WEBVTT

0:00:03.700000 --> 0:00:08.560000
 Hello everyone and welcome to the next
 section of the course where we

0:00:08.560000 --> 0:00:13.200000
 are going to be taking a look
 at two factor authentication.

0:00:13.200000 --> 0:00:17.480000
 And in the next video within this section
 we're going to be obviously

0:00:17.480000 --> 0:00:24.940000
 looking at bypasses or means of bypassing
 two factor authentication implementations

0:00:24.940000 --> 0:00:28.360000
 or different types of two
 factor authentication.

0:00:28.360000 --> 0:00:33.300000
 Now, obviously you may be wondering,
 you know, given that the name itself,

0:00:33.300000 --> 0:00:39.540000
 you know, two factor authentication
 contains the word authentication.

0:00:39.540000 --> 0:00:43.920000
 Why we didn't cover this in the authentication
 testing section of this

0:00:43.920000 --> 0:00:49.400000
 course. And the reason for that is because,
 you know, two factor authentication

0:00:49.400000 --> 0:00:55.520000
 needs to be thought of as an augmentation
 of any authentication mechanism

0:00:55.520000 --> 0:01:00.200000
 really. Obviously, you know, it wouldn't
 make sense to have two factor

0:01:00.200000 --> 0:01:05.960000
 authentication for, let's say, you know,
 authenticating with an API, although

0:01:05.960000 --> 0:01:07.620000
 that can be done.

0:01:07.620000 --> 0:01:11.780000
 It needs to be understood, you know,
 as I said, as an augmentation, as

0:01:11.780000 --> 0:01:17.080000
 a security mechanism or a way of securing
 the authentication process.

0:01:17.080000 --> 0:01:27.240000
 It also, you know, plays quite important
 role, you know, in managing or

0:01:27.240000 --> 0:01:30.840000
 I should say, verifying identities
 and I'll explain what that means.

0:01:30.840000 --> 0:01:33.520000
 Of course, this will start to
 make sense as we progress.

0:01:33.520000 --> 0:01:38.120000
 So I know that I introduced you to two
 factor authentication, you know,

0:01:38.120000 --> 0:01:43.520000
 multi factor authentication and various
 other authentication mechanisms

0:01:43.520000 --> 0:01:45.200000
 early on in this course.

0:01:45.200000 --> 0:01:48.780000
 But I think we need to take a sort of
 a deep dive to understand exactly

0:01:48.780000 --> 0:01:54.920000
 what it is. So simply put two factor
 authentication also abbreviated as

0:01:54.920000 --> 0:02:00.640000
 two FA as some of you know it is a security
 measure that requires users

0:02:00.640000 --> 0:02:06.780000
 to verify their identity using two
 distinct factors before granting or

0:02:06.780000 --> 0:02:09.440000
 before your granted access to a system.

0:02:09.440000 --> 0:02:13.540000
 Now these factors and I'm, you know,
 sort of simplified it here a little

0:02:13.540000 --> 0:02:18.380000
 bit are typically something you
 know and something you have.

0:02:18.380000 --> 0:02:22.800000
 That's sort of the general idea, right,
 in terms of the implementation

0:02:22.800000 --> 0:02:24.260000
 and how it works.

0:02:24.260000 --> 0:02:27.640000
 Something you know is typically going
 to be your account password.

0:02:27.640000 --> 0:02:30.240000
 So you have an email and
 you have a password.

0:02:30.240000 --> 0:02:31.620000
 That's the first step, right?

0:02:31.620000 --> 0:02:33.240000
 So something you know.

0:02:33.240000 --> 0:02:40.860000
 And then the second what is now the
 second factor of authentication is

0:02:40.860000 --> 0:02:42.260000
 going to be something you have.

0:02:42.260000 --> 0:02:46.920000
 So that can be something outside or
 yeah, pretty much I think the word

0:02:46.920000 --> 0:02:52.040000
 outside makes the most sense something
 that is not what you know.

