WEBVTT

0:00:16.340000 --> 0:00:20.640000
 In this video, we're going to be taking
 all of the manual techniques and

0:00:20.640000 --> 0:00:24.740000
 methodologies that we had learned or
 taken a look at in the previous video

0:00:24.740000 --> 0:00:28.420000
 and putting them into action in a lab.

0:00:28.420000 --> 0:00:33.240000
 So as I've mentioned, this video
 has a lab associated with it.

0:00:33.240000 --> 0:00:38.540000
 This lab is going to provide you with
 access to a deliberately vulnerable

0:00:38.540000 --> 0:00:42.320000
 web application called OASP Motelide 2.

0:00:42.320000 --> 0:00:45.480000
 Now, you may be thinking to yourself,
 why aren't we running these tests

0:00:45.480000 --> 0:00:47.720000
 on real-world web applications?

0:00:47.720000 --> 0:00:52.020000
 We will do that when we'll be taking
 a look at each of the SQL injection

0:00:52.020000 --> 0:00:54.840000
 vulnerability types and subtypes.

0:00:54.840000 --> 0:00:58.420000
 But with regards to identification,
 there's a good reason why I'm using

0:00:58.420000 --> 0:01:01.380000
 OASP Motelide and that
 will become evident.

0:01:01.380000 --> 0:01:07.400000
 I have frequently or I've always utilized
 OASP Motelide 2 to teach students

0:01:07.400000 --> 0:01:09.580000
 about SQL injection.

0:01:09.580000 --> 0:01:13.980000
 And from my experience, this has been
 one of the most important lessons

0:01:13.980000 --> 0:01:18.140000
 and labs that students have gone through
 because it clarifies a lot of

0:01:18.140000 --> 0:01:22.120000
 their questions with regards to identification
 or the process of identifying

0:01:22.120000 --> 0:01:25.640000
 SQL injection vulnerabilities.

0:01:25.640000 --> 0:01:30.180000
 One thing to note as well is that when
 you start this lab, it'll provide

0:01:30.180000 --> 0:01:35.600000
 you with a link, a public link accessible
 on the internet or to your instance

0:01:35.600000 --> 0:01:42.060000
 of the OASP Motelide 2 deliberately
 vulnerable web application.

0:01:42.060000 --> 0:01:45.160000
 You will not be provided with
 your own Kali Linux system.

0:01:45.160000 --> 0:01:50.700000
 So in this particular video will not
 be utilizing Kali Linux, but I'll

0:01:50.700000 --> 0:01:55.900000
 be accessing the, I'll be accessing
 Motelide 2 from my own Kali Linux

0:01:55.900000 --> 0:01:57.900000
 VM. So just keep that in mind.

0:01:57.900000 --> 0:02:02.280000
 In the next video, we'll be using the
 same lab, but we'll be exploring

0:02:02.280000 --> 0:02:03.560000
 the process with ZAP.

0:02:03.560000 --> 0:02:07.860000
 So you'll also need your own Kali Linux
 system for that with ZAP installed.

0:02:07.860000 --> 0:02:11.160000
 If you're not aware of how to do that,
 you can check out the web proxies

0:02:11.160000 --> 0:02:12.520000
 course if you haven't already.

0:02:12.520000 --> 0:02:16.440000
 But again, these ones will not
 have any Kali Linux system.

0:02:16.440000 --> 0:02:20.540000
 So I'll be walking through what you need
 to do on your own Kali box, which

0:02:20.540000 --> 0:02:22.720000
 I think a lot of you prefer.

0:02:22.720000 --> 0:02:25.620000
 With that being said, we have got a
 lot to cover and I'll be covering

0:02:25.620000 --> 0:02:28.800000
 things sequentially in a
 way that will make sense.

0:02:28.800000 --> 0:02:31.740000
 So I'm going to switch over to my Kali
 VM and I'm going to fire up the

0:02:31.740000 --> 0:02:33.560000
 lab and we can get started.

0:02:33.560000 --> 0:02:38.140000
 You're free to go through the lab beforehand
 and test out the SQL injection

0:02:38.140000 --> 0:02:42.820000
 of vulnerability exercises or you can
 watch the video and then go through

0:02:42.820000 --> 0:02:45.540000
 it yourself either way,
 whatever works for you.

0:02:45.540000 --> 0:02:49.220000
 So I am going to switch over
 and we'll get started.

0:02:49.220000 --> 0:02:51.520000
 So I'll see you there.

0:02:51.520000 --> 0:02:58.460000
 All right, so I'm back within my Kali
 VM and I've launched the lab and

0:02:58.460000 --> 0:03:00.560000
 it's provided me with this URL.

0:03:00.560000 --> 0:03:03.360000
 In your case, your URL
 might be different.

0:03:03.360000 --> 0:03:04.700000
 However, don't worry about that.

0:03:04.700000 --> 0:03:06.500000
 Everything will still apply.

0:03:06.500000 --> 0:03:10.000000
 Now, before we get started in the previous
 video, I'd mentioned one of

0:03:10.000000 --> 0:03:14.520000
 the GitHub repositories that is called
 SQL injection payload list.

0:03:14.520000 --> 0:03:19.920000
 It's essentially a free set of SQL
 injection payloads for the various

0:03:19.920000 --> 0:03:23.440000
 types or sub types of SQL
 injection techniques.

0:03:23.440000 --> 0:03:26.840000
 So right over here, you have generic
 SQL injection payloads.

0:03:26.840000 --> 0:03:30.840000
 The only issue with this particular
 repositories is no explanation has

0:03:30.840000 --> 0:03:34.660000
 been given as to what they're used for,
 but they're sorted at a high level

0:03:34.660000 --> 0:03:38.840000
 in that we have error based payloads
 here that can be used either for

0:03:38.840000 --> 0:03:43.580000
 integer based injection or
 string based injection.

