WEBVTT

0:00:09.520000 --> 0:00:15.040000
 Hello everyone and welcome to the Advanced
 Injection Attacks course here

0:00:15.040000 --> 0:00:22.640000
 at INE. Now before we begin this course
 I always like going over the course

0:00:22.640000 --> 0:00:28.000000
 at a high level and sort of taking a look
 at exactly what we'll be covering

0:00:28.000000 --> 0:00:34.600000
 and this as you see is quite important
 because it sort of gives you a

0:00:34.600000 --> 0:00:38.760000
 high-level overview of everything so
 you know you sort of know what to

0:00:38.760000 --> 0:00:46.020000
 expect generally speaking and secondly
 and more importantly at least in

0:00:46.020000 --> 0:00:52.160000
 my opinion we will be touching on the
 learning outcomes or the learning

0:00:52.160000 --> 0:00:56.740000
 objectives for this course and as I've
 said many times before this is

0:00:56.740000 --> 0:01:01.480000
 very important because it allows you
 as the student or the person watching

0:01:01.480000 --> 0:01:09.820000
 this to essentially you know set up or
 define you know with my recommendations

0:01:09.820000 --> 0:01:14.280000
 what you will know and what you will be
 able to do by the end of the course

0:01:14.280000 --> 0:01:20.160000
 and this is important you know for
 me as well because again it allows

0:01:20.160000 --> 0:01:24.340000
 me to define at the beginning of the
 course what should be covered or

0:01:24.340000 --> 0:01:27.860000
 what I expect to cover and more importantly
 what I would expect you to

0:01:27.860000 --> 0:01:32.480000
 know in terms of knowledge and what
 I would expect you to be able to do

0:01:32.480000 --> 0:01:37.280000
 in terms of skills and abilities at
 the end of the course but hopefully

0:01:37.280000 --> 0:01:40.640000
 all of that makes sense without further
 ado let's kick off and get some

0:01:40.640000 --> 0:01:45.680000
 of the formalities out of the way so
 who am I my name is Alexis Ahmed

0:01:45.680000 --> 0:01:50.460000
 I'm the offensive security already
 I'm instructor here at INE I'm also

0:01:50.460000 --> 0:01:56.080000
 a red team lead founder of HAC Exploit
 you know a company that's performed

0:01:56.080000 --> 0:02:02.420000
 almost 500 pen tests you know at this
 point and a lot of I would say about

0:02:02.420000 --> 0:02:11.000000
 40% of which have been on web applications
 or you know for clients whose

0:02:11.000000 --> 0:02:16.560000
 business is primarily operated on the web
 so I have quite a bit of experience

0:02:16.560000 --> 0:02:20.760000
 but with that being said I'm pretty
 sure you're already familiar with

0:02:20.760000 --> 0:02:25.860000
 me let's start off by taking a look at
 some of the key concepts that will

0:02:25.860000 --> 0:02:31.940000
 be covered in this course and the objective
 here is just to again give

0:02:31.940000 --> 0:02:36.600000
 you a lay of the land so first things
 first we'll touch on the fundamentals

0:02:36.600000 --> 0:02:43.160000
 of SQL injection and also have explained
 why this course is called advanced

0:02:43.160000 --> 0:02:48.840000
 injection attacks because it goes beyond
 just SQL injection or no SQL

0:02:48.840000 --> 0:02:54.420000
 injection and we you know touch on various
 other injection-based attacks

0:02:54.420000 --> 0:02:59.140000
 but we'll start off by getting or by you
 know taking a look at the fundamentals

0:02:59.140000 --> 0:03:04.160000
 of SQL injection so you know the basic
 stuff what is SQL injection the

0:03:04.160000 --> 0:03:10.220000
 various types of SQL injection how to
 test for SQL injection how to find

0:03:10.220000 --> 0:03:13.540000
 SQL injection vulnerabilities etc.

0:03:13.540000 --> 0:03:20.120000
 The next key concept is and this is
 sort of the core of this course in

0:03:20.120000 --> 0:03:26.880000
 relation to SQL injection and that is automating
 exploitation of SQL injection

0:03:26.880000 --> 0:03:31.900000
 vulnerabilities with SQL map and this
 will all be facilitated through

0:03:31.900000 --> 0:03:36.620000
 practical labs that utilize real-world
 web application so it's going to

0:03:36.620000 --> 0:03:41.500000
 be very much based in the real world
 and the objective here is to again

0:03:41.500000 --> 0:03:46.020000
 allow you to see what various types of
 SQL injection vulnerabilities look

0:03:46.020000 --> 0:03:51.660000
 like in the wild ranging from error
-based you know all the way to you

0:03:51.660000 --> 0:03:57.080000
 know blind etc. And more importantly
 how to automate or streamline the

0:03:57.080000 --> 0:04:01.840000
 exploitation of these vulnerabilities
 within the real-world web apps using

0:04:01.840000 --> 0:04:04.480000
 a tool like SQL map.

