WEBVTT

0:00:03.980000 --> 0:00:06.380000
 Hello everyone and welcome.

0:00:06.380000 --> 0:00:10.780000
 In this video we're going to be
 taking a look at XML injection.

0:00:10.780000 --> 0:00:15.860000
 We're also going to be taking a look
 at some of the other XML related

0:00:15.860000 --> 0:00:19.080000
 attacks or XML attacks,
 if that makes sense.

0:00:19.080000 --> 0:00:23.840000
 But the focus is going to be XML injection
 and we're going to learn about

0:00:23.840000 --> 0:00:28.280000
 what it is, what it involves different
 types of injection attacks against

0:00:28.280000 --> 0:00:32.740000
 XML. And then we're going to take a
 look at a practical example using

0:00:32.740000 --> 0:00:36.060000
 one of the labs on the INE platform.

0:00:36.060000 --> 0:00:40.220000
 So we're going to start over the theoretical
 stuff first and then put

0:00:40.220000 --> 0:00:41.500000
 it all into context.

0:00:41.500000 --> 0:00:43.040000
 So let's get started.

0:00:43.040000 --> 0:00:48.000000
 The previous video, you sort of got
 an idea as to what XML is, how it

0:00:48.000000 --> 0:00:51.720000
 works, how it's used, the
 formatting, syntax, etc.

0:00:51.720000 --> 0:00:55.000000
 And I hope that was sort of illuminating
 because it's really going to

0:00:55.000000 --> 0:00:56.200000
 come into play here.

0:00:56.200000 --> 0:01:00.360000
 So XML injection, what is XML injection?

0:01:00.360000 --> 0:01:05.320000
 Well, XML injection is a vulnerability that
 occurs when an attacker manipulates

0:01:05.320000 --> 0:01:11.360000
 user input to inject malicious XML data
 or let's say malformed XML data

0:01:11.360000 --> 0:01:14.580000
 into an XML document or query.

0:01:14.580000 --> 0:01:19.500000
 Now, this will all depend on how the web
 application is using XML as you'll

0:01:19.500000 --> 0:01:21.400000
 see in the practical section.

0:01:21.400000 --> 0:01:25.840000
 But this can lead to unauthorized access,
 data leakage or manipulation

0:01:25.840000 --> 0:01:30.920000
 of the application behavior or the
 way it essentially operates.

0:01:30.920000 --> 0:01:34.360000
 It's important to note, and this is
 something that I really wanted to

0:01:34.360000 --> 0:01:39.000000
 approach the correct way, that
 XML injection is a broad term.

0:01:39.000000 --> 0:01:43.600000
 It's not a specific vulnerability because
 there's different types of XML

0:01:43.600000 --> 0:01:48.180000
 injection. It's a broader term that
 refers to manipulating or injecting

0:01:48.180000 --> 0:01:53.220000
 malicious XML content into a
 system that processes XML.

0:01:53.220000 --> 0:01:58.540000
 And it exploits vulnerabilities in
 applications that accept XML input

0:01:58.540000 --> 0:02:00.620000
 or use XML based queries.

0:02:00.620000 --> 0:02:05.200000
 The second point there being the most
 important to interact with data

0:02:05.200000 --> 0:02:10.260000
 sources. Now, as you'll see, not just
 in this video, but in the next video,

0:02:10.260000 --> 0:02:17.000000
 where we'll take a look at external entities
 and external entity injection,

0:02:17.000000 --> 0:02:21.520000
 that generally speaking falls under
 XML injection, because XML injection

0:02:21.520000 --> 0:02:26.800000
 is sort of a broad category that includes
 subtypes, if you will, subtypes

0:02:26.800000 --> 0:02:27.940000
 of vulnerabilities.

0:02:27.940000 --> 0:02:31.580000
 So, how exactly does XML injection work?

0:02:31.580000 --> 0:02:35.140000
 Well, just like any other injection
 attack or vulnerability we've looked

0:02:35.140000 --> 0:02:39.000000
 at in this course, as well as others,
 it all starts from an input point

0:02:39.000000 --> 0:02:45.400000
 or an application input, right?

0:02:45.400000 --> 0:02:49.100000
 So, XML input or identify an application
 that's using XML to a certain

0:02:49.100000 --> 0:02:54.380000
 extent, and then identify application
 inputs that accept XML input.

0:02:54.380000 --> 0:03:00.560000
 So, you know, you can think of via APIs
 rest, sorry, not rest, soap, web

0:03:00.560000 --> 0:03:04.740000
 services or forms, login
 forms, red forms, etc.

0:03:04.740000 --> 0:03:07.000000
 And then of course, you have
 your malicious payload.

0:03:07.000000 --> 0:03:10.840000
 So, the attacker injects additional
 XML elements or attributes into the

0:03:10.840000 --> 0:03:16.000000
 input, right? And the impact is that
 the XML structure is modified to

0:03:16.000000 --> 0:03:19.200000
 bypass, you know, authentication, for
 example, or retrieve unauthorized

0:03:19.200000 --> 0:03:24.000000
 data. And that's pretty much it, just
 like any other injection attack,

0:03:24.000000 --> 0:03:25.940000
 the workflow is fairly simple.

0:03:25.940000 --> 0:03:35.740000
 But the differences or the advanced
 aspect of XML-based attacks all come

0:03:35.740000 --> 0:03:40.120000
 into play when we'll be exploring the
 different types of injection, if

0:03:40.120000 --> 0:03:40.920000
 that makes sense.