0:03:43.580000 --> 0:03:47.320000
 And you can see there's inclusion
 of Boolean operations.

0:03:47.320000 --> 0:03:51.940000
 There's also inclusion of if
 we take a look at it here.

0:03:51.940000 --> 0:03:55.780000
 There's also the inclusion
 of other categories.

0:03:55.780000 --> 0:04:00.300000
 So for example, generic time based SQL
 injection payloads or blind injection,

0:04:00.300000 --> 0:04:04.860000
 where you can utilize time based operation
 or time based injection to

0:04:04.860000 --> 0:04:09.460000
 verify that injection is
 indeed possible or not.

0:04:09.460000 --> 0:04:13.780000
 The same, I believe we also have
 union payloads right over here.

0:04:13.780000 --> 0:04:17.720000
 So we'll be referencing this at certain
 points in time, although I'm going

0:04:17.720000 --> 0:04:22.580000
 to be really focusing on the detection
 or identification technique.

0:04:22.580000 --> 0:04:28.120000
 So the reason why I love OAS
 Motilide is for two reasons.

0:04:28.120000 --> 0:04:32.780000
 Number one, I can control the security
 level and I'll be increasing the

0:04:32.780000 --> 0:04:37.040000
 security level to the highest to show
 you what input sanitization or input

0:04:37.040000 --> 0:04:38.780000
 validation looks like.

0:04:38.780000 --> 0:04:42.880000
 But for now, we're going to keep it at
 security level zero, which assumes

0:04:42.880000 --> 0:04:48.740000
 or means that the all application inputs
 do not have any input validation,

0:04:48.740000 --> 0:04:50.320000
 which is a good thing.

0:04:50.320000 --> 0:04:51.940000
 So that's the first thing I like.

0:04:51.940000 --> 0:04:57.100000
 The second thing I like is that regardless
 of the SQL injection technique,

0:04:57.100000 --> 0:05:01.560000
 you are utilizing specifically in the
 case of error based injection, even

0:05:01.560000 --> 0:05:07.060000
 with others, if there is a mistake
 in your SQL payload or your syntax,

0:05:07.060000 --> 0:05:08.460000
 an error will be displayed.

0:05:08.460000 --> 0:05:12.300000
 So again, it's not tied to the payload
 you're using or the type of SQL

0:05:12.300000 --> 0:05:14.380000
 injection vulnerability or exploiting.

0:05:14.380000 --> 0:05:19.180000
 It's just displayed for students and,
 you know, for instructors, really,

0:05:19.180000 --> 0:05:23.220000
 to essentially show you what's going
 on in the background, what query

0:05:23.220000 --> 0:05:27.800000
 is being used, and that'll help you
 understand what payloads to use.

0:05:27.800000 --> 0:05:33.520000
 So to get started, what we're going
 to start off with is the login form

0:05:33.520000 --> 0:05:34.320000
 right over here.

0:05:34.320000 --> 0:05:37.320000
 So we're currently not logged
 in, as you can see here.

0:05:37.320000 --> 0:05:41.260000
 And I'm going to click on login and
 over here, we have a simple login

0:05:41.260000 --> 0:05:47.180000
 form, right? And at the moment, as I
 said, security level is set to zero.

0:05:47.180000 --> 0:05:50.980000
 So the first thing you need to do,
 or you can do manually, obviously,

0:05:50.980000 --> 0:05:57.100000
 is try and view the actual source code
 of the web page to try and see

0:05:57.100000 --> 0:06:03.860000
 if there is a link to the actual login
.php script or login.php page, if

0:06:03.860000 --> 0:06:06.000000
 as it were, that handles.

0:06:06.000000 --> 0:06:08.340000
 There we are. So we can see it here.

0:06:08.340000 --> 0:06:11.960000
 So, you know, we can probably try and
 open this in a new tab, just to

0:06:11.960000 --> 0:06:15.340000
 see whether we can explore what's going
 on with regards to the query.

0:06:15.340000 --> 0:06:18.160000
 But that's really not important
 at this point in time.

0:06:18.160000 --> 0:06:22.680000
 We can just, you know, pass in simple
 tests, use name and password, and

0:06:22.680000 --> 0:06:24.180000
 you can see account doesn't exist.

0:06:24.180000 --> 0:06:27.960000
 So the first thing that we need to do,
 or that is recommended, is obviously

0:06:27.960000 --> 0:06:29.680000
 the single quote, right?

0:06:29.680000 --> 0:06:33.260000
 So if we take a look at the URL, you
 can see that once, when we submit

0:06:33.260000 --> 0:06:38.980000
 the value for the parameters, use name
 and password, they are not passed

0:06:38.980000 --> 0:06:40.960000
 in the URL at all.

0:06:40.960000 --> 0:06:44.940000
 All right, so that means we would, they're
 being passed in the HTTP request.

0:06:44.940000 --> 0:06:49.920000
 We don't really need to analyze the
 request with a web proxy just yet.

0:06:49.920000 --> 0:06:53.640000
 But we can start off by doing some, you
 know, simple enumeration or simple

0:06:53.640000 --> 0:06:57.180000
 testing, so error-based testing
 where we use a single quote.

0:06:57.180000 --> 0:07:05.760000
 And that is going to essentially act
 as a delimiter for, and, you know,

0:07:05.760000 --> 0:07:11.140000
 after this point, we can start putting
 this is going to terminate the

0:07:11.140000 --> 0:07:14.140000
 string literal. So this is the
 cool thing with Motility.

0:07:14.140000 --> 0:07:18.900000
 So if I just hit log in here, so this
 is error-based injection, and indeed

0:07:18.900000 --> 0:07:19.960000
 an error is displayed.

