WEBVTT

0:00:03.840000 --> 0:00:09.500000
 So we are going to be taking a look at
 how to use SQL map, you know, both

0:00:09.500000 --> 0:00:13.180000
 the basic options that we explored in
 the previous video and the advanced

0:00:13.180000 --> 0:00:14.780000
 stuff we've looked at here.

0:00:14.780000 --> 0:00:17.740000
 And we're going to be
 leveraging a live lab.

0:00:17.740000 --> 0:00:21.260000
 This video has a lab environment
 associated with it.

0:00:21.260000 --> 0:00:24.340000
 So just below this video,
 you'll see the lab.

0:00:24.340000 --> 0:00:27.640000
 One thing I want to point out is that
 this lab will not provide you, will

0:00:27.640000 --> 0:00:30.680000
 not provide you with a calilinic system.

0:00:30.680000 --> 0:00:35.320000
 It'll just provide you with a URL to
 the target web application, which

0:00:35.320000 --> 0:00:37.720000
 is a real-world web application.

0:00:37.720000 --> 0:00:41.440000
 And you will need to have your own calilinic
 system or any of, you know,

0:00:41.440000 --> 0:00:42.960000
 you can use your host operating system.

0:00:42.960000 --> 0:00:45.680000
 Actually for SQL map, you will need Kali.


0:00:45.680000 --> 0:00:51.560000
 So yeah, you will need a distro, a Linux
 distro that, you know, actually

0:00:51.560000 --> 0:00:54.700000
 has SQL map on it.

0:00:54.700000 --> 0:00:56.780000
 Kali being the most obvious option.

0:00:56.780000 --> 0:00:59.160000
 And you'll also need burp suite or zap.

0:00:59.160000 --> 0:01:02.160000
 If you're going to run through all
 of, you know, everything that we've

0:01:02.160000 --> 0:01:03.220000
 learned thus far.

0:01:03.220000 --> 0:01:05.760000
 Anyway, I don't want to
 take too much time here.

0:01:05.760000 --> 0:01:07.500000
 I'm going to fire up my lab.

0:01:07.500000 --> 0:01:12.340000
 And I'll see you on my calilinic
 system in a couple of seconds.

0:01:12.340000 --> 0:01:18.280000
 All right. So I am back
 in my calilinics VM.

0:01:18.280000 --> 0:01:19.760000
 I've started up the lab.

0:01:19.760000 --> 0:01:25.240000
 And as I mentioned, you'll be provided
 with the URL to the target web

0:01:25.240000 --> 0:01:27.560000
 application when you start the lab.

0:01:27.560000 --> 0:01:34.360000
 So I've already fired up burp suite
 and I've opened up the burp browser.

0:01:34.360000 --> 0:01:37.180000
 And I've opened up the
 web application here.

0:01:37.180000 --> 0:01:40.660000
 So this is the lab, the
 target web application.

0:01:40.660000 --> 0:01:45.240000
 And you can see it definitely is
 a real-world web application.

0:01:45.240000 --> 0:01:49.000000
 And one thing I would like to point
 out before we begin is I'm going to

0:01:49.000000 --> 0:01:52.820000
 be approaching this as
 I would a real penta.

0:01:52.820000 --> 0:01:58.600000
 So I'm not going to be going over the steps
 involving, you know, fingerprinting

0:01:58.600000 --> 0:02:06.060000
 the web app or performing recon, you
 know, performing fuzzing, etc.

0:02:06.060000 --> 0:02:10.640000
 I'm just going to reload the page here
 and I'm going to go into burp into

0:02:10.640000 --> 0:02:12.560000
 the HTTP history.

0:02:12.560000 --> 0:02:17.460000
 And let's start off with some basic recon,
 which is going to be important

0:02:17.460000 --> 0:02:20.580000
 in, yeah, and you'll actually see why.

0:02:20.580000 --> 0:02:27.340000
 One thing I'll also do here, which
 I always fail to do before I begin

0:02:27.340000 --> 0:02:31.660000
 recording a video and that is to
 increase the font size here.

0:02:31.660000 --> 0:02:35.180000
 So you can actually see the requests
 a little bit better as well as the

0:02:35.180000 --> 0:02:39.380000
 responses. I'll just increase
 the HTTP message display.

0:02:39.380000 --> 0:02:41.780000
 Hopefully that's a little bit better.

0:02:41.780000 --> 0:02:46.980000
 So anyway, I just made, you know,
 just loaded the web page.

0:02:46.980000 --> 0:02:49.720000
 You can see just get request here.

0:02:49.720000 --> 0:02:56.260000
 This is the request here and you can
 see quite a few headers, nothing

0:02:56.260000 --> 0:02:57.820000
 out of the ordinary though.

0:02:57.820000 --> 0:02:59.240000
 And this is the response.

0:02:59.240000 --> 0:03:02.740000
 Now, the response, we can see that
 there's quite a bit of info that's

0:03:02.740000 --> 0:03:10.780000
 exposed. We have a set cookie, which gives
 us a PHP session ID here, regardless

0:03:10.780000 --> 0:03:13.300000
 of authentication.

0:03:13.300000 --> 0:03:16.160000
 But that's a good sign anyway.

0:03:16.160000 --> 0:03:21.620000
 And we can see that the server header
 is also included, which is not a

0:03:21.620000 --> 0:03:25.500000
 good thing. But that tells us that, you
 know, the web service Apache 2418

0:03:25.500000 --> 0:03:29.600000
 and the OS banner is displayed
 listed out there as Ubuntu.

0:03:29.600000 --> 0:03:32.920000
 Now, taking a look at the response here.

0:03:32.920000 --> 0:03:35.980000
 More specifically, the source.

0:03:35.980000 --> 0:03:38.320000
 I don't want to see the actual
 rendered web page.

0:03:38.320000 --> 0:03:43.780000
 We can actually see that in the meta
 tags right over here of the home

0:03:43.780000 --> 0:03:48.260000
 page, it actually tells us what we're
 dealing with in terms of the web

0:03:48.260000 --> 0:03:53.860000
 application. This appears to be open
 source third party web application

0:03:53.860000 --> 0:03:57.420000
 called Indonesia and the
 version is given to us.

0:03:57.420000 --> 0:04:03.140000
 So 8.7 and it's the tagline
 is build your own portal.

0:04:03.140000 --> 0:04:08.560000
 So it looks like some sort of portal
 development or open source portal

0:04:08.560000 --> 0:04:11.820000
 system, which is very interesting.

0:04:11.820000 --> 0:04:15.520000
 We can see there's sort of a
 portal for an organization.

0:04:15.520000 --> 0:04:22.420000
 You have news, catalog forum information
 about gallery, Geruda, et cetera.

0:04:22.420000 --> 0:04:27.980000
 Okay. So we know it's the
 name is in Indonesia.

0:04:27.980000 --> 0:04:31.320000
 So I'm going to fire up or
 open up my terminal here.