0:03:40.920000 --> 0:03:44.160000
 So, there's a couple of key characteristics
 that you need to be aware

0:03:44.160000 --> 0:03:47.100000
 of, right? In terms of XML injection.

0:03:47.100000 --> 0:03:50.680000
 So, firstly, you're targeting XML
 input fields or XML queries.

0:03:50.680000 --> 0:03:55.600000
 Secondly, you know, inject new
 elements, attributes or data.

0:03:55.600000 --> 0:03:59.000000
 And, you know, this particular type
 of attack is often used to bypass

0:03:59.000000 --> 0:04:03.540000
 authentication, manipulate data, obviously,
 or trigger unexpected behavior

0:04:03.540000 --> 0:04:05.120000
 in the application.

0:04:05.120000 --> 0:04:09.120000
 So, let's take a look at a very basic
 example of XML injection, where

0:04:09.120000 --> 0:04:13.220000
 a vulnerable application passes
 XML input from the user.

0:04:13.220000 --> 0:04:17.020000
 So, in this case, you can see what's being
 taken is a username and password,

0:04:17.020000 --> 0:04:23.620000
 right? And then this is an example of
 XML injections, where the attacker

0:04:23.620000 --> 0:04:24.860000
 injects a payload.

0:04:24.860000 --> 0:04:28.400000
 In this case, do not take the payload
 that I've put in here seriously.

0:04:28.400000 --> 0:04:33.140000
 I'm just using the SQL injection payload
 just to show you what it would

0:04:33.140000 --> 0:04:38.060000
 look like, because if I went into like
 tag injection at this point in

0:04:38.060000 --> 0:04:39.800000
 time, it would really confuse you.

0:04:39.800000 --> 0:04:42.100000
 So, I'm just using a placeholder there.

0:04:42.100000 --> 0:04:44.980000
 But the bottom line is that's where
 you would perform the injection.

0:04:44.980000 --> 0:04:48.700000
 Now, what you exactly you
 inject is the key, right?

0:04:48.700000 --> 0:04:52.840000
 Now, what this would lead to is that,
 you know, you would potentially

0:04:52.840000 --> 0:04:57.700000
 be able to manipulate an XML-based query,
 in this case, to bypass authentication.

0:04:57.700000 --> 0:05:00.020000
 So, just wanted to highlight that.

0:05:00.020000 --> 0:05:05.040000
 Now, that brings us to arguably one
 of the most important slides in this

0:05:05.040000 --> 0:05:06.980000
 slide deck or in this presentation.

0:05:06.980000 --> 0:05:11.720000
 And that is the different types of XML
 injection attacks or vulnerabilities.

0:05:11.720000 --> 0:05:15.100000
 So, the ones I've highlighted in red are
 the ones we are going to be focusing

0:05:15.100000 --> 0:05:17.940000
 on in this video and in the next video.

0:05:17.940000 --> 0:05:20.680000
 And it'll become clear why.

0:05:20.680000 --> 0:05:23.800000
 But we obviously have the X, you know,
 the first type, which is XML data

0:05:23.800000 --> 0:05:29.020000
 manipulation, where you alter
 XML data to behavior.

0:05:29.020000 --> 0:05:32.980000
 The impact of this will be data tampering
 by passing authentication.

0:05:32.980000 --> 0:05:36.820000
 You then have tag injection, right,
 which will be exploring precisely

0:05:36.820000 --> 0:05:41.660000
 in this video, where you inject new or
 modified XML tags into the document.

0:05:41.660000 --> 0:05:46.500000
 So, what the impact here would be privilege
 escalation or XML passing

0:05:46.500000 --> 0:05:50.820000
 issues, both of which we'll actually see,
 you know, hands-on or practically.

0:05:50.820000 --> 0:05:55.300000
 We then have X-path injection, which
 will not be covering in this course.

0:05:55.300000 --> 0:05:58.120000
 Again, it's not really important why.

0:05:58.120000 --> 0:06:02.840000
 But this will be covered most likely
 in the server side course.

0:06:02.840000 --> 0:06:06.260000
 But this is where you inject
 malicious X-path expression.

0:06:06.260000 --> 0:06:11.020000
 So, the impact being unauthorized data
 access, authentication, bypass,

0:06:11.020000 --> 0:06:16.100000
 etc. The other vulnerability or the
 next one, arguably the most popular,

0:06:16.100000 --> 0:06:20.480000
 if you will, when it comes down to
 XML, is going to be the, you know,

0:06:20.480000 --> 0:06:25.640000
 X-X-E or XML external entity, where
 you exploit external entities in XML

0:06:25.640000 --> 0:06:28.860000
 processing. We'll be exploring this
 in the next video, so we don't need

0:06:28.860000 --> 0:06:30.760000
 to dive into it right now.

0:06:30.760000 --> 0:06:34.620000
 But we also have other types, which, you
 know, really wouldn't be considered

0:06:34.620000 --> 0:06:38.980000
 injection, you know, injection-based attacks,
 like Billy and Laughs attack.

0:06:38.980000 --> 0:06:44.460000
 But we also have attribute injection,
 where it's sort of, there's quite

0:06:44.460000 --> 0:06:46.040000
 a few categories.

0:06:46.040000 --> 0:06:51.280000
 In my mind, you know, this type of categorization
 is important, you know,

0:06:51.280000 --> 0:06:54.020000
 so you understand exactly
 what you're doing.

0:06:54.020000 --> 0:06:56.440000
 But attribute injection
 is self-explanatory.

0:06:56.440000 --> 0:07:01.040000
 You are injecting or manipulating
 attributes in XML.

