best if I show it to you.

0:39:34.800000 --> 0:39:38.480000
 But then we need to output this and
 I'm just going to call our word list

0:39:38.480000 --> 0:39:40.820000
 passwords dot txt.

0:39:40.820000 --> 0:39:43.440000
 All right, so there we are.

0:39:43.440000 --> 0:39:47.520000
 It's going to generate 3125 lines.

0:39:47.520000 --> 0:39:52.080000
 And now if I cat out the contents of
 passwords dot txt, you can actually

0:39:52.080000 --> 0:39:56.920000
 see that is just variations of that
 particular character set and all of

0:39:56.920000 --> 0:40:03.560000
 them meet the criteria we specified
 off in this particular case.

0:40:03.560000 --> 0:40:08.040000
 Let's see, did I specify that correctly
 when generating it so crunch 55

0:40:08.040000 --> 0:40:12.000000
 ax 4m? Yeah, I did.

0:40:12.000000 --> 0:40:16.220000
 So it's just going to be variations
 and there'll all be five characters,

0:40:16.220000 --> 0:40:18.520000
 as you can see here.

0:40:18.520000 --> 0:40:24.020000
 So five characters and you know, you
 can go if we use a tool like, let's

0:40:24.020000 --> 0:40:35.440000
 say, head passwords dot so this is
 what a brute force attack is you're

0:40:35.440000 --> 0:40:39.180000
 using what in for you have gathered from
 the login form about the password

0:40:39.180000 --> 0:40:43.140000
 policy to generate a word list that again
 will probably give you the permutations

0:40:43.140000 --> 0:40:48.360000
 that probably or I should say potentially
 contain the correct password.

0:40:48.360000 --> 0:40:52.340000
 But as you know, brute force attack
 stick a while now, how are we going

0:40:52.340000 --> 0:40:54.240000
 to perform this brute force?

0:40:54.240000 --> 0:41:02.260000
 Well, we're going to need to I want
 to modify the original script.

0:41:02.260000 --> 0:41:07.260000
 But I think what I'm going to do is
 let me copy what it's called request

0:41:07.260000 --> 0:41:14.220000
 dot pi and I'm just going to call this
 we'll just call this capture, capture

0:41:14.220000 --> 0:41:18.320000
 brute dot pi. So I'm just going to
 create a copy and then I'm going to

0:41:18.320000 --> 0:41:20.720000
 we're going to modify this here.

0:41:20.720000 --> 0:41:23.840000
 So this is all fine.

0:41:23.840000 --> 0:41:25.560000
 We're also going to keep the rejects.

0:41:25.560000 --> 0:41:30.480000
 But now what we need to get rid of
 is this right over here, because we

0:41:30.480000 --> 0:41:32.360000
 don't want that displayed to us.

0:41:32.360000 --> 0:41:34.000000
 We want to actually process it.

0:41:34.000000 --> 0:41:37.000000
 So we'll still use Python.

0:41:37.000000 --> 0:41:43.880000
 What we're going to do is we're going
 to say with open and in this case,

0:41:43.880000 --> 0:41:46.000000
 we're going to need the password list.

0:41:46.000000 --> 0:41:48.600000
 So this is passwords dot txt.

0:41:48.600000 --> 0:41:52.500000
 If you're working a different directory
 or your script is stored in a

0:41:52.500000 --> 0:41:55.620000
 different directory, then where your
 word list is, make sure to specify

0:41:55.620000 --> 0:41:57.000000
 the absolute path.

0:41:57.000000 --> 0:41:59.800000
 I would recommend working the same
 directory in my case on the desktop

0:41:59.800000 --> 0:42:02.600000
 password dot txt.

0:42:02.600000 --> 0:42:08.660000
 And what we want to do is we
 want to, you know, read.

0:42:08.660000 --> 0:42:12.260000
 So essentially reading or telling the
 script to read what's in the word

0:42:12.260000 --> 0:42:16.240000
 list. So read as f.

0:42:16.240000 --> 0:42:18.680000
 Uh, just use that there.

0:42:18.680000 --> 0:42:21.920000
 So okay, we have the indentation and
 then we're going to use a for loops

0:42:21.920000 --> 0:42:24.240000
 of for password in f.

0:42:24.240000 --> 0:42:27.440000
 f is just, you know, used
 to represent the file.

0:42:27.440000 --> 0:42:32.120000
 So for every password in the in the word
 list, we want to do the following.

0:42:32.120000 --> 0:42:34.600000
 So we're going to create
 a password variable.

0:42:34.600000 --> 0:42:40.960000
 We're going to say password
 equal password dot r strip.

0:42:40.960000 --> 0:42:44.420000
 So yeah, pass it r strip.

0:42:44.420000 --> 0:42:48.160000
 And then we're going to say the response.


0:42:48.160000 --> 0:42:55.560000
 Response is going to be we need to
 make the request the get request.

0:42:55.560000 --> 0:43:02.880000
 So session dot get and in here, let me use
 single quotes there for standardization.

