WEBVTT

0:00:03.600000 --> 0:00:08.520000
 Hello everyone and welcome to this video
 and this section of the course

0:00:08.520000 --> 0:00:11.040000
 we will be taking a look
 at attacking LDAP.

0:00:11.040000 --> 0:00:16.640000
 Now the objective for this section is
 not to explore all of the potential

0:00:16.640000 --> 0:00:23.580000
 or available attacks that you can perform against
 LDAP or LDAP based implementations.

0:00:23.580000 --> 0:00:27.480000
 We are going to be taking a look
 at LDAP injection specifically.

0:00:27.480000 --> 0:00:33.000000
 In order for you to understand LDAP
 injection or in order for it to all

0:00:33.000000 --> 0:00:37.980000
 make sense, you actually need to understand
 at least in my view what LDAP

0:00:37.980000 --> 0:00:40.960000
 is, what it's used for,
 how it works, etc.

0:00:40.960000 --> 0:00:45.680000
 And more importantly, as with all of
 the injection attacks that we've

0:00:45.680000 --> 0:00:50.220000
 gone through, you can probably tell by
 this point that it's quite important

0:00:50.220000 --> 0:00:56.740000
 that you understand the technology, whether
 it be a backend or a relational

0:00:56.740000 --> 0:01:01.240000
 database, let's say, or a non-relational
 database, you need to understand

0:01:01.240000 --> 0:01:09.520000
 how you communicate with these
 services or solutions.

0:01:09.520000 --> 0:01:15.520000
 I'm not saying that LDAP is like a MySQL
 database, it's not, but you need

0:01:15.520000 --> 0:01:22.320000
 to understand the LDAP syntax because
 the syntax is, or the rules for

0:01:22.320000 --> 0:01:28.120000
 the syntax are going to be very important,
 especially when we will be

0:01:28.120000 --> 0:01:34.300000
 exploring the actual process of injecting
 performing LDAP injection.

0:01:34.300000 --> 0:01:37.900000
 The bottom line is that in this video,
 we're going to be getting this

0:01:37.900000 --> 0:01:43.440000
 formal introduction to LDAP, understanding
 how it works, what it's used

0:01:43.440000 --> 0:01:47.380000
 for typically, and how it is used in
 web applications, which is sort of

0:01:47.380000 --> 0:01:52.660000
 the key here. To begin
 with, what is LDAP?

0:01:52.660000 --> 0:01:57.140000
 Now it's fairly clear that LDAP is
 an abbreviation, but what is it an

0:01:57.140000 --> 0:01:59.400000
 abbreviation for?

0:01:59.400000 --> 0:02:04.080000
 Well, LDAP is the lightweight
 directory access protocol.

0:02:04.080000 --> 0:02:08.600000
 Now this is a protocol, and the keyword
 there's protocol that is used

0:02:08.600000 --> 0:02:15.840000
 to modify and or query directory services
 over TCP IP, typically speaking,

0:02:15.840000 --> 0:02:20.240000
 right? Now that begs the question,
 what is a directory service?

0:02:20.240000 --> 0:02:25.320000
 I'm pretty sure you've heard of it,
 active directory, does that ring a

0:02:25.320000 --> 0:02:29.080000
 bell? Well, this is essentially
 what we're referring to here.

0:02:29.080000 --> 0:02:37.240000
 So an active or a directory service
 is a specialized database like, it's

0:02:37.240000 --> 0:02:42.100000
 not really a database, but it's a database
 like system that operates over

0:02:42.100000 --> 0:02:48.600000
 a network, typically that stores and
 organizes data in a hierarchical

0:02:48.600000 --> 0:02:53.120000
 structure, which means there's form
 to the way stuff is stored.

0:02:53.120000 --> 0:02:57.980000
 It's not relational or
 anything like that.

0:02:57.980000 --> 0:03:00.260000
 It has a hierarchy.

0:03:00.260000 --> 0:03:06.240000
 Now that begs the question, why is this
 or what use cases would require

0:03:06.240000 --> 0:03:07.720000
 this type of structure?

0:03:07.720000 --> 0:03:13.660000
 Well, directory services are commonly
 used or commonly found in enterprise

0:03:13.660000 --> 0:03:21.760000
 environments, and they're typically
 found in enterprise environments for

0:03:21.760000 --> 0:03:27.600000
 their ability of pretty much to manage
 and provide access to information,

0:03:27.600000 --> 0:03:33.880000
 such as user accounts, groups, permissions,
 and other organizational resources.

0:03:33.880000 --> 0:03:40.820000
 So an organization, if it wants to be
 successful or a going concern, let's

0:03:40.820000 --> 0:03:46.520000
 say into the foreseeable future, is going
 to be heavily focused on organization

0:03:46.520000 --> 0:03:57.060000
 and rules and bureaucracy, etc.

0:03:57.060000 --> 0:04:02.420000
 And there's going let's say digital infrastructure
 to fit into this hierarchical

0:04:02.420000 --> 0:04:07.160000
 model. Now I'm making this is a I'm
 sort of trivializing it here, but

0:04:07.160000 --> 0:04:15.220000
 I'm trying to give you or I'm trying
 to explain why this this type of

0:04:15.220000 --> 0:04:20.380000
 structure is used and what types of individuals
 or organizations or institutions

0:04:20.380000 --> 0:04:26.560000
 actually find this useful or find have
 a need for this type of structure.

0:04:26.560000 --> 0:04:29.620000
 So that brings us to the next point.