0:04:31.320000 --> 0:04:33.200000
 And I'm just going to go into my desktop.


0:04:33.200000 --> 0:04:38.720000
 So I have a working location or working
 directory here that I'm aware

0:04:38.720000 --> 0:04:43.680000
 of. And I'm going to run a search sploit
 scan to see whether we have any

0:04:43.680000 --> 0:04:51.800000
 known, known exploits for
 Indonesia specifically.

0:04:51.800000 --> 0:04:56.100000
 So let's see search, ploit, and Indonesia,
 am I pronouncing that correctly

0:04:56.100000 --> 0:05:00.720000
 or spelling it? Let me go back in here.

0:05:00.720000 --> 0:05:03.320000
 So that is and Indonesia.

0:05:03.320000 --> 0:05:07.000000
 Let me go ahead and copy that there.

0:05:07.000000 --> 0:05:11.480000
 Sorry, let me paste that in there.

0:05:11.480000 --> 0:05:19.640000
 Let's see. There we are.

0:05:19.640000 --> 0:05:22.760000
 Very interesting results,
 but remember it's 8.7.

0:05:22.760000 --> 0:05:27.300000
 So there's quite a bit of SQL injection
 going on here, but that's no version

0:05:27.300000 --> 0:05:28.680000
 is listed there.

0:05:28.680000 --> 0:05:34.760000
 We have 8.2 cross-site scripting, multiple
 vulnerabilities for 8.4, 8

0:05:34.760000 --> 0:05:37.960000
.4, another SQL injection vulnerability.

0:05:37.960000 --> 0:05:44.820000
 And then 8.7, we have RID being
 the parameters, SQL injection.

0:05:44.820000 --> 0:05:49.660000
 And we then have 8.7 multiple vulnerabilities,
 which is the most, which

0:05:49.660000 --> 0:05:54.340000
 is the latest. And you can see, given
 the fact that these are TXD files,

0:05:54.340000 --> 0:05:56.220000
 these are just POCs.

0:05:56.220000 --> 0:05:59.080000
 So I'm going to go ahead
 and copy the latest one.

0:05:59.080000 --> 0:06:08.020000
 So use a share exploit DB, exploits,
 PHP, web apps, and that is 4659,

0:06:08.020000 --> 0:06:14.020000
 4659. TXT, I'll just copy to my desktop.

0:06:14.020000 --> 0:06:18.240000
 All right. So now I'm just going to
 get the contents of the POC here and

0:06:18.240000 --> 0:06:22.400000
 let's see what vulnerabilities are
 actually listed out in this POC.

0:06:22.400000 --> 0:06:27.460000
 Okay. So there we are, exploit title,
 Indonesia portal banners dot PHP

0:06:27.460000 --> 0:06:37.460000
 SQL injection. This was disclosed or
 discovered 2019 version 8.7 tested

0:06:37.460000 --> 0:06:42.800000
 on Windows. So we might, it shouldn't
 really affect anything.

0:06:42.800000 --> 0:06:45.400000
 And here we have the POC,
 so SQL injection.

0:06:45.400000 --> 0:06:51.080000
 So the parameters are PID, which I'm
 assuming is an abbreviation for the

0:06:51.080000 --> 0:06:55.880000
 banner ID. The page is banners dot PHP.

0:06:55.880000 --> 0:06:57.240000
 And they actually have
 given us a payload.

0:06:57.240000 --> 0:07:03.120000
 Now this payload appears to be,
 let's see, it's URL encoded.

0:07:03.120000 --> 0:07:09.460000
 Let me see this, it's called
 an attack button here.

0:07:09.460000 --> 0:07:11.960000
 So hold on, yeah, it's
 actually given here.

0:07:11.960000 --> 0:07:18.520000
 So the get method is we need to make
 a, yeah, it's a get request.

0:07:18.520000 --> 0:07:21.640000
 So get request banners dot PHP.

0:07:21.640000 --> 0:07:29.200000
 Op is equal to click and bid ban ID is
 equal to the actual ID or actually

0:07:29.200000 --> 0:07:34.080000
 this is where the injection is
 happening right over here.

0:07:34.080000 --> 0:07:39.780000
 And this appears to be
 a union based payload.

0:07:39.780000 --> 0:07:45.880000
 So what we're going to do is we're now
 going to assume we've identified

0:07:45.880000 --> 0:07:48.460000
 a vulnerability exists, right?

0:07:48.460000 --> 0:07:52.860000
 Not verified, we've identified a SQL
 injection vulnerability, but we need

0:07:52.860000 --> 0:07:56.600000
 to verify it. So this is typically
 where I would bring in a tool like

0:07:56.600000 --> 0:08:04.320000
 SQL map. However, I'm not going to,
 I'm not going to actually tell it

0:08:04.320000 --> 0:08:09.580000
 as we, you know, to begin with what
 type of technique we want to test

0:08:09.580000 --> 0:08:15.320000
 for. What I'm going to do is, by the
 way, where is this on the actual

0:08:15.320000 --> 0:08:18.920000
 website here? This looks like a banner.

0:08:18.920000 --> 0:08:22.940000
 Ah, so at the bottom here, you can
 see, let's click on it here.

0:08:22.940000 --> 0:08:28.280000
 Mod dot PHP, it just takes us to this
 actually see if we got it in our

0:08:28.280000 --> 0:08:35.780000
 requests here. So again, I wanted to
 do this as organically as possible.

0:08:35.780000 --> 0:08:40.740000
 There we are. So mod dot PHP,
 this is the one here.

0:08:40.740000 --> 0:08:46.760000
 This is the actual URL and the parameter
 OP click is equal to BID, which

0:08:46.760000 --> 0:08:47.620000
 is equal to three.

0:08:47.620000 --> 0:08:48.600000
 It's a get request.

0:08:48.600000 --> 0:08:49.980000
 So this is the one.

0:08:49.980000 --> 0:08:56.280000
 The response is not found, which is why
 it probably takes us to this page

0:08:56.280000 --> 0:09:01.460000
 here. Okay. So let's go
 back into burp here.

0:09:01.460000 --> 0:09:05.420000
 We can see we have a session ID, which
 means I'm, I don't think we need

0:09:05.420000 --> 0:09:08.400000
 a session. I will actually probably do.

0:09:08.400000 --> 0:09:09.960000
 And this is the prime.

0:09:09.960000 --> 0:09:15.680000
 This is sort of the prime opportunity
 to show you that instead of crafting

0:09:15.680000 --> 0:09:21.960000
 our own SQL map scan, where we specify
 the cookie for authentication,

0:09:21.960000 --> 0:09:26.200000
 even though there's no authentication,
 when the other HTTP headers, we

0:09:26.200000 --> 0:09:30.840000
 can actually just save this request
 here, which is a get request.

0:09:30.840000 --> 0:09:33.600000
 And I'm going to save
 it on my desktop here.

