WEBVTT

0:00:03.880000 --> 0:00:06.120000
 Hello everyone and welcome to this video.


0:00:06.120000 --> 0:00:11.460000
 In this video we're going to be taking a
 look at cookies and cookie parameters.

0:00:11.460000 --> 0:00:16.800000
 So as I said in the previous video,
 there's some important things that

0:00:16.800000 --> 0:00:20.020000
 we need to be aware of and I'm sure
 that you are aware of to a certain

0:00:20.020000 --> 0:00:22.780000
 extent, probably even more than me.

0:00:22.780000 --> 0:00:27.940000
 But I wanted to sort of highlight or
 again just get a refresher or give

0:00:27.940000 --> 0:00:31.200000
 you guys a refresher of cookies because
 they're going to be increasingly

0:00:31.200000 --> 0:00:37.240000
 important in the session management
 testing section as well in addition

0:00:37.240000 --> 0:00:40.520000
 to that to also go over cookie parameters
 and sort of explain what they

0:00:40.520000 --> 0:00:44.920000
 mean and how they affect you and what
 to test for or as you'd say what

0:00:44.920000 --> 0:00:55.560000
 to look out for and you know really
 just outline what cookie parameters

0:00:55.560000 --> 0:00:59.500000
 mean I should say simply put.

0:00:59.500000 --> 0:01:01.100000
 So what are cookies?

0:01:01.100000 --> 0:01:05.460000
 Well, cookies are small pieces of data
 stored on a user's browser by websites

0:01:05.460000 --> 0:01:06.960000
 that they visit.

0:01:06.960000 --> 0:01:10.520000
 They're primarily used to retain information
 between user sessions enabling

0:01:10.520000 --> 0:01:13.980000
 websites to remember the user's state
 such as login status preferences

0:01:13.980000 --> 0:01:16.400000
 and other session specific data.

0:01:16.400000 --> 0:01:19.800000
 Key point is other session specific data.


0:01:19.800000 --> 0:01:23.160000
 Now in the case of session management
 cookies are vital as I explained

0:01:23.160000 --> 0:01:26.420000
 in the previous videos they typically
 store a session ID that uniquely

0:01:26.420000 --> 0:01:30.820000
 identifies a user across multiple page
 requests helping the server maintain

0:01:30.820000 --> 0:01:35.980000
 a continuous session quote unquote
 throughout the user's visit.

0:01:35.980000 --> 0:01:39.080000
 Now how are cookies used
 in session management?

0:01:39.080000 --> 0:01:42.960000
 We went over this briefly in the previous
 video but diving a little bit

0:01:42.960000 --> 0:01:47.080000
 deeper into it when a user logs in the
 server creates a session and often

0:01:47.080000 --> 0:01:50.080000
 generates a unique session
 ID to represent it.

0:01:50.080000 --> 0:01:53.180000
 The session ID stored in a cookie and
 sent to the user's browser with

0:01:53.180000 --> 0:01:54.500000
 each subsequent request.

0:01:54.500000 --> 0:01:57.620000
 The browser includes the session cookie
 allowing the server to recognize

0:01:57.620000 --> 0:02:03.740000
 the user's session without needing or
 having the user to reauthenticate.

0:02:03.740000 --> 0:02:07.720000
 The mechanism or this mechanism ensures
 a smooth and personalized experience

0:02:07.720000 --> 0:02:13.320000
 by you know retaining the login status
 or your authentication as it were

0:02:13.320000 --> 0:02:17.300000
 your shopping cart contents for example
 another session related data like

0:02:17.300000 --> 0:02:23.140000
 your language preferences light
 mode or dark mode etc.

0:02:23.140000 --> 0:02:24.600000
 There's many other you know things.

0:02:24.600000 --> 0:02:27.140000
 Now that brings us to cookie parameters.

0:02:27.140000 --> 0:02:30.640000
 Now I mentioned some of them in the previous
 video but diving deeper into

0:02:30.640000 --> 0:02:34.820000
 them you know to enhance security cookies
 can be configured with various

0:02:34.820000 --> 0:02:38.600000
 attributes that control how they behave.

0:02:38.600000 --> 0:02:42.420000
 Now I'm really covering the ones that
 I'm not covering all of them I'm

0:02:42.420000 --> 0:02:46.520000
 covering the more the ones more specific
 to what we are doing or the ones

0:02:46.520000 --> 0:02:50.840000
 relevant let's say to authentication
 and session management testing for

0:02:50.840000 --> 0:02:52.760000
 you as a web app and tester right.

0:02:52.760000 --> 0:02:57.320000
 So we have the first most obvious
 one which is HTTP only.

0:02:57.320000 --> 0:03:01.120000
 This attribute prevents client side scripts
 you know typically JavaScript

0:03:01.120000 --> 0:03:05.780000
 in your browser from accessing the cookie
 so whenever you have that you

0:03:05.780000 --> 0:03:10.820000
 know that's what it's there for so this
 helps protect against cross-site

0:03:10.820000 --> 0:03:15.640000
 scripting attacks which could otherwise
 allow an attacker to access sensitive

0:03:15.640000 --> 0:03:21.160000
 cookie data by setting the cookie to
 as HTTP only it is accessible only

0:03:21.160000 --> 0:03:25.520000
 to the server reducing the risk of
 exposure to malicious scripts.