0:04:29.620000 --> 0:04:34.600000
 And that is that the LDAP database structure
 is based on a directory tree

0:04:34.600000 --> 0:04:41.740000
 of entries. Now we'll get into the nomenclature
 around LDAP and in this

0:04:41.740000 --> 0:04:45.780000
 case directory services, but for now,
 just think of it as a directory

0:04:45.780000 --> 0:04:55.020000
 tree. So a good example of this is
 the same directory tree you have in

0:04:55.020000 --> 0:04:57.040000
 your operating system on Windows.

0:04:57.040000 --> 0:05:00.800000
 So if you open if you're running Windows,
 you can open up a command.

0:05:00.800000 --> 0:05:05.020000
 You can open up the command prompt or
 the terminal and type in tree, and

0:05:05.020000 --> 0:05:09.440000
 it'll give you this tree like directory
 structure or at least show you

0:05:09.440000 --> 0:05:10.300000
 what it looks like.

0:05:10.300000 --> 0:05:15.140000
 Now that's not what directory services
 are, but it's that sort of tree,

0:05:15.140000 --> 0:05:20.980000
 tree structure where you start off
 at the root of the file system.

0:05:20.980000 --> 0:05:23.380000
 So let's say the root of the C drive.

0:05:23.380000 --> 0:05:29.160000
 And then you have let's say program
 files or users and this all forms

0:05:29.160000 --> 0:05:33.440000
 in a tree structure where you have the
 topmost and then it keeps cascading

0:05:33.440000 --> 0:05:37.520000
 with indents to show you, you know, you
 have a tree and then they're branches

0:05:37.520000 --> 0:05:40.540000
 and then they're sub branches,
 so on and so forth.

0:05:40.540000 --> 0:05:46.200000
 That's what a tree, you know, a directory
 tree or that type of structure,

0:05:46.200000 --> 0:05:48.260000
 that's what it looks like, right?

0:05:48.260000 --> 0:05:49.680000
 At a very basic level.

0:05:49.680000 --> 0:05:53.500000
 So I'm trying to use examples to help
 you visualize it because I think

0:05:53.500000 --> 0:05:56.400000
 it's very important.

0:05:56.400000 --> 0:06:02.100000
 And continuing on, there's a couple of
 things you need to know about LDAP.

0:06:02.100000 --> 0:06:08.080000
 So one of the key things to understand,
 and this is really important for

0:06:08.080000 --> 0:06:13.000000
 me as one of the key things that I sort
 of had to understand that actually

0:06:13.000000 --> 0:06:21.020000
 made, you know, using LDAP or Active
 Directory, let's say much easier

0:06:21.020000 --> 0:06:28.220000
 to understand. And that is LDAP is
 object oriented, okay, meaning that

0:06:28.220000 --> 0:06:36.280000
 every entry in an LDAP directory service
 is an instance of an object and

0:06:36.280000 --> 0:06:41.960000
 therefore must correspond to the rules
 defined for that object's attributes.

0:06:41.960000 --> 0:06:45.960000
 So let's take Active Directory
 as an example.

0:06:45.960000 --> 0:06:51.500000
 Every object, let's say your user account
 in a domain, let's say, I'll

0:06:51.500000 --> 0:06:53.940000
 use my name, Alexis, right?

0:06:53.940000 --> 0:06:59.780000
 That would be an entry, okay?

0:06:59.780000 --> 0:07:10.540000
 And in LDAP or, you know, any directory
 service for that matter, my entry,

0:07:10.540000 --> 0:07:13.800000
 you know, Alexis would be
 an instance of an object.

0:07:13.800000 --> 0:07:17.440000
 So it's, you know, treated as an object
 and a specific object with attributes

0:07:17.440000 --> 0:07:22.140000
 that helps it or distinguishes it from
 other objects because they could

0:07:22.140000 --> 0:07:28.480000
 be computers. For example, they could
 be organizational units, another

0:07:28.480000 --> 0:07:34.840000
 example. And the second point here
 that I mentioned in that paragraph,

0:07:34.840000 --> 0:07:39.980000
 where I say must correspond to the rules
 defined for that object's attributes,

0:07:39.980000 --> 0:07:46.340000
 this is where based on the type of object,
 let's say, so user accounts,

0:07:46.340000 --> 0:07:49.420000
 domain admins, user groups, etc.

0:07:49.420000 --> 0:07:57.580000
 What this is referring to is that in
 order for me to be a user, depending

0:07:57.580000 --> 0:08:02.420000
 on the structure that's defined, I need
 to fall into, let's say, a number

0:08:02.420000 --> 0:08:07.420000
 of organizational units like employees,
 there could be other ones that

0:08:07.420000 --> 0:08:10.960000
 are more specific, like
 accountants, IT, etc.

0:08:10.960000 --> 0:08:13.440000
 So that's the key.

0:08:13.440000 --> 0:08:19.200000
 The the the most important thing to remember
 is that LDAP is object oriented,

0:08:19.200000 --> 0:08:23.260000
 which means simply put that every entry
 in an LDAP directory services

0:08:23.260000 --> 0:08:29.640000
 instance of an object and must correspond
 to the rules defined for that

0:08:29.640000 --> 0:08:31.100000
 object's attributes.

0:08:31.100000 --> 0:08:35.940000
 So in addition to that, or in addition
 to querying objects from a directory

0:08:35.940000 --> 0:08:41.140000
 database, LDAP can be used can also be
 used for management and authentication

0:08:41.140000 --> 0:08:46.300000
 tasks, as I'm sure you're aware of,
 or if you're not now, you know, now

0:08:46.300000 --> 0:08:49.700000
 one thing that I would like to point
 out, because I may have inferred

0:08:49.700000 --> 0:08:54.420000
 it and I knew I was, that's why I added
 this very important notice in

0:08:54.420000 --> 0:08:59.960000
 this slide is that it's important to
 note that LDAP is a protocol for

0:08:59.960000 --> 0:09:02.600000
 accessing directory services.