0:02:52.040000 --> 0:02:55.720000
 So it can be the password or
 another type of password.

0:02:55.720000 --> 0:03:02.080000
 But it has to be related or it has
 to operate through the means of you

0:03:02.080000 --> 0:03:03.220000
 know something you have.

0:03:03.220000 --> 0:03:09.000000
 So that could either be a smartphone
 or a hardware token or even an email

0:03:09.000000 --> 0:03:11.740000
 account, right, as we'll soon see.

0:03:11.740000 --> 0:03:17.740000
 So the whole idea is that by requiring
 a second layer of verification,

0:03:17.740000 --> 0:03:22.980000
 two factor authentication reduces the
 risk of unauthorized access and

0:03:22.980000 --> 0:03:26.800000
 protects user accounts even if
 the passwords are compromised.

0:03:26.800000 --> 0:03:30.440000
 So the idea is again, I'll
 use a very basic example.

0:03:30.440000 --> 0:03:34.060000
 Let's say you're logged into an account
 on it doesn't really matter what

0:03:34.060000 --> 0:03:38.360000
 web application it is and you
 want to change your password.

0:03:38.360000 --> 0:03:41.820000
 That would be a good place to
 have to factor authentication.

0:03:41.820000 --> 0:03:44.700000
 The reason that I know you've probably
 seen it, the reason that exists

0:03:44.700000 --> 0:03:50.860000
 is because regardless of the fact that
 you are authenticated to the web

0:03:50.860000 --> 0:03:56.580000
 application, it's always a good thing to
 have another layer of authentication

0:03:56.580000 --> 0:04:04.500000
 or I should say authorization to essentially
 re-verify your identity.

0:04:04.500000 --> 0:04:09.560000
 Not really it has very little to do
 with authentication, but you know

0:04:09.560000 --> 0:04:12.240000
 your identity. So what does that mean?

0:04:12.240000 --> 0:04:15.860000
 Well, it means that someone could have
 got your username and password

0:04:15.860000 --> 0:04:18.600000
 and that someone is not you.

0:04:18.600000 --> 0:04:20.480000
 It's someone let's say malicious.

0:04:20.480000 --> 0:04:24.220000
 They shouldn't have those credentials
 and now they're logged into your

0:04:24.220000 --> 0:04:26.520000
 account and they want to
 change your password.

0:04:26.520000 --> 0:04:30.760000
 Well, you can pretty much guess or you
 can see why two factor authentication

0:04:30.760000 --> 0:04:35.780000
 is so important or how it would help
 in this scenario because again, when

0:04:35.780000 --> 0:04:40.280000
 performing certain actions within a web
 application, whether you're performing

0:04:40.280000 --> 0:04:45.080000
 online banking or in the case of the
 example I gave you changing your

0:04:45.080000 --> 0:04:49.640000
 password, that is something that will
 affect you and consequently I should

0:04:49.640000 --> 0:04:51.360000
 say the owner of the account.

0:04:51.360000 --> 0:04:56.360000
 So someone obviously authenticated
 as you, but in order to verify that

0:04:56.360000 --> 0:05:01.220000
 it is you because you want to do something
 that again, the web application

0:05:01.220000 --> 0:05:06.980000
 deems fit or deems it necessary to
 actually verify your identity.

0:05:06.980000 --> 0:05:10.640000
 You know, at that point you have
 two factor authentication.

0:05:10.640000 --> 0:05:13.280000
 So again, very, very
 simple to understand.

0:05:13.280000 --> 0:05:17.980000
 It just adds that additional layer of
 I should say, you know, authorization

0:05:17.980000 --> 0:05:23.100000
 or verification of your identity because
 if you remember in the previous

0:05:23.100000 --> 0:05:26.780000
 slide, you know, something you know
 and something you have and that's

0:05:26.780000 --> 0:05:30.540000
 why, you know, with two factor authentication,
 there's multiple types.

