WEBVTT

0:00:03.480000 --> 0:00:05.980000
 Hello everyone and welcome.

0:00:05.980000 --> 0:00:11.420000
 In this video we're going to be taking
 a look at how to identify and exploit

0:00:11.420000 --> 0:00:16.140000
 a SQL injection vulnerability
 in HTTP headers.

0:00:16.140000 --> 0:00:20.680000
 So moving away from the standard application
 inputs that you probably

0:00:20.680000 --> 0:00:24.800000
 come across now or that
 we've taken a look at.

0:00:24.800000 --> 0:00:29.300000
 In the previous video we saw a registration
 form and we saw how to test

0:00:29.300000 --> 0:00:43.200000
 the parameters included in the body
 of the actual request that is sent

0:00:43.200000 --> 0:00:47.020000
 when you actually register an account.

0:00:47.020000 --> 0:00:58.060000
 Previously we now it's time to turn
 our attention to the actual some of

0:00:58.060000 --> 0:01:01.800000
 the other application inputs
 or input points if you will.

0:01:01.800000 --> 0:01:07.200000
 One of them or one category being the
 HTTP headers and more specifically

0:01:07.200000 --> 0:01:12.720000
 in this video we'll be exploring the
 user agent which I've probably given

0:01:12.720000 --> 0:01:21.060000
 away a bit too much but yeah so that's
 sort of the core or the objective

0:01:21.060000 --> 0:01:25.000000
 of this video and more importantly we're
 going to be leveraging or utilizing

0:01:25.000000 --> 0:01:31.720000
 SQL map to actually do this to assist
 us in identifying the A whether

0:01:31.720000 --> 0:01:38.420000
 there is indeed a vulnerability you
 know SQL injection vulnerability and

0:01:38.420000 --> 0:01:45.280000
 secondly the type of SQL injection vulnerability
 and then we'll actually

0:01:45.280000 --> 0:01:47.020000
 you know identify the payload.

0:01:47.020000 --> 0:01:51.360000
 So with that being said in order to
 demonstrate this goes without saying

0:01:51.360000 --> 0:01:54.180000
 that we're going to be utilizing
 a practical lab.

0:01:54.180000 --> 0:01:57.340000
 So this video has a lab
 associated with it.

0:01:57.340000 --> 0:02:02.620000
 The lab is just going to be below this
 video and one thing I'd like to

0:02:02.620000 --> 0:02:08.660000
 point out is that this lab specifically
 actually provides you with a pre

0:02:08.660000 --> 0:02:12.400000
-configured calilinic system so you
 don't need to use your own which is

0:02:12.400000 --> 0:02:16.460000
 great. So what I'm going to do is I'm
 going to fire up my lab and I'll

0:02:16.460000 --> 0:02:20.860000
 see you back in the lab environment
 in a couple of seconds.

0:02:20.860000 --> 0:02:26.860000
 See you there. All right so I'm currently
 within the lab environment and

0:02:26.860000 --> 0:02:31.620000
 as you can see you're going to be brought
 into a calilinic system that's

0:02:31.620000 --> 0:02:33.900000
 already you know ready to go.

0:02:33.900000 --> 0:02:36.840000
 Now you'll not see this Firefox window.

0:02:36.840000 --> 0:02:42.640000
 I just opened that up again for the sake
 of brevity of this demonstration

0:02:42.640000 --> 0:02:47.700000
 but in order to access the target you
 know web application you just need

0:02:47.700000 --> 0:02:51.140000
 to navigate to the domain SQLI.labs.

0:02:51.140000 --> 0:02:58.040000
 It's a local domain and this particular
 target web application is essentially

0:02:58.040000 --> 0:03:03.540000
 designed to teach you some of the more
 advanced SQL injection techniques

0:03:03.540000 --> 0:03:08.240000
 and will actually be revisiting this
 you know these set of challenges

0:03:08.240000 --> 0:03:16.980000
 in more detail. In the filter evasion
 course we'll be focused specifically

0:03:16.980000 --> 0:03:27.180000
 on bypassing filters or bypassing filters,
 various types of filters etc.

0:03:27.180000 --> 0:03:32.000000
 And these will obviously be specific to
 vulnerabilities like SQL injection.

0:03:32.000000 --> 0:03:38.220000
 Now for the purpose of this demonstration
 I'll be using SQLI-1.

0:03:38.220000 --> 0:03:46.820000
 If you want to continue along and try
 some of the other labs by all means

0:03:46.820000 --> 0:03:52.940000
 go ahead you can see that they're ranked
 by difficulty and you know I

0:03:52.940000 --> 0:03:57.960000
 personally would recommend you know
 doing second and third one but there

0:03:57.960000 --> 0:04:04.580000
 we are. So you can see right over here
 that it's fairly simple just click

0:04:04.580000 --> 0:04:08.940000
 on a challenge in this case I'll click
 on the first one and it takes us

0:04:08.940000 --> 0:04:11.380000
 to this particular web application.