0:09:02.600000 --> 0:09:04.840000
 Okay, that's why I was quite general.

0:09:04.840000 --> 0:09:08.140000
 And I was using active directories as
 an example, right, because active

0:09:08.140000 --> 0:09:12.360000
 directory is actually directory service
 LDAP is a protocol that is used

0:09:12.360000 --> 0:09:15.260000
 for accessing directory services.

0:09:15.260000 --> 0:09:18.600000
 It is not a storage mechanism itself.

0:09:18.600000 --> 0:09:22.480000
 Our directory in and of itself, and
 we'll get into the formatting and

0:09:22.480000 --> 0:09:28.240000
 how it works and how you can use, you
 know, LDAP and active directory,

0:09:28.240000 --> 0:09:31.140000
 you know, so don't worry about that now.

0:09:31.140000 --> 0:09:34.500000
 Don't, you know, jump the ship just yet.

0:09:34.500000 --> 0:09:42.340000
 LDAP ports. So I think we need to understand
 what ports it uses, even

0:09:42.340000 --> 0:09:46.380000
 though it's not really relevant at
 this point, but LDAP uses specific

0:09:46.380000 --> 0:09:48.380000
 ports for communication.

0:09:48.380000 --> 0:09:53.800000
 Depending on whether the connection is
 plaintext or secured with encryption.

0:09:53.800000 --> 0:09:57.780000
 So, you know, you have 389, which is
 the default port for plaintext LDAP

0:09:57.780000 --> 0:10:02.940000
 communication. You also have LDAP,
 LDAP, or LDAP S, if you will, this

0:10:02.940000 --> 0:10:07.420000
 is the default port for secure LDAP communications,
 essentially inferring

0:10:07.420000 --> 0:10:12.320000
 the presence of a certificate to encrypt
 communication in transit, right?

0:10:12.320000 --> 0:10:15.080000
 So that's ports 636.

0:10:15.080000 --> 0:10:18.060000
 You then have 3268 and 3269.

0:10:18.060000 --> 0:10:24.480000
 3268 is the global catalog, you know,
 global catalog over plaintext LDAP.

0:10:24.480000 --> 0:10:33.040000
 Likewise, 3269 global catalog LDAPs,
 or LDAP S, this is over the global

0:10:33.040000 --> 0:10:36.040000
 catalog over secure LDAP.

0:10:36.040000 --> 0:10:38.300000
 So just wanted to clear that out.

0:10:38.300000 --> 0:10:41.180000
 Now, I know you're probably
 quite confused.

0:10:41.180000 --> 0:10:43.320000
 And don't worry, it'll all make sense.

0:10:43.320000 --> 0:10:47.640000
 The reason they need to introduce this
 is we'll become apparent in the

0:10:47.640000 --> 0:10:50.920000
 next video, and we're actually
 talking about LDAP injection.

0:10:50.920000 --> 0:10:55.540000
 You know, generally speaking, you'll
 never see LDAP explained in various

0:10:55.540000 --> 0:10:59.380000
 resources online that, you
 know, books, courses, etc.

0:10:59.380000 --> 0:11:05.020000
 that explain or trying to teach you LDAP
 injection can be very confusing,

0:11:05.020000 --> 0:11:11.340000
 you know, especially if you're this
 your first time learning about LDAP

0:11:11.340000 --> 0:11:16.340000
 injection, if you dive straight into
 the actual attacks, it's going to

0:11:16.340000 --> 0:11:20.340000
 be a very difficult process, you know,
 in order for you to understand

0:11:20.340000 --> 0:11:22.140000
 what you're actually doing.

0:11:22.140000 --> 0:11:24.060000
 And that I think is very important.

0:11:24.060000 --> 0:11:30.180000
 So, to sort of bring us back to the
 whole web app and testing side of

0:11:30.180000 --> 0:11:34.220000
 things, we need, I thought it'd be
 important to let you or to explain

0:11:34.220000 --> 0:11:41.600000
 how web applications typically use
 LDAP, or what they use LDAP for.

0:11:41.600000 --> 0:11:47.120000
 Okay. So generally speaking, web applications
 use LDAP to a authenticate

0:11:47.120000 --> 0:11:51.580000
 users, so validate usernames and passwords
 against directory entries.

0:11:51.580000 --> 0:11:55.720000
 So they use the protocol to, let's say,
 interact with a directory service,

0:11:55.720000 --> 0:11:57.460000
 whatever that may be.

0:11:57.460000 --> 0:11:59.520000
 Secondly, authorize access.

0:11:59.520000 --> 0:12:05.360000
 So check user roles and permissions
 for specific resources and see query

0:12:05.360000 --> 0:12:10.440000
 directory data. So retrieve user or
 organizational information from the

0:12:10.440000 --> 0:12:15.040000
 directory. An example use case is, you
 know, a company web portal might

0:12:15.040000 --> 0:12:20.920000
 authenticate employees using an LDAP server
 like Microsoft Active Directory,

0:12:20.920000 --> 0:12:28.240000
 or Open LDAP. Open LDAP is now what
 you would, you know, what you would

0:12:28.240000 --> 0:12:33.500000
 construe as, you know, being
 similar to Active Directory.

0:12:33.500000 --> 0:12:37.080000
 LDAP is just a protocol, remember,
 this is very important.