0:07:01.040000 --> 0:07:04.280000
 And then you have schema poisoning,
 where you manipulate XML schemas for

0:07:04.280000 --> 0:07:06.020000
 malicious purposes.

0:07:06.020000 --> 0:07:09.260000
 Not really that common anymore,
 but there you are.

0:07:09.260000 --> 0:07:13.080000
 You also have XML bombs, where you large,
 you know, large or deeply nested

0:07:13.080000 --> 0:07:18.180000
 XML documents are injected or somehow
 input to overload the servers.

0:07:18.180000 --> 0:07:20.920000
 These are mostly denial of service,
 hence the reason we're not covering

0:07:20.920000 --> 0:07:23.440000
 them. And then X include injection.

0:07:23.440000 --> 0:07:27.480000
 This is where you include malicious
 external content in XML.

0:07:27.480000 --> 0:07:32.940000
 The impact is fairly obvious, file inclusion,
 sensitive information disclosure.

0:07:32.940000 --> 0:07:37.500000
 And then XML content manipulation is
 where you inject malicious content

0:07:37.500000 --> 0:07:43.600000
 for the sole purpose of disrupting or
 exploiting the application logic.

0:07:43.600000 --> 0:07:46.780000
 We're generally speaking, would fall
 under any of these categories.

0:07:46.780000 --> 0:07:50.700000
 It all depends on the impact, which
 is why I highlighted the impact or

0:07:50.700000 --> 0:07:57.300000
 the objective column to sort of help
 you understand what is possible.

0:07:57.300000 --> 0:08:00.760000
 And of course, this is not exclusive,
 or I'm not saying this is set in

0:08:00.760000 --> 0:08:04.800000
 stone. At the end of the day, it'll
 all rely or all depend on the way

0:08:04.800000 --> 0:08:08.040000
 the application is using XML, right?

0:08:08.040000 --> 0:08:10.940000
 But with that being said, the ones
 in red are sort of going to be the

0:08:10.940000 --> 0:08:15.420000
 focus here. And again, the reason for
 me making that decision comes down

0:08:15.420000 --> 0:08:22.560000
 to a couple of factors, a the prevalence
 of said vulnerabilities and the

0:08:22.560000 --> 0:08:28.260000
 fact that they're sort of represented
 overwhelmingly when it comes down

0:08:28.260000 --> 0:08:32.120000
 to XML attacks. Now that may
 change, and it has changed.

0:08:32.120000 --> 0:08:37.100000
 But the one that's always remained is,
 you know, standard tag injection,

0:08:37.100000 --> 0:08:39.380000
 X, X, E, X path is there.

0:08:39.380000 --> 0:08:41.600000
 But as I said, we're not
 covering that right now.

0:08:41.600000 --> 0:08:48.040000
 And then of course, to a less extent,
 you're also likely to find attribute

0:08:48.040000 --> 0:08:53.020000
 injection. But mostly, it's the ones
 highlighted in red that you're likely

0:08:53.020000 --> 0:08:59.540000
 to come across or are arguably the
 most, you know, have the potential

0:08:59.540000 --> 0:09:04.280000
 to cause the most impact just based
 on, you know, what's possible.

0:09:04.280000 --> 0:09:08.460000
 So let's take a look at XML tag injection,
 because it's sort of the focus

0:09:08.460000 --> 0:09:13.980000
 here. So XML tag injection is a specific
 type of XML injection, where

0:09:13.980000 --> 0:09:17.400000
 the attacker adds or modifies
 XML tags in the input.

0:09:17.400000 --> 0:09:21.940000
 And it focuses on manipulating the structure
 of the XML document by injecting

0:09:21.940000 --> 0:09:24.380000
 new or unexpected tags.

0:09:24.380000 --> 0:09:28.680000
 And the key characteristics are a focuses
 on injecting tags rather than

0:09:28.680000 --> 0:09:30.740000
 data or attributes.

0:09:30.740000 --> 0:09:36.240000
 And remember, there's a very important
 thing that I need to mention here.

0:09:36.240000 --> 0:09:43.720000
 That first key characteristic is not
 100% accurate, especially when you

0:09:43.720000 --> 0:09:47.860000
 think about it from the perspective
 of a pen test, and as we'll see, a

0:09:47.860000 --> 0:09:54.180000
 tag, an injected tag could be considered
 data or could have legitimate

0:09:54.180000 --> 0:09:59.920000
 data. But the key is that instead of
 injecting data, you're using a tag

0:09:59.920000 --> 0:10:04.940000
 right for the injection, but that tag
 or that payload that you're injecting

0:10:04.940000 --> 0:10:10.260000
 that comprises of tags
 could contain data.

0:10:10.260000 --> 0:10:12.860000
 So it's important that
 you keep that in mind.

0:10:12.860000 --> 0:10:16.960000
 It's typically or often used to modify
 the XML document structure, disrupt

0:10:16.960000 --> 0:10:22.380000
 passing or trigger unexpected behavior
 in the application or web application.

0:10:22.380000 --> 0:10:26.640000
 So here's example one of what XML tag
 injection looks like, where the

0:10:26.640000 --> 0:10:29.060000
 attacker injects the admin tag.

0:10:29.060000 --> 0:10:35.320000
 What's happening here is that the role
 tags used to define the role of

0:10:35.320000 --> 0:10:39.680000
 the user. So this could be potentially a
 privilege escalation of vulnerability,

0:10:39.680000 --> 0:10:44.200000
 or you could gain the impact would
 be privilege escalation.