0:07:19.960000 --> 0:07:23.020000
 Now, remember, we're talking
 about database enumeration.

0:07:23.020000 --> 0:07:27.180000
 If we take a look at the error message
 here, what you'll typically see

0:07:27.180000 --> 0:07:31.720000
 in a real world web application that is
 vulnerable to error-based injection,

0:07:31.720000 --> 0:07:35.500000
 if we used the single quote, you would
 see an error like this saying you

0:07:35.500000 --> 0:07:39.400000
 have an error in your SQL syntax, and
 you can again verify this by taking

0:07:39.400000 --> 0:07:40.940000
 a look at the slides.

0:07:40.940000 --> 0:07:44.540000
 This tells us that we're dealing
 with a MySQL database.

0:07:44.540000 --> 0:07:47.660000
 All right, and that is also highlighted
 here, where it says, check the

0:07:47.660000 --> 0:07:51.660000
 manual that corresponds to your MySQL
 server version for the right syntax

0:07:51.660000 --> 0:07:55.300000
 to use near the following at line one.

0:07:55.300000 --> 0:08:00.580000
 And then the great thing with Motility
 is it shows you the query that

0:08:00.580000 --> 0:08:04.300000
 is being used by the web application
 to send data to the database for

0:08:04.300000 --> 0:08:06.600000
 processing and where you went wrong.

0:08:06.600000 --> 0:08:10.700000
 So in this case, this terminates the
 string literal, the quote that we

0:08:10.700000 --> 0:08:13.540000
 specified, and that's obviously
 a syntax error.

0:08:13.540000 --> 0:08:15.060000
 And as a result, we get an error.

0:08:15.060000 --> 0:08:21.100000
 Now what this tells us is our query,
 or this particular application input

0:08:21.100000 --> 0:08:24.740000
 is not being sanitized, because we're
 able to pass in special characters

0:08:24.740000 --> 0:08:27.020000
 like quotes or single quotes, as it were.


0:08:27.020000 --> 0:08:30.860000
 And this is being processed by the database,
 and the database can process

0:08:30.860000 --> 0:08:34.800000
 it because it doesn't understand what
 you mean when you specify another

0:08:34.800000 --> 0:08:38.660000
 single quote, and you don't close it,
 or you try and encapsulate any info

0:08:38.660000 --> 0:08:44.480000
 within it. So the point I'm making
 here is what we can try and do now,

0:08:44.480000 --> 0:08:52.200000
 is we can try and utilize a Boolean operation
 to bypass the authentication

0:08:52.200000 --> 0:08:54.360000
 or bypass the login screen.

0:08:54.360000 --> 0:08:59.680000
 Now this is a trick that has been known
 for quite a while on web applications

0:08:59.680000 --> 0:09:03.400000
 or on login forms that don't
 have any input validation.

0:09:03.400000 --> 0:09:07.640000
 And that is to utilize
 the single quote there.

0:09:07.640000 --> 0:09:11.340000
 And obviously in this case, again,
 if we take a look at the query, and

0:09:11.340000 --> 0:09:15.460000
 this is one thing that I wanted to point
 out, we can see the double single

0:09:15.460000 --> 0:09:20.300000
 quotes here, where the username, where
 the username would be encapsulated.

0:09:20.300000 --> 0:09:23.680000
 And that tells us what, if you go back
 to the slides in the previous video,

0:09:23.680000 --> 0:09:26.480000
 it tells us that this is string, right?

0:09:26.480000 --> 0:09:30.280000
 So this, the parameter, the username
 parameter is treated as a string.

0:09:30.280000 --> 0:09:33.640000
 So that means we would always
 need to use a single quote.

0:09:33.640000 --> 0:09:38.380000
 If we tried to, you know, perform just,
 we can say, and, you know, without

0:09:38.380000 --> 0:09:42.700000
 any single quote, and we hit enter,
 that would not be processed by the

0:09:42.700000 --> 0:09:47.180000
 database, right, or would not be handled
 as a legit, essentially be passed

0:09:47.180000 --> 0:09:49.040000
 within the single quotes.

0:09:49.040000 --> 0:09:51.300000
 And obviously that user doesn't exist.

0:09:51.300000 --> 0:09:56.840000
 So what we could do is say zero, or
 sorry, single quote, or one equals

0:09:56.840000 --> 0:09:59.260000
 one, so an operation that's always true.

0:09:59.260000 --> 0:10:01.680000
 If we hit enter, we're
 going to get an error.

0:10:01.680000 --> 0:10:03.160000
 So I'll hit login.

0:10:03.160000 --> 0:10:04.620000
 And what's the error?

0:10:04.620000 --> 0:10:08.180000
 Well, firstly, we have an error
 in our in our syntax, right?

0:10:08.180000 --> 0:10:11.540000
 But if we take a look at the query,
 we can say it says select from the

0:10:11.540000 --> 0:10:16.040000
 column username, from the table called
 accounts where the username equals

0:10:16.040000 --> 0:10:21.520000
 two. And what we did with the single quote,
 as you can see, we have essentially,

0:10:21.520000 --> 0:10:24.320000
 it's terminated the string literal.

0:10:24.320000 --> 0:10:30.040000
 And now what we have done here is we
 are putting in our payload in here.

0:10:30.040000 --> 0:10:33.760000
 All right. And that's why it's,
 you know, open, closed, etc.

0:10:33.760000 --> 0:10:35.960000
 So this is open and closed here.

0:10:35.960000 --> 0:10:39.160000
 Whereas previously, that
 was not the case.

0:10:39.160000 --> 0:10:45.460000
 So the purpose of the single quote is
 to again, close the string literal

0:10:45.460000 --> 0:10:49.140000
 that encompasses the username input
 field or the, you know, the actual

0:10:49.140000 --> 0:10:54.900000
 parameter, then whatever we specify
 afterwards is the injected payload.