0:12:37.080000 --> 0:12:41.860000
 So you're actually using LDAP to facilitate
 this, you know, querying of

0:12:41.860000 --> 0:12:48.880000
 directory data from, you know,
 Active Directory, etc.

0:12:48.880000 --> 0:12:52.340000
 And these are very basic examples.

0:12:52.340000 --> 0:12:58.780000
 And don't worry, as I said, you'll
 actually see, you'll actually get a

0:12:58.780000 --> 0:13:08.200000
 practical, or a, I should say, a realistic
 understanding of how LDAP is

0:13:08.200000 --> 0:13:09.520000
 used in the next video.

0:13:09.520000 --> 0:13:13.200000
 But for now, I'm, you know, I'm trying
 to keep it as simple as possible.

0:13:13.200000 --> 0:13:20.780000
 Now, from this slide on, this stuff
 is going to be very important.

0:13:20.780000 --> 0:13:24.080000
 And more importantly, it is going to
 be the final section of the slides

0:13:24.080000 --> 0:13:25.760000
 where I talk about the syntax.

0:13:25.760000 --> 0:13:31.300000
 But in order for you to understand
 the syntax, which again, the syntax

0:13:31.300000 --> 0:13:35.380000
 and writing queries, you know, essentially
 just like SQL injection, no

0:13:35.380000 --> 0:13:42.520000
 SQL injection, are quite pivotal, or
 are the core of actually performing

0:13:42.520000 --> 0:13:46.260000
 injection. So the LDAP
 directory structure.

0:13:46.260000 --> 0:13:51.660000
 Okay. Now the LDAP database is organized
 as a hierarchical structure called

0:13:51.660000 --> 0:13:55.020000
 a directory information tree, or DIT.

0:13:55.020000 --> 0:13:59.760000
 And as I said, it resembles a tree like
 structure where each entry represents

0:13:59.760000 --> 0:14:02.920000
 a single object, there could
 be a user group or resource.

0:14:02.920000 --> 0:14:08.220000
 And entries are defined by attributes
 like use ID, canonical name, CN,

0:14:08.220000 --> 0:14:13.100000
 mail, etc. And entries are arranged
 hierarchically with parent and child

0:14:13.100000 --> 0:14:17.860000
 relationships. So starting off, and
 I'll give you an example of what it

0:14:17.860000 --> 0:14:20.700000
 looks like the, you know,
 directory structure.

0:14:20.700000 --> 0:14:22.940000
 We have the root of the tree.

0:14:22.940000 --> 0:14:25.560000
 This is the topmost entry
 in the LDAP hierarchy.

0:14:25.560000 --> 0:14:30.940000
 The root of the tree is typically defined
 by the domain name of the organization.

0:14:30.940000 --> 0:14:33.560000
 So if you've worked with active directory,
 you know, the, you know, DC

0:14:33.560000 --> 0:14:39.120000
 is equal to example, DC,
 you know, fairly simple.

0:14:39.120000 --> 0:14:42.400000
 So domain name of the organization.

0:14:42.400000 --> 0:14:45.800000
 And then organizational units, you
 should be familiar with that.

0:14:45.800000 --> 0:14:49.300000
 Again, if you have used active directory,
 these are logical containers

0:14:49.300000 --> 0:14:56.600000
 or buckets, if you will, but containers
 is a better word that, that group

0:14:56.600000 --> 0:14:57.940000
 related entries.

0:14:57.940000 --> 0:15:02.740000
 So a few slides back, I mentioned organizational
 units, depending on how

0:15:02.740000 --> 0:15:06.480000
 the company wants to set it up or an
 organization wants to use them, could

0:15:06.480000 --> 0:15:10.080000
 use to represent large groups
 of individuals, let's say.

0:15:10.080000 --> 0:15:13.980000
 So, you know, employees, generally speaking,
 or employees of a particular

0:15:13.980000 --> 0:15:19.340000
 office, or a particular department,
 and then they can even go further,

0:15:19.340000 --> 0:15:26.620000
 or can be very fine-grained, and say,
 HR, accountants, marketing, IT,

0:15:26.620000 --> 0:15:29.340000
 you know, so on and so forth.

0:15:29.340000 --> 0:15:34.400000
 And an example of this, you know, OU
 users, OU groups, OU departments,

0:15:34.400000 --> 0:15:40.460000
 you know, pretty much whatever you want,
 as long as there's some context

0:15:40.460000 --> 0:15:44.880000
 behind it. That brings
 us then to entries.

0:15:44.880000 --> 0:15:49.200000
 Okay. So I've talked about entries before,
 but these are individual records

0:15:49.200000 --> 0:15:53.040000
 that represent objects, such as users,
 groups, or devices, but devices

0:15:53.040000 --> 0:15:55.200000
 being computers, etc.

0:15:55.200000 --> 0:15:59.700000
 Or, you know, that are part of a domain,
 let's say, inactive directory.

0:15:59.700000 --> 0:16:04.680000
 They are defined by a unique distinguished
 name, which is abbreviated

0:16:04.680000 --> 0:16:10.540000
 to, as DN, which specifies the
 entries position in the tree.

0:16:10.540000 --> 0:16:15.040000
 Remember the tree format that
 I was, sort of explaining.

0:16:15.040000 --> 0:16:24.180000
 And the whole idea behind a hierarchical
 structure is that some objects,

0:16:24.180000 --> 0:16:30.940000
 or some entries, let's say, are more
 senior than the others, while others

0:16:30.940000 --> 0:16:36.000000
 that fall under these entries
 can be seen as branches.

0:16:36.000000 --> 0:16:43.080000
 So they essentially further out from
 the actual root or the, you know,

0:16:43.080000 --> 0:16:46.360000
 from the actual trunk of the tree.