0:05:30.540000 --> 0:05:35.180000
 You can either get a message directly
 to your phone number and that's

0:05:35.180000 --> 0:05:39.800000
 something that, you know, hopefully
 only you have and, you know, they

0:05:39.800000 --> 0:05:42.560000
 could also be authenticator apps, etc.

0:05:42.560000 --> 0:05:46.220000
 So that brings us to the types
 of two factor authentication.

0:05:46.220000 --> 0:05:49.220000
 So you have your SMS based
 two factor authentication.

0:05:49.220000 --> 0:05:53.140000
 That typically comes in the form of
 a one time passcode, which is, you

0:05:53.140000 --> 0:06:00.060000
 know, OTP, which is registered
 mobile number.

0:06:00.060000 --> 0:06:03.840000
 The advantages of this are that it's
 very easy to use and it's widely

0:06:03.840000 --> 0:06:07.860000
 adopted. The disadvantages of the cons
 are, you know, it's vulnerable

0:06:07.860000 --> 0:06:12.100000
 to sim swapping or, you know, sim swapping
 attacks, interception, and

0:06:12.100000 --> 0:06:14.060000
 of course, phishing attacks.

0:06:14.060000 --> 0:06:18.500000
 You then have the other arguably one of
 the most common forms of two factor

0:06:18.500000 --> 0:06:22.380000
 authentication and that is the, you know,
 two fact email based two factor

0:06:22.380000 --> 0:06:27.120000
 authentication. So in this case, most
 of you are probably familiar with

0:06:27.120000 --> 0:06:31.260000
 it. An OTP or verification
 link is sent to your email.

0:06:31.260000 --> 0:06:36.000000
 The advantages of this are you don't
 need an additional device.

0:06:36.000000 --> 0:06:39.600000
 Something you have, as I said, could
 also be an email address and it's

0:06:39.600000 --> 0:06:41.020000
 quite convenient.

0:06:41.020000 --> 0:06:44.480000
 The cons of it are that, you know,
 it's very risky if your emails are

0:06:44.480000 --> 0:06:47.320000
 part of the compromise.

0:06:47.320000 --> 0:06:51.740000
 So SMS email based and then you have
 your time based one time password.

0:06:51.740000 --> 0:06:55.720000
 So this is a unique code that's generated
 based on time synchronization

0:06:55.720000 --> 0:07:00.480000
 using apps like Google Authenticator
 or hardware tokens.

0:07:00.480000 --> 0:07:02.960000
 Again, some of you may
 be familiar with that.

0:07:02.960000 --> 0:07:05.920000
 The advantages of this are that, you
 know, obviously it's more secure

0:07:05.920000 --> 0:07:11.980000
 than SMS or email based methods and
 the disadvantages are pretty obvious

0:07:11.980000 --> 0:07:15.560000
 as well. You know, it requires quite
 a bit of a setup and a secondary

0:07:15.560000 --> 0:07:17.520000
 device or token.

0:07:17.520000 --> 0:07:21.160000
 And then of course you have the authenticator
 apps, which is not really

0:07:21.160000 --> 0:07:25.780000
 a type of two factor authentication,
 but more so a facilitation or a way

0:07:25.780000 --> 0:07:27.140000
 of facilitating it.

0:07:27.140000 --> 0:07:31.900000
 So, you know, apps like Microsoft Authenticator
 or Orphy generate TOTP

0:07:31.900000 --> 0:07:34.560000
 codes directly on the user's device.

0:07:34.560000 --> 0:07:38.200000
 The advantages of this are there's obviously
 no reliance on external communication

0:07:38.200000 --> 0:07:41.520000
 channels, therefore reducing risk.

0:07:41.520000 --> 0:07:45.080000
 And the disadvantages are that it's
 quite inconvenient if the device is

0:07:45.080000 --> 0:07:47.520000
 lost or damaged.