0:04:11.380000 --> 0:04:14.820000
 All right and you can navigate through
 the challenges using this switcher.

0:04:14.820000 --> 0:04:19.800000
 Each challenge is you know has its
 own unique sub domain sequential so

0:04:19.800000 --> 0:04:26.120000
 the first challenge will be 1.sqlI
.labs second will be 2 so on and so

0:04:26.120000 --> 0:04:33.700000
 forth. And you can see in this case
 send your secret code and that we

0:04:33.700000 --> 0:04:37.900000
 essentially need to you know identify and
 exploit a SQL injection vulnerability

0:04:37.900000 --> 0:04:41.120000
 and then find this secret code.

0:04:41.120000 --> 0:04:46.600000
 But yeah so we're going to need burp suite
 to understand a couple of things.

0:04:46.600000 --> 0:04:50.740000
 So I'm just going to open up Foxy proxy
 here and just configure the burp

0:04:50.740000 --> 0:04:54.960000
 suite or enable the burp suite profile
 there and then I'm going to open

0:04:54.960000 --> 0:05:01.140000
 up my menu here web application analysis
 and burp suite and that'll fire

0:05:01.140000 --> 0:05:03.620000
 up or open up burp suite for us.

0:05:03.620000 --> 0:05:10.940000
 There we go and I'll just click on start
 and we'll just get this up and

0:05:10.940000 --> 0:05:14.760000
 running. We don't need burp's browser
 because again Firefox has already

0:05:14.760000 --> 0:05:21.120000
 been configured with Foxy proxy so we
 can just open this up and just give

0:05:21.120000 --> 0:05:23.740000
 me a few seconds as I increase
 the font size.

0:05:23.740000 --> 0:05:27.120000
 I'll just you know pause the video here
 and get back to you and I've made

0:05:27.120000 --> 0:05:30.700000
 everything a little bit clearer to read.

0:05:30.700000 --> 0:05:35.160000
 All right so on back I've just made
 things a little bit larger the user

0:05:35.160000 --> 0:05:41.160000
 interface font as well as the HTTP message
 font and we're going to keep

0:05:41.160000 --> 0:05:44.880000
 intercept on and now on the challenge
 page I'm just going to reload and

0:05:44.880000 --> 0:05:46.520000
 let's see what we have here.

0:05:46.520000 --> 0:05:53.640000
 So there we are we can see simple get
 request made to 1.sqli.labs and

0:05:53.640000 --> 0:05:59.360000
 from this point now you know we can
 pretty much leverage SQL map to try

0:05:59.360000 --> 0:06:06.840000
 and tell us or to essentially identify
 what parameters are indeed vulnerable

0:06:06.840000 --> 0:06:10.620000
 but in this case as I mentioned we're
 going to be testing the user agent

0:06:10.620000 --> 0:06:15.540000
 header here. So I'm going to save this
 and I'll save it on my desktop

0:06:15.540000 --> 0:06:22.380000
 and I'll just call it request.txt or
 alternatively you can just run SQL

0:06:22.380000 --> 0:06:25.880000
 map manually which actually
 I prefer in this case.

0:06:25.880000 --> 0:06:31.600000
 So I'll just copy this here and I'll
 open up a terminal and let me make

0:06:31.600000 --> 0:06:33.520000
 sure I zoom in so you can see everything.


0:06:33.520000 --> 0:06:39.280000
 So I'll say SQL map URL put that in
 there and the parameter is going to

0:06:39.280000 --> 0:06:46.600000
 be user agent and actually yeah in addition
 to this let's just hit enter

0:06:46.600000 --> 0:06:50.620000
 because I doubt this will work actually
 it looks like it did work.

0:06:50.620000 --> 0:06:57.300000
 So there we are it's recommended you
 know this is to only to perform only

0:06:57.300000 --> 0:07:01.620000
 basic unit as if there's not at least
 one other technique found you want

0:07:01.620000 --> 0:07:05.560000
 to reduce the default is yes so
 let's go with that for now.