0:10:44.200000 --> 0:10:50.280000
 So if we injected and we knew that there
 was an admin tag, the injected

0:10:50.280000 --> 0:10:53.880000
 admin tag would trick the application into
 assigning the attacker administrative

0:10:53.880000 --> 0:10:56.280000
 privileges. That's quite common.

0:10:56.280000 --> 0:10:59.920000
 And then example two here, we have a
 little bit more of a complex example

0:10:59.920000 --> 0:11:08.060000
 where you can see that right over here,
 we have the users and then user,

0:11:08.060000 --> 0:11:13.600000
 and then the attributes there being
 username, password, and then group.

0:11:13.600000 --> 0:11:19.000000
 So if either updating his profile, in
 this particular case, the user would

0:11:19.000000 --> 0:11:24.640000
 be Joe, or during the registration
 process, Joe is able to inject some

0:11:24.640000 --> 0:11:28.800000
 XML meta characters, and we'll talk about
 meta characters within the document

0:11:28.800000 --> 0:11:33.920000
 meta characters, sort of like delimiters
 or anything that we'll actually

0:11:33.920000 --> 0:11:38.440000
 get to it. So what happens is that if
 the application fails to contextually

0:11:38.440000 --> 0:11:41.880000
 validate data or input, it is
 vulnerable to XML injection.

0:11:41.880000 --> 0:11:46.380000
 So I'm actually giving you the handbook
 here for identifying the presence

0:11:46.380000 --> 0:11:50.840000
 of an XML injection vulnerability,
 in this case, more specifically, or

0:11:50.840000 --> 0:11:57.280000
 specifically, in this case, the
 XML tag injection vulnerability.

0:11:57.280000 --> 0:12:06.440000
 So the meta characters are your single
 quote, double quote, less than,

0:12:06.440000 --> 0:12:09.440000
 and greater than, and of
 course, the ampersand.

0:12:09.440000 --> 0:12:16.120000
 So again, leveraging or still following
 along with this example, in order

0:12:16.120000 --> 0:12:19.520000
 to test the application against XML
 injection, we have to inject meta

0:12:19.520000 --> 0:12:22.800000
 characters attempting to break
 some of the structures.

0:12:22.800000 --> 0:12:27.920000
 So this will essentially result in throwing
 exceptions or the web application

0:12:27.920000 --> 0:12:30.740000
 throwing exceptions during
 the XML passing.

0:12:30.740000 --> 0:12:35.940000
 So just think of error based SQL injection,
 where you throw a single quote,

0:12:35.940000 --> 0:12:40.780000
 and you're looking for specific output
 that indicates a the presence of

0:12:40.780000 --> 0:12:48.820000
 a SQL injection vulnerability, or b the presence
 of a SQL injection vulnerability,

0:12:48.820000 --> 0:12:54.780000
 and instead of also and b the type
 of SQL injection vulnerability.

0:12:54.780000 --> 0:12:58.880000
 So if you don't get an error, it doesn't
 really mean that it's not vulnerable

0:12:58.880000 --> 0:13:02.360000
 to SQL injection, it might
 be blind SQL injection.

0:13:02.360000 --> 0:13:04.860000
 And in this case, this
 is sort of error based.

0:13:04.860000 --> 0:13:09.660000
 So you're likely to see some kind of error
 indicating that yes, this particular

0:13:09.660000 --> 0:13:15.720000
 parameter, sorry, this particular field
 is indeed vulnerable to XML injection.

0:13:15.720000 --> 0:13:22.120000
 So that brings us to testing for XML injection,
 where I want to talk specifically

0:13:22.120000 --> 0:13:29.040000
 about how you can identify XML injection
 vulnerabilities using the what

0:13:29.040000 --> 0:13:33.280000
 I'd mentioned previously, the meta
 characters, right over here.

0:13:33.280000 --> 0:13:36.840000
 So that's what we're sort
 of getting into right now.

0:13:36.840000 --> 0:13:40.220000
 So we start off with single
 and double quotes.

0:13:40.220000 --> 0:13:43.360000
 So single and double quotes are used
 to define an attribute value in the

0:13:43.360000 --> 0:13:48.240000
 tag. This should give you an idea as
 to when they should be used, if that

0:13:48.240000 --> 0:13:52.960000
 makes sense. So in this case, you have
 group ID is equal to ID, double

0:13:52.960000 --> 0:13:56.420000
 quote, right? These are
 sort of valid uses.

0:13:56.420000 --> 0:14:00.600000
 And then an idea like the following will
 make the XML incorrect, essentially

0:14:00.600000 --> 0:14:06.060000
 showing you what inserting a double
 quote or single quote will do, you

0:14:06.060000 --> 0:14:11.460000
 know, therefore indicating the the presence
 of a an injection vulnerability,

0:14:11.460000 --> 0:14:13.400000
 tag injection vulnerability.

0:14:13.400000 --> 0:14:16.920000
 And then the other meta character is
 the ampersand, right, which is used

0:14:16.920000 --> 0:14:19.300000
 to represent entities
 in the following way.

0:14:19.300000 --> 0:14:23.160000
 So you have the ampersand and
 then entity name, semicolon.

0:14:23.160000 --> 0:14:27.680000
 Now, by injecting something like ampersand
 name, we can trigger an error

0:14:27.680000 --> 0:14:29.020000
 if the entity is not defined.

0:14:29.020000 --> 0:14:33.180000
 So you actually don't need to provide
 an entity name just using an ampersand

0:14:33.180000 --> 0:14:38.340000
 should throw an error unless there's
 something interesting going on.