0:07:47.520000 --> 0:07:51.760000
 Now, let's take a look at some of the
 more, some of the more common two

0:07:51.760000 --> 0:07:55.120000
 factor authentication bypass
 techniques, right?

0:07:55.120000 --> 0:07:59.020000
 So obviously, given what I've just explained,
 it makes sense that social

0:07:59.020000 --> 0:08:01.860000
 engineering is, you know,
 will play a part in this.

0:08:01.860000 --> 0:08:04.640000
 And that's why we have phishing,
 phishing and smishing.

0:08:04.640000 --> 0:08:07.640000
 So in the case of phishing,
 you know, it's quite simple.

0:08:07.640000 --> 0:08:11.500000
 Attackers create fake login pages to
 trick users into entering both their

0:08:11.500000 --> 0:08:15.580000
 password and OTP, which is then captured
 and then they redirect it or

0:08:15.580000 --> 0:08:17.880000
 they use it on the legitimate website.

0:08:17.880000 --> 0:08:21.080000
 In the case of phishing, which is voice
 phishing, the attacker, this is

0:08:21.080000 --> 0:08:22.340000
 quite common now.

0:08:22.340000 --> 0:08:27.000000
 Attackers impersonate support agents,
 you know, supposedly belonging to

0:08:27.000000 --> 0:08:31.780000
 the web application or working for the
 company or, you know, the organization

0:08:31.780000 --> 0:08:34.820000
 that owns the web application
 that you're using.

0:08:34.820000 --> 0:08:38.880000
 And they do this in order to obtain
 your OTPs over the phone.

0:08:38.880000 --> 0:08:42.580000
 You then have smishing,
 which is SMS phishing.

0:08:42.580000 --> 0:08:46.340000
 So attackers send fraudulent messages
 to obtain OTPs or redirect users

0:08:46.340000 --> 0:08:47.440000
 to fake websites.

0:08:47.440000 --> 0:08:49.440000
 That's also quite common.

0:08:49.440000 --> 0:08:53.280000
 And then we obviously have some other
 ways of bypassing to a FA and that

0:08:53.280000 --> 0:08:58.860000
 comes down to the flaws in the actual implementation
 of two-factor authentication.

0:08:58.860000 --> 0:09:02.300000
 So the first of which is
 a weak backup mechanism.

0:09:02.300000 --> 0:09:06.280000
 So attackers exploit recovery processes
 like using security questions

0:09:06.280000 --> 0:09:07.460000
 or backup codes.

0:09:07.460000 --> 0:09:12.520000
 You also have session fixation and poor
 token validation where insecure

0:09:12.520000 --> 0:09:17.280000
 handling of tokens can now, you know, potentially
 allow replay or manipulation

0:09:17.280000 --> 0:09:21.100000
 attacks. You then have token
 interception, right?

0:09:21.100000 --> 0:09:25.140000
 So in this case, the obvious
 suspects come to mind.

0:09:25.140000 --> 0:09:27.980000
 We have the man in the middle attacks
 where attackers intercept two FA

0:09:27.980000 --> 0:09:32.700000
 tokens that have been transmitted or
 are being transmitted via unencrypted

0:09:32.700000 --> 0:09:36.820000
 channels. Otherwise, if it was encrypted,
 they wouldn't be able to read

0:09:36.820000 --> 0:09:40.220000
 it. And then of course, we have SIM
 swapping where attackers convince

0:09:40.220000 --> 0:09:44.540000
 a telecom provider to transfer the
 victim's phone number to a new SIM

0:09:44.540000 --> 0:09:47.220000
 card enabling them to receive OTPs.

0:09:47.220000 --> 0:09:51.740000
 And then we also have another type here,
 which is SSL stripping, not that

0:09:51.740000 --> 0:09:56.680000
 common anymore, where attackers downgrade
 HTTPS connections to HTTP to

0:09:56.680000 --> 0:10:01.440000
 intercept OTPs that have been
 sent over insecure channels.