0:04:04.480000 --> 0:04:10.280000
 The next key concept is going to be
 focused on advanced SQL injection

0:04:10.280000 --> 0:04:16.040000
 techniques or vulnerabilities the two
 of which which I guess are what

0:04:16.040000 --> 0:04:20.000000
 you typically consider advanced not
 because they're hard to perform but

0:04:20.000000 --> 0:04:25.640000
 because you know they essentially involve
 a multitude of steps in comparison

0:04:25.640000 --> 0:04:31.060000
 to traditional SQL injection vulnerabilities
 so we'll take a look at out

0:04:31.060000 --> 0:04:36.240000
 of out of band SQL injection vulnerabilities
 or now they can be performed

0:04:36.240000 --> 0:04:40.380000
 as well as second order SQL injection
 which as you know if you're a bug

0:04:40.380000 --> 0:04:43.660000
 bounty hunter or your experienced pen
 tester you know they're actually

0:04:43.660000 --> 0:04:46.900000
 quite a lot more common
 than you'd expect.

0:04:46.900000 --> 0:04:51.700000
 We'll then touch on no SQL injection
 which sort of will bring us to the

0:04:51.700000 --> 0:04:57.360000
 end of the you know the traditional
 or SQL injection as a whole and then

0:04:57.360000 --> 0:05:01.440000
 we'll move on to other injection-based
 vulnerabilities or attacks like

0:05:01.440000 --> 0:05:05.360000
 LDAP injection so you will learn about
 you know what LDAP is what it's

0:05:05.360000 --> 0:05:09.060000
 used for how it's typically implemented
 in real-world web applications

0:05:09.060000 --> 0:05:14.560000
 and then how to perform LDAP injection both
 you know the standard or traditional

0:05:14.560000 --> 0:05:17.380000
 and blind LDAP injection.

0:05:17.380000 --> 0:05:21.860000
 We then have ORM injection I'll not
 touch upon this right now in terms

0:05:21.860000 --> 0:05:28.800000
 of what will be exploring but it is
 you know it is an upcoming injection

0:05:28.800000 --> 0:05:32.540000
-based vulnerability that I think you need
 to be aware of and then we obviously

0:05:32.540000 --> 0:05:40.000000
 have XML or XXE injection I should say
 but you know XML external entity

0:05:40.000000 --> 0:05:46.640000
 injection which again is also quite
 prevalent but the objective here is

0:05:46.640000 --> 0:05:51.880000
 to go beyond SQL injection and also
 no SQL injection by taking a look

0:05:51.880000 --> 0:05:57.460000
 at all the other you know injection
-based attacks of vulnerabilities but

0:05:57.460000 --> 0:06:01.240000
 you know based on this list you're pretty
 much going to be asking yourself

0:06:01.240000 --> 0:06:05.900000
 well why aren't we covering every injection
-based attack and the answer

0:06:05.900000 --> 0:06:11.760000
 to that is two-fold A this categorization
 or this filtering of what topics

0:06:11.760000 --> 0:06:15.480000
 to cover is really based on my experience
 and what I see being the most

0:06:15.480000 --> 0:06:21.480000
 prevalent and secondly other injection
-based vulnerabilities or attacks

0:06:21.480000 --> 0:06:27.780000
 for example that are related to you
 know server side will be covered in

0:06:27.780000 --> 0:06:34.300000
 the server side attacks course so things
 like server side template injection

0:06:34.300000 --> 0:06:38.400000
 you know will be covered in that course
 and the objective is to sort of

0:06:38.400000 --> 0:06:43.480000
 split them up based on you know correctly
 organizing these vulnerabilities

0:06:43.480000 --> 0:06:50.320000
 or attacks into individual courses that
 you know for example server side

0:06:50.320000 --> 0:06:54.000000
 it would be wise for me to cover server
 side related injection vulnerabilities

0:06:54.000000 --> 0:06:58.260000
 in that course as opposed to this one
 and actually make it'll help you

0:06:58.260000 --> 0:07:02.560000
 understand the whole process a lot more
 what we're focusing on this we're

0:07:02.560000 --> 0:07:05.360000
 what we're going to be focusing on
 in this course you know going to be

0:07:05.360000 --> 0:07:10.560000
 what you'd expect SQL injection no SQL
 injection and then LDAP injection

0:07:10.560000 --> 0:07:17.680000
 ORM injection XML or you know XXE injection
 so quite a lot of stuff in

0:07:17.680000 --> 0:07:22.020000
 here and hopefully that makes sense
 so at a high level this is what to