0:09:33.600000 --> 0:09:37.640000
 I'm just going to call it,
 we'll just call it portal.

0:09:37.640000 --> 0:09:44.180000
 Okay. And basically, for include request
 and responses, that is fine.

0:09:44.180000 --> 0:09:46.380000
 We're not going to give it an extension.

0:09:46.380000 --> 0:09:48.180000
 Just save it like so.

0:09:48.180000 --> 0:09:51.640000
 All right. So now we can
 get started with SQL map.

0:09:51.640000 --> 0:09:58.000000
 So I'll do the, the obvious thing and
 we'll not start off with any specific

0:09:58.000000 --> 0:10:01.240000
 options, just general scan and
 let's see where it leads us.

0:10:01.240000 --> 0:10:04.920000
 And this will show you why that
 it's never a good idea.

0:10:04.920000 --> 0:10:12.280000
 Okay. So first things first, as I said,
 I've saved that there and we can

0:10:12.280000 --> 0:10:16.260000
 now just open up a new tab
 here and I'll zoom in.

0:10:16.260000 --> 0:10:21.660000
 We have the portal there, the
 portal request that we saved.

0:10:21.660000 --> 0:10:25.980000
 So SQL map, just want to show
 you the what you get.

0:10:25.980000 --> 0:10:30.340000
 So you can open up the help menu or
 the documentation right over here.

0:10:30.340000 --> 0:10:36.940000
 And you can see that there's advanced
 help using the double H right over

0:10:36.940000 --> 0:10:41.600000
 here. But we have the URL option,
 which I went over the data.

0:10:41.600000 --> 0:10:46.140000
 This you can see options are categorized
 in or organized in categories

0:10:46.140000 --> 0:10:47.460000
 based on what they do.

0:10:47.460000 --> 0:10:52.560000
 So the request options, you can see
 these options can be used to specify

0:10:52.560000 --> 0:10:54.160000
 how to connect to the target URL.

0:10:54.160000 --> 0:10:58.560000
 So we have the data, which I explained
 the data string to be sent through

0:10:58.560000 --> 0:11:00.760000
 the post cookie.

0:11:00.760000 --> 0:11:06.120000
 You know, HTTP cookie had a value there,
 where they want to use a random

0:11:06.120000 --> 0:11:10.120000
 agent. These are really not that relevant
 to us because we're using a

0:11:10.120000 --> 0:11:14.720000
 saved request or an interceptor request,
 if you will, injection, we have

0:11:14.720000 --> 0:11:16.660000
 the parameter DBMS.

0:11:16.660000 --> 0:11:21.300000
 So force back and DBMS to,
 to provide it value.

0:11:21.300000 --> 0:11:26.580000
 So you can actually tell SQL map,
 hey, the back end DBMS is my SQL.

0:11:26.580000 --> 0:11:27.700000
 Don't you doubt it.

0:11:27.700000 --> 0:11:30.740000
 And then we have detection, so level
 and risk, which I explained in the

0:11:30.740000 --> 0:11:34.340000
 slide. So level one to five
 risk is just one to three.

0:11:34.340000 --> 0:11:38.660000
 The defaults are both one techniques
 I already explained.

0:11:38.660000 --> 0:11:43.200000
 So this is the technique option allows
 you to specify the SQL injection

0:11:43.200000 --> 0:11:47.540000
 technique you want to
 test for enumeration.

0:11:47.540000 --> 0:11:51.880000
 This is, I already explained this in
 the previous video, operating system,

0:11:51.880000 --> 0:11:54.880000
 etc. And then you have the wizard, where
 we're not going to use the wizard.

0:11:54.880000 --> 0:11:58.380000
 That's not, if you're performing a pen
 test, you shouldn't be using the

0:11:58.380000 --> 0:12:01.620000
 wizard. This that's what
 this video will show you.

0:12:01.620000 --> 0:12:07.500000
 Or I hope, you know, we'll sort of
 cover so you can avoid that anyway.

0:12:07.500000 --> 0:12:09.160000
 So we have the request.

0:12:09.160000 --> 0:12:11.020000
 So we'll say SQL map.

0:12:11.020000 --> 0:12:13.020000
 And then R for the request.

0:12:13.020000 --> 0:12:15.800000
 And then the request name is just portal.


0:12:15.800000 --> 0:12:23.260000
 And then what we do need to specify is
 the parameter that we want to test

0:12:23.260000 --> 0:12:26.800000
 for injection. And in this
 case, the parameter is BID.

0:12:26.800000 --> 0:12:30.220000
 And we can actually see that
 yes, it is in the URL.

0:12:30.220000 --> 0:12:35.860000
 So we actually don't need to specify
 a level, nor do we need to specify

0:12:35.860000 --> 0:12:39.400000
 risk, although it might be necessary
 anyway, let's test it out.

0:12:39.400000 --> 0:12:41.540000
 Let's see what we get, right?

0:12:41.540000 --> 0:12:46.220000
 So the payload, sorry,
 the parameter is BID.

0:12:46.220000 --> 0:12:50.920000
 That's what we want to, you know, this
 is the parameter we want to essentially

0:12:50.920000 --> 0:12:55.960000
 inject. So right over here, you
 can see there's a redirect.

0:12:55.960000 --> 0:12:59.680000
 So we'll go with the default, which
 is yes, we obviously want to follow.

0:12:59.680000 --> 0:13:02.820000
 And so SQL map is going to do its thing.

0:13:02.820000 --> 0:13:07.740000
 All right. So at the moment, a heuristic
 test shows that it's probably

0:13:07.740000 --> 0:13:14.060000
 not injectable. But now you can start
 to see why this that SQL map really

0:13:14.060000 --> 0:13:22.660000
 works well. When you tell it what type of
 technique you want to use, essentially

0:13:22.660000 --> 0:13:26.200000
 assuming that you've already identified
 that there is a vulnerability.

0:13:26.200000 --> 0:13:29.740000
 And more importantly, again, generally
 speaking, you don't need to be

0:13:29.740000 --> 0:13:33.860000
 100% sure. But what technique
 actually works?

0:13:33.860000 --> 0:13:39.160000
 So one thing it does tell us that right
 over here, the parameter BID appears

0:13:39.160000 --> 0:13:41.880000
 to be and Boolean based blind.

0:13:41.880000 --> 0:13:45.040000
 That's the first it's detected.

0:13:45.040000 --> 0:13:51.160000
 So Boolean based blind, the heuristic
 test shows that the back end DBMS

0:13:51.160000 --> 0:13:56.560000
 could be MySQL. Do you want to skip
 the test payloads for other?

0:13:56.560000 --> 0:13:58.580000
 Yes, we want to do that, please.

0:13:58.580000 --> 0:14:03.220000
 For the remaining test, you want to include
 all tests, extending provided

0:14:03.220000 --> 0:14:11.140000
 level. No. Okay, so now
 generic inline queries.

