WEBVTT

0:00:03.680000 --> 0:00:06.440000
 Hello everyone and welcome.

0:00:06.440000 --> 0:00:10.120000
 In this video we're going to be getting
 an introduction to advanced injection

0:00:10.120000 --> 0:00:20.180000
 attacks. I already laid the groundwork
 in terms of explaining to you what

0:00:20.180000 --> 0:00:23.360000
 exactly will be covered in this course.

0:00:23.360000 --> 0:00:29.420000
 But now obviously I want to turn my attention
 to advanced injection attacks

0:00:29.420000 --> 0:00:34.340000
 and obviously sort of explain a couple
 of things just so that you're aware

0:00:34.340000 --> 0:00:36.380000
 of how everything is organized.

0:00:36.380000 --> 0:00:41.640000
 As I mentioned in the course overview
 video, the objective for this course

0:00:41.640000 --> 0:00:47.540000
 is to go beyond just SQL injection and
 no SQL injection but also explore

0:00:47.540000 --> 0:00:54.020000
 some of the other relevant common injection
 based vulnerabilities and

0:00:54.020000 --> 0:00:59.600000
 or attacks. And so with that being
 said I just want to sort of explain

0:00:59.600000 --> 0:01:04.320000
 injection attacks or sort of give a
 definition to it so you understand

0:01:04.320000 --> 0:01:09.040000
 exactly what I'm referring to when I
 say injection attacks or injection

0:01:09.040000 --> 0:01:13.160000
 based vulnerabilities, especially
 in relation to web applications.

0:01:13.160000 --> 0:01:16.080000
 So what are injection attacks?

0:01:16.080000 --> 0:01:19.980000
 Well injection attacks occur when a
 web application or an application

0:01:19.980000 --> 0:01:25.260000
 generally speaking improperly process
 untrusted input, right?

0:01:25.260000 --> 0:01:29.900000
 So just think of a web app or an application
 that allows for user input.

0:01:29.900000 --> 0:01:35.920000
 These attacks of vulnerabilities occur
 when that input is improperly processed

0:01:35.920000 --> 0:01:39.140000
 or is let's say not validated.

0:01:39.140000 --> 0:01:44.760000
 Now the back end or the way that input
 is processed is where the nuances

0:01:44.760000 --> 0:01:50.580000
 exist. So for example, when we're dealing
 with web applications that have

0:01:50.580000 --> 0:01:54.300000
 a relational database, that's where
 you have SQL injection, right?

0:01:54.300000 --> 0:01:57.680000
 If it's not, if it's a non relational
 database, that's where you have

0:01:57.680000 --> 0:01:59.220000
 no SQL injection.

0:01:59.220000 --> 0:02:03.680000
 We also have some other inputs that
 may not exist in the typical formats

0:02:03.680000 --> 0:02:04.900000
 that you would expect.

0:02:04.900000 --> 0:02:07.780000
 So not a login form or
 something like that.

0:02:07.780000 --> 0:02:15.040000
 That essentially, you know, involve
 inputting data into an application

0:02:15.040000 --> 0:02:21.440000
 or web app through some non-standard
 means or endpoints if you will.

0:02:21.440000 --> 0:02:24.680000
 And that's where you have some
 of the other injection attacks.

0:02:24.680000 --> 0:02:29.520000
 For example, LDAP injection,
 X, X, E, etc.

0:02:29.520000 --> 0:02:35.000000
 But in essence, just think of it from
 the perspective of web applications.

0:02:35.000000 --> 0:02:41.740000
 And the key thing to understand is pretty
 much any input that you know,

0:02:41.740000 --> 0:02:46.260000
 regardless of the back end or how the
 input is processed, any application

0:02:46.260000 --> 0:02:51.660000
 or web application that accepts user input
 in whatever format is susceptible

0:02:51.660000 --> 0:02:58.040000
 to an injection vulnerability, whatever
 that vulnerability may be, right?