0:07:22.020000 --> 0:07:27.340000
 expect in terms of key concepts and
 then we now have the major topics

0:07:27.340000 --> 0:07:31.560000
 which are closely related to the key concepts
 so as I mentioned SQL injection

0:07:31.560000 --> 0:07:35.960000
 fundamentals will be taking a look
 at the testing methodology for SQL

0:07:35.960000 --> 0:07:40.640000
 injection so you know how to correctly
 test for SQL injection vulnerabilities

0:07:40.640000 --> 0:07:46.940000
 how to automate SQL injection attacks using
 SQL map I mentioned that advanced

0:07:46.940000 --> 0:07:52.580000
 techniques no SQL injection LDAP injection
 ORM injection XXE injection

0:07:52.580000 --> 0:07:58.100000
 and so the major topics are closely
 related to the key concepts and that

0:07:58.100000 --> 0:08:03.380000
 that is that is in place for very good
 reason because I don't want you

0:08:03.380000 --> 0:08:10.340000
 to get confused but you know these the
 key concepts and the major topics

0:08:10.340000 --> 0:08:13.660000
 are also going to give us our learning
 outcomes so based on what I laid

0:08:13.660000 --> 0:08:18.520000
 out there it's very clear that you know
 starting off with the first one

0:08:18.520000 --> 0:08:23.780000
 in this course you learn to identify
 and execute common techniques like

0:08:23.780000 --> 0:08:28.000000
 error-based union-based Boolean-based
 SQL injection vulnerabilities along

0:08:28.000000 --> 0:08:32.620000
 with some strategies or some footnotes
 on how you can prevent them by

0:08:32.620000 --> 0:08:36.880000
 again leveraging or exploring what they
 look like in the real world right

0:08:36.880000 --> 0:08:42.220000
 in terms of attack automation by the
 end of the course or you know during

0:08:42.220000 --> 0:08:49.520000
 this course but let me use let me use
 the former in terms of the tense

0:08:49.520000 --> 0:08:53.340000
 that I'm speaking in so by the end of
 the course you should have mastered

0:08:53.340000 --> 0:08:58.620000
 you know how to use tools like SQL map to
 automate the detection and exploitation

0:08:58.620000 --> 0:09:03.660000
 of various SQL injection vulnerabilities
 that at least is my hope so you

0:09:03.660000 --> 0:09:09.440000
 may already be familiar with SQL map
 and you know there's no issue with

0:09:09.440000 --> 0:09:14.060000
 that but hopefully there's a couple
 of extra tidbits or tips that I you

0:09:14.060000 --> 0:09:17.240000
 know I'll be able to share with you one
 thing I'd like to point out before

0:09:17.240000 --> 0:09:22.980000
 we proceed in the context of SQL map
 and stuff like the tamper the tamper

0:09:22.980000 --> 0:09:28.380000
 scripts evasion etc those will all be
 covered in a separate course which

0:09:28.380000 --> 0:09:35.600000
 is the filter filter evasion and and
 WAF bypass course we will be focusing

0:09:35.600000 --> 0:09:43.640000
 primarily on again you know trying to
 evade filters and of course bypassing

0:09:43.640000 --> 0:09:47.860000
 web application firewall so in this in
 this particular course we'll touch

0:09:47.860000 --> 0:09:52.320000
 on it lightly but I'll not this is
 not going to be the focus so we're

0:09:52.320000 --> 0:09:57.520000
 just going to take a look at you know
 using SQL map at quite a at quite

0:09:57.520000 --> 0:10:02.840000
 an advanced level and how to you know
 how to really operationalize it

0:10:02.840000 --> 0:10:07.060000
 during a pen test and then of course
 advanced SQL injection techniques

0:10:07.060000 --> 0:10:11.860000
 so by the end of the course you'll be
 you'll firstly know about them you

0:10:11.860000 --> 0:10:17.900000
 know in this case the vulnerabilities
 or techniques being the out of band

0:10:17.900000 --> 0:10:21.980000
 and second order but you'll also be
 able to identify and exploit them

0:10:21.980000 --> 0:10:26.340000
 so that's my hope there in terms of
 no SQL injection fairly simple you

0:10:26.340000 --> 0:10:30.620000
 learn how to identify and exploit no
 SQL injection vulnerabilities in

0:10:30.620000 --> 0:10:35.800000
 databases like MongoDB and then we have
 LDAP injection so you learn how

0:10:35.800000 --> 0:10:40.320000
 LDAP systems are exploited through injection
 attacks and you get the knowledge

0:10:40.320000 --> 0:10:45.260000
 so what LDAP is how it works how it's
 implemented and more importantly

0:10:45.260000 --> 0:10:49.720000
 how you can go about exploiting it and we
 will we may go beyond just traditional

