WEBVTT

0:00:03.660000 --> 0:00:09.860000
 Hello everyone and welcome to the
 OAuth section of this course.

0:00:09.860000 --> 0:00:15.480000
 In this section we're going to be getting
 an introduction to OAuth, sort

0:00:15.480000 --> 0:00:17.760000
 of, you know, understanding how it works.


0:00:17.760000 --> 0:00:21.800000
 And then we'll be taking a look at some
 of the more, I would say, common

0:00:21.800000 --> 0:00:24.940000
 OAuth attacks or attacks against OAuth.

0:00:24.940000 --> 0:00:29.980000
 Now, in this video I'm going to
 be introducing you to OAuth.

0:00:29.980000 --> 0:00:37.180000
 However, there is quite a bit of theoretical
 knowledge or information

0:00:37.180000 --> 0:00:44.160000
 that I've added to this slide deck
 that will essentially play into the

0:00:44.160000 --> 0:00:51.120000
 attacking OAuth lab demonstration in
 the next video that, you know, pretty

0:00:51.120000 --> 0:00:54.540000
 much is focused on the practical aspect.

0:00:54.540000 --> 0:00:59.240000
 Now, given that is the case, what I'm
 going to be doing in this video

0:00:59.240000 --> 0:01:05.020000
 is just introducing you to OAuth and
 then I'll sort of explain or outline

0:01:05.020000 --> 0:01:09.680000
 where you can find the complete slide
 deck, which I'll also explain to

0:01:09.680000 --> 0:01:12.420000
 you and how it's structured.

0:01:12.420000 --> 0:01:19.440000
 And I'll also explain how the next lab
 or the lab that comes after this

0:01:19.440000 --> 0:01:25.680000
 video sort of will fill in the blanks
 in terms of understanding the various

0:01:25.680000 --> 0:01:27.420000
 types of attacks.

0:01:27.420000 --> 0:01:31.780000
 So to kick things off, what is OAuth?

0:01:31.780000 --> 0:01:38.140000
 Well, I'll not even start off with
 OAuth too, but OAuth is sort of the

0:01:38.140000 --> 0:01:42.200000
 main web standard for authorization
 between services.

0:01:42.200000 --> 0:01:47.800000
 Services can be, you know, web applications
 communicating with each other,

0:01:47.800000 --> 0:01:51.640000
 APIs, etc. What is it used for?

0:01:51.640000 --> 0:01:56.760000
 Well, OAuth is used to authorize third
-party apps in order to access services

0:01:56.760000 --> 0:02:00.980000
 or data from a provider with
 which you have an account.

0:02:00.980000 --> 0:02:07.080000
 So again, just think of using or, you
 know, signing in with your Gmail

0:02:07.080000 --> 0:02:12.300000
 account, for example, into an application
 or providing an application

0:02:12.300000 --> 0:02:13.900000
 with specific permissions.

0:02:13.900000 --> 0:02:20.480000
 How do those two, you know, web applications
 or services interact with

0:02:20.480000 --> 0:02:27.400000
 each other? And, you know, what's the
 framework through which, you know,

0:02:27.400000 --> 0:02:31.000000
 roles, permissions are specified?

0:02:31.000000 --> 0:02:35.460000
 So, for example, if you have, let's say,
 an application or a web application,

0:02:35.460000 --> 0:02:43.780000
 like an email client, you know, apart
 from Gmail and you'd like to sort

0:02:43.780000 --> 0:02:51.560000
 of utilize Gmail or your Gmail account,
 your Gmail email within that third

0:02:51.560000 --> 0:02:57.040000
-party web application, which again is
 just a, just think of it as a webmail

0:02:57.040000 --> 0:03:04.780000
 account. OAuth is used to, as an example,
 is what would be used to, you

0:03:04.780000 --> 0:03:09.680000
 know, sign in, firstly, to your Gmail
 through the third-party application

0:03:09.680000 --> 0:03:16.480000
 and then facilitate the, it'll then facilitate
 the authorization in terms

0:03:16.480000 --> 0:03:22.780000
 of what, you know, the webmail web application
 will be able to read from

0:03:22.780000 --> 0:03:28.500000
 Gmail. And the bottom line is that,
 you know, built into this process,

0:03:28.500000 --> 0:03:33.720000
 you get to decide, you know, through
 a set of options or permissions,

0:03:33.720000 --> 0:03:40.080000
 what you want to, what you want this third
-party web application to access.