0:14:38.340000 --> 0:14:42.900000
 As I go on to state here, additionally,
 we can attempt to remove the final

0:14:42.900000 --> 0:14:49.640000
 semicolon, generating a
 malformed XML structure.

0:14:49.640000 --> 0:14:52.880000
 And then of course, you have
 your angular parentheses.

0:14:52.880000 --> 0:14:57.220000
 So using angular using the angular
 parentheses, we can begin to define

0:14:57.220000 --> 0:15:02.840000
 several areas within the XML document,
 such as tag names, comments, and

0:15:02.840000 --> 0:15:03.920000
 c data sections.

0:15:03.920000 --> 0:15:08.380000
 So, you know, not really
 important at the moment.

0:15:08.380000 --> 0:15:09.580000
 But there we are anyway.

0:15:09.580000 --> 0:15:14.100000
 So we're now at the practical section
 of this course, or of this video,

0:15:14.100000 --> 0:15:21.740000
 I should say. And as I lab associated
 with it, it's going to be just below.

0:15:21.740000 --> 0:15:26.860000
 It's just the lab is going to
 be just below this video.

0:15:26.860000 --> 0:15:29.360000
 And it's called XML injection.

0:15:29.360000 --> 0:15:33.980000
 So you'll be provided with access to
 a preconfigured calilinic system.

0:15:33.980000 --> 0:15:35.880000
 And let's not waste any more time.

0:15:35.880000 --> 0:15:40.000000
 I'm going to fire up my lab environment,
 and I'll see you in there in

0:15:40.000000 --> 0:15:44.040000
 a couple of seconds.

0:15:44.040000 --> 0:15:47.680000
 All right, so I am back within
 the lab environment.

0:15:47.680000 --> 0:15:50.560000
 And as you can see, you'll be provided
 with access to a preconfigured

0:15:50.560000 --> 0:15:53.060000
 calilinic system within your browser.

0:15:53.060000 --> 0:15:56.220000
 And the target web application, which
 is essentially a set of challenges,

0:15:56.220000 --> 0:16:06.700000
 is accessible on or via the URL, HTTP,
 not HTTPS, info dot XML injection

0:16:06.700000 --> 0:16:13.460000
 dot labs. Okay, and for the purpose of
 this demonstration, I'm just going

0:16:13.460000 --> 0:16:18.240000
 to be using XML V one or the first
 lab, you can go through the others.

0:16:18.240000 --> 0:16:20.140000
 It's a challenge lab.

0:16:20.140000 --> 0:16:24.820000
 The solutions have been documented
 in the lab documentation.

0:16:24.820000 --> 0:16:30.880000
 But these are designed to be challenges
 anyway, we'll click on XML V one.

0:16:30.880000 --> 0:16:35.920000
 And there we are, we can see we have
 a login form and we can also register

0:16:35.920000 --> 0:16:41.580000
 now for the sake of brevity of this
 demonstration, the vulnerable form

0:16:41.580000 --> 0:16:43.540000
 is not the login form.

0:16:43.540000 --> 0:16:44.860000
 It's the registration form.

0:16:44.860000 --> 0:16:47.360000
 So let's click on the registration form.

0:16:47.360000 --> 0:16:51.180000
 And you can see tasks us for a
 name, username and password.

0:16:51.180000 --> 0:16:57.540000
 Now, if we view the page source here,
 we can see that nothing too crazy

0:16:57.540000 --> 0:17:00.040000
 or nothing too out of the
 order is happening.

0:17:00.040000 --> 0:17:03.660000
 We have a function that's being executed,
 which appears to be a JavaScript

0:17:03.660000 --> 0:17:07.560000
 function. So it's probably wise to
 take a look at what that does.

0:17:07.560000 --> 0:17:13.300000
 But you can see we have the placeholder
 is just name ID name user password.

0:17:13.300000 --> 0:17:17.300000
 Okay. So let's try and create
 a standard account.

0:17:17.300000 --> 0:17:20.580000
 Okay, so I'm just going
 to call this user test.

0:17:20.580000 --> 0:17:24.000000
 Okay, and we'll say the username
 is test as well.

0:17:24.000000 --> 0:17:26.540000
 And the password is just
 going to be password.

0:17:26.540000 --> 0:17:29.500000
 All right, so this is typically what
 you do in a pen test, just create

0:17:29.500000 --> 0:17:32.280000
 a legitimate user sign up.

0:17:32.280000 --> 0:17:35.840000
 And you can see it says at the bottom
 here, welcome aboard test.

0:17:35.840000 --> 0:17:37.220000
 You can log in here.

0:17:37.220000 --> 0:17:40.500000
 All right, interesting, very, very interesting
 to see how that is passed

0:17:40.500000 --> 0:17:45.080000
 back. That's probably a good indicator
 that there is, you know, that XML

0:17:45.080000 --> 0:17:48.520000
 is being used because this is typically
 how it's used, right?

0:17:48.520000 --> 0:18:00.460000
 So we can click on login and let's see what
 it means to type that in correctly.

0:18:00.460000 --> 0:18:04.720000
 So there we go. And it says, oh boy,
 I'm sorry, buddy, but you're not

0:18:04.720000 --> 0:18:05.980000
 an elite member.

0:18:05.980000 --> 0:18:07.480000
 And that's the core of this challenge.

0:18:07.480000 --> 0:18:15.100000
 So the objective here is to utilize
 XML injection, more specifically XML

0:18:15.100000 --> 0:18:20.000000
 tag injection to elevate our privileges
 to that, you know, hopefully of

0:18:20.000000 --> 0:18:23.540000
 an admin. Okay, so we
 can take a step back.