0:16:46.360000 --> 0:16:50.100000
 Anyway, I'm going to stop using the tree
 example, the actual tree example.

0:16:50.100000 --> 0:16:55.040000
 But examples of this are, you know,
 canonical name John, or sorry, John

0:16:55.040000 --> 0:17:02.980000
 Doe. And then you need to say,
 where does John Doe fit?

0:17:02.980000 --> 0:17:07.280000
 Well, under the organizational
 unit users, uh huh.

0:17:07.280000 --> 0:17:13.400000
 And under what domain DC, under what
 domain that in this case, example

0:17:13.400000 --> 0:17:17.480000
.com. So you see, you can see it, you
 sort of start with John, and then

0:17:17.480000 --> 0:17:23.740000
 organizational unit users, and then,
 so back to the domain root.

0:17:23.740000 --> 0:17:29.780000
 So the root, and then you have OUs,
 and then under OUs, you have, you

0:17:29.780000 --> 0:17:34.800000
 know, in this case, users, essentially
 identified using CN, which is canonical

0:17:34.800000 --> 0:17:41.760000
 name. And then of course, the attributes,
 which is where, you know, I

0:17:41.760000 --> 0:17:46.700000
 wanted to sort of, you know, it's quite
 important, but attributes, these

0:17:46.700000 --> 0:17:49.440000
 are key value pairs that
 describe an entry.

0:17:49.440000 --> 0:17:57.060000
 So again, CN common name, John Doe, there
 can also be canonical male John

0:17:57.060000 --> 0:18:00.100000
 Doe, John Doe at example.com.

0:18:00.100000 --> 0:18:03.240000
 So hopefully you're starting
 to understand it, right?

0:18:03.240000 --> 0:18:13.000000
 And here's an example of, you know, the,
 the root, so the company domain.

0:18:13.000000 --> 0:18:17.640000
 And then under that, you have users,
 organizational unit, in this example,

0:18:17.640000 --> 0:18:18.800000
 users, and then groups.

0:18:18.800000 --> 0:18:23.380000
 And then under each of them, you have
 your entries, in the case of users,

0:18:23.380000 --> 0:18:25.640000
 you're likely to find users.

0:18:25.640000 --> 0:18:29.780000
 So you can see that this, this, this
 follows exactly what you'd find in

0:18:29.780000 --> 0:18:34.260000
 an organization where you start off
 with the CEO, and then you have, you

0:18:34.260000 --> 0:18:38.460000
 know, the C suite, and then actually
 CEO would be part of C suite, but

0:18:38.460000 --> 0:18:42.360000
 everyone under him, and then everyone
 under those individuals, and it

0:18:42.360000 --> 0:18:43.480000
 keeps cascading.

0:18:43.480000 --> 0:18:44.860000
 It's the same sort of structure.

0:18:44.860000 --> 0:18:50.840000
 So the, what's important is the OUs,
 you can see that organizational units

0:18:50.840000 --> 0:18:55.820000
 need to make sense, or hopefully they
 should make sense in that under

0:18:55.820000 --> 0:19:02.060000
 users, you'd expect to find users,
 under groups, you'd expect to find

0:19:02.060000 --> 0:19:06.680000
 groups. Yeah. And these entries, this
 is the root here, organizational

0:19:06.680000 --> 0:19:09.620000
 units. So hopefully this is making sense.


0:19:09.620000 --> 0:19:13.740000
 Now, if it's not making sense, or you're
 asking, is it why do I need to

0:19:13.740000 --> 0:19:16.300000
 understand this in order to
 understand LDAAP injection?

0:19:16.300000 --> 0:19:22.200000
 Don't worry, because all of these words
 you're seeing or abbreviated versions

0:19:22.200000 --> 0:19:30.020000
 or forms, abbreviations of words will
 come into play when we are creating

0:19:30.020000 --> 0:19:35.200000
 our queries or injecting
 them, I should say.

0:19:35.200000 --> 0:19:40.900000
 Okay. So now before we actually move
 on to explore the LDAP syntax and

0:19:40.900000 --> 0:19:45.100000
 escape abilities, let's take a closer
 look at directory databases, which

0:19:45.100000 --> 0:19:48.660000
 are inherent, you know, component
 of LDAP implementations.

0:19:48.660000 --> 0:19:53.660000
 More specifically, we need to understand
 how objects in a directory access

0:19:53.660000 --> 0:20:00.080000
 via LDAP are stored, how they're stored,
 and what format they're stored

0:20:00.080000 --> 0:20:09.200000
 in. Now, before we actually continue
 to everything, I listed out here,

0:20:09.200000 --> 0:20:11.360000
 or the syntax, etc.

0:20:11.360000 --> 0:20:15.640000
 I know you're pretty confused, because
 I've sort of jumbled up the terms

0:20:15.640000 --> 0:20:19.080000
 and stuff like that, while, you know,
 an example of that is while stating

0:20:19.080000 --> 0:20:23.100000
 LDAP is a protocol, I'm referring
 to the LDAP directory structure.

0:20:23.100000 --> 0:20:27.360000
 So I need to clarify that I knew you'd
 be confused, but don't worry.

0:20:27.360000 --> 0:20:30.240000
 It'll all make sense after
 this next slide.

0:20:30.240000 --> 0:20:36.140000
 So when referring, and this is, you
 know, colloquially speaking, this

0:20:36.140000 --> 0:20:38.680000
 is what you typically see.