0:03:40.080000 --> 0:03:44.360000
 So, for example, you may not want to
 import your contacts from Gmail.

0:03:44.360000 --> 0:03:50.120000
 You may not want to sync your calendar to
 this third-party webmail application.

0:03:50.120000 --> 0:03:52.960000
 That's pretty much it, you
 know, at a high level.

0:03:52.960000 --> 0:03:57.700000
 So, you know, if you, you may have thought
 that you've never encountered

0:03:57.700000 --> 0:04:02.680000
 OAuth before, you know, if you've used
 the modern, if you've used modern

0:04:02.680000 --> 0:04:07.960000
 web applications or you've been on
 the internet over the last five to,

0:04:07.960000 --> 0:04:12.000000
 it's actually, I would say a decade,
 then, you know, you've come across

0:04:12.000000 --> 0:04:18.380000
 OAuth. So, you now know, you now have
 a name to give to this particular

0:04:18.380000 --> 0:04:24.820000
 service or this sort of magic bridge
 between one application and the other

0:04:24.820000 --> 0:04:26.140000
 one service and the other.

0:04:26.140000 --> 0:04:32.000000
 So, that brings us to the components
 that make up OAuth as a whole.

0:04:32.000000 --> 0:04:37.320000
 So, there's quite a few and I'm going
 to touch on all of them, but let's

0:04:37.320000 --> 0:04:39.140000
 start off with the resource owner.

0:04:39.140000 --> 0:04:43.900000
 So, this is the entity that can grant
 access to a protected resource.

0:04:43.900000 --> 0:04:46.480000
 This is typically the end user, right?

0:04:46.480000 --> 0:04:48.580000
 So, that's you, if you will.

0:04:48.580000 --> 0:04:49.720000
 You then have the client.

0:04:49.720000 --> 0:04:53.520000
 So, this is the application requesting
 access to a protected resource

0:04:53.520000 --> 0:04:56.500000
 on behalf of the resource owner.

0:04:56.500000 --> 0:05:00.200000
 This is also called the relying party.

0:05:00.200000 --> 0:05:04.640000
 So, that's the client, then
 we have the resource server.

0:05:04.640000 --> 0:05:07.820000
 So, this is the server hosting
 the protected resources.

0:05:07.820000 --> 0:05:11.820000
 This is the API that you want to access.

0:05:11.820000 --> 0:05:17.340000
 And again, in this case, it's referencing
 a gallery, for an example, which,

0:05:17.340000 --> 0:05:22.240000
 again, will make sense as we proceed,
 because this is all part of the

0:05:22.240000 --> 0:05:29.080000
 attack scenarios that have laid out
 from a technical perspective in the

0:05:29.080000 --> 0:05:35.040000
 slides. And we will later be exploring
 them in the lab that comes after

0:05:35.040000 --> 0:05:39.560000
 this video. So, we also have
 the authorization server.

0:05:39.560000 --> 0:05:40.960000
 So, this is very important.

0:05:40.960000 --> 0:05:45.800000
 This is the server that authenticates
 the resource owner and issues access

0:05:45.800000 --> 0:05:49.180000
 tokens after getting
 proper authorization.

0:05:49.180000 --> 0:05:54.280000
 So, you may, you know, you may have finally
 understood why we're covering

0:05:54.280000 --> 0:05:57.940000
 OAuth and how it relates to
 token-based authentication.

0:05:57.940000 --> 0:06:02.920000
 Although, in this case, it's not so much
 authentication, more so authorization.

0:06:02.920000 --> 0:06:09.640000
 And the authorization is also, or frequently
 also called the identity

0:06:09.640000 --> 0:06:12.740000
 provider IDP abbreviated as.

0:06:12.740000 --> 0:06:15.120000
 We also have the user agent.