0:10:54.900000 --> 0:10:57.740000
 And that's what will be executed.

0:10:57.740000 --> 0:10:59.700000
 So in this case, what's the issue?

0:10:59.700000 --> 0:11:04.540000
 Well, the issue is if we take a look
 at the query, what's happening here

0:11:04.540000 --> 0:11:06.440000
 is this statement is being terminated.

0:11:06.440000 --> 0:11:11.140000
 All right, so that means that in this
 particular case, we need, we'll

0:11:11.140000 --> 0:11:13.120000
 need to add a comment here.

0:11:13.120000 --> 0:11:14.940000
 Now there are two ways
 of adding a comment.

0:11:14.940000 --> 0:11:19.700000
 So we can use the double hyphen
 login that doesn't work.

0:11:19.700000 --> 0:11:25.060000
 So we can say single quote, or one equals
 one, and then the hash or pound

0:11:25.060000 --> 0:11:26.880000
 symbol, and we hit enter.

0:11:26.880000 --> 0:11:31.420000
 And that will be equals to true, or
 that operation will always be true.

0:11:31.420000 --> 0:11:35.700000
 And as a result, we that is sent back
 to the web application and the web

0:11:35.700000 --> 0:11:39.620000
 application thinks that yes, this user
 is logged in, and we're logged

0:11:39.620000 --> 0:11:43.240000
 in as the user admin right over here.

0:11:43.240000 --> 0:11:48.280000
 All right, so that is how to bypass a
 simple authentication or login form

0:11:48.280000 --> 0:11:55.860000
 that has no input validation or user
 input validation or sanitization.

0:11:55.860000 --> 0:12:00.960000
 All right, so that's the first, the first
 example that I always like using

0:12:00.960000 --> 0:12:02.660000
 when I'm when I'm teaching this topic.

0:12:02.660000 --> 0:12:07.200000
 So again, you can always refer
 back to this GitHub repo.

0:12:07.200000 --> 0:12:09.260000
 And you can use either one of them.

0:12:09.260000 --> 0:12:13.240000
 So for example, you can also change
 the one equals one to whatever you

0:12:13.240000 --> 0:12:17.440000
 want. As I said, the difference between,
 and this is something that you

0:12:17.440000 --> 0:12:22.720000
 need to test, the you you need to essentially
 go through a testing process

0:12:22.720000 --> 0:12:27.740000
 where where you essentially try and
 verify what is being treated as a

0:12:27.740000 --> 0:12:31.780000
 comment, because in certain cases,
 the double hyphen, if that is being

0:12:31.780000 --> 0:12:35.860000
 is being sanitized by the web application,
 that might not be possible

0:12:35.860000 --> 0:12:40.760000
 to inject. So you always need to try
 the the pound or the hash symbol.

0:12:40.760000 --> 0:12:45.560000
 If you're trying to invoke a a comment,
 right, or to terminate at that

0:12:45.560000 --> 0:12:48.060000
 point and not execute anything after.

0:12:48.060000 --> 0:12:54.960000
 So we can also try and use other SQL
 commands here, like having one equals

0:12:54.960000 --> 0:12:59.360000
 one. So if this of course was integer
 based, and we would just put that

0:12:59.360000 --> 0:13:01.320000
 in there, then that would work.

0:13:01.320000 --> 0:13:05.280000
 But in this case, you would need to
 obviously use the single quote, it's

0:13:05.280000 --> 0:13:07.900000
 going to terminate the string literal.

0:13:07.900000 --> 0:13:10.680000
 So I'll hit enter.

0:13:10.680000 --> 0:13:12.600000
 And in this case, that doesn't work.

0:13:12.600000 --> 0:13:17.340000
 All right. So the reason that's not
 working in the case of, you know,

0:13:17.340000 --> 0:13:22.000000
 bypassing a login is obviously down
 to the logical operator being used.

0:13:22.000000 --> 0:13:26.780000
 Now, if we used and I don't think
 that would work as well.

0:13:26.780000 --> 0:13:29.000000
 So we can say, and one equals one.

0:13:29.000000 --> 0:13:30.280000
 And we can hit enter.

0:13:30.280000 --> 0:13:31.800000
 Yes, and that doesn't work.

0:13:31.800000 --> 0:13:34.940000
 So this all depends on
 the initial query here.

0:13:34.940000 --> 0:13:40.440000
 We're obviously when we put in the string,
 the single quote that's essentially

0:13:40.440000 --> 0:13:44.260000
 terminates the string literal and then
 anything after that is going to

0:13:44.260000 --> 0:13:50.140000
 be executed. So what we're doing now
 is the reason we use the logical

0:13:50.140000 --> 0:13:55.000000
 operator, as I said, is we need something
 that will always result in true,

0:13:55.000000 --> 0:13:56.540000
 or will always be true.

0:13:56.540000 --> 0:13:59.260000
 And therefore, you know, in this
 case, bypasses the login.

0:13:59.260000 --> 0:14:05.020000
 Now, what we can do is let's take a look
 at some of the injection exercises

0:14:05.020000 --> 0:14:06.880000
 by navigating to ORSP.

0:14:06.880000 --> 0:14:09.160000
 And I'll just go home here for a second.

0:14:09.160000 --> 0:14:15.700000
 ORSP 2017. And we want to take a look at
 A1 injection, which is SQL injection.

0:14:15.700000 --> 0:14:16.940000
 And there's multiple exercises.

0:14:16.940000 --> 0:14:20.100000
 There's extract data via user info.

0:14:20.100000 --> 0:14:24.080000
 So these are just examples of application
 inputs that you are likely to

0:14:24.080000 --> 0:14:26.020000
 experience or likely to come by.