0:02:58.040000 --> 0:03:01.900000
 But the bottom line is that this vulnerability
 then allows an attacker

0:03:01.900000 --> 0:03:06.820000
 to inject malicious code or commands
 into the application's execution

0:03:06.820000 --> 0:03:13.040000
 flow. So the bottom line is the application
 input is expecting a specific

0:03:13.040000 --> 0:03:17.060000
 type of input and it does not check for
 or does not have any restrictions

0:03:17.060000 --> 0:03:20.660000
 to ensure that the input entered
 is legal or allowed.

0:03:20.660000 --> 0:03:24.660000
 The attacker identifies that, hey,
 there is no validation of input and

0:03:24.660000 --> 0:03:30.900000
 they inject or input malicious code or
 pretty much non-standard or commands

0:03:30.900000 --> 0:03:35.480000
 or code or input that the application
 or web application is not expecting.

0:03:35.480000 --> 0:03:39.060000
 And as a result, you get to make the
 web application or the application

0:03:39.060000 --> 0:03:45.240000
 as a whole, do something that, again, is
 not expected or potentially dangerous,

0:03:45.240000 --> 0:03:50.760000
 right? The bottom line is you inject
 or input, you know, your malicious

0:03:50.760000 --> 0:03:55.340000
 code, commands or queries into the
 application's execution flow.

0:03:55.340000 --> 0:03:57.620000
 And of course, that's not something
 that should be happening.

0:03:57.620000 --> 0:04:01.500000
 And that's what injection attacks or
 injection based vulnerabilities are.

0:04:01.500000 --> 0:04:06.600000
 So this exploitation manipulates the
 how the application interacts with

0:04:06.600000 --> 0:04:08.640000
 its underlying systems.

0:04:08.640000 --> 0:04:12.900000
 These could be databases, file
 systems or operating systems.

0:04:12.900000 --> 0:04:17.700000
 So for example, command injection, the
 command injection vulnerability.

0:04:17.700000 --> 0:04:22.080000
 Again, in this case, you know, if you
 have some experience with it, there's

0:04:22.080000 --> 0:04:25.720000
 an application input that
 essentially is taken.

0:04:25.720000 --> 0:04:29.320000
 So let's say a web page that allows
 you to ping or to perform a ping,

0:04:29.320000 --> 0:04:33.240000
 right? That ping is performed by
 the underlying operating system.

0:04:33.240000 --> 0:04:38.580000
 However, if there's no restrictions on
 that input form or field regarding

0:04:38.580000 --> 0:04:43.820000
 what types of commands you can enter,
 for example, if it did not restrict

0:04:43.820000 --> 0:04:49.060000
 input to IP addresses and would allow
 for system commands to be executed,

0:04:49.060000 --> 0:04:54.040000
 then the attacker can essentially, you
 know, input system commands that

0:04:54.040000 --> 0:04:56.720000
 would then be executed by
 the underlying server.

0:04:56.720000 --> 0:04:58.920000
 And so that's the way to think of it.

0:04:58.920000 --> 0:05:00.180000
 It doesn't matter.

0:05:00.180000 --> 0:05:02.380000
 It's not really important.

0:05:02.380000 --> 0:05:07.200000
 What happens to the input data as long
 as it's processed, that's really

0:05:07.200000 --> 0:05:12.700000
 what constitutes an injection or, you
 know, input based vulnerability,

0:05:12.700000 --> 0:05:14.540000
 that makes sense.

0:05:14.540000 --> 0:05:17.460000
 So hopefully it's starting
 to all come together.

0:05:17.460000 --> 0:05:21.740000
 So that brings us to another
 important point.

0:05:21.740000 --> 0:05:26.460000
 And that is sort of visualizing the flow
 based on what I've just explained,

0:05:26.460000 --> 0:05:30.320000
 but also I sort of wanted to
 build on that explanation.

0:05:30.320000 --> 0:05:34.760000
 So that begs the question, what are
 some of the key characteristics of

0:05:34.760000 --> 0:05:36.180000
 injection based attacks?

0:05:36.180000 --> 0:05:39.560000
 So firstly, there's exploitation
 of input validation.