0:06:15.120000 --> 0:06:20.400000
 So, the agent, this is the agent used
 by the resource owner to interact

0:06:20.400000 --> 0:06:25.300000
 with the client, for example, a browser
 or a mobile application, which

0:06:25.300000 --> 0:06:32.220000
 is actually quite important as you want
 to be, as a web application developer,

0:06:32.220000 --> 0:06:37.240000
 you want to be aware of the
 most likely scenarios.

0:06:37.240000 --> 0:06:43.300000
 The use of OAuth is going
 to come in from.

0:06:43.300000 --> 0:06:47.780000
 So, you know, if you have a mobile application,
 then generally speaking,

0:06:47.780000 --> 0:06:51.180000
 you want to streamline that process,
 or you want to be aware of how it

0:06:51.180000 --> 0:06:58.240000
 differs from, you know, working within,
 you know, a web browser on, you

0:06:58.240000 --> 0:07:01.160000
 know, let's say, a traditional desktop.

0:07:01.160000 --> 0:07:03.400000
 That brings us to the scope.

0:07:03.400000 --> 0:07:08.340000
 So, given that I mentioned authorization,
 which is different from authentication

0:07:08.340000 --> 0:07:13.700000
 and, you know, session management, you
 know, whenever we're talking about

0:07:13.700000 --> 0:07:17.020000
 authorization, this always
 brings up the scope, right?

0:07:17.020000 --> 0:07:21.180000
 Because authorization deals with what
 you can do, what you can access,

0:07:21.180000 --> 0:07:24.340000
 you know, stuff like that.

0:07:24.340000 --> 0:07:29.020000
 And whenever you're talking about the
 stuff you can do and the stuff you

0:07:29.020000 --> 0:07:33.720000
 can access, there always has to be
 a scope, just like, again, being a

0:07:33.720000 --> 0:07:37.700000
 human being within any country
 or within the world.

0:07:37.700000 --> 0:07:44.280000
 The scope, you know, if I was to juxtapose
 that example against OAuth

0:07:44.280000 --> 0:07:51.400000
 scopes, the scope would be, you know,
 in the real world, the rules or

0:07:51.400000 --> 0:07:56.660000
 laws that essentially state what you
 can and can do, what you can and

0:07:56.660000 --> 0:08:01.520000
 can't access, what you can and
 cannot consume, et cetera.

0:08:01.520000 --> 0:08:04.800000
 So, that's the way to think
 of the OAuth scope.

0:08:04.800000 --> 0:08:10.020000
 So, OAuth scopes, you know, actions or
 privilege, or privilege is requested

0:08:10.020000 --> 0:08:14.700000
 from the service visible through
 the scope parameter.

0:08:14.700000 --> 0:08:20.240000
 They read, write, and, you know, access
 contacts, typically speaking.

0:08:20.240000 --> 0:08:24.580000
 So, read is fairly simple to understand,
 write self-explanatory access

0:08:24.580000 --> 0:08:29.660000
 contacts. Again, these are some of
 the more common ones and, you know,

0:08:29.660000 --> 0:08:35.300000
 their values are going to be, or, you
 know, the specification of the scopes

0:08:35.300000 --> 0:08:37.180000
 is where things get interesting.

0:08:37.180000 --> 0:08:43.480000
 So, now that you have an understanding
 of that, what is the flow, the

0:08:43.480000 --> 0:08:44.760000
 OAuth flow, right?

0:08:44.760000 --> 0:08:49.260000
 So, how do you go from, how do you essentially
 go from point A to point

0:08:49.260000 --> 0:08:55.600000
 A being, you know, the point when you
 just click on the button to authorize

0:08:55.600000 --> 0:09:00.980000
 an application to use another or
 to interact with another, right?

0:09:00.980000 --> 0:09:07.820000
 So, in OAuth 2.0, the interactions between
 the user and her browser, the

0:09:07.820000 --> 0:09:12.780000
 authorization server and the resource
 server can be performed in four

0:09:12.780000 --> 0:09:14.380000
 different flows.

0:09:14.380000 --> 0:09:17.560000
 So, firstly, the authorization
 code grants.

0:09:17.560000 --> 0:09:22.360000
 So, the client redirects the user or the
 resource owner to an authorization

0:09:22.360000 --> 0:09:28.040000
 server to ask the user whether the client
 can access his or her resources.