0:14:11.140000 --> 0:14:14.980000
 So let's see testing.

0:14:14.980000 --> 0:14:17.320000
 Okay, it's now going to perform the test.


0:14:17.320000 --> 0:14:18.660000
 So this is time based blind.

0:14:18.660000 --> 0:14:20.500000
 So there's going to be some sleep.

0:14:20.500000 --> 0:14:24.580000
 So in this case, it asked me, do you
 want to include all tests, extending

0:14:24.580000 --> 0:14:30.120000
 provided level. One values.

0:14:30.120000 --> 0:14:32.500000
 No. Okay, so there we are.

0:14:32.500000 --> 0:14:34.220000
 So we can see that.

0:14:34.220000 --> 0:14:37.960000
 Let me just see the results here.

0:14:37.960000 --> 0:14:42.960000
 Blind, get parameter BID
 appears to be MySQL, etc.

0:14:42.960000 --> 0:14:44.420000
 Time based blind.

0:14:44.420000 --> 0:14:45.660000
 Okay, there we are.

0:14:45.660000 --> 0:14:46.600000
 It's actually done.

0:14:46.600000 --> 0:14:50.800000
 So SQL map can be used to
 identify vulnerabilities.

0:14:50.800000 --> 0:14:55.840000
 Okay, as long as at least you have the.

0:14:55.840000 --> 0:14:59.120000
 The parameter that you want to
 test for injection, right?

0:14:59.120000 --> 0:15:02.900000
 So we can see right over here, SQL map
 identified the following injection

0:15:02.900000 --> 0:15:08.020000
 points. With a total of 42 HTTP requests.


0:15:08.020000 --> 0:15:14.280000
 So we can see that Boolean based blind,
 which is actually very nice.

0:15:14.280000 --> 0:15:18.880000
 And then we have time based blind, which
 will obviously take some time.

0:15:18.880000 --> 0:15:22.880000
 And it gives you the test payload that
 you can actually use to test the

0:15:22.880000 --> 0:15:24.100000
 injection for yourself.

0:15:24.100000 --> 0:15:30.740000
 So if we say Boolean based blind, I'll
 go in here and let's send this

0:15:30.740000 --> 0:15:32.300000
 to the repeater.

0:15:32.300000 --> 0:15:35.600000
 So actually, what did we just copy?

0:15:35.600000 --> 0:15:40.720000
 OP. So from OP right over here, we're
 going to paste that in there.

0:15:40.720000 --> 0:15:43.800000
 We'll probably want to URL encode this.

0:15:43.800000 --> 0:15:47.640000
 So control you. Let's send
 that if that gives us.

0:15:47.640000 --> 0:15:50.680000
 So yeah, that look like it worked.

0:15:50.680000 --> 0:15:55.140000
 Let's see. Let's see with anything.

0:15:55.140000 --> 0:15:56.380000
 Yeah, so it's blind.

0:15:56.380000 --> 0:16:01.980000
 All we know is we get a 200 response.

0:16:01.980000 --> 0:16:07.200000
 There we go. What else did we get here?

0:16:07.200000 --> 0:16:10.060000
 Time based blind.

0:16:10.060000 --> 0:16:15.160000
 So OP what I'm going to do is we will
 modify this to 10 seconds to see

0:16:15.160000 --> 0:16:18.620000
 if it actually stalls the server, which
 will actually show you how dangerous

0:16:18.620000 --> 0:16:21.340000
 this is. So I'll just go back.

0:16:21.340000 --> 0:16:24.980000
 I'll undo. Let's see the
 response time here.

0:16:24.980000 --> 0:16:26.760000
 OK, just with the normal.

0:16:26.760000 --> 0:16:29.960000
 I'll get rid of that there within
 just to the normal request.

0:16:29.960000 --> 0:16:32.680000
 So we'll say send not found.

0:16:32.680000 --> 0:16:38.460000
 That's fine. We can actually
 see right over here.

0:16:38.460000 --> 0:16:43.140000
 This is 246 milliseconds
 right at the bottom.

0:16:43.140000 --> 0:16:45.980000
 Send it again to 47 to 46.

0:16:45.980000 --> 0:16:51.420000
 OK, now let's put our time
 based payload in here.

0:16:51.420000 --> 0:16:56.360000
 So OP, we'll need to URL
 encode this definitely.

0:16:56.360000 --> 0:17:05.320000
 OK, let's send. Wait a minute.

0:17:05.320000 --> 0:17:12.480000
 Hold on a second.

0:17:12.480000 --> 0:17:20.340000
 Hmm. So that looks fine.

0:17:20.340000 --> 0:17:23.240000
 Let's take a look at this payload again.

0:17:23.240000 --> 0:17:27.240000
 Union actually union probably
 will not take much time.

0:17:27.240000 --> 0:17:29.560000
 The original POC listed out.

0:17:29.560000 --> 0:17:33.980000
 Yeah, what appears to be a union.

0:17:33.980000 --> 0:17:36.340000
 Union based SQL injection.

0:17:36.340000 --> 0:17:40.840000
 In this case, time based query sleep.

0:17:40.840000 --> 0:17:49.920000
 And select two 508 from
 select sleep five.

0:17:49.920000 --> 0:17:53.240000
 OK, yeah, so actually that's very weird.

0:17:53.240000 --> 0:17:59.940000
 Let me just go back a second
 undo all of this.

0:17:59.940000 --> 0:18:06.620000
 Let me say OP. Let me just make sure
 I'm formatting this correctly.

0:18:06.620000 --> 0:18:07.820000
 Paste that in there.

0:18:07.820000 --> 0:18:16.160000
 So OP. Let's do a double encode there.

0:18:16.160000 --> 0:18:18.720000
 Bring this back here.

0:18:18.720000 --> 0:18:20.540000
 OK, wait a minute.

0:18:20.540000 --> 0:18:23.540000
 That's 251 to 50.

0:18:23.540000 --> 0:18:29.820000
 Interesting. Sleep.

0:18:29.820000 --> 0:18:34.900000
 Let's undo this for a second.

0:18:34.900000 --> 0:18:35.720000
 That's interesting.

0:18:35.720000 --> 0:18:40.060000
 I wanted to actually see it is
 time based time based blind.

0:18:40.060000 --> 0:18:55.560000
 Interesting. So select.

0:18:55.560000 --> 0:19:00.100000
 I think I don't know what
 the mistake I made anyway.

0:19:00.100000 --> 0:19:04.700000
 So it looks like there's three types.

0:19:04.700000 --> 0:19:07.020000
 And the one in the POC was the union.

0:19:07.020000 --> 0:19:15.340000
 So what if now we wanted to specify
 a specific technique?

0:19:15.340000 --> 0:19:20.060000
 Like we wanted to test, you know, if
 we wanted to utilize a union based

0:19:20.060000 --> 0:19:25.100000
 SQL injection. Well, actually before
 we do that, I actually wanted to

0:19:25.100000 --> 0:19:28.280000
 point out that it does the DBMS.