0:05:39.560000 --> 0:05:43.280000
 So it's not that you don't want your
 web application to have application

0:05:43.280000 --> 0:05:45.740000
 inputs, because you know,
 they are useful.

0:05:45.740000 --> 0:05:48.740000
 You want people to log in or,
 you know, provide data.

0:05:48.740000 --> 0:05:53.660000
 What you want to do is to ensure that
 that input or the input data is

0:05:53.660000 --> 0:06:00.840000
 validated to ensure that nothing illegal
 or malicious is included in or

0:06:00.840000 --> 0:06:04.300000
 is essentially input by users
 or attackers, right?

0:06:04.300000 --> 0:06:08.520000
 So injection attacks target vulnerabilities
 where input data is not properly

0:06:08.520000 --> 0:06:10.820000
 sanitized or validated.

0:06:10.820000 --> 0:06:13.680000
 Secondly, manipulation
 of queries or commands.

0:06:13.680000 --> 0:06:18.100000
 So the injected payload in the case
 of databases, let's say, alters the

0:06:18.100000 --> 0:06:23.060000
 logic of queries or commands that are
 sent back to, you know, to the back

0:06:23.060000 --> 0:06:24.980000
 end system where they are processed.

0:06:24.980000 --> 0:06:28.920000
 And then of course, wide range of targets
 as you've probably been able

0:06:28.920000 --> 0:06:33.520000
 to tell. So these attacks can affect
 databases, so SQL databases, non

0:06:33.520000 --> 0:06:38.580000
 relational databases, directory services
 like LDAP, XML passes, that's

0:06:38.580000 --> 0:06:42.580000
 where you have x, x, e injection,
 and even operating systems.

0:06:42.580000 --> 0:06:51.580000
 That's where you have sort
 of pseudo technical level.

0:06:51.580000 --> 0:06:54.800000
 You have your user input, then you
 have the application where they're

0:06:54.800000 --> 0:06:56.820000
 supposed to be validation.

0:06:56.820000 --> 0:06:59.660000
 And, you know, hopefully they
 should be validation.

0:06:59.660000 --> 0:07:03.580000
 And then that's sent to the back end
 system, whether it be a database,

0:07:03.580000 --> 0:07:05.560000
 the operating system, etc.

0:07:05.560000 --> 0:07:09.940000
 And the bottom line is what you're trying
 to do firstly is identify application

0:07:09.940000 --> 0:07:14.260000
 inputs or areas in a web application
 where you can input data, whatever

0:07:14.260000 --> 0:07:19.860000
 they may be. And secondly,
 you test to be monetized.

0:07:19.860000 --> 0:07:23.940000
 If not, you then start, you know, playing
 around with what you can get

0:07:23.940000 --> 0:07:29.680000
 the web application to do or rather
 what you can, you can essentially

0:07:29.680000 --> 0:07:31.560000
 get processed by the back end system.

0:07:31.560000 --> 0:07:36.620000
 So in the case of SQL injection, you're
 sending SQL queries, right?

0:07:36.620000 --> 0:07:38.920000
 And these are processed
 by the database, right?

0:07:38.920000 --> 0:07:41.640000
 And not by the web application, because
 the web application is supposed

0:07:41.640000 --> 0:07:46.240000
 to validate that, hey, no one should
 be putting in any illegal characters

0:07:46.240000 --> 0:07:50.920000
 or any data that looks like an SQL query.


0:07:50.920000 --> 0:07:54.180000
 If that fails, then regardless of what
 is sent, it's going to be sent

0:07:54.180000 --> 0:07:54.680000
 to the database.

0:07:54.680000 --> 0:07:58.680000
 And if it's a legitimate SQL query, for
 example, it's going to be processed

0:07:58.680000 --> 0:07:59.620000
 by the database.

0:07:59.620000 --> 0:08:01.940000
 And the database will return the data.