0:10:01.440000 --> 0:10:05.060000
 That brings me now to the final section
 where this is quite important,

0:10:05.060000 --> 0:10:10.500000
 where our outline, at least for me,
 what my two two FA testing process

0:10:10.500000 --> 0:10:11.820000
 or methodology is.

0:10:11.820000 --> 0:10:15.340000
 And the reason why it's sort of my own,
 which again, I've sort of built

0:10:15.340000 --> 0:10:19.960000
 over the years, and it also has, you
 know, various other influences that,

0:10:19.960000 --> 0:10:24.020000
 you know, come from my peers experience,
 etcetera, you know, that the

0:10:24.020000 --> 0:10:28.180000
 reason for me sort of using my own or
 listing it out here is because there

0:10:28.180000 --> 0:10:30.820000
 isn't one that's really well defined.

0:10:30.820000 --> 0:10:34.540000
 Or I shouldn't say I should say that,
 you know, there isn't one defined

0:10:34.540000 --> 0:10:39.720000
 in the WSDG. So it all starts off with
 information gathering, like with

0:10:39.720000 --> 0:10:43.620000
 anything related to pen testing, where
 you start off by identifying the

0:10:43.620000 --> 0:10:45.860000
 two factor authentication mechanism.

0:10:45.860000 --> 0:10:51.260000
 So you you determine the type of two FA
 used SMS email to your TPA authenticate

0:10:51.260000 --> 0:10:52.840000
 app hardware token.

0:10:52.840000 --> 0:10:55.020000
 You then understand the
 application workflow.

0:10:55.020000 --> 0:10:59.340000
 So you analyze the login flow registration
 process to a fair enrollment.

0:10:59.340000 --> 0:11:04.040000
 And the recovery mechanisms, then you
 review the two FA configuration.

0:11:04.040000 --> 0:11:07.720000
 So you check the security
 features specifically now.

0:11:07.720000 --> 0:11:12.480000
 So token length, expiration time rate
 limiting will actually touch on,

0:11:12.480000 --> 0:11:17.080000
 you know, the use of rate limiting on
 OTPs or two FA in the next video.

0:11:17.080000 --> 0:11:20.780000
 But then I move on to the actual testing
 where I test the authentication

0:11:20.780000 --> 0:11:24.560000
 flow. So I usually start off by
 verifying the OTP strength.

0:11:24.560000 --> 0:11:29.060000
 So that essentially involves testing
 for predictable or short OTPs and

0:11:29.060000 --> 0:11:32.000000
 whether I can recreate them
 or I can see a pattern.

0:11:32.000000 --> 0:11:38.320000
 I then ensure or test for the OTPs expiration
 after use or after reasonable

0:11:38.320000 --> 0:11:42.780000
 time to see whether I can reuse it
 or whether it, you know, it takes a

0:11:42.780000 --> 0:11:45.040000
 while to expire, which
 is not a good thing.

0:11:45.040000 --> 0:11:49.220000
 We then have token replay, where I attempt
 to reuse a previously intercepted

0:11:49.220000 --> 0:11:53.240000
 or valid OTP. And then, you know, just
 see whether the application accepts

0:11:53.240000 --> 0:11:56.880000
 it or rejects it or it throws
 out some funny errors, right?

0:11:56.880000 --> 0:12:00.640000
 And then from a network security perspective,
 you know, network traffic

0:12:00.640000 --> 0:12:05.380000
 monitoring, I inspect whether OTPs are
 transmitted over encrypted channels.

0:12:05.380000 --> 0:12:09.240000
 And, you know, I can't really intercept
 and, you know, then read through

0:12:09.240000 --> 0:12:14.540000
 a particular packet or essentially analyze,
 intercept and analyze, decode,

0:12:14.540000 --> 0:12:19.900000
 you know, a request that
 has an OTP, let's say.