0:10:49.720000 --> 0:10:54.980000
 injection when we talking about LDAP but
 the focus will be on LDAP injection

0:10:54.980000 --> 0:11:00.100000
 primarily and then ORM injection so you
 know learn how to exploit weaknesses

0:11:00.100000 --> 0:11:05.200000
 in ORM generated queries in order to
 manipulate application behavior and

0:11:05.200000 --> 0:11:10.480000
 then finally XXE injection you'll by
 the end of the course you'd have

0:11:10.480000 --> 0:11:13.960000
 developed a comprehensive understanding
 of XXE injection and of course

0:11:13.960000 --> 0:11:21.260000
 you'll be able to identify and exploit
 XXE injection vulnerabilities but

0:11:21.260000 --> 0:11:24.900000
 with that being said you can see it's
 very organized everything makes

0:11:24.900000 --> 0:11:29.980000
 sense and as I said don't worry about the
 other injection related vulnerabilities

0:11:29.980000 --> 0:11:38.820000
 you know like SSDI and the rest of them
 we will cover them in the server

0:11:38.820000 --> 0:11:44.100000
-side attacks course so those are the
 learning outcomes and finally I just

0:11:44.100000 --> 0:11:47.740000
 want to touch on the pre-requisites
 so these are my recommendations as

0:11:47.740000 --> 0:11:51.800000
 to what you should know what you should
 be able to do or you know generally

0:11:51.800000 --> 0:11:55.640000
 speaking what you should be comfortable
 with before going into this course

0:11:55.640000 --> 0:11:59.720000
 so firstly I would highly recommend
 that you have a familiarity with the

0:11:59.720000 --> 0:12:05.620000
 ORM top 10 and the ORM web security testing
 guide which I've sort of mentioned

0:12:05.620000 --> 0:12:10.660000
 iterated and used not just in this course
 but in a lot of the other courses

0:12:10.660000 --> 0:12:24.940000
 so we'll be using it again as sort of
 a reference point or as a you operate

0:12:24.940000 --> 0:12:31.660000
 methodically I would highly recommend
 that you have experience in using

0:12:31.660000 --> 0:12:38.740000
 web proxies like burp and or zap either
 off is perfectly fine but what

0:12:38.740000 --> 0:12:42.240000
 that means is that you shouldn't this
 shouldn't be your first time using

0:12:42.240000 --> 0:12:47.540000
 burp suite or zap you should have some
 experience with it more specifically

0:12:47.540000 --> 0:12:54.380000
 the repeat and true decoder etc in the
 context of burp I'd highly recommend

0:12:54.380000 --> 0:12:57.700000
 that you have knowledge of different types
 of SQL injection vulnerabilities

0:12:57.700000 --> 0:13:03.860000
 that's always a plus and finally this
 is not really mandatory but you

0:13:03.860000 --> 0:13:07.860000
 should have exploited at least one SQL
 injection vulnerability regardless

0:13:07.860000 --> 0:13:12.480000
 as to whether it was you know in a vulnerable
 web application intentionally

0:13:12.480000 --> 0:13:18.880000
 vulnerable web application in a lab
 in your own environment or even you

0:13:18.880000 --> 0:13:24.020000
 know you may be experienced in SQL injection
 so the bottom line is that

0:13:24.020000 --> 0:13:28.420000
 you should have exploited you know at
 least one SQL injection vulnerability

0:13:28.420000 --> 0:13:33.080000
 and seeing what it was like how you go
 from zero to identifying an endpoint

0:13:33.080000 --> 0:13:38.740000
 and then of course testing DBMS identification
 identifying the type so

0:13:38.740000 --> 0:13:44.380000
 is it error-based you know what works
 using SQL map etc all of that will

0:13:44.380000 --> 0:13:52.920000
 be point out I would say having a familiarity
 with burp suite and or zap

0:13:52.920000 --> 0:13:56.420000
 and just having a knowledge of the different
 types of SQL injection vulnerabilities

0:13:56.420000 --> 0:14:00.940000
 now if you don't there's going to be the
 fundamental section for SQL injection

0:14:00.940000 --> 0:14:08.360000
 that was extrapolated from the EWPT
 course called SQL injection attacks

0:14:08.360000 --> 0:14:12.320000
 so if you're this your first time getting
 into SQL injection or you need

0:14:12.320000 --> 0:14:17.220000
 to brush up your or you know jog your
 memory the first section of the

0:14:17.220000 --> 0:14:20.940000
 course is going to be focused on the
 fundamental so we've got you covered

0:14:20.940000 --> 0:14:24.940000
 either way with that being said that
 brings us to the end of the course

0:14:24.940000 --> 0:14:28.340000
 overview video and I'm really excited
 to get started with this course