0:08:01.940000 --> 0:08:05.340000
 But the web application then determines
 whether it's displayed on the

0:08:05.340000 --> 0:08:09.300000
 on the actual website screen or the
 page where you actually perform the

0:08:09.300000 --> 0:08:12.900000
 injection. That's where you have error
 based injection, for example, error

0:08:12.900000 --> 0:08:17.260000
 based in the sense that you know that
 SQL injection is successful because

0:08:17.260000 --> 0:08:20.940000
 an error is displayed, the error being
 an issue with the query that you

0:08:20.940000 --> 0:08:23.660000
 provided. So hopefully that makes sense.

0:08:23.660000 --> 0:08:27.240000
 The bottom line or the key point that
 I want you to take away from this

0:08:27.240000 --> 0:08:36.140000
 is pretty much any endpoint or any application
 input is sort of a target

0:08:36.140000 --> 0:08:37.940000
 for an injection attack.

0:08:37.940000 --> 0:08:41.900000
 Now what that attack is, what the vulnerability
 could be, that's all going

0:08:41.900000 --> 0:08:44.760000
 to be dependent on the web application
 you're targeting.

0:08:44.760000 --> 0:08:48.980000
 Hence, the reason we're going to cover
 SQL injection, no SQL injection,

0:08:48.980000 --> 0:08:52.920000
 LDAP injection, and of course, X, X,
 X, E injection, and a few others,

0:08:52.920000 --> 0:08:58.580000
 right? So those are some of the key
 characteristics of injection attacks

0:08:58.580000 --> 0:09:01.080000
 or injection based vulnerabilities.

0:09:01.080000 --> 0:09:04.760000
 Now, I also wanted to highlight which
 I already did the types of injection

0:09:04.760000 --> 0:09:07.980000
 vulnerabilities, but more importantly,
 the ones we're going to be focusing

0:09:07.980000 --> 0:09:09.420000
 on in this course.

0:09:09.420000 --> 0:09:13.500000
 As I mentioned in the previous video,
 the course overview video, this

0:09:13.500000 --> 0:09:17.520000
 is not an exhaustive list of in you
 know, injection based or input based

0:09:17.520000 --> 0:09:19.040000
 vulnerabilities.

0:09:19.040000 --> 0:09:22.140000
 But these are the ones that are the
 most prevalent and the ones we'll

0:09:22.140000 --> 0:09:23.560000
 be covering in this course.

0:09:23.560000 --> 0:09:29.360000
 So we have SQL injection, no SQL injection,
 LDAP injection, ORM injection,

0:09:29.360000 --> 0:09:31.520000
 and then of course, X, X, X, E injection.


0:09:31.520000 --> 0:09:36.500000
 The server side related injection vulnerabilities
 or attacks will be covered

0:09:36.500000 --> 0:09:38.980000
 in the server side attacks course.

0:09:38.980000 --> 0:09:46.580000
 So, you know, stuff like, well, not
 SSRF specifically, but SSRI as an

0:09:46.580000 --> 0:09:51.160000
 example. And I've sort of outlined
 what these vulnerabilities are, but

0:09:51.160000 --> 0:09:56.020000
 we will be diving into each of them,
 you know, and we'll be doing so in

0:09:56.020000 --> 0:09:57.120000
 quite a bit of depth.

0:09:57.120000 --> 0:10:00.380000
 So these are just general
 definitions here.

0:10:00.380000 --> 0:10:05.180000
 And finally, I just want to point out,
 you know, why I'm sort of going

0:10:05.180000 --> 0:10:10.140000
 beyond SQL injection and sort of focusing
 on injection attacks in general.

0:10:10.140000 --> 0:10:17.100000
 Firstly, the first reason is the fact
 that injection based vulnerabilities

0:10:17.100000 --> 0:10:22.620000
 are one or, you know, have been an R
 one of the top ranked vulnerabilities

0:10:22.620000 --> 0:10:26.080000
 in the ORM top 10 for the
 last 10 years, I think.

0:10:26.080000 --> 0:10:30.260000
 So in 2017, the ORM top
 10 2017, it was first.

0:10:30.260000 --> 0:10:32.700000
 So the most critical.

0:10:32.700000 --> 0:10:38.720000
 And in 2021, the current version of
 the top 10, it is ranked third.