0:14:26.020000 --> 0:14:30.080000
 And the login one we've already taken
 a look at, you know, we've explored

0:14:30.080000 --> 0:14:34.340000
 error based and then obviously we have
 utilized some a Boolean operation

0:14:34.340000 --> 0:14:35.960000
 to bypass the login.

0:14:35.960000 --> 0:14:45.720000
 We also have the insert really commonly
 found, but we also have blind

0:14:45.720000 --> 0:14:49.500000
 SQL injection via timing
 and SQL map practice.

0:14:49.500000 --> 0:14:53.180000
 And I'll go through them as I would,
 you know, if I was explaining this

0:14:53.180000 --> 0:14:57.220000
 to students, which is exactly
 what I'm doing.

0:14:57.220000 --> 0:15:00.300000
 So we'll go to extract
 data and use the info.

0:15:00.300000 --> 0:15:06.060000
 And this is slightly different because
 this particular input essentially

0:15:06.060000 --> 0:15:08.040000
 performs a user lookup, right?

0:15:08.040000 --> 0:15:13.060000
 So for example, what I would need to
 do is put in a name and a password,

0:15:13.060000 --> 0:15:17.760000
 right? And if the account exists, it'll
 display that user's information.

0:15:17.760000 --> 0:15:22.020000
 Okay, so if I say, you know, for example,
 Alexis and password, and let's

0:15:22.020000 --> 0:15:25.920000
 see if I have a user account, I don't
 cause I haven't registered, it's

0:15:25.920000 --> 0:15:28.700000
 going to tell us right over here,
 bad username or password.

0:15:28.700000 --> 0:15:32.880000
 So with Motelide, the great thing, as
 I've said, is we can use the single

0:15:32.880000 --> 0:15:37.280000
 quote there to obviously
 invoke an error, right?

0:15:37.280000 --> 0:15:38.700000
 So error based injection.

0:15:38.700000 --> 0:15:42.500000
 And in this case, the error tells us,
 you know, it provides us with the

0:15:42.500000 --> 0:15:46.200000
 error, which tells us exactly
 what we need, we knew.

0:15:46.200000 --> 0:15:48.820000
 But really what I'm focused
 on here is the query.

0:15:48.820000 --> 0:15:50.540000
 So this is a slightly different query.

0:15:50.540000 --> 0:15:55.180000
 We're not selecting a particular column
 within the table accounts, we're

0:15:55.180000 --> 0:15:59.080000
 selecting everything from accounts,
 where the username and password.

0:15:59.080000 --> 0:16:03.420000
 So we're now matching the username
 and password, which means, and this

0:16:03.420000 --> 0:16:07.900000
 is very important, you need to take into
 con and this is where the comments

0:16:07.900000 --> 0:16:13.220000
 come into play, you need to be cognizant
 of what is being executed after

0:16:13.220000 --> 0:16:16.000000
 the query that is executed after.

0:16:16.000000 --> 0:16:20.340000
 Okay, so let me show you something
 here in the username, I'll pass in

0:16:20.340000 --> 0:16:23.380000
 the single quote and a password,
 I'll pass in the password here.

0:16:23.380000 --> 0:16:25.600000
 So I'll pass that through.

0:16:25.600000 --> 0:16:30.060000
 And now you can see how things or how
 information is being passed in.

0:16:30.060000 --> 0:16:36.480000
 All right, so what happens is when we
 inject, when we use the single quote,

0:16:36.480000 --> 0:16:40.180000
 you can obviously tell how
 it's being injected, right?

0:16:40.180000 --> 0:16:46.340000
 Now, what happens, and this is something
 I should have done on the login

0:16:46.340000 --> 0:16:53.580000
 screen, what if we say, or single quote,
 or equals, and then we put the

0:16:53.580000 --> 0:16:58.400000
 integers, or encapsulate
 them in quotes, right?

0:16:58.400000 --> 0:17:01.220000
 And we'll not use a comment and we'll
 put in a value for password, just

0:17:01.220000 --> 0:17:04.120000
 to take a look at what's
 been sent via the query.

0:17:04.120000 --> 0:17:07.260000
 So in this particular case, you
 can see what's happened, right?

0:17:07.260000 --> 0:17:11.300000
 When you talk about string based injection,
 when we put the single quote,

0:17:11.300000 --> 0:17:14.020000
 what it does is it injects it in there.

0:17:14.020000 --> 0:17:18.720000
 And then after that is where we put
 the query that we want injected sort

0:17:18.720000 --> 0:17:21.980000
 of replacing it, but it terminates
 the string literal for the username

0:17:21.980000 --> 0:17:25.200000
 parameter. And you can see
 the closed quote there.

0:17:25.200000 --> 0:17:32.560000
 Now, when we, in this particular case,
 when we say one or one equals one,

0:17:32.560000 --> 0:17:35.560000
 and we use a comment and we'll put in
 a password and let's see what happened

0:17:35.560000 --> 0:17:39.520000
 here, or what happens, the SQL
 injection is successful.

0:17:39.520000 --> 0:17:42.500000
 So I did we don't even need to put
 in a value for the password.

0:17:42.500000 --> 0:17:45.220000
 But what happens here is
 this is set to true.

0:17:45.220000 --> 0:17:49.080000
 So going back to the actual query,
 if we just take a look at it, when

0:17:49.080000 --> 0:17:54.180000
 we utilize that Boolean operation or that
 Boolean payload, it's essentially

0:17:54.180000 --> 0:17:56.060000
 going to display everything.

0:17:56.060000 --> 0:18:01.380000
 So select all from accounts, so every
 record in accounts, and all the

0:18:01.380000 --> 0:18:04.860000
 columns, or all the attributes
 for all of the records.