0:19:28.280000 --> 0:19:31.580000
 It gives us the banner
 and fingerprinting.

0:19:31.580000 --> 0:19:36.820000
 So we can see that the web server operating
 system is Linux Ubuntu 1604

0:19:36.820000 --> 0:19:41.660000
 or 1610. Web server is 2418.

0:19:41.660000 --> 0:19:46.000000
 Back end is, yeah, this is probably
 what we don't have.

0:19:46.000000 --> 0:19:51.700000
 So what we can actually do to get the
 DBMS banner is I'll go ahead and

0:19:51.700000 --> 0:19:56.300000
 say, yeah, the request is portal.

0:19:56.300000 --> 0:20:02.180000
 The parameter BID we're then
 going to say technique.

0:20:02.180000 --> 0:20:06.000000
 We're going to use union.

0:20:06.000000 --> 0:20:08.080000
 Let's see, you know, well, we're here.

0:20:08.080000 --> 0:20:09.500000
 We might as well test it out.

0:20:09.500000 --> 0:20:11.920000
 And then I'm going to tell.

0:20:11.920000 --> 0:20:15.120000
 SQL map, hey, give us the banner.

0:20:15.120000 --> 0:20:19.560000
 And actually I'm going to, we probably
 need to speed this up.

0:20:19.560000 --> 0:20:24.040000
 So I'll just say threads
 is equal to three.

0:20:24.040000 --> 0:20:26.480000
 Let's see what we get here.

0:20:26.480000 --> 0:20:31.080000
 And I'll show you how to use the batch
 option to actually skip these prompts.

0:20:31.080000 --> 0:20:34.540000
 There we are. So this gives
 you additional info.

0:20:34.540000 --> 0:20:38.620000
 So you can see the back end DBMS that
 was given to us earlier, not related

0:20:38.620000 --> 0:20:40.100000
 to the banner option.

0:20:40.100000 --> 0:20:45.300000
 Says it's greater than equal to five
 or five point zero point twelve.

0:20:45.300000 --> 0:20:47.580000
 However, that's not specific enough.

0:20:47.580000 --> 0:20:51.380000
 In this case, the banner tells us
 is five point five point five six.

0:20:51.380000 --> 0:20:53.620000
 So we actually get the exact version.

0:20:53.620000 --> 0:20:55.140000
 And I just wanted to point that out.

0:20:55.140000 --> 0:20:58.840000
 So we actually saw that union worked.

0:20:58.840000 --> 0:21:02.700000
 So just, you know, union
 based SQL injection.

0:21:02.700000 --> 0:21:07.120000
 Okay, so this is now I'm now going to
 follow what I would typically do.

0:21:07.120000 --> 0:21:11.580000
 So we know that A, there is a SQL injection
 vulnerability that affects

0:21:11.580000 --> 0:21:13.980000
 the BID or banner ID parameter.

0:21:13.980000 --> 0:21:17.040000
 We know that we have three
 techniques we can use.

0:21:17.040000 --> 0:21:20.740000
 I'm going to stick to union, union based.


0:21:20.740000 --> 0:21:23.520000
 And now we can get rid
 of the banner option.

0:21:23.520000 --> 0:21:26.020000
 And let's do some DBS.

0:21:26.020000 --> 0:21:31.800000
 Let's try and get enumerate the
 databases stored in the DBMS.

0:21:31.800000 --> 0:21:34.140000
 And I'm going to go with the default.

0:21:34.140000 --> 0:21:36.120000
 Yes, obviously we want
 to follow the redirect.

0:21:36.120000 --> 0:21:40.240000
 There we are fetching database
 names, starting three threads.

0:21:40.240000 --> 0:21:45.300000
 There we are. So we get three databases
 stored within the back end of

0:21:45.300000 --> 0:21:50.080000
 the DBMS or RDBMS, which
 in this case is MySQL.

0:21:50.080000 --> 0:21:55.040000
 We have information schema, which is native
 to actually contains the database

0:21:55.040000 --> 0:22:02.300000
 schema portal database, which is, I'm
 guessing the one used by endonesia.

0:22:02.300000 --> 0:22:05.000000
 I believe is what is
 called and then test.

0:22:05.000000 --> 0:22:08.120000
 Okay, so we are now have database.

0:22:08.120000 --> 0:22:09.280000
 What do we do now?

0:22:09.280000 --> 0:22:13.780000
 Well, we can actually try and see
 what's in some of these databases.

0:22:13.780000 --> 0:22:18.940000
 And in order to do this, we are going
 to say, I'm going to zoom in a little

0:22:18.940000 --> 0:22:24.340000
 bit here. No more DBS because
 we know what's in there.

0:22:24.340000 --> 0:22:26.600000
 Actually, I've forgotten what's in there.


0:22:26.600000 --> 0:22:29.000000
 We have it's called portal database.

0:22:29.000000 --> 0:22:30.760000
 We're going to start off with that one.

0:22:30.760000 --> 0:22:38.220000
 So we're going to say, hey, SQL map,
 I want you to tell me what's in the

0:22:38.220000 --> 0:22:41.420000
 database called portal database.

0:22:41.420000 --> 0:22:43.940000
 And you know what?

0:22:43.940000 --> 0:22:49.200000
 Let's start the tables because
 I want to see them.

0:22:49.200000 --> 0:22:53.480000
 We're not selecting a specific table
 because we don't know any tables

0:22:53.480000 --> 0:22:56.680000
 within the portal database database yet.

0:22:56.680000 --> 0:23:00.560000
 So there we are fetching the tables
 and we can see our, we've retrieved

0:23:00.560000 --> 0:23:03.600000
 some mighty interesting tables in here.

0:23:03.600000 --> 0:23:08.160000
 So we have authors, banner, the typical
 CMS tables you'd expect to see,

0:23:08.160000 --> 0:23:12.280000
 you know, that store different types of
 info, different types of relational

0:23:12.280000 --> 0:23:16.400000
 info or data. Do we have a users?

0:23:16.400000 --> 0:23:17.420000
 Looks like we do.

0:23:17.420000 --> 0:23:21.720000
 There we are. So there we are database,
 portal database, 33 tables.

0:23:21.720000 --> 0:23:27.380000
 We have authors, banner and this one here,
 the infamous users, which hopefully

0:23:27.380000 --> 0:23:29.900000
 has some juicy passwords for us.

0:23:29.900000 --> 0:23:36.060000
 Anyway, so we now know
 what tables we have.

0:23:36.060000 --> 0:23:39.520000
 And by the way, pay attention to where
 all your logs are being stored

0:23:39.520000 --> 0:23:43.820000
 because you can always refer back to,
 again, the results of your scan.

0:23:43.820000 --> 0:23:45.440000
 This is not the data.

0:23:45.440000 --> 0:23:47.540000
 Just the results is log data.