0:12:19.900000 --> 0:12:24.120000
 I then move on to rate limiting and
 lockout mechanisms where, you know,

0:12:24.120000 --> 0:12:28.620000
 perform a brute force on the OTPs or,
 you know, perform a OTP brute force.

0:12:28.620000 --> 0:12:33.140000
 So I utilize tools like BERB Suite,
 more specifically, the intruder to

0:12:33.140000 --> 0:12:34.500000
 brute force OTPs.

0:12:34.500000 --> 0:12:40.040000
 This is all part of this is built in
 or, you know, requires, you know,

0:12:40.040000 --> 0:12:43.340000
 the information that we gathered from
 the other two phases, as you can

0:12:43.340000 --> 0:12:47.180000
 probably tell. And then, you know,
 I sort of verify if the application

0:12:47.180000 --> 0:12:50.120000
 implements rate limiting or
 any lockout mechanisms.

0:12:50.120000 --> 0:12:54.100000
 Again, this is something we'll look
 at specifically in the next video.

0:12:54.100000 --> 0:12:56.820000
 And then I also try an
 enumerate valid OTPs.

0:12:56.820000 --> 0:13:00.660000
 So I look for response differences,
 for example, error messages or HTTP

0:13:00.660000 --> 0:13:05.600000
 status codes that reveal
 valid or invalid OTPs.

0:13:05.600000 --> 0:13:11.120000
 And then, of course, depending on the
 nature of the 2FA implementation

0:13:11.120000 --> 0:13:17.180000
 that I'm testing, there's some additional
 advanced 2FA bypass techniques.

0:13:17.180000 --> 0:13:22.660000
 So as we saw, OAuth open ID issues
 where I test for flaws in external

0:13:22.660000 --> 0:13:26.680000
 authentication mechanisms that allow,
 you know, bypassing 2FA potentially

0:13:26.680000 --> 0:13:31.080000
 replay attacks where, you know, you
 replay captured OTPs in different

0:13:31.080000 --> 0:13:34.260000
 parts of the application,
 you know, login payment.

0:13:34.260000 --> 0:13:39.360000
 That, you know, as yielded some very,
 very fruitful results for me during

0:13:39.360000 --> 0:13:45.260000
 pen tests. But more so, you know, when
 I was working on a hybrid, a web

0:13:45.260000 --> 0:13:48.960000
 application that sort of had a hybrid
 nature in that they were, you know,

0:13:48.960000 --> 0:13:52.820000
 this is very common in banking, where
 you have the online banking system

0:13:52.820000 --> 0:13:56.520000
 and then the mobile app and the mobile
 app is really where a lot of the

0:13:56.520000 --> 0:13:59.180000
 fun happens. So yeah.

0:13:59.180000 --> 0:14:02.640000
 And then we obviously have server side
 validation where you inspect where

0:14:02.640000 --> 0:14:06.920000
 the token validation happens on the
 server side or if it's handled on

0:14:06.920000 --> 0:14:11.720000
 the client, which again is not
 as uncommon as you may believe.

0:14:11.720000 --> 0:14:15.500000
 But that's something that's
 always good to keep in mind.

0:14:15.500000 --> 0:14:19.560000
 All right. So hopefully that was a good enough
 introduction to fact authentication

0:14:19.560000 --> 0:14:24.860000
 as well as, you know, the different
 ways to bypass 2FA, the different

0:14:24.860000 --> 0:14:30.020000
 types of 2FA authentication mechanisms
 or, you know, the various forms

0:14:30.020000 --> 0:14:32.580000
 of 2FA implementation.

0:14:32.580000 --> 0:14:37.780000
 And my personal methodology on how I
 go about testing 2FA authentication

0:14:37.780000 --> 0:14:41.600000
 with that being said, that's
 going to be for this video.

0:14:41.600000 --> 0:14:44.000000
 And I will be seeing you
 in the next video.