0:18:23.540000 --> 0:18:27.100000
 And let's go to the registration
 form right over here.

0:18:27.100000 --> 0:18:30.940000
 Okay. And what we're now going to do
 is use what we learned in the slides

0:18:30.940000 --> 0:18:36.300000
 in terms of finding XML injection vulnerabilities
 by using some of the

0:18:36.300000 --> 0:18:38.080000
 meta characters I spoke of.

0:18:38.080000 --> 0:18:42.900000
 Okay. Now while we're waiting for that
 there, I'm just going to leave

0:18:42.900000 --> 0:18:46.000000
 the login page open there,
 because we may need it.

0:18:46.000000 --> 0:18:50.480000
 And we're going to test each of these
 fields, because each, you know,

0:18:50.480000 --> 0:18:53.980000
 pretty much any one of them could be
 vulnerable, or all of them could

0:18:53.980000 --> 0:18:57.020000
 be vulnerable to to XML injection.

0:18:57.020000 --> 0:18:59.280000
 So I always like starting
 with the first one.

0:18:59.280000 --> 0:19:00.740000
 So let's use the ampersand.

0:19:00.740000 --> 0:19:03.660000
 That's always been a
 good good one for me.

0:19:03.660000 --> 0:19:07.780000
 And I'm just going to call this user
 to so we actually know what we're

0:19:07.780000 --> 0:19:11.380000
 doing. So the first user
 normal users just test.

0:19:11.380000 --> 0:19:12.920000
 And this one is going to be two.

0:19:12.920000 --> 0:19:16.560000
 And the password will just say
 password right over here.

0:19:16.560000 --> 0:19:22.200000
 Now if the name parameter or the name
 field here is vulnerable to XML

0:19:22.200000 --> 0:19:26.180000
 injection, then we should
 get an XML pass error.

0:19:26.180000 --> 0:19:27.700000
 But let's see what happens.

0:19:27.700000 --> 0:19:29.100000
 So it's sign up.

0:19:29.100000 --> 0:19:33.600000
 And in this case, does not look vulnerable,
 because it actually doesn't

0:19:33.600000 --> 0:19:34.980000
 throw back any errors.

0:19:34.980000 --> 0:19:38.320000
 Okay. And of course we
 can try and log in.

0:19:38.320000 --> 0:19:40.020000
 So let's try and log in.

0:19:40.020000 --> 0:19:44.340000
 So we'll say two and password.

0:19:44.340000 --> 0:19:47.740000
 Interesting. So I'm thinking username
 or password is probably what we

0:19:47.740000 --> 0:19:50.480000
 want. Yeah, exactly as I expected.

0:19:50.480000 --> 0:19:55.460000
 So we'll go to register here,
 and open up a new page.

0:19:55.460000 --> 0:20:01.880000
 So I'll now say we'll, we'll create a
 user with the name three, the username

0:20:01.880000 --> 0:20:04.760000
 will also be actually,
 we want to inject here.

0:20:04.760000 --> 0:20:07.920000
 So we're going to use the ampersand.

0:20:07.920000 --> 0:20:11.360000
 And the password will just say
 password right over here.

0:20:11.360000 --> 0:20:13.820000
 And let's click on sign up.

0:20:13.820000 --> 0:20:15.500000
 And oh, there we go.

0:20:15.500000 --> 0:20:21.240000
 So oh my god, what have you done XML
 pass entity reference, no name.

0:20:21.240000 --> 0:20:22.980000
 And that's because we use the ampersand.

0:20:22.980000 --> 0:20:25.320000
 So remember, this is used
 to specify an entity name.

0:20:25.320000 --> 0:20:27.160000
 We mentioned it in the slides.

0:20:27.160000 --> 0:20:28.720000
 And there we are.

0:20:28.720000 --> 0:20:32.860000
 We've confirmed that there, you know,
 the username field is is vulnerable

0:20:32.860000 --> 0:20:35.120000
 to XML injection.

0:20:35.120000 --> 0:20:41.960000
 Okay, now in order for us to, you know,
 perform the injection here, in

0:20:41.960000 --> 0:20:46.460000
 alignment with our object, our objective
 of elevating our privileges,

0:20:46.460000 --> 0:20:51.720000
 we actually need to understand, you
 know, what tags are being used.

0:20:51.720000 --> 0:20:57.740000
 And if we just use the developer tools
 and inspect here, and, you know,

0:20:57.740000 --> 0:21:01.460000
 if you remember, when we are taking
 a look at the source of the, of this

0:21:01.460000 --> 0:21:04.780000
 web page, we saw that there was a function
 being called that's used for

0:21:04.780000 --> 0:21:08.640000
 registration. So we're going
 to the debugger here.

0:21:08.640000 --> 0:21:13.140000
 And we go, there we are one dot XML
 injection dot labs under JS, which

0:21:13.140000 --> 0:21:17.560000
 is JavaScript, we have core dot JS,
 okay, which is self explanatory.

0:21:17.560000 --> 0:21:20.360000
 I don't know if I can zoom in here.

0:21:20.360000 --> 0:21:22.680000
 Let's see, can I zoom in?

0:21:22.680000 --> 0:21:26.340000
 Let me try and increase the font size.

0:21:26.340000 --> 0:21:27.820000
 All right, there we are.

0:21:27.820000 --> 0:21:30.240000
 You should be able to read
 that a little bit better.

0:21:30.240000 --> 0:21:33.980000
 But yeah, so you can see this
 was the function being called.

0:21:33.980000 --> 0:21:41.120000
 So if I go back in here, and I just
 click on view page source, WSLoggin

0:21:41.120000 --> 0:21:42.840000
 is used for logging in.