0:23:47.540000 --> 0:23:51.900000
 So, you know, if you have a clear terminal,
 you can actually refer back

0:23:51.900000 --> 0:23:55.340000
 to the results. So we have users and
 we also have portal con, but let's

0:23:55.340000 --> 0:23:57.000000
 play around with users.

0:23:57.000000 --> 0:24:03.620000
 So we now want to tell SQL map that
 instead of listing out tables, we

0:24:03.620000 --> 0:24:06.100000
 want to use a specific table.

0:24:06.100000 --> 0:24:10.880000
 We want to query a specific table and that's
 when you use the hyphen uppercase

0:24:10.880000 --> 0:24:14.320000
 T. And in this case, we say users.

0:24:14.320000 --> 0:24:19.000000
 Now, if I just hit enter, you'll
 see something interesting happen.

0:24:19.000000 --> 0:24:24.900000
 So I'll just hit enter here and
 let's go ahead and say yes.

0:24:24.900000 --> 0:24:32.180000
 All right. So it gives us the results we
 got previously, but nothing regarding

0:24:32.180000 --> 0:24:37.240000
 what is inside the users table.

0:24:37.240000 --> 0:24:40.280000
 Well, why is this?

0:24:40.280000 --> 0:24:47.820000
 Well, the reason this is the case is
 because we did not tell SQL map or,

0:24:47.820000 --> 0:24:50.740000
 you know, we want to actually
 dump the info in there.

0:24:50.740000 --> 0:24:55.180000
 So we'll say dump and follow
 the redirect pesky redirect.

0:24:55.180000 --> 0:24:55.780000
 I'll show you out.

0:24:55.780000 --> 0:24:58.060000
 Get rid of that in a second.

0:24:58.060000 --> 0:24:59.220000
 But there we are.

0:24:59.220000 --> 0:25:07.680000
 We can see this here and now
 we're getting the data.

0:25:07.680000 --> 0:25:10.900000
 So these, there we go.

0:25:10.900000 --> 0:25:15.920000
 Okay. It's not formatted correctly because
 I'd zoomed in, but I'll just

0:25:15.920000 --> 0:25:18.800000
 zoom out to show you what
 we have in there.

0:25:18.800000 --> 0:25:21.800000
 So just on the same scan again.

0:25:21.800000 --> 0:25:26.280000
 There we are. So we have
 a the table users.

0:25:26.280000 --> 0:25:27.880000
 When we dump, we're dumping everything.

0:25:27.880000 --> 0:25:29.760000
 We have a use ID.

0:25:29.760000 --> 0:25:33.960000
 What appears to be we have the
 password, which is hashed here.

0:25:33.960000 --> 0:25:37.420000
 Yeah, that looks weak.

0:25:37.420000 --> 0:25:42.300000
 This is this MD five.

0:25:42.300000 --> 0:25:48.920000
 Let's see. I should identify a.

0:25:48.920000 --> 0:25:53.020000
 Wait a minute. Yeah.

0:25:53.020000 --> 0:25:54.940000
 I should identify.

0:25:54.940000 --> 0:25:56.920000
 I can't remember actually.

0:25:56.920000 --> 0:26:01.960000
 No, wait a minute.

0:26:01.960000 --> 0:26:04.500000
 Yeah, it's specified here.

0:26:04.500000 --> 0:26:05.700000
 That's interesting.

0:26:05.700000 --> 0:26:08.040000
 This might be MD five.

0:26:08.040000 --> 0:26:09.580000
 I can't believe I've forgotten this.

0:26:09.580000 --> 0:26:11.620000
 Anyway, we can actually crack it.

0:26:11.620000 --> 0:26:15.800000
 I'll just will create a
 pile called hash.txt.

0:26:15.800000 --> 0:26:21.320000
 I'll paste it in there and I'll just
 say John, John should detect this.

0:26:21.320000 --> 0:26:33.660000
 Let's see. I think I've already
 cracked this before.

0:26:33.660000 --> 0:26:43.180000
 So let me just move it to DB
 move hash to DB hash.txt.

0:26:43.180000 --> 0:26:48.620000
 Say John DB hash.txt.

0:26:48.620000 --> 0:26:51.520000
 It's already cracked.

0:26:51.520000 --> 0:26:55.000000
 That's weird. It's just password.

0:26:55.000000 --> 0:27:00.260000
 The default, fairly easy to
 crack is just password.

0:27:00.260000 --> 0:27:02.760000
 But no user info is listed here.

0:27:02.760000 --> 0:27:05.020000
 Just the user ID.

0:27:05.020000 --> 0:27:07.380000
 We can see last login.

0:27:07.380000 --> 0:27:09.520000
 I can't see any user information.

0:27:09.520000 --> 0:27:14.780000
 It's all blank URL, etc.

0:27:14.780000 --> 0:27:28.380000
 But anyway, that's how to dump the
 contents of a specific table.

0:27:28.380000 --> 0:27:31.620000
 You can pretty much try and
 see what's in the others.

0:27:31.620000 --> 0:27:35.220000
 So if I just clear this out,
 let me zoom back in.

0:27:35.220000 --> 0:27:38.680000
 I know this video is stretched for
 quite a while, but let's go back in

0:27:38.680000 --> 0:27:41.240000
 here. No hash identifier.

0:27:41.240000 --> 0:27:44.180000
 Let's just go in here.

0:27:44.180000 --> 0:27:49.020000
 DBS. Let's see what the
 other database was.

0:27:49.020000 --> 0:27:51.880000
 By the way, if you want to skip the
 prompts and follow the defaults, you

0:27:51.880000 --> 0:27:54.200000
 can just say batch.

0:27:54.200000 --> 0:27:58.400000
 There we go. It'll now just
 use the default responses.

0:27:58.400000 --> 0:28:00.240000
 There we are. And we have tests.

0:28:00.240000 --> 0:28:02.320000
 So let's see what we have in test here.

0:28:02.320000 --> 0:28:09.140000
 So let's say D test and then tables.

0:28:09.140000 --> 0:28:13.220000
 And actually, let's include batch.

0:28:13.220000 --> 0:28:23.000000
 I'm getting tired of hitting the Y key.

0:28:23.000000 --> 0:28:27.280000
 Hm. No, it probably looks,
 probably is empty.

0:28:27.280000 --> 0:28:28.940000
 Okay. But we know what's in there.

0:28:28.940000 --> 0:28:32.760000
 Now, there were some other things that
 I had mentioned in the previous

0:28:32.760000 --> 0:28:35.780000
 video, as well as the
 slides in this video.

0:28:35.780000 --> 0:28:41.580000
 And that was, for example, checking
 if the current DB user being used

0:28:41.580000 --> 0:28:48.080000
 by the portal. It's actually
 a database admin.

0:28:48.080000 --> 0:28:49.260000
 So how would we do that?

0:28:49.260000 --> 0:28:54.460000
 Well, all we need to do is
 just ask the question.