0:43:02.880000 --> 0:43:07.220000
 I'm just going to copy this
 here, copy your lab IP.

0:43:07.220000 --> 0:43:10.160000
 And we're then going to
 paste that in there.

0:43:10.160000 --> 0:43:15.200000
 And then from this point on, we can
 say output is going to be equal to

0:43:15.200000 --> 0:43:22.100000
 re dot search. And then we're
 going to say rejects.

0:43:22.100000 --> 0:43:26.680000
 So doing what it did previously
 on the initial script.

0:43:26.680000 --> 0:43:30.720000
 So just search the response
 for the rejects.

0:43:30.720000 --> 0:43:35.180000
 And then we're going to say cookies
 is equal to session dot cookies dot

0:43:35.180000 --> 0:43:42.300000
 get dictionary. And we're going to say
 capture create a new variable called

0:43:42.300000 --> 0:43:51.260000
 capture. That's going to be equal to
 evaluate and then output, output

0:43:51.260000 --> 0:44:04.160000
 dot group. Okay, and then we need
 to, yes, we've grouped that.

0:44:04.160000 --> 0:44:13.640000
 But let's see, we can then say for each
 attempt print, trying password.

0:44:13.640000 --> 0:44:17.840000
 And then we can just, you know, making
 a very nice interface here.

0:44:17.840000 --> 0:44:21.680000
 Just displayed to the user there.

0:44:21.680000 --> 0:44:25.080000
 Like so, just concatenate that there.

0:44:25.080000 --> 0:44:31.640000
 And then we're going to create
 the array, username.

0:44:31.640000 --> 0:44:34.060000
 So we need to, we're now performing
 the brute force.

0:44:34.060000 --> 0:44:37.480000
 We know the username that's going
 to be the same for each request.

0:44:37.480000 --> 0:44:40.600000
 So that's going to be admin.

0:44:40.600000 --> 0:44:47.480000
 And then password is just going to be
 the value of password, which we've

0:44:47.480000 --> 0:44:50.960000
 already said is, you know, it's going
 to read from the word list for,

0:44:50.960000 --> 0:44:57.480000
 you know, it's going to read a password
 from the word list for each attempt.

0:44:57.480000 --> 0:45:00.700000
 So that's just password.

0:45:00.700000 --> 0:45:04.520000
 And then we need to pass in the capture.

0:45:04.520000 --> 0:45:13.860000
 So capture is going to be
 what has been evaluated.

0:45:13.860000 --> 0:45:15.820000
 So that's why we did the evaluation here.


0:45:15.820000 --> 0:45:21.020000
 So this variable holds, uses the e-valve
 function here to, to essentially

0:45:21.020000 --> 0:45:29.000000
 calculate what's in the output group
 with the, you know, we're essentially

0:45:29.000000 --> 0:45:30.620000
 passing the first parameter here.

0:45:30.620000 --> 0:45:32.740000
 So it's going to be the rejects match.

0:45:32.740000 --> 0:45:37.720000
 So whatever, well, whatever the arithmetic
 evaluation or expression is,

0:45:37.720000 --> 0:45:43.520000
 or the, you know, the actual, the actual
 mathematical operation is going

0:45:43.520000 --> 0:45:47.060000
 to be evaluated or calculated, you
 know, using this particular e-valve

0:45:47.060000 --> 0:45:51.620000
 function. And then what we're doing
 now is just saying, pass the answer

0:45:51.620000 --> 0:45:54.000000
 in the data array here.

0:45:54.000000 --> 0:46:00.080000
 So we're going to say capture
 is capture like so.

0:46:00.080000 --> 0:46:06.440000
 And by the way, these, this is curly
 braces, my bad, I was about to make

0:46:06.440000 --> 0:46:09.280000
 another fatal mistake here.

0:46:09.280000 --> 0:46:15.860000
 There we go. And what we'll do now
 is say output is going to be equal

0:46:15.860000 --> 0:46:19.120000
 to session dot post.

0:46:19.120000 --> 0:46:24.240000
 So making a post here to HTTP, the
 address of the server in your case,

0:46:24.240000 --> 0:46:29.320000
 make sure to change it, because it's
 going to be different in your lab.

0:46:29.320000 --> 0:46:42.040000
 And in this particular case, I believe
 we can actually verify it in a

0:46:42.040000 --> 0:46:46.100000
 second. I think it uses
 the login endpoint.

0:46:46.100000 --> 0:46:53.820000
 And we're then going to say cookies is
 equal to, we need to pass the session

0:46:53.820000 --> 0:46:57.060000
 ID for each session, because
 each request is unique.

0:46:57.060000 --> 0:47:00.060000
 So data is equal to data.

0:47:00.060000 --> 0:47:07.940000
 And then we need to have some error
 management or, yeah, we'll just say

0:47:07.940000 --> 0:47:18.840000
 if error, so if we get this string
 here, then, you know, password not

0:47:18.840000 --> 0:47:25.780000
 found. So we'll just say if it matches
 error, not in output dot text,

0:47:25.780000 --> 0:47:30.360000
 in this case, if error is not in output
 dot text, then that means we've

0:47:30.360000 --> 0:47:31.060000
 found the password.

