WEBVTT

0:00:03.560000 --> 0:00:09.820000
 Hello everyone and welcome to the Advanced
 Injection Attacks course summary.

0:00:09.820000 --> 0:00:15.140000
 So this is the final video of this
 course where we sort of revisit or

0:00:15.140000 --> 0:00:20.760000
 review everything we've covered in the
 course and sort of see, you know,

0:00:20.760000 --> 0:00:24.620000
 how far we've come from the course
 overview of the first video of the

0:00:24.620000 --> 0:00:30.080000
 course and also validate that we essentially
 that I covered everything

0:00:30.080000 --> 0:00:32.520000
 that I told you I was going to cover.

0:00:32.520000 --> 0:00:36.440000
 So this is a very, very useful milestone.


0:00:36.440000 --> 0:00:41.840000
 You know, at the end of each course
 it's very important to again just

0:00:41.840000 --> 0:00:48.160000
 look back and see what, you know, everything
 you've learned and everything

0:00:48.160000 --> 0:00:52.200000
 you should be able to do from
 a practical perspective.

0:00:52.200000 --> 0:00:58.500000
 So let's kick things off by revisiting
 the key concepts that again I outlined

0:00:58.500000 --> 0:01:01.420000
 in the course overview video.

0:01:01.420000 --> 0:01:05.880000
 So these were sort of the major topics
 that I wanted to cover starting

0:01:05.880000 --> 0:01:07.840000
 off with the fundamentals
 of SQL injection.

0:01:07.840000 --> 0:01:12.480000
 Again, that was covered quite extensively,
 not just the fundamentals but

0:01:12.480000 --> 0:01:15.160000
 also building on that.

0:01:15.160000 --> 0:01:20.000000
 We also took a look at how to automate
 identification and exploitation

0:01:20.000000 --> 0:01:23.880000
 with SQL maps. So we actually went a
 little bit further by also covering

0:01:23.880000 --> 0:01:30.700000
 the identification portion, which I
 really did not intend to within of

0:01:30.700000 --> 0:01:35.660000
 course, explore advanced SQL injection
 techniques more specifically second

0:01:35.660000 --> 0:01:36.700000
 order SQL injection.

0:01:36.700000 --> 0:01:41.240000
 I would say in a more practical sense,
 but you also understood or gotten

0:01:41.240000 --> 0:01:46.720000
 understanding of the, you know, the
 out of band techniques in terms of

0:01:46.720000 --> 0:01:54.600000
 HTTP or DNS based exaltration, for example,
 we also covered no SQL injection,

0:01:54.600000 --> 0:02:00.340000
 you know, limited to Mongo primarily,
 but still gave it enough coverage.

0:02:00.340000 --> 0:02:06.940000
 We then, you know, explored LDAP injection
 ORM injection and of course,

0:02:06.940000 --> 0:02:12.660000
 XXC injection primarily, but we also
 explored a couple of other XXC or

0:02:12.660000 --> 0:02:14.300000
 XML based attacks.

0:02:14.300000 --> 0:02:18.880000
 So we actually went over or covered
 more than we were supposed to, you

0:02:18.880000 --> 0:02:21.440000
 know, in terms of the key concepts.

0:02:21.440000 --> 0:02:26.520000
 So if we revisit the learning outcomes,
 again, these are exactly the same

0:02:26.520000 --> 0:02:31.280000
 that, you know, I sort of laid
 out in the course of you.

0:02:31.280000 --> 0:02:34.400000
 So they haven't changed at all.

0:02:34.400000 --> 0:02:40.620000
 So the first was, you know, the fundamentals
 or the essentials of SQL

0:02:40.620000 --> 0:02:45.840000
 injection. So by the end of this course,
 you should have learned how to

0:02:45.840000 --> 0:02:50.420000
 identify and execute common techniques,
 SQL injection techniques like

0:02:50.420000 --> 0:02:55.980000
 error based union based and Boolean
 based SQL injection along with some

0:02:55.980000 --> 0:03:01.940000
 tidbits on how, you know, they can be prevented,
 which, you know, we actually

0:03:01.940000 --> 0:03:09.020000
 covered in addition to some more SQL
 injection vulnerabilities, you know,

0:03:09.020000 --> 0:03:17.340000
 like time based blind, et cetera.

0:03:17.340000 --> 0:03:20.380000
 And then we also suggested the use of
 tools like SQL map to automate the

0:03:20.380000 --> 0:03:23.760000
 detection and exploitation of
 SQL injection vulnerabilities.

0:03:23.760000 --> 0:03:26.500000
 And I don't think there's
 anything to add there.

0:03:26.500000 --> 0:03:30.880000
 We pretty much covered that quite extensively
 using different examples.

0:03:30.880000 --> 0:03:34.520000
 So quite happy with how that was covered.