0:18:04.860000 --> 0:18:10.040000
 And in this case, we're using the the
 Boolean or logical operator or to

0:18:10.040000 --> 0:18:14.320000
 say where, you know, if this is true,
 and in this case, we're using an

0:18:14.320000 --> 0:18:17.520000
 operation that's always going to be
 true, then display all of that.

0:18:17.520000 --> 0:18:20.360000
 And that's exactly what the
 web application required.

0:18:20.360000 --> 0:18:26.820000
 And we're using a comment to get rid
 of the actual of this particular,

0:18:26.820000 --> 0:18:30.240000
 the second query that checks or
 tries to match the password.

0:18:30.240000 --> 0:18:36.940000
 So if I say one or one, so I'll use
 single quote or one, and then I'll

0:18:36.940000 --> 0:18:39.920000
 use the found symbol there.

0:18:39.920000 --> 0:18:43.320000
 And I put in the password, I just want
 to show you that this comment here,

0:18:43.320000 --> 0:18:47.960000
 the pound symbol will make anything
 after it a comment.

0:18:47.960000 --> 0:18:50.000000
 In this case, it worked.

0:18:50.000000 --> 0:18:54.480000
 And that's because we're just saying
 or one, right, which which also works

0:18:54.480000 --> 0:18:57.900000
 if we take a look at the payload here,
 or the payload list here, that

0:18:57.900000 --> 0:19:00.200000
 should also work with a one equals zero.

0:19:00.200000 --> 0:19:02.260000
 Yeah, so pretty much the same thing.

0:19:02.260000 --> 0:19:05.940000
 But typically, you want to use an
 operation that is always correct.

0:19:05.940000 --> 0:19:12.380000
 Right. So we can say again, in this
 case, one, or one, sorry, in this

0:19:12.380000 --> 0:19:16.120000
 case, that's going to
 be or one equals one.

0:19:16.120000 --> 0:19:19.920000
 And I'll just put a comment there, and
 we can hit view account details.

0:19:19.920000 --> 0:19:23.840000
 And again, I said that's going to display
 all the records within that

0:19:23.840000 --> 0:19:24.660000
 particular table.

0:19:24.660000 --> 0:19:28.060000
 And in this case, we're able to enumerate
 the username password and signature

0:19:28.060000 --> 0:19:31.580000
 and the passwords are not encrypted.

0:19:31.580000 --> 0:19:34.380000
 So we can now use these
 credentials to log in.

0:19:34.380000 --> 0:19:39.500000
 And this is an example of, you know,
 error based SQL injection.

0:19:39.500000 --> 0:19:45.520000
 And the key thing that I wanted to highlight
 there was how the query itself

0:19:45.520000 --> 0:19:49.800000
 and the way it treats the parameters
 will affect the payload that you

0:19:49.800000 --> 0:19:53.220000
 use. Now we'll try others, of course,
 but one thing that I want to highlight

0:19:53.220000 --> 0:20:00.920000
 here before we actually proceed is going
 to be obviously the URL parameters,

0:20:00.920000 --> 0:20:03.060000
 because we haven't, I really
 didn't show you that.

0:20:03.060000 --> 0:20:08.240000
 But if we just perform a quick test here,
 I'm just going to go back home.

0:20:08.240000 --> 0:20:12.700000
 And we go into user info by default,
 nothing is being specified in the

0:20:12.700000 --> 0:20:18.960000
 URL. However, we say test and test,
 we'll we hit view account details.

0:20:18.960000 --> 0:20:22.100000
 Now we can see that that is
 being sent via the URL.

0:20:22.100000 --> 0:20:25.560000
 What that means is that we don't need
 to perform the injection via the

0:20:25.560000 --> 0:20:28.180000
 input form. It's just a small difference.


0:20:28.180000 --> 0:20:33.440000
 But we can say right over here in the
 username, the value of the username

0:20:33.440000 --> 0:20:35.880000
 parameter, we can perform
 our injection in there.

0:20:35.880000 --> 0:20:41.980000
 So we say single quote, to perform some
 error based injection and we get

0:20:41.980000 --> 0:20:43.520000
 that error there.

0:20:43.520000 --> 0:20:51.140000
 So username, we can then append to this
 and say, or one equals one, hit

0:20:51.140000 --> 0:20:54.520000
 enter and the injection is done in
 this case done look like it's done

0:20:54.520000 --> 0:20:58.480000
 successfully. Error one equals one.

0:20:58.480000 --> 0:21:01.460000
 So that's username or one equals one.

0:21:01.460000 --> 0:21:03.920000
 This is where we now have URL and coding.


0:21:03.920000 --> 0:21:05.920000
 So we hit enter.

0:21:05.920000 --> 0:21:09.660000
 And in this case, looks like we're
 getting a bit of an error.

0:21:09.660000 --> 0:21:12.480000
 So that is set up successfully.

0:21:12.480000 --> 0:21:15.260000
 Let us try and use the pound symbol.

0:21:15.260000 --> 0:21:20.660000
 And excellent. So this brings
 me to my working via the URL.

0:21:20.660000 --> 0:21:26.320000
 So in this case, what I'll do
 is I will copy this URL here.

0:21:26.320000 --> 0:21:28.440000
 And we are going to open up burp suite.

0:21:28.440000 --> 0:21:29.660000
 So you don't need to do this.

0:21:29.660000 --> 0:21:31.220000
 But I'm just showing you as an example.

0:21:31.220000 --> 0:21:35.380000
 And we'll use both burp and zap throughout
 this course, just to show you

0:21:35.380000 --> 0:21:37.040000
 that I'm not biased either way.

0:21:37.040000 --> 0:21:40.540000
 But there is some functionality that
 will be exploring in the next video

0:21:40.540000 --> 0:21:45.220000
 that is available only
 in OASP zap in burp.