0:20:38.680000 --> 0:20:43.860000
 When referring to the LDAP directory
 structure, you are referring, or

0:20:43.860000 --> 0:20:48.660000
 I am referring to the structure used
 by directory services that implement

0:20:48.660000 --> 0:20:53.140000
 the LDAP protocol to organize
 and manage data.

0:20:53.140000 --> 0:20:58.020000
 Okay, so what's the role
 of the LDAP protocol?

0:20:58.020000 --> 0:21:02.640000
 Well, LDAP defines how directory
 data is accessed and managed.

0:21:02.640000 --> 0:21:06.640000
 So querying, adding, modifying
 entries, etc.

0:21:06.640000 --> 0:21:14.340000
 And active directory, or active directory
 services utilizes LDAP.

0:21:14.340000 --> 0:21:20.580000
 Okay. Now, in terms of again, going back
 to the role of the LDAP protocol,

0:21:20.580000 --> 0:21:25.180000
 it works with the hierarchical structure,
 but does not dictate.

0:21:25.180000 --> 0:21:30.140000
 I'm referring to the protocol here does
 not dictate or enforce the specific

0:21:30.140000 --> 0:21:32.780000
 organization of the directory.

0:21:32.780000 --> 0:21:37.960000
 Now that brings us to directory services,
 okay, which is something completely

0:21:37.960000 --> 0:21:42.620000
 different that utilizes LDAP, or
 they typically utilize LDAP.

0:21:42.620000 --> 0:21:45.120000
 So this refers to the structure.

0:21:45.120000 --> 0:21:48.900000
 It's so the structure itself is defined
 and maintained by the directory

0:21:48.900000 --> 0:21:53.640000
 service. What's an example
 of a directory service?

0:21:53.640000 --> 0:21:57.160000
 Obviously, Microsoft Active
 Directory and open LDAP.

0:21:57.160000 --> 0:22:02.320000
 Okay. And this is organized as, as
 I mentioned in the previous slides,

0:22:02.320000 --> 0:22:08.760000
 as a directory information tree or DIT, where
 entries are arranged hierarchically.

0:22:08.760000 --> 0:22:13.000000
 An example of a hierarchy is or the
 hierarchical structure, you know,

0:22:13.000000 --> 0:22:14.760000
 would be, we have the root.

0:22:14.760000 --> 0:22:19.180000
 So DC equal examples, DC COM is created
 managed by the directory service,

0:22:19.180000 --> 0:22:24.760000
 while the LDAP protocol provides
 the means to interact with it.

0:22:24.760000 --> 0:22:28.640000
 Now, again, the reason I'm explaining
 this is because you can see I sort

0:22:28.640000 --> 0:22:29.980000
 of use the same heading here.

0:22:29.980000 --> 0:22:35.840000
 And you may have thought, well, you
 mentioned LDAP is a, you know, LDAP

0:22:35.840000 --> 0:22:40.020000
 is a protocol, but you're talking about
 its directory, you know, structure.

0:22:40.020000 --> 0:22:45.360000
 What's all what's all of that about
 what I'm referring to is the fact

0:22:45.360000 --> 0:22:51.980000
 that in order for you to, you know,
 use LDAP or the LDAP protocol with

0:22:51.980000 --> 0:22:58.140000
 your directory service, you know, they
 obviously need to be aligned with

0:22:58.140000 --> 0:23:04.080000
 one another. And, and as I mentioned,
 Active Directory, you know, pretty

0:23:04.080000 --> 0:23:06.680000
 much implements LDAP or uses it.

0:23:06.680000 --> 0:23:12.260000
 The protocol that is LDAP, what I'm
 referring to is the, you know, the

0:23:12.260000 --> 0:23:13.940000
 LDAP protocol here.

0:23:13.940000 --> 0:23:18.300000
 And as a result, the structure needs,
 you know, the structure needs to

0:23:18.300000 --> 0:23:22.600000
 be aligned in terms of the
 directory structure.

0:23:22.600000 --> 0:23:27.680000
 And yeah, so Active Directory
 is fully compatible with LDAP.

0:23:27.680000 --> 0:23:32.000000
 That's why you see, you know, in an active
 directory environment 38, both

0:23:32.000000 --> 0:23:33.720000
 389 is used, etc.

0:23:33.720000 --> 0:23:37.300000
 Of course, you have Kerberos for
 authentication on port 88.

0:23:37.300000 --> 0:23:40.880000
 But what I was referring to here was
 the actual structure, you know, the

0:23:40.880000 --> 0:23:45.200000
 directory structure for, you know, directory
 services or, you know, ones

0:23:45.200000 --> 0:23:48.800000
 that are compatible with LDAP, since
 that's what we're focusing on.

0:23:48.800000 --> 0:23:52.800000
 So that, now this brings
 us to the LDIF format.

0:23:52.800000 --> 0:23:56.760000
 Okay. Now this is very important because
 objects in directory databases,

0:23:56.760000 --> 0:24:01.160000
 accessed via LDAP are stored in LDIF.

0:24:01.160000 --> 0:24:03.780000
 All right. Now what is LDIF?

0:24:03.780000 --> 0:24:09.140000
 LDIF is the LDAP data interchange format.


0:24:09.140000 --> 0:24:13.900000
 Okay. This is a standard plaintext
 format used to represent directory

0:24:13.900000 --> 0:24:18.260000
 entries or perform directory operations,
 for example, adding modifying

0:24:18.260000 --> 0:24:20.220000
 or deleting entries.

0:24:20.220000 --> 0:24:25.560000
 A directory database can support LDIF
 by defining its assumptions in a

0:24:25.560000 --> 0:24:30.960000
 LDIF file. It can be a plain text file,
 simply containing directory data

0:24:30.960000 --> 0:24:34.560000
 representation, as well as LDAP commands.