0:07:05.560000 --> 0:07:10.720000
 So over here we can see it says use
 agent does not seem injectable to

0:07:10.720000 --> 0:07:17.920000
 be injectable that is and yeah all tested
 parameters are not injectable

0:07:17.920000 --> 0:07:23.680000
 we can leverage the level and risk options
 for want to perform more tests

0:07:23.680000 --> 0:07:30.880000
 however in this case there's one that
 I wanted to point out here we could

0:07:30.880000 --> 0:07:38.060000
 try and leverage the random agent option
 so I'll just open up the help

0:07:38.060000 --> 0:07:44.720000
 menu here advanced help I should say
 and what we're looking for is the

0:07:44.720000 --> 0:07:49.740000
 user agent which should not be it should
 be under this category right

0:07:49.740000 --> 0:07:56.380000
 over here let me just see if I can find
 it not DB enumeration one second

0:07:56.380000 --> 0:08:05.320000
 it should be somewhere here user agent
 so this is the injection we're

0:08:05.320000 --> 0:08:11.900000
 looking for where is it so we're looking
 for request yeah so somewhere

0:08:11.900000 --> 0:08:18.260000
 around here we should be able to find
 it so let's see CSRF I can't seem

0:08:18.260000 --> 0:08:27.080000
 to find the user agent or random agent
 I should say let me just let's

0:08:27.080000 --> 0:08:30.900000
 see let's go up here a little bit there
 we are random agent so use randomly

0:08:30.900000 --> 0:08:38.180000
 selected HTTP user agent header value
 so let's try this now um and just

0:08:38.180000 --> 0:08:49.920000
 go back in here and we'll just say
 random agent agent okay so the back

0:08:49.920000 --> 0:08:55.360000
 end DBMS is MySQL we want to skip testing
 are the you know to skip test

0:08:55.360000 --> 0:09:00.160000
 payloads for the DBMS's yes we do for
 the remaining tests do we want to

0:09:00.160000 --> 0:09:04.960000
 include all tests for MySQL extending
 the provided level and risk values

0:09:04.960000 --> 0:09:11.120000
 no we don't we can do that once we've
 confirmed you know the presence

0:09:11.120000 --> 0:09:17.280000
 of SQL injection vulnerability in the
 you know the user agent header so

0:09:17.280000 --> 0:09:21.380000
 there we are you can see right over
 here it tells us that the parameter

0:09:21.380000 --> 0:09:25.560000
 user agent is indeed vulnerable do we
 want to continue testing the others

0:09:25.560000 --> 0:09:30.480000
 they aren't any others so we'll just
 say no and voila you can see right

0:09:30.480000 --> 0:09:40.240000
 over here um parameter user agent is
 generic injectable and then over

0:09:40.240000 --> 0:09:45.720000
 here you can see the the actual SQL the
 types of SQL injection vulnerabilities

0:09:45.720000 --> 0:09:52.880000
 and more importantly the payload so error
 based time based blind and union

0:09:52.880000 --> 0:09:57.300000
 query which are all you know good options
 so we have error based here

0:09:57.300000 --> 0:10:05.320000
 which is not bad at all so what we can
 do now is sorry instead of specifying

0:10:05.320000 --> 0:10:15.700000
 yeah we'll say we can say DBS let's
 see whether we able to get that so

0:10:15.700000 --> 0:10:21.720000
 there we are available databases one
 SQL SQL injection labs that's for

0:10:21.720000 --> 0:10:27.780000
 this challenge so we can specify that
 and then list the tables in here

0:10:27.780000 --> 0:10:38.140000
 okay we just have browsers and we can
 then say we want the table uh browsers

0:10:38.140000 --> 0:10:50.080000
 and we can then say dump and this looks
 like all uh yeah all the user

0:10:50.080000 --> 0:10:55.400000
 agents there quite a bit of info in here
 and let me just zoom out a little

0:10:55.400000 --> 0:11:01.100000
 bit here and so we can see everything
 right over here yeah this is all

0:11:01.100000 --> 0:11:05.760000
 the requests we did with SQL maps it
 looks like this this web app saves

0:11:05.760000 --> 0:11:10.520000
 your browser user agent which is you
 know pretty cool send your secret

0:11:10.520000 --> 0:11:16.560000
 code there um one other users with
 your same browser uh interesting so

0:11:16.560000 --> 0:11:26.600000
 uh let's see uh right over here um these
 just uh let's see and let's go

0:11:26.600000 --> 0:11:37.480000
 right over here to the top all right
 so um one thing that um I wanted

0:11:37.480000 --> 0:11:45.320000
 to do here is I just ran um you know
 in the browsers table um I just ran

0:11:45.320000 --> 0:11:49.780000
 a columns or you know specified that
 I wanted to list out the columns

0:11:49.780000 --> 0:11:55.100000
 um and the reason for that is in order
 to get the code I'm assuming uh

0:11:55.100000 --> 0:11:59.640000
 right over here you know with your
 same browser as you can see here I

0:11:59.640000 --> 0:12:05.440000
 wanted to just see um whether we could
 search because with SQL map you

0:12:05.440000 --> 0:12:12.020000
 can actually search a specific um column
 if you will uh so you know if

0:12:12.020000 --> 0:12:30.260000
 I uh let's see um let's see if this
 works so um if I say databases do

0:12:30.260000 --> 0:12:36.420000
 we we actually don't need databases
 we can just say um let's try this