0:28:54.460000 --> 0:28:58.540000
 Is DBA. That's pretty much it.

0:28:58.540000 --> 0:29:02.960000
 And didn't specify the batch this time,
 but we can see it's going to see

0:29:02.960000 --> 0:29:07.720000
 if the current user is DBA
 fetching the current user.

0:29:07.720000 --> 0:29:13.640000
 In this case, it's seeing right over
 here fetching current user is DBA

0:29:13.640000 --> 0:29:17.740000
 false. Okay. So it's not the
 current user is not a DBA.

0:29:17.740000 --> 0:29:22.300000
 All right. Now, there's a couple of
 other database enumeration options

0:29:22.300000 --> 0:29:27.380000
 you can use that I didn't really want
 to point out at this point in time.

0:29:27.380000 --> 0:29:31.380000
 Or I didn't mention in the slides,
 but I want to point out right now.

0:29:31.380000 --> 0:29:36.640000
 Not that important, but for example,
 if I wanted to retrieve the current,

0:29:36.640000 --> 0:29:43.080000
 the name of the current DBA, sorry,
 the current DBMS user, because, you

0:29:43.080000 --> 0:29:48.020000
 know, we sort of checked if they are
 admin or if it is admin and it isn't.

0:29:48.020000 --> 0:29:52.820000
 But I think it would be very interesting
 to see what the current user's

0:29:52.820000 --> 0:29:57.780000
 name is. Hold on a second.

0:29:57.780000 --> 0:30:01.720000
 That's weird. Current user,
 that should work.

0:30:01.720000 --> 0:30:10.440000
 Hah. Threads technique.

0:30:10.440000 --> 0:30:13.040000
 Yeah, that actually should work.

0:30:13.040000 --> 0:30:17.560000
 So if I say current DB.

0:30:17.560000 --> 0:30:23.840000
 No, that's weird.

0:30:23.840000 --> 0:30:28.380000
 Hmm. Oh, sorry. I think I'm actually
 using it incorrectly.

0:30:28.380000 --> 0:30:33.920000
 It should actually be mentioned here.

0:30:33.920000 --> 0:30:36.740000
 Yeah, current DB.

0:30:36.740000 --> 0:30:41.960000
 Current user, current DB.

0:30:41.960000 --> 0:30:51.260000
 I think I remember why I think
 I know why this is not working.

0:30:51.260000 --> 0:30:53.340000
 That's very weird.

0:30:53.340000 --> 0:30:58.220000
 Current DB, that was the correct format.

0:30:58.220000 --> 0:31:05.300000
 Current DB, retrieve DBMS.

0:31:05.300000 --> 0:31:31.380000
 Okay, unless let's see, I think I had
 forgotten that used to work prior

0:31:31.380000 --> 0:31:37.260000
 to that. Let's see table names.

0:31:37.260000 --> 0:31:42.480000
 Fetching current database,
 current fetching tables.

0:31:42.480000 --> 0:31:44.280000
 Yeah, does it get the actual user?

0:31:44.280000 --> 0:31:45.640000
 That's very strange.

0:31:45.640000 --> 0:31:53.180000
 You want to use common
 table existence tables.

0:31:53.180000 --> 0:31:57.660000
 Actually, that's the incorrect thing.

0:31:57.660000 --> 0:32:06.680000
 Let's see. Yeah, portal database.

0:32:06.680000 --> 0:32:18.140000
 I don't know why I was using that there.

0:32:18.140000 --> 0:32:19.860000
 Yeah, there we go.

0:32:19.860000 --> 0:32:23.860000
 So that runs correctly.

0:32:23.860000 --> 0:32:38.400000
 Hmm, I wonder if I just say
 right over here, users.

0:32:38.400000 --> 0:32:42.240000
 Whether that actually enumerates it.

0:32:42.240000 --> 0:32:44.840000
 Yeah, fetching database users.

0:32:44.840000 --> 0:32:50.180000
 Yeah, just portal database.

0:32:50.180000 --> 0:32:52.380000
 Well, I think that was
 probably confusing me.

0:32:52.380000 --> 0:32:56.380000
 So that's very interesting.

0:32:56.380000 --> 0:33:00.140000
 So is DBA, we already went through.

0:33:00.140000 --> 0:33:06.360000
 Yeah, and I think as I pointed down,
 there's also a couple of, sorry,

0:33:06.360000 --> 0:33:08.800000
 that is, HH, a couple of other options.

0:33:08.800000 --> 0:33:10.760000
 Yeah, and the database enumeration.

0:33:10.760000 --> 0:33:12.600000
 That's very strange.

0:33:12.600000 --> 0:33:19.820000
 All current user, current database,
 host name, user password hashes.

0:33:19.820000 --> 0:33:27.780000
 We can obviously retrieve everything
 or dump all, which will actually

0:33:27.780000 --> 0:33:30.380000
 take quite a bit of time.

0:33:30.380000 --> 0:33:33.660000
 And of course, there's the schema,
 which I actually wanted to show you

0:33:33.660000 --> 0:33:38.940000
 because that's quite important.

0:33:38.940000 --> 0:33:41.780000
 I'm just going to say yes, then.

0:33:41.780000 --> 0:33:47.740000
 The schema is quite important.

0:33:47.740000 --> 0:33:53.660000
 That gives you, you know, just again,
 the scheme of the DB here, where

0:33:53.660000 --> 0:34:02.720000
 you can then, this is typically used
 for, you know, DB identification

0:34:02.720000 --> 0:34:04.000000
 mostly manually.

0:34:04.000000 --> 0:34:12.660000
 But over here, we have, we can actually
 try for, execute OS command here.

0:34:12.660000 --> 0:34:16.300000
 OS shell will, I don't think will work
 because we don't know much about

0:34:16.300000 --> 0:34:21.400000
 where the web application is being.

0:34:21.400000 --> 0:34:25.380000
 We know it's Apache, but we don't know
 whether it's being stored in a

0:34:25.380000 --> 0:34:31.020000
 particular folder, or where the web application
 is stored in var www.html.

0:34:31.020000 --> 0:34:33.620000
 Anyway, I think I can show you this.

0:34:33.620000 --> 0:34:37.160000
 So just cancel the schema scan here.

0:34:37.160000 --> 0:34:45.700000
 If I say OS shell before
 we do anything else.

0:34:45.700000 --> 0:34:49.460000
 I don't think it'll work.

0:34:49.460000 --> 0:34:58.100000
 There we are. Okay, so
 we're dealing with PHP.

0:34:58.100000 --> 0:35:00.060000
 So we'll go with option four.

0:35:00.060000 --> 0:35:03.380000
 Do you want to provoke full path?

0:35:03.380000 --> 0:35:08.000000
 Yes, we do. Yeah, it will.

0:35:08.000000 --> 0:35:10.760000
 It should prompt us for the directory.

0:35:10.760000 --> 0:35:16.640000
 So, unable to automatically retrieve
 the web server document route.