0:21:45.220000 --> 0:21:48.620000
 It is available in burp, but in the trial
 version, and you need a license.

0:21:48.620000 --> 0:21:53.400000
 And so I'll go into the proxy and
 I'll open up the burp browser.

0:21:53.400000 --> 0:21:55.200000
 So I can do everything from within here.

0:21:55.200000 --> 0:21:57.240000
 And I'll just open that in there.

0:21:57.240000 --> 0:22:01.440000
 And I'll just turn off intercept and
 we'll go back in here into the into

0:22:01.440000 --> 0:22:05.440000
 OASP motility. I'm just going through
 this with my proxy and we're going

0:22:05.440000 --> 0:22:08.120000
 to injection and user info.

0:22:08.120000 --> 0:22:13.680000
 All right, so now we'll just put
 in some test parameters here.

0:22:13.680000 --> 0:22:18.340000
 So again, user lookup test and test,
 I'll go into burp suite and turn

0:22:18.340000 --> 0:22:22.920000
 on intercept so we can intercept the
 what appears to be a GET request,

0:22:22.920000 --> 0:22:25.500000
 but it could be a post let's hit submit.

0:22:25.500000 --> 0:22:27.200000
 So it is a GET request.

0:22:27.200000 --> 0:22:30.440000
 So it's being sent via the
 URL or as URL parameters.

0:22:30.440000 --> 0:22:34.840000
 Now, what I was trying to point out
 is that when you're doing URL based

0:22:34.840000 --> 0:22:39.240000
 injection specifically, and this you
 may run into this where the input

0:22:39.240000 --> 0:22:44.200000
 is not available via the actual web application
 or in the form of an application

0:22:44.200000 --> 0:22:47.960000
 input form like using an impass
 word and stuff like that.

0:22:47.960000 --> 0:22:53.420000
 If I say, you know, or one equals one,
 and let's see if this works, I

0:22:53.420000 --> 0:22:56.040000
 just want to show you something
 really cool here.

0:22:56.040000 --> 0:22:57.940000
 So that's not working.

0:22:57.940000 --> 0:22:59.600000
 I forwarded the request is not working.

0:22:59.600000 --> 0:23:02.360000
 So let's try and see what this issue is.

0:23:02.360000 --> 0:23:07.560000
 So again, I'll just resubmit
 some test values here.

0:23:07.560000 --> 0:23:12.780000
 And now I'll get rid of that and I'll
 say, or one equals one same thing.

0:23:12.780000 --> 0:23:15.280000
 The only thing I need to
 do now is URL encoded.

0:23:15.280000 --> 0:23:19.060000
 So I'll highlight my payload, including
 the single quote, and I'll use

0:23:19.060000 --> 0:23:24.360000
 control U on my keyboard to encode this
 is called URL encoding, because

0:23:24.360000 --> 0:23:28.780000
 URLs cannot process certain characters,
 special characters.

0:23:28.780000 --> 0:23:33.200000
 So if we forward this now, there we are.

0:23:33.200000 --> 0:23:34.880000
 So it looks like we have an error.

0:23:34.880000 --> 0:23:37.060000
 I encoded it a little bit too much.

0:23:37.060000 --> 0:23:40.880000
 So let's try this again.

0:23:40.880000 --> 0:23:43.620000
 Say test and test.

0:23:43.620000 --> 0:23:45.520000
 And this is what I wanted to show you.

0:23:45.520000 --> 0:23:50.420000
 Sorry, not on on Firefox, rather, but
 in the burp suite browser here,

0:23:50.420000 --> 0:23:51.980000
 which is chromium.

0:23:51.980000 --> 0:23:53.860000
 So I'll say view account details.

0:23:53.860000 --> 0:23:58.520000
 What happens if we append to the actual
 username and I say, you know,

0:23:58.520000 --> 0:24:00.260000
 or one equals one.

0:24:00.260000 --> 0:24:04.080000
 And I submit this all for this here.

0:24:04.080000 --> 0:24:08.180000
 Nothing yet. Alright, so let's perform
 these tests a little bit more.

0:24:08.180000 --> 0:24:13.640000
 So we'll resubmit that again, get rid
 of tests or tests rather and say,

0:24:13.640000 --> 0:24:20.620000
 or in this particular case, yeah,
 we'll just say, or one equals one.

0:24:20.620000 --> 0:24:22.920000
 And there's a good reason I'm doing this.


0:24:22.920000 --> 0:24:24.520000
 So you'll actually see this shortly.

0:24:24.520000 --> 0:24:30.080000
 So now I'll just again, highlight that
 and say one time URL encode for

0:24:30.080000 --> 0:24:33.360000
 that there. There we are.

0:24:33.360000 --> 0:24:38.180000
 So this is something that's very important
 because as I said, coming back

0:24:38.180000 --> 0:24:44.700000
 to the inception of the problem, what
 if this particular, this particular

0:24:44.700000 --> 0:24:50.220000
 page did not have any input form where
 you can inject stuff directly via

0:24:50.220000 --> 0:24:56.140000
 the form and have the have the web
 application set up the URL for you.

0:24:56.140000 --> 0:24:58.880000
 And the parameters were
 in the URL themselves.

0:24:58.880000 --> 0:25:03.860000
 So you know, sort of like when you
 have the index dot PHP page equals

0:25:03.860000 --> 0:25:07.780000
 or ID equals one, the injection
 needs to be done via the URL.

0:25:07.780000 --> 0:25:13.580000
 And your best friend here is always
 going to be a web proxy, like, like

0:25:13.580000 --> 0:25:16.200000
 burp suite or OASP zap.

0:25:16.200000 --> 0:25:21.120000
 Alright, so that's a URL based
 testing or injection.