0:21:42.840000 --> 0:21:44.460000
 This form is not vulnerable.

0:21:44.460000 --> 0:21:49.280000
 So if we click on register here, and
 we view the page source here, you

0:21:49.280000 --> 0:21:55.720000
 can see that the function WS register
 is being used for registration.

0:21:55.720000 --> 0:22:00.540000
 So going back to the developer tools
 under debugger, you can see we have

0:22:00.540000 --> 0:22:02.600000
 the WS register function.

0:22:02.600000 --> 0:22:08.280000
 And in this case, using Ajax, which
 you should not surprise me.

0:22:08.280000 --> 0:22:09.980000
 But you can see we have X error.

0:22:09.980000 --> 0:22:14.500000
 So we know for sure that
 XML is being used.

0:22:14.500000 --> 0:22:18.700000
 Okay. And then we have the function
 WS log in, not really important.

0:22:18.700000 --> 0:22:20.480000
 But wait a minute.

0:22:20.480000 --> 0:22:22.080000
 What do we have here?

0:22:22.080000 --> 0:22:27.120000
 We have something called, we have a
 function called WS register old and

0:22:27.120000 --> 0:22:34.020000
 oh boy, look, look at this looks like
 a developer left the XML schema.

0:22:34.020000 --> 0:22:37.440000
 It's not really a DTD, because this
 is not the format you would expect

0:22:37.440000 --> 0:22:47.020000
 it in. This actually looks like a schema,
 or the structure, you know,

0:22:47.020000 --> 0:22:53.400000
 the actual schema structure
 that is, is being used here.

0:22:53.400000 --> 0:22:56.360000
 Now we don't know if this has been updated,
 because there's a reason this

0:22:56.360000 --> 0:22:58.300000
 has been called old.

0:22:58.300000 --> 0:23:04.080000
 But there we are, we can actually see
 how the registration form works.

0:23:04.080000 --> 0:23:07.740000
 So we know that the username
 field is vulnerable.

0:23:07.740000 --> 0:23:12.480000
 And we can see right over how it works.

0:23:12.480000 --> 0:23:14.860000
 So we have the root here.

0:23:14.860000 --> 0:23:19.520000
 So user, and then under user, we have
 a rule, which is I'm guessing the

0:23:19.520000 --> 0:23:22.880000
 role. So actually hold on.

0:23:22.880000 --> 0:23:24.960000
 Let's see how this works.

0:23:24.960000 --> 0:23:29.880000
 Yeah, I'm guessing that's the role, which
 means if normal users are registered

0:23:29.880000 --> 0:23:36.360000
 with a rule of two, then that means
 if we change this to one, that would

0:23:36.360000 --> 0:23:37.720000
 be an admin, hopefully.

0:23:37.720000 --> 0:23:42.820000
 And then we can see name, the name is
 input here, not a lot of sanitization

0:23:42.820000 --> 0:23:50.220000
 going on. But if we take a look at
 the username tags here, what we can

0:23:50.220000 --> 0:23:57.040000
 do is you can see it is expecting,
 as I mentioned in the introduction

0:23:57.040000 --> 0:24:00.220000
 to XML video, every tag
 needs to be closed.

0:24:00.220000 --> 0:24:05.880000
 Okay, now we can take advantage of
 this by closing the username tag.

0:24:05.880000 --> 0:24:07.520000
 Okay, so we close it.

0:24:07.520000 --> 0:24:14.320000
 We can specify a user, but then we can
 specify a username, but that will

0:24:14.320000 --> 0:24:15.840000
 just be a dummy username.

0:24:15.840000 --> 0:24:19.400000
 And we then close the username tag,
 and then we need to close the user

0:24:19.400000 --> 0:24:24.760000
 tag. But immediately after that, if
 this field is indeed vulnerable to

0:24:24.760000 --> 0:24:34.780000
 XML injection, we can actually, we can
 actually inject some other, some

0:24:34.780000 --> 0:24:36.020000
 other tags here.

0:24:36.020000 --> 0:24:40.860000
 And what we can do is actually, you
 know, create or use the user tag,

0:24:40.860000 --> 0:24:43.920000
 open the user tag to create another user.


0:24:43.920000 --> 0:24:49.740000
 Now with the rule, the rule tag and
 set that to one, and then set the

0:24:49.740000 --> 0:24:55.180000
 name to, you know, something cool,
 set the username to something cool.

0:24:55.180000 --> 0:25:10.700000
 And we don't the name tag as well as,
 actually, we would need to have

0:25:10.700000 --> 0:25:15.460000
 the username tag open to open it again,
 because remember, we closed it.

0:25:15.460000 --> 0:25:22.020000
 So the reason we need to specify it
 is because that's how the XML knows

0:25:22.020000 --> 0:25:25.780000
 that it's valid, because you're specifying
 username, and then it'll close

0:25:25.780000 --> 0:25:27.820000
 it for us right over here.

0:25:27.820000 --> 0:25:32.700000
 So in essence, what we're doing is, let
 me actually generate it here before

0:25:32.700000 --> 0:25:36.840000
 we actually use it so that I know that
 I'm logically saying, or that I'm

0:25:36.840000 --> 0:25:38.540000
 doing something logical.

0:25:38.540000 --> 0:25:43.900000
 So what we're doing is we're essentially
 saying, we can specify just a

0:25:43.900000 --> 0:25:48.480000
 dummy username, like so, and then we
 can close the username tag, like

0:25:48.480000 --> 0:25:53.940000
 so, and the user tag, right over here,
 and then create a new user tag

0:25:53.940000 --> 0:25:58.440000
 for the new user registration.