0:24:34.560000 --> 0:24:39.120000
 These files are used to read, write
 and update data in a directory.

0:24:39.120000 --> 0:24:43.740000
 So this is an example of what an LDIF
 file looks like, where I've sort

0:24:43.740000 --> 0:24:48.400000
 of, you can see there's multiple, I
 added line numbers to this example.

0:24:48.400000 --> 0:24:52.000000
 And I've sort of represented what
 each of the lines represent.

0:24:52.000000 --> 0:24:56.400000
 So lines one to three, you can see you
 have right over here, dndc object

0:24:56.400000 --> 0:25:02.360000
 class. Okay. And in the case of line
 one, two, and three, we're defining

0:25:02.360000 --> 0:25:04.060000
 the top level domain.

0:25:04.060000 --> 0:25:09.140000
 So, you know, org, as you can see here,
 being the example used, and then

0:25:09.140000 --> 0:25:12.000000
 lines five to eight, we're
 defining the sub domain.

0:25:12.000000 --> 0:25:18.260000
 So sample company, for example,
 sample company.org.

0:25:18.260000 --> 0:25:20.120000
 Hopefully that's making sense.

0:25:20.120000 --> 0:25:25.420000
 If the top level domain is org, then
 the sub domain would be, you know,

0:25:25.420000 --> 0:25:28.940000
 if the sub domain is sample company,
 then it would become sample company

0:25:28.940000 --> 0:25:33.080000
.org, because it falls under
 the top level domain.

0:25:33.080000 --> 0:25:36.920000
 And then lines 10 to 16, we're defining,
 we define two organizational

0:25:36.920000 --> 0:25:40.180000
 units or we use it and marketing.

0:25:40.180000 --> 0:25:41.580000
 So you can see them here.

0:25:41.580000 --> 0:25:47.220000
 So dnohu it, that falls under
 the sub domain sample company.

0:25:47.220000 --> 0:25:54.640000
 And you know, the top level domain, which
 is org object class organizational

0:25:54.640000 --> 0:25:57.700000
 unit, oh, you it.

0:25:57.700000 --> 0:25:59.480000
 Okay. And then we have the
 other one for marketing.

0:25:59.480000 --> 0:26:05.160000
 And then lines 18 to 26 is, you know,
 where we, you know, we then add

0:26:05.160000 --> 0:26:11.960000
 objects to the domain sample company.org
 and assign attributes with values.

0:26:11.960000 --> 0:26:17.140000
 For example, sn stands for surname, cn
 stands for canonical name or first

0:26:17.140000 --> 0:26:20.620000
 name, while male is a placeholder
 for an email address.

0:26:20.620000 --> 0:26:26.700000
 So you can see that here, the
 object class is personal data.

0:26:26.700000 --> 0:26:33.220000
 And we in this particular case, you know,
 we assign attributes with values.

0:26:33.220000 --> 0:26:39.820000
 In this case, we have, you know, sn
 as I mentioned, we also have a use

0:26:39.820000 --> 0:26:42.040000
 ID organizational unit, mail phone.

0:26:42.040000 --> 0:26:47.320000
 So if we created a user, these would
 be the attributes that would be used

0:26:47.320000 --> 0:26:53.320000
 to define where that entry or that object,
 if you will, would would fall

0:26:53.320000 --> 0:26:55.460000
 under the hierarchy.

0:26:55.460000 --> 0:26:57.640000
 So hopefully, that makes sense.

0:26:57.640000 --> 0:27:01.840000
 And then of course, that brings us to
 the actual core here of what I wanted

0:27:01.840000 --> 0:27:04.920000
 to cover in this video originally,
 which is the LDAP syntax.

0:27:04.920000 --> 0:27:10.420000
 So given that LDAP is a protocol, if you
 will, the LDAP, you know, protocol

0:27:10.420000 --> 0:27:15.400000
 has its own structure for querying
 the backend database directory, if

0:27:15.400000 --> 0:27:19.400000
 you will. And it utilizes operators
 that you should be pretty familiar

0:27:19.400000 --> 0:27:23.400000
 with, the equal to logical
 or logical not.

0:27:23.400000 --> 0:27:26.560000
 If you've done programming, you know,
 this is only slightly different.

0:27:26.560000 --> 0:27:33.280000
 You know, in some programming languages,
 the all would be a double pipe.

0:27:33.280000 --> 0:27:40.940000
 Logical not actually, as always,
 remained as one exclamation mark.

0:27:40.940000 --> 0:27:44.620000
 And logical land would just
 be an ampersand here.

0:27:44.620000 --> 0:27:46.360000
 And then wild card, very important.

0:27:46.360000 --> 0:27:48.900000
 This represents any string
 or character, right?

0:27:48.900000 --> 0:27:52.480000
 But its use will become really important,
 especially when we get into

0:27:52.480000 --> 0:27:55.760000
 injection. I'm sure you
 can already tell why.

0:27:55.760000 --> 0:28:01.560000
 The key thing to note is that these operators
 are used in larger expressions,

0:28:01.560000 --> 0:28:03.720000
 what we call LDAP queries.

0:28:03.720000 --> 0:28:08.460000
 And below, you can find some exemplary
 LDAP queries, or you know, what

0:28:08.460000 --> 0:28:14.640000
 I would consider to be ones that sort
 of explain or best explain, you

0:28:14.640000 --> 0:28:22.520000
 know, what the queries, what the queries
 would look like, what information

0:28:22.520000 --> 0:28:24.820000
 you're likely is likely to be queried.