0:47:31.060000 --> 0:47:37.980000
 So we're just indent here, and
 we'll say print password found.

0:47:37.980000 --> 0:47:44.020000
 So if we don't get an error in the response
 or in output dot text, then

0:47:44.020000 --> 0:47:47.000000
 that means that the password
 has been found, hopefully.

0:47:47.000000 --> 0:47:52.340000
 So password found, and then we'll just pass
 in the password for that particular

0:47:52.340000 --> 0:47:59.120000
 loop, you know, for that particular
 unique loop, you know, over here.

0:47:59.120000 --> 0:48:02.900000
 So, and then break, that's
 very important, right?

0:48:02.900000 --> 0:48:05.360000
 So we need to break it after
 it gets the correct password.

0:48:05.360000 --> 0:48:07.820000
 Anyway, we'll write and quit.

0:48:07.820000 --> 0:48:16.220000
 And then now we'll say Python, capture
 brute dot pi, and hit enter looks

0:48:16.220000 --> 0:48:17.480000
 like I made a mistake.

0:48:17.480000 --> 0:48:21.940000
 I did so passwords dot
 txt is my word list.

0:48:21.940000 --> 0:48:27.500000
 So looks like I said password dot txt,
 always make a mistake there, passwords

0:48:27.500000 --> 0:48:30.760000
 dot txt, hopefully they aren't any
 because it's evaluating it from the

0:48:30.760000 --> 0:48:33.820000
 top. There we are, it's working and
 it's now going to perform the brute

0:48:33.820000 --> 0:48:38.160000
 force. And when it finds the correct
 password, it tells us the correct

0:48:38.160000 --> 0:48:42.000000
 password. And it looks like the password
 was just the character set that

0:48:42.000000 --> 0:48:45.000000
 was told to us. So let's actually
 try and log in now.

0:48:45.000000 --> 0:48:48.040000
 I'll load up a new session here.

0:48:48.040000 --> 0:48:51.020000
 And in this case, it's going to be admin.


0:48:51.020000 --> 0:48:52.480000
 And then I'll paste in the password.

0:48:52.480000 --> 0:48:54.500000
 And then I need to put in a capture.

0:48:54.500000 --> 0:49:01.980000
 So that's 885 5 plus 117.

0:49:01.980000 --> 0:49:06.220000
 And that's going to be 8 972, 8 972.

0:49:06.220000 --> 0:49:08.980000
 Sign in. And there we go.

0:49:08.980000 --> 0:49:10.040000
 We get our flag.

0:49:10.040000 --> 0:49:14.160000
 So that's pretty much it
 for the practical demo.

0:49:14.160000 --> 0:49:18.520000
 The code that I've used in this demonstration
 is going to be part of the

0:49:18.520000 --> 0:49:19.460000
 lab documentation.

0:49:19.460000 --> 0:49:23.780000
 So if you're feeling a bit confused
 don't worry, it's included.

0:49:23.780000 --> 0:49:26.940000
 But what we did was fairly simple.

0:49:26.940000 --> 0:49:31.620000
 And this is now what, you know, this
 is the type of testing that I would

0:49:31.620000 --> 0:49:33.440000
 expect you to become comfortable with.

0:49:33.440000 --> 0:49:37.300000
 You really need to understand
 how the web application works.

0:49:37.300000 --> 0:49:42.320000
 And you can see how important
 documenting your tests is.

0:49:42.320000 --> 0:49:45.220000
 But with that being said, that brings us
 to the end of the practical demonstration

0:49:45.220000 --> 0:49:47.960000
 section of this video.

0:49:47.960000 --> 0:49:51.760000
 All right. So that was
 quite a lengthy demo.

0:49:51.760000 --> 0:49:54.680000
 I apologize for how long it went, but
 there's a lot of stuff that I wanted

0:49:54.680000 --> 0:49:56.760000
 to explain. Okay.

0:49:56.760000 --> 0:50:01.380000
 So that was testing for one
 week lockout mechanism.

0:50:01.380000 --> 0:50:03.860000
 In the next video, we're going to be
 taking a look at one that you've

0:50:03.860000 --> 0:50:05.080000
 probably encountered before.

0:50:05.080000 --> 0:50:07.520000
 And that is rate limiting
 an account lockout.

0:50:07.520000 --> 0:50:11.280000
 So what happens if you enter a password
 incorrectly three or five times,

0:50:11.280000 --> 0:50:15.200000
 for example, maybe 10 times, the account
 gets locked and there's a cool

0:50:15.200000 --> 0:50:17.700000
 down period or maybe
 your IP gets blocked.

0:50:17.700000 --> 0:50:19.080000
 How do we bypass that?

0:50:19.080000 --> 0:50:21.500000
 Well, that's what we'll be exploring
 in the next video.

0:50:21.500000 --> 0:50:24.420000
 So with that being said, that's
 going to be it for this video.

0:50:24.420000 --> 0:50:26.580000
 And I'll be seeing you in the next video.