0:09:28.040000 --> 0:09:33.260000
 After the user confirms or accepts,
 the client obtains an authorization

0:09:33.260000 --> 0:09:38.080000
 code that the client can exchange
 for an access token.

0:09:38.080000 --> 0:09:42.560000
 This access token enables the client
 to access resources from the resource

0:09:42.560000 --> 0:09:47.580000
 owner. We then have the implicit grant,
 which is a simplification of the

0:09:47.580000 --> 0:09:51.700000
 authorization code grant, where the
 client obtains the access to a token

0:09:51.700000 --> 0:09:56.100000
 directly, rather than being issued
 an authorization code.

0:09:56.100000 --> 0:10:02.160000
 We then have the other option where the
 resource owner, the resource owner

0:10:02.160000 --> 0:10:06.880000
 password credentials grant, that's typically
 what it's called, but this

0:10:06.880000 --> 0:10:13.380000
 enables the client to obtain an access
 token by using the username and

0:10:13.380000 --> 0:10:15.620000
 password of the resource owner.

0:10:15.620000 --> 0:10:20.860000
 And then, you know, the client credentials
 grant, which enables the client

0:10:20.860000 --> 0:10:25.980000
 to obtain an access token by using or through
 the use of its own credentials.

0:10:25.980000 --> 0:10:31.780000
 So, there's a couple of key points
 or important points that I want to

0:10:31.780000 --> 0:10:45.200000
 go over regarding clients to begin with.

0:10:45.200000 --> 0:10:50.500000
 So, we can use these access tokens
 to access an API as an example.

0:10:50.500000 --> 0:10:55.080000
 The access token is almost
 always a bearer token.

0:10:55.080000 --> 0:10:58.880000
 So, again, if you remember what we covered
 in the token-based authentication

0:10:58.880000 --> 0:11:03.480000
 video, I hope things are starting to make
 sense now on your sort of joining

0:11:03.480000 --> 0:11:08.320000
 the dots. It's also important to note
 that it's not always going to be

0:11:08.320000 --> 0:11:12.740000
 a bearer token. There's also other instances
 where the applications will

0:11:12.740000 --> 0:11:16.560000
 use JWTs as access tokens.

0:11:16.560000 --> 0:11:22.860000
 And hopefully that all makes sense, and
 that brings us to the common OAuth

0:11:22.860000 --> 0:11:25.040000
 attacks section.

0:11:25.040000 --> 0:11:29.760000
 And this is the section that I mentioned
 would be, I would not be delivering

0:11:29.760000 --> 0:11:32.260000
 in video format.

0:11:32.260000 --> 0:11:35.780000
 You know, as opposed to that, this slide
 deck will be made available to

0:11:35.780000 --> 0:11:40.740000
 you. And you can access it in the course
 files zip archive that you can

0:11:40.740000 --> 0:11:43.500000
 download directly from this course page.

0:11:43.500000 --> 0:11:46.560000
 And you may be wondering to yourself,
 well, why are you not explaining

0:11:46.560000 --> 0:11:50.860000
 this? Well, again, there are quite
 a few that I can demonstrate.

0:11:50.860000 --> 0:11:54.800000
 And it would not make sense for me to
 demonstrate, you know, all of them

0:11:54.800000 --> 0:11:59.300000
 that I've listed out here from a theoretical
 perspective, because it can

0:11:59.300000 --> 0:12:03.180000
 be quite hard to understand if you're
 not familiar, or if this is your

0:12:03.180000 --> 0:12:08.360000
 first time interacting with OAuth, you
 know, from a security perspective

0:12:08.360000 --> 0:12:12.040000
 or from the point of view of a
 penetration tester, let's say.

0:12:12.040000 --> 0:12:16.440000
 And so for that reason, I opted to, again,
 utilize a very well-documented

0:12:16.440000 --> 0:12:22.760000
 lab that, again, comes after this video,
 where, again, pretty much, I

0:12:22.760000 --> 0:12:28.300000
 would say, all of the attacks under
 the common OAuth attacks section,

0:12:28.300000 --> 0:12:33.320000
 within the slides, are
 covered and explained.