0:28:24.820000 --> 0:28:28.560000
 So for example, in this case, a canonical
 name or common name, John, what

0:28:28.560000 --> 0:28:29.700000
 will that query do?

0:28:29.700000 --> 0:28:34.020000
 It'll fetch personal entries where
 the canonical name is John.

0:28:34.020000 --> 0:28:38.240000
 Okay. And the key, the reason why I
 consider these to be exemplaries,

0:28:38.240000 --> 0:28:41.140000
 because it's sort of addressing
 an important point.

0:28:41.140000 --> 0:28:49.020000
 And that is the case sensitive nature
 of the queries in relation to the

0:28:49.020000 --> 0:28:51.120000
 two specific entries.

0:28:51.120000 --> 0:28:56.060000
 In the next one, with a wild card, you
 can see we have canonical canonical

0:28:56.060000 --> 0:28:59.660000
 name is equal to J and then wild card.

0:28:59.660000 --> 0:29:01.080000
 So what will this do?

0:29:01.080000 --> 0:29:04.960000
 Well, this will fetch personal entries
 where the canonical name starts

0:29:04.960000 --> 0:29:09.460000
 with an uppercase J as a wild
 card is placed in the query.

0:29:09.460000 --> 0:29:16.800000
 So it'll pretty much give us all entries
 where the CN begins with the

0:29:16.800000 --> 0:29:19.720000
 letter uppercase J.

0:29:19.720000 --> 0:29:27.540000
 Okay. So another thing that I need to point
 out is that LDAP query expressions

0:29:27.540000 --> 0:29:31.460000
 can also be concatenated, resulting in
 a sample query like the one below,

0:29:31.460000 --> 0:29:35.240000
 where you can see right over here.

0:29:35.240000 --> 0:29:38.440000
 And they follow this typical syntax.

0:29:38.440000 --> 0:29:41.980000
 So in this case, what's happening is
 that the first or operator, so the

0:29:41.980000 --> 0:29:48.100000
 pipe symbol is used in order to indicate
 that we either look for all records

0:29:48.100000 --> 0:29:54.940000
 that essentially have a surname that
 starts with, and in this case, the

0:29:54.940000 --> 0:30:01.420000
 what I'm referring to here, if I go
 back to the, let me go back here,

0:30:01.420000 --> 0:30:03.640000
 I just want to make something very clear.


0:30:03.640000 --> 0:30:15.440000
 You can see we had defined, you know,
 I'm sort of using this for that

0:30:15.440000 --> 0:30:22.200000
 particular query, where
 Sn stands for surname.

0:30:22.200000 --> 0:30:26.120000
 So I just wanted to clarify that it's
 not something that standardizes.

0:30:26.120000 --> 0:30:30.360000
 I mentioned you as the organizational
 user using a directory service would

0:30:30.360000 --> 0:30:32.760000
 define what that means.

0:30:32.760000 --> 0:30:37.320000
 So first or operators used in order
 to indicate that we either look for

0:30:37.320000 --> 0:30:43.220000
 all records of the surname that starts
 with a so or a canonical name that

0:30:43.220000 --> 0:30:53.580000
 starts with B. And the concatenation
 sort of infers two checks, if you

0:30:53.580000 --> 0:30:56.560000
 will. So you can see that here.

0:30:56.560000 --> 0:31:01.880000
 So we start, we open the first brackets,
 we say or and then you specify

0:31:01.880000 --> 0:31:09.060000
 what, you know, you essentially specify
 the specifics or your of the or

0:31:09.060000 --> 0:31:16.640000
 operation. So you know, Sn surname equals
 a or not and or the canonical

0:31:16.640000 --> 0:31:20.120000
 name starts with a B lower
 case in this case.

0:31:20.120000 --> 0:31:25.860000
 So I know there can be a bit confusing,
 but yeah, that's the, that's pretty

0:31:25.860000 --> 0:31:27.940000
 much LDAP in a nutshell.

0:31:27.940000 --> 0:31:31.980000
 Hopefully that makes sense is maybe
 a bit confusing, but don't worry.

0:31:31.980000 --> 0:31:38.820000
 It always is to begin with, directory
 services can be can be quite tricky

0:31:38.820000 --> 0:31:41.060000
 to sort of visualize.

0:31:41.060000 --> 0:31:45.560000
 For me, it's very important that I can
 sort of see it visually or visualize,

0:31:45.560000 --> 0:31:51.920000
 you know, a concept like this, but
 obviously, your understanding of a

0:31:51.920000 --> 0:31:54.920000
 technology protocol, etc.

0:31:54.920000 --> 0:31:58.240000
 improves when you interact with it and
 you can actually test things out

0:31:58.240000 --> 0:32:01.720000
 that are maybe not so clear.

0:32:01.720000 --> 0:32:05.220000
 And yeah, so that's going to be it
 for this video now that we sort of

0:32:05.220000 --> 0:32:08.980000
 have an understanding of LDAP, I would
 say, not the best understanding,

0:32:08.980000 --> 0:32:12.520000
 but hopefully, you know, you you actually
 learned a couple of things.

0:32:12.520000 --> 0:32:16.780000
 Now that we have this understanding,
 we can now move on to LDAP injection.

0:32:16.780000 --> 0:32:21.400000
 So the focus of the next video is going
 to be on LDAP injection and what

0:32:21.400000 --> 0:32:26.460000
 the attacks, what the attack looks like,
 what the queries look like, etc.

0:32:26.460000 --> 0:32:29.160000
 So with that being said, that's
 going to be it for this video.

0:32:29.160000 --> 0:32:31.220000
 And I will be seeing you
 in the next video.