0:25:58.440000 --> 0:26:03.340000
 So user, and then under user, we would
 need to say the rule, instead of

0:26:03.340000 --> 0:26:07.380000
 two, we can set it to one,
 close the rule tag.

0:26:07.380000 --> 0:26:12.780000
 Okay, and then we need to set the name,
 remember, so the name can be our

0:26:12.780000 --> 0:26:18.240000
 new name, we'll just call this account
 pond, or pond, if you will, close

0:26:18.240000 --> 0:26:27.220000
 that. And then because now we want the
 username field to operate correctly,

0:26:27.220000 --> 0:26:33.480000
 we just need to say username, like
 so, and then just specify the name

0:26:33.480000 --> 0:26:34.740000
 of the new username.

0:26:34.740000 --> 0:26:40.540000
 So we're using this to yeah, so fairly
 simple what's going on, we're just

0:26:40.540000 --> 0:26:44.860000
 closing the original username tag there.

0:26:44.860000 --> 0:26:49.800000
 And because we're injecting it, you
 know, ideally this would not work.

0:26:49.800000 --> 0:26:55.320000
 It's part of the injection, but we also
 close the hold on, what am I saying,

0:26:55.320000 --> 0:26:56.820000
 use the same tag?

0:26:56.820000 --> 0:26:59.360000
 No, that's going to be the user tag.

0:26:59.360000 --> 0:27:01.180000
 What am I saying here?

0:27:01.180000 --> 0:27:06.720000
 So yeah, use a tag, and then we create
 a new user tag to essentially start

0:27:06.720000 --> 0:27:10.200000
 this process again, but now
 we specify what we want.

0:27:10.200000 --> 0:27:14.820000
 So the rule is going to be one, and
 then we set a new name, and then we

0:27:14.820000 --> 0:27:18.920000
 set a new username, and this particular
 username tag here will close it

0:27:18.920000 --> 0:27:22.340000
 for us, and therefore create
 the new user with that info.

0:27:22.340000 --> 0:27:24.340000
 So let's test it out.

0:27:24.340000 --> 0:27:31.040000
 Okay, so now we'll just call this
 user, we can just say useless.

0:27:31.040000 --> 0:27:34.280000
 It really doesn't matter what we specify
 here, but then here is where

0:27:34.280000 --> 0:27:36.600000
 we would inject this right over here.

0:27:36.600000 --> 0:27:43.820000
 Let me open this up, and let me make
 sure there's no trailing spaces here.

0:27:43.820000 --> 0:27:45.740000
 Although I don't think
 that would be an issue.

0:27:45.740000 --> 0:27:47.280000
 Yeah, that should be fine.

0:27:47.280000 --> 0:27:55.000000
 So we copy this here, and the password
 would just be, we can just go with

0:27:55.000000 --> 0:27:58.300000
 password what what we've used previously.


0:27:58.300000 --> 0:28:03.360000
 So the new user that would be created
 would be called pond, not useless,

0:28:03.360000 --> 0:28:07.460000
 because remember, we're essentially
 doing it, we're creating a new user

0:28:07.460000 --> 0:28:11.180000
 using these tags or via XML injection.

0:28:11.180000 --> 0:28:16.880000
 So we hit sign up, and there we are,
 we can see it says welcome aboard

0:28:16.880000 --> 0:28:20.660000
 useless, and I'm not sure if that actually
 completed, but we can try and

0:28:20.660000 --> 0:28:26.180000
 log in. So we're going to use the new
 user called pond, and password,

0:28:26.180000 --> 0:28:31.180000
 and this user should have the rule
 or the rule of one, meaning admin.

0:28:31.180000 --> 0:28:32.920000
 And there we are, boom.

0:28:32.920000 --> 0:28:37.680000
 So congratulations, you're now an elite
 member, or you're an elite member

0:28:37.680000 --> 0:28:44.260000
 now, and we have the customary
 1337 or 1337 there.

0:28:44.260000 --> 0:28:47.020000
 Anyway, that's what I
 wanted to demonstrate.

0:28:47.020000 --> 0:28:50.880000
 This is as simple as it gets when we're
 talking about tag based injection

0:28:50.880000 --> 0:28:53.040000
 or XML tag injection.

0:28:53.040000 --> 0:28:56.420000
 And with that being said, that brings us
 to the end of the practical demonstration

0:28:56.420000 --> 0:28:59.060000
 section of this video.

0:28:59.060000 --> 0:29:05.660000
 All right, so that was XML injection,
 more specifically tag injection,

0:29:05.660000 --> 0:29:07.880000
 and hopefully found it valuable.

0:29:07.880000 --> 0:29:10.820000
 Make sure you go through the
 rest of the challenges.

0:29:10.820000 --> 0:29:15.040000
 Very, very nice, very well built to sort
 of demonstrate what XML injection

0:29:15.040000 --> 0:29:22.380000
 is all about. But now we're going to
 move on to another type of XML, you

0:29:22.380000 --> 0:29:27.280000
 know, attack or vulnerability
 that we explored briefly here.

0:29:27.280000 --> 0:29:33.100000
 And that's X X E or XML external
 entity injection.

0:29:33.100000 --> 0:29:35.080000
 We're going to be exploring
 that in the next video.

0:29:35.080000 --> 0:29:38.320000
 So with that being said, that's
 going to be it for this video.

0:29:38.320000 --> 0:29:40.960000
 And I'll be seeing you in the next video.