0:25:21.120000 --> 0:25:23.260000
 Always keep that in mind.

0:25:23.260000 --> 0:25:25.800000
 Never ever ignore the URL.

0:25:25.800000 --> 0:25:30.420000
 Right, because parameters could be being
 passed via the URL and are not

0:25:30.420000 --> 0:25:34.780000
 you're not able to make the injection
 via an input form or a field like

0:25:34.780000 --> 0:25:39.840000
 so. Now, just to show you again, what
 this would look like and that the

0:25:39.840000 --> 0:25:42.400000
 web application does it
 for you automatically.

0:25:42.400000 --> 0:25:47.020000
 If I say sorry, single quote or one
 equals one, the same thing pretty

0:25:47.020000 --> 0:25:54.820000
 much. And I submit that if I go back
 to this here, let's see if I go back

0:25:54.820000 --> 0:25:59.380000
 here and I forward this, you can see
 that that is done automatically.

0:25:59.380000 --> 0:26:04.840000
 So it's URL encoded, as I said, you
 can do that very easily with burp

0:26:04.840000 --> 0:26:10.500000
 suite by just highlighting and using
 the control U keys on your keyboard,

0:26:10.500000 --> 0:26:16.760000
 or you can always copy whatever you
 want to encode like this here.

0:26:16.760000 --> 0:26:21.420000
 And you navigate into burp suite and
 you go into the decoder and paste

0:26:21.420000 --> 0:26:26.000000
 in that there. And then you can say
 encode perform URL encoding and that

0:26:26.000000 --> 0:26:30.220000
 will perform some extreme encoding
 for you, which may not always work.

0:26:30.220000 --> 0:26:34.080000
 Because remember, when I encoded it
 twice, the web application for some

0:26:34.080000 --> 0:26:36.200000
 reason did not handle it well.

0:26:36.200000 --> 0:26:39.500000
 So again, manual testing
 is always awesome.

0:26:39.500000 --> 0:26:41.900000
 And it's really, really
 cool for this reason.

0:26:41.900000 --> 0:26:45.760000
 And you know, this is not the only
 reason alone, but you get the idea.

0:26:45.760000 --> 0:26:47.280000
 So I'll forward that there.

0:26:47.280000 --> 0:26:49.660000
 And that injection was successful.

0:26:49.660000 --> 0:26:57.420000
 Now, what happens when the application
 does not have an input form that

0:26:57.420000 --> 0:26:59.980000
 allows you to directly
 perform the injection.

0:26:59.980000 --> 0:27:05.580000
 And you can't see any parameters within
 the actual URL where you can perform

0:27:05.580000 --> 0:27:07.500000
 the injection directly there.

0:27:07.500000 --> 0:27:11.820000
 Well, again, in this particular case,
 you need to rely on a web proxy

0:27:11.820000 --> 0:27:13.160000
 like burp suite.

0:27:13.160000 --> 0:27:17.600000
 So I'm going to ask 2017 and what we
 want to take a look at is under SQL

0:27:17.600000 --> 0:27:23.080000
 map practice, you want to take a look
 at the exercise, view someone's

0:27:23.080000 --> 0:27:27.260000
 blog. All right, so I'll just turn
 off intercept temporarily there.

0:27:27.260000 --> 0:27:31.560000
 Now the way this works, as you can see,
 is it allows you to view the blog

0:27:31.560000 --> 0:27:36.240000
 entries or the blogs for a particular
 user on this web application.

0:27:36.240000 --> 0:27:40.740000
 So for example, I can show all entries
 right over here, pay attention

0:27:40.740000 --> 0:27:44.220000
 to the URL. So no parameter
 is being specified.

0:27:44.220000 --> 0:27:48.700000
 So when I specified the user admin, typically
 with if this was being passed

0:27:48.700000 --> 0:27:53.140000
 in the URL, or, you know, we had a
 parameter, an injectable parameter,

0:27:53.140000 --> 0:27:58.000000
 you typically see, you know, view someone's
 blog.php question mark, something

0:27:58.000000 --> 0:28:03.640000
 like this, ID equals to Alexis or admin
 or something like that, or maybe

0:28:03.640000 --> 0:28:06.400000
 something like name or author.

0:28:06.400000 --> 0:28:12.720000
 So if I say author equals admin,
 let's see if that works.

0:28:12.720000 --> 0:28:14.560000
 All right, so that doesn't work.

0:28:14.560000 --> 0:28:18.340000
 All right, so you get the idea, you
 will obviously be dealing with these

0:28:18.340000 --> 0:28:21.740000
 types of application inputs.

0:28:21.740000 --> 0:28:25.500000
 Now why am I saying the application inputs,
 the application inputs, because

0:28:25.500000 --> 0:28:28.980000
 we're allowed to make the
 selection manually.

0:28:28.980000 --> 0:28:32.900000
 And obviously this data is being
 sent to the web application.

0:28:32.900000 --> 0:28:36.460000
 And obviously it's being, it's
 interacting with a database.

0:28:36.460000 --> 0:28:40.380000
 The reason it's interacting with the database
 is because obviously, firstly,

0:28:40.380000 --> 0:28:44.660000
 in the case of motilla day, if we just
 chose, you know, an author at random

0:28:44.660000 --> 0:28:48.960000
 here, you can see the way the data
 is being displayed is in a tabular

0:28:48.960000 --> 0:28:53.560000
 format. But we also, you can tell just
 given its nature that this info

0:28:53.560000 --> 0:28:58.660000
 is being stored in a database, because
 a comment is a is typically stored

0:28:58.660000 --> 0:29:03.140000
 in a different column, or even in a different
 table, usernames is probably

0:29:03.140000 --> 0:29:06.360000
 being referenced in the in the accounts
 table, you get the idea.