0:35:16.640000 --> 0:35:19.500000
 So common locations.

0:35:19.500000 --> 0:35:22.700000
 Brute for search.

0:35:22.700000 --> 0:35:26.840000
 We can just go for common, even though
 I don't think that's going to work.

0:35:26.840000 --> 0:35:31.420000
 So we'll just try and see what var www
 is going to try and upload a Stasia

0:35:31.420000 --> 0:35:33.460000
 into the common directories.

0:35:33.460000 --> 0:35:36.040000
 You'd expect the web application
 to be stored.

0:35:36.040000 --> 0:35:37.500000
 In this case, we know it's Apache.

0:35:37.500000 --> 0:35:41.640000
 So var www.html, var www.html.

0:35:41.640000 --> 0:35:43.920000
 Hddocs is there as well.

0:35:43.920000 --> 0:35:46.120000
 Hddocs, that should work.

0:35:46.120000 --> 0:35:49.740000
 If not, we'll have to just see.

0:35:49.740000 --> 0:35:54.100000
 I doubt any of them will work actually.

0:35:54.100000 --> 0:35:56.900000
 Maybe they will or we will see.

0:35:56.900000 --> 0:36:00.900000
 But I'm guessing the web application
 is stored under a different path

0:36:00.900000 --> 0:36:07.240000
 or folder. A then any of these route
 in any of these directories.

0:36:07.240000 --> 0:36:11.040000
 What's in the POC actually?

0:36:11.040000 --> 0:36:14.340000
 It's just and Indonesia.

0:36:14.340000 --> 0:36:19.820000
 So maybe var www.html and Indonesia.

0:36:19.820000 --> 0:36:24.920000
 Maybe. Of course, that's not a good
 idea, but we can see it's not going

0:36:24.920000 --> 0:36:29.840000
 to be Nginx. So we can just
 say we don't batch them.

0:36:29.840000 --> 0:36:33.580000
 There we go. Yes.

0:36:33.580000 --> 0:36:45.880000
 Or BHP. Actually, we might be
 able to enumerate something.

0:36:45.880000 --> 0:36:51.280000
 I just say test, for example.

0:36:51.280000 --> 0:36:55.060000
 Yeah, it's going through
 a proxy, most likely.

0:36:55.060000 --> 0:36:56.440000
 That's why. Yeah.

0:36:56.440000 --> 0:37:01.740000
 Okay. So we can just go full path,
 disclosure, and then say, I think,

0:37:01.740000 --> 0:37:05.040000
 specify a comma separated list here.

0:37:05.040000 --> 0:37:08.240000
 Custom location.

0:37:08.240000 --> 0:37:11.800000
 So we can just say var www.

0:37:11.800000 --> 0:37:13.560000
 Put that in there.

0:37:13.560000 --> 0:37:17.360000
 We can then save our www.html.

0:37:17.360000 --> 0:37:18.460000
 Paste that there.

0:37:18.460000 --> 0:37:22.000000
 And then we can maybe try
 something a bit different.

0:37:22.000000 --> 0:37:25.880000
 So var www.getgridofthe87.

0:37:25.880000 --> 0:37:30.440000
 And then another one var www.html.

0:37:30.440000 --> 0:37:32.900000
 Get rid of the 87 there.

0:37:32.900000 --> 0:37:37.760000
 Hit enter. Okay.

0:37:37.760000 --> 0:37:40.340000
 It looks like now these are working.

0:37:40.340000 --> 0:37:50.860000
 There's not been written.

0:37:50.860000 --> 0:37:55.020000
 Or it's in a Docker container,
 which actually.

0:37:55.020000 --> 0:38:04.880000
 Yeah. Probably not.

0:38:04.880000 --> 0:38:07.260000
 Anyway, we have that.

0:38:07.260000 --> 0:38:11.040000
 I don't think this is going
 to work, but we also had.

0:38:11.040000 --> 0:38:16.700000
 The other option here,
 which was OS command.

0:38:16.700000 --> 0:38:21.740000
 So, you know, just a system command here.


0:38:21.740000 --> 0:38:26.500000
 In this case, I just want
 to make sure the.

0:38:26.500000 --> 0:38:28.040000
 Yeah. That's correct.

0:38:28.040000 --> 0:38:29.900000
 So that's going to be cool to go.

0:38:29.900000 --> 0:38:36.760000
 Am I. Let's go ahead and
 see whether this works.

0:38:36.760000 --> 0:38:46.140000
 PHP. Most likely it's going to
 ask us for the same thing.

0:38:46.140000 --> 0:38:49.600000
 We can actually try and
 brute force search.

0:38:49.600000 --> 0:38:57.560000
 That's very weird.

0:38:57.560000 --> 0:39:07.040000
 Enter for none. Oh, yeah,
 it's going to go through.

0:39:07.040000 --> 0:39:13.120000
 Let's see. See. Using generated
 directory list here.

0:39:13.120000 --> 0:39:15.500000
 There's quite a bit of stuff in here.

0:39:15.500000 --> 0:39:17.960000
 Okay. Yeah, that's going to take it.

0:39:17.960000 --> 0:39:21.680000
 Anyway, I think that's all that
 I wanted to highlight for now.

0:39:21.680000 --> 0:39:26.260000
 We'll be exploring the usage of SQL
 map in the next set of videos.

0:39:26.260000 --> 0:39:28.020000
 Again, against real world web apps.

0:39:28.020000 --> 0:39:31.240000
 This is taken quite a bit of time, but
 that brings us to the end of the

0:39:31.240000 --> 0:39:34.880000
 practical demonstration
 section of this video.

0:39:34.880000 --> 0:39:42.160000
 All right. So that was how to utilize
 SQL map pretty much an amalgamation

0:39:42.160000 --> 0:39:48.080000
 of both the essentials that we explored
 in the previous video, as well

0:39:48.080000 --> 0:39:50.820000
 as some of the advanced
 options and all of them.

0:39:50.820000 --> 0:39:54.200000
 But that's generally speaking.

0:39:54.200000 --> 0:39:58.900000
 How it works, as well as the methodology,
 which is sort of a key thing.

0:39:58.900000 --> 0:40:02.340000
 Or one of the key objectives that I sort
 of wanted to outline in the fact

0:40:02.340000 --> 0:40:10.020000
 that knowing the vulnerability, knowing,
 you know, identifying a vulnerability

0:40:10.020000 --> 0:40:14.020000
 first and then using SQL map as a way
 to learn more about a SQL injection

0:40:14.020000 --> 0:40:18.840000
 vulnerability before you even get into
 exploitation is probably the most

0:40:18.840000 --> 0:40:23.620000
 efficient. About going about things.

0:40:23.620000 --> 0:40:26.940000
 But yeah, without being said, that's
 going to be it for this video.

0:40:26.940000 --> 0:40:29.200000
 And I'll be seeing you in the next video.