0:12:36.420000 --> 0:12:42.360000
 out so I'm just going to say search
 and then uh not sure how much of the

0:12:42.360000 --> 0:12:48.100000
 user agent is actually stored but let's
 try just this right over here

0:12:48.100000 --> 0:12:56.560000
 so Firefox 91.0 um and uh sorry let's
 go back in here but that in there

0:12:56.560000 --> 0:13:03.880000
 like so it and uh the honest you come
 up to consider provided columns

0:13:03.880000 --> 0:13:11.920000
 as exact columns as like column names
 uh actually else probably probably

0:13:11.920000 --> 0:13:27.180000
 right of me to um to have specified
 the I'll just say no here um uh yeah

0:13:27.180000 --> 0:13:33.220000
 so that's exactly what I figured so we
 can say um you know search database

0:13:33.220000 --> 0:13:42.980000
 and then we can then specify uh let's
 see within the one SQL iLabs database

0:13:42.980000 --> 0:13:58.280000
 we can search for um yeah well we can
 actually say for example search

0:13:58.280000 --> 0:14:05.520000
 um let's put that in there let's try
 this uh yeah this gonna ask for a

0:14:05.520000 --> 0:14:12.800000
 column name so we'll just say uh tables
 okay let's start there so we have

0:14:12.800000 --> 0:14:21.460000
 browsers so we'll say the table is browsers
 and uh table browsers columns

0:14:21.460000 --> 0:14:32.260000
 okay now so we're going to say id browser
 count we can go for one actually

0:14:32.260000 --> 0:14:42.540000
 so we can say now um let's see let's
 set the time to one and then we say

0:14:42.540000 --> 0:15:11.580000
 search we'll just say um count okay yeah
 with that's the um uh okay there's

0:15:11.580000 --> 0:15:18.860000
 quite a few with ones here which is
 quite interesting now so um um yeah

0:15:18.860000 --> 0:15:24.920000
 that's just uh the count there so maybe
 we can try uh let's see what was

0:15:24.920000 --> 0:15:32.340000
 the other column name here um we got
 that there's the column name would

0:15:32.340000 --> 0:15:45.840000
 be the browser right so we can say browser
 let's go with the default go

0:15:45.840000 --> 0:16:04.660000
 with the default there and these are
 all the SQL map ones so okay i'm

0:16:04.660000 --> 0:16:09.360000
 just gonna wait for this to complete
 all right my apologies given that

0:16:09.360000 --> 0:16:14.140000
 i know i um also going through this
 challenge for the first time but as

0:16:14.140000 --> 0:16:20.840000
 i was exploring uh few requests to the
 repeater here i actually saw that

0:16:20.840000 --> 0:16:25.720000
 uh right over here it says uh the head
 of you know find the name of the

0:16:25.720000 --> 0:16:31.660000
 browser with the id of one which i'm
 guessing is the code um so you know

0:16:31.660000 --> 0:16:37.520000
 we might as well try this here so i'm
 just going to copy that there um

0:16:37.520000 --> 0:16:52.380000
 and just uh for that there just getting
 the uh the user agent with the

0:16:52.380000 --> 0:16:56.140000
 id of one in the database anyway that
 took a bit longer than i expected

0:16:56.140000 --> 0:16:59.780000
 but yeah it's always good to go through
 this stuff um anyway these are

0:16:59.780000 --> 0:17:04.500000
 great challenges as you can see um
 to sort of assess uh not only your

0:17:04.500000 --> 0:17:08.380000
 injection skills but your database enumeration
 skills and sort of understanding

0:17:08.380000 --> 0:17:13.720000
 in this case you know the the type of
 info uh you're looking for i actually

0:17:13.720000 --> 0:17:18.400000
 showed you a couple of advanced features
 or what i think to be advanced

0:17:18.400000 --> 0:17:23.880000
 like the ability to search um but yeah
 so that brings us to the end of

0:17:23.880000 --> 0:17:28.360000
 the practical demonstration section
 and i'll see you back in the slides

0:17:28.360000 --> 0:17:35.780000
 all right so that was uh SQL injection
 via the user agent header um hopefully

0:17:35.780000 --> 0:17:40.580000
 you found that valuable i highly recommend
 that you go through not only

0:17:40.580000 --> 0:17:44.400000
 that challenge but some of the others
 some of the other ones might be

0:17:44.400000 --> 0:17:50.160000
 a bit uh difficult but um again that's
 the idea we'll be exploring pretty

0:17:50.160000 --> 0:17:54.640000
 much all of the rest of the challenges
 uh in a separate course or in a

0:17:54.640000 --> 0:17:59.000000
 different course when you know we'll be
 exploring um the process of leveraging

0:17:59.000000 --> 0:18:03.420000
 tamper scripts for you know filters
 and stuff like that but with that