0:12:33.320000 --> 0:12:39.680000
 So, for example, if I just show you
 how the slides are structured, you

0:12:39.680000 --> 0:12:45.780000
 can see that in this particular case,
 I'm sort of using different examples

0:12:45.780000 --> 0:12:54.140000
 or scenarios that are built around real
-world websites or web applications

0:12:54.140000 --> 0:12:55.640000
 that you're familiar with.

0:12:55.640000 --> 0:13:00.340000
 So, in this particular case, I'll
 just go over a couple of them.

0:13:00.340000 --> 0:13:08.060000
 As you can see, we have the next one
 that is now technique-specific.

0:13:08.060000 --> 0:13:12.260000
 So, you can see the techniques are listed
 to the left, and then the implementation

0:13:12.260000 --> 0:13:16.240000
 of the technique is going
 to be to the right here.

0:13:16.240000 --> 0:13:22.200000
 So, in this case, we have the unvalidated
 redirect URI parameter, and

0:13:22.200000 --> 0:13:25.120000
 we also have weak authorization codes.

0:13:25.120000 --> 0:13:26.580000
 How to test for that?

0:13:26.580000 --> 0:13:31.500000
 We also have the everlasting authorization
 codes on unexpiring.

0:13:31.500000 --> 0:13:37.220000
 Authorization codes not bound to a particular
 client, and I've, you know,

0:13:37.220000 --> 0:13:39.540000
 used as many visualizations as I can.

0:13:39.540000 --> 0:13:44.640000
 We then have the weak handle-based
 access and refresh tokens, which is

0:13:44.640000 --> 0:13:45.960000
 then continued here.

0:13:45.960000 --> 0:13:50.180000
 Then the, you know, insecure storage
 of handle-based access and refresh

0:13:50.180000 --> 0:13:55.120000
 tokens. Refresh token
 not bound to client.

0:13:55.120000 --> 0:13:59.980000
 And then there's also another, you
 know, attack scenario here that is

0:13:59.980000 --> 0:14:03.080000
 a little bit more advanced where I sort
 of walk you through, as I would

0:14:03.080000 --> 0:14:10.720000
 in previous videos, an example of what
 a, I would say, sort of intermediate

0:14:10.720000 --> 0:14:15.180000
 attack flow, an attack would look like,
 and I've sort of outlined the

0:14:15.180000 --> 0:14:17.480000
 flow of the steps involved.

0:14:17.480000 --> 0:14:19.260000
 And you can see that there.

0:14:19.260000 --> 0:14:21.160000
 So, it's quite extensive.

0:14:21.160000 --> 0:14:25.840000
 The bottom line is that this is really
 all theoretical, and, you know,

0:14:25.840000 --> 0:14:31.380000
 there's no way it would be possible
 for you to actually go through and

0:14:31.380000 --> 0:14:34.900000
 understand all of this without, you
 know, putting it into action.

0:14:34.900000 --> 0:14:40.220000
 So, the lab, as I said, called attacking
 OAuth, you know, right after

0:14:40.220000 --> 0:14:43.780000
 this video pretty much explains
 what is in the slide.

0:14:43.780000 --> 0:14:49.900000
 So, if you want to go through the common
 OAuth attacks, again, you can

0:14:49.900000 --> 0:14:56.900000
 access this particular slide deck, slide
 deck in PDF format in the course

0:14:56.900000 --> 0:15:03.300000
 files zip archive, you know, on
 this particular course page.

0:15:03.300000 --> 0:15:07.060000
 So, you just scroll to the top and you'll
 see the course files download

0:15:07.060000 --> 0:15:11.040000
 the zip and you'll find this particular
 slide deck in PDF format.

0:15:11.040000 --> 0:15:13.920000
 And you can then go through it and also,
 you know, use it as a reference

0:15:13.920000 --> 0:15:20.100000
 as you go through the lab, which again
 does have documentation in the,

0:15:20.100000 --> 0:15:22.980000
 you know, that comes after this video.

0:15:22.980000 --> 0:15:26.720000
 So, with that being said, that brings
 us to the end of this video, and

0:15:26.720000 --> 0:15:29.140000
 I will be seeing you in the next video.