0:03:25.520000 --> 0:03:31.480000
 You then have secure secure is you know
 as the name suggests this means

0:03:31.480000 --> 0:03:36.180000
 that a secure cookie is only transmitted
 over HTTPS connections not HTTP

0:03:36.180000 --> 0:03:38.780000
 so there needs to be an SSL set.

0:03:38.780000 --> 0:03:43.320000
 This is very useful because it prevents
 it prevents the cookie or you

0:03:43.320000 --> 0:03:47.980000
 know within a GET request from being
 sent over unencrypted HTTP which

0:03:47.980000 --> 0:03:52.360000
 obviously as you know is unencrypted which
 means it's vulnerable to interception

0:03:52.360000 --> 0:03:55.820000
 and more specifically as a pen tester
 you're aware of man in the middle

0:03:55.820000 --> 0:04:00.780000
 attacks. So again even if you try it
 right now on a real world website

0:04:00.780000 --> 0:04:05.160000
 that you use with burp suite you can
 actually see that you know over HTTPS

0:04:05.160000 --> 0:04:08.580000
 is typically what you would
 expect with cookies.

0:04:08.580000 --> 0:04:13.480000
 So this ensures that the cookie data
 is encrypted in transit protecting

0:04:13.480000 --> 0:04:18.440000
 it from man in the middle attacks or
 interception as it were or what you'd

0:04:18.440000 --> 0:04:20.160000
 call eavesdropping.

0:04:20.160000 --> 0:04:23.600000
 You then have same site now this is very
 important some of you are probably

0:04:23.600000 --> 0:04:26.980000
 familiar with it so the same site attribute
 restricts cookies from being

0:04:26.980000 --> 0:04:31.980000
 sent with cross-site requests which helps
 prevent cross-site request forgery

0:04:31.980000 --> 0:04:36.020000
 attacks. Now there are three modes primarily
 we have the strict mode this

0:04:36.020000 --> 0:04:40.100000
 is where you know the cookies only sent
 in a first party context so the

0:04:40.100000 --> 0:04:44.200000
 site user is currently the site
 the user is currently visiting.

0:04:44.200000 --> 0:04:47.760000
 You then have a lax mode where the
 cookie is sent with the first party

0:04:47.760000 --> 0:04:51.600000
 and some top level GET requests making
 it slightly more flexible than

0:04:51.600000 --> 0:04:54.140000
 strict and then none right.

0:04:54.140000 --> 0:04:58.540000
 In this case the cookie is sent with both
 first party and cross-site requests

0:04:58.540000 --> 0:05:06.100000
 and this option requires the cookie
 to be secure the secure attribute

0:05:06.100000 --> 0:05:10.980000
 to be set. So same site helps reduce
 the risk of unauthorized requests

0:05:10.980000 --> 0:05:14.920000
 that rely on the user's session
 so very very important.

0:05:14.920000 --> 0:05:18.220000
 We then have a couple of others that
 are relevant to the testing which

0:05:18.220000 --> 0:05:22.300000
 I mentioned in the previous video the
 end of the previous video so that

0:05:22.300000 --> 0:05:24.600000
 is expiration or max age.

0:05:24.600000 --> 0:05:27.860000
 This parameter controls the lifespan
 of a cookie determining how long

0:05:27.860000 --> 0:05:30.760000
 it persists before it is deleted.

0:05:30.760000 --> 0:05:34.500000
 Session cookies are deleted once the
 browser is closed while persistent

0:05:34.500000 --> 0:05:38.400000
 cookies remain stored for
 a specified duration.

0:05:38.400000 --> 0:05:41.800000
 Limiting the cookies duration reduces
 the window for potential misuse

0:05:41.800000 --> 0:05:45.340000
 as cookies expire after the set time.

0:05:45.340000 --> 0:05:48.340000
 So let me give you an example
 of what these look like.

0:05:48.340000 --> 0:05:54.520000
 So here's an example where pretty much
 set in this particular case you

0:05:54.520000 --> 0:05:58.500000
 have a request and a response, HTTP
 request and response when the first

0:05:58.500000 --> 0:06:03.220000
 one you can see we make posts here where
 we're logging in with the following

0:06:03.220000 --> 0:06:07.660000
 parameters and their values and then
 in the in the response this is an

0:06:07.660000 --> 0:06:09.700000
 example of how those can be set.

0:06:09.700000 --> 0:06:15.440000
 So we have set cookie session ID, HTTP
 only, secure, same site, lacks

0:06:15.440000 --> 0:06:17.100000
 and then a path.

0:06:17.100000 --> 0:06:20.960000
 So that's an example of how they implemented
 and what they look like but

0:06:20.960000 --> 0:06:25.100000
 hopefully that gives you a bit more
 clarity as to where you know you'll

0:06:25.100000 --> 0:06:27.280000
 typically see these.

0:06:27.280000 --> 0:06:30.180000
 With that being said that brings
 us to the end of this video.

0:06:30.180000 --> 0:06:34.320000
 The next video will be taking a look
 at you know playing around with the

0:06:34.320000 --> 0:06:41.520000
 cookies and I guess we can call it
 cookie tampering and this is all in

0:06:41.520000 --> 0:06:44.280000
 relation to you know session
 management testing.

0:06:44.280000 --> 0:06:48.300000
 So that being said that's going to
 be it for this video and I will be

0:06:48.300000 --> 0:06:50.380000
 seeing you in the next video.