0:10:38.720000 --> 0:10:43.100000
 And when we talk about ORM top 10 and
 the injection category, it's not

0:10:43.100000 --> 0:10:47.420000
 referring specifically to SQL injection,
 there's a whole plethora of injection

0:10:47.420000 --> 0:10:50.160000
 based vulnerabilities
 that falls under it.

0:10:50.160000 --> 0:10:54.140000
 Hence, again, the, you know, the reason
 why I sort of wanted to explain

0:10:54.140000 --> 0:10:59.580000
 this. And secondly, you know, fairly obvious
 is the prevalence of injection

0:10:59.580000 --> 0:11:00.960000
 based vulnerabilities.

0:11:00.960000 --> 0:11:04.960000
 So injection flows affect applications
 across industries, whether it's

0:11:04.960000 --> 0:11:07.360000
 e-commerce, finance, healthcare and more.


0:11:07.360000 --> 0:11:12.340000
 And also the prevalence, the increased
 prevalence of these vulnerabilities

0:11:12.340000 --> 0:11:17.760000
 in in APIs. So injection vulnerabilities
 are also common in RESTful and

0:11:17.760000 --> 0:11:23.860000
 SOAP APIs. So as I said, any input
 or any part of the web application

0:11:23.860000 --> 0:11:30.020000
 that allows a user to input or send
 back data to the web server, the web

0:11:30.020000 --> 0:11:34.940000
 application, the API endpoint is a candidate
 for an injection attack or

0:11:34.940000 --> 0:11:39.160000
 is possibly susceptible to an
 injection based vulnerability.

0:11:39.160000 --> 0:11:42.140000
 We also have exploitation at scale.

0:11:42.140000 --> 0:11:47.620000
 And what I'm referring to there is the
 fact that we have automated tools

0:11:47.620000 --> 0:11:51.340000
 like SQL map, which makes it quite easy.

0:11:51.340000 --> 0:11:57.820000
 In fact, quite a whole lot easier for
 attackers to identify and exploit

0:11:57.820000 --> 0:12:00.180000
 injection flows at scale.

0:12:00.180000 --> 0:12:05.340000
 And in certain cases, I'll not touch
 too much upon this, you know, the

0:12:05.340000 --> 0:12:09.280000
 simplicity and power of injection attacks,
 make them a primary attack

0:12:09.280000 --> 0:12:11.380000
 vector, one of the primary ones.

0:12:11.380000 --> 0:12:15.000000
 And of course, I've just highlighted,
 you know, some examples of the real

0:12:15.000000 --> 0:12:20.120000
 world impact of SQL injection vulnerabilities,
 specifically like talk,

0:12:20.120000 --> 0:12:26.020000
 talk in 2015, Equifax 2017, that was caused
 by SQL injection vulnerability,

0:12:26.020000 --> 0:12:33.080000
 you know, which led to a breach that
 compromised 147 million records.

0:12:33.080000 --> 0:12:36.800000
 And our approach that I've listed here
 for this course is sequential.

0:12:36.800000 --> 0:12:41.000000
 So we'll start off with the fundamentals,
 so SQL injection fundamentals.

0:12:41.000000 --> 0:12:46.380000
 And then we'll move on to automating
 SQL injection with the SQL map, quite

0:12:46.380000 --> 0:12:49.900000
 a bit of stuff will explore there, then
 the advanced SQL injection techniques

0:12:49.900000 --> 0:12:56.560000
 like second order out of bound, then
 we'll move to no SQL injection, and

0:12:56.560000 --> 0:13:01.860000
 then we'll move to LDAP injection or
 M injection, and then XSE injection.

0:13:01.860000 --> 0:13:10.720000
 And that's where we'll very organized
 or structured understanding of how

0:13:10.720000 --> 0:13:12.200000
 we'll move from one to the other.

0:13:12.200000 --> 0:13:16.420000
 So we start over with the classics,
 then move on to some of the others.

0:13:16.420000 --> 0:13:19.360000
 But with that being said, that brings
 us to the end of this video, and

0:13:19.360000 --> 0:13:21.580000
 I will be seeing you in the next video.