0:03:34.520000 --> 0:03:38.940000
 And then of course, advanced SQL injection
 techniques by the end of the

0:03:38.940000 --> 0:03:43.100000
 course, you should be able to identify and
 exploit SQL injection vulnerabilities

0:03:43.100000 --> 0:03:48.140000
 or leverage techniques like, you know,
 out of, out of band and the second

0:03:48.140000 --> 0:03:53.340000
 order SQL injection, more so from a
 practical perspective, second order

0:03:53.340000 --> 0:03:58.440000
 out of band again, was a little bit
 difficult to demonstrate given the

0:03:58.440000 --> 0:04:03.780000
 requirements, the, the environmental
 requirements or prerequisites there.

0:04:03.780000 --> 0:04:08.880000
 But hopefully you were able to understand
 it with the explanations and

0:04:08.880000 --> 0:04:13.200000
 the various type of attacks scenarios
 that I laid out there.

0:04:13.200000 --> 0:04:16.520000
 And then in terms of no SQL injection,
 by the end of the course, you should

0:04:16.520000 --> 0:04:19.720000
 have learned how to identify and exploit
 no SQL injection vulnerabilities

0:04:19.720000 --> 0:04:21.740000
 in databases like Mongo.

0:04:21.740000 --> 0:04:26.120000
 So again, we stuck primarily to Mongo.

0:04:26.120000 --> 0:04:31.520000
 And yeah, I'm fairly happy
 with, with that.

0:04:31.520000 --> 0:04:33.140000
 And hopefully you are too.

0:04:33.140000 --> 0:04:35.860000
 So up to this point, we're looking good.

0:04:35.860000 --> 0:04:37.160000
 We covered everything.

0:04:37.160000 --> 0:04:39.900000
 Hopefully again, you share
 the same sentiment.

0:04:39.900000 --> 0:04:41.680000
 We then have LDAP injections.

0:04:41.680000 --> 0:04:46.440000
 So by the end of the course, you should
 have learned how LDAP systems,

0:04:46.440000 --> 0:04:48.400000
 you know, the various
 LDAP implementations.

0:04:48.400000 --> 0:04:52.080000
 So we actually went a little bit over
 here in terms of what we were supposed

0:04:52.080000 --> 0:04:56.200000
 to cover, but we learned quite
 a bit about LDAP theoretically.

0:04:56.200000 --> 0:05:00.560000
 And that's the objective there was for
 me, you know, you need to understand

0:05:00.560000 --> 0:05:05.180000
 LDAP quite well in order for you to
 understand injections or injection

0:05:05.180000 --> 0:05:09.740000
 based attacks, especially in relation
 to the web or how LDAP is utilized

0:05:09.740000 --> 0:05:15.560000
 there. So again, I think you can, you
 probably also agree with me that

0:05:15.560000 --> 0:05:17.460000
 we covered that quite well.

0:05:17.460000 --> 0:05:20.140000
 We then have ORM injections.

0:05:20.140000 --> 0:05:24.280000
 So by the end of the course, you should
 be able to firstly understand

0:05:24.280000 --> 0:05:33.920000
 ORM, you know, and manipulate
 application behavior.

0:05:33.920000 --> 0:05:37.900000
 And then finally, XSE injection, which
 as I mentioned previously or a

0:05:37.900000 --> 0:05:43.740000
 couple of minutes ago, we actually covered
 a few more XML related attacks.

0:05:43.740000 --> 0:05:46.820000
 But the bottom line is you should have
 developed a comprehensive understanding

0:05:46.820000 --> 0:05:54.760000
 of XML injection or, you know, XSE
 injection, I should say, the former

0:05:54.760000 --> 0:05:59.560000
 being XML external entity injection.

0:05:59.560000 --> 0:06:04.700000
 Yeah. So those were the learning outcomes
 that we had laid out in the

0:06:04.700000 --> 0:06:06.320000
 course overview video.

0:06:06.320000 --> 0:06:07.560000
 So nothing has changed.

0:06:07.560000 --> 0:06:11.660000
 And I think revisiting them, you can
 see that, yes, we pretty much hit

0:06:11.660000 --> 0:06:13.480000
 on every one of them.

0:06:13.480000 --> 0:06:15.780000
 So those are the learning outcomes.

0:06:15.780000 --> 0:06:20.160000
 That brings us to the real world applications
 of what you've just learned.

0:06:20.160000 --> 0:06:23.380000
 So how can you use this knowledge?

0:06:23.380000 --> 0:06:28.180000
 How can you use your newly acquired
 skills or abilities?

0:06:28.180000 --> 0:06:33.600000
 Well, starting off, these are very formative
 skills or this is very formative

0:06:33.600000 --> 0:06:38.580000
 knowledge in that the techniques covered
 in this course form the core

0:06:38.580000 --> 0:06:45.500000
 of what you'd expect to be a professional
 web application penetration

0:06:45.500000 --> 0:06:51.140000
 testers repertoire, essentially equipping
 you with the skills to identify

0:06:51.140000 --> 0:06:55.200000
 critical vulnerabilities, I should say,
 injection based vulnerabilities

0:06:55.200000 --> 0:07:01.920000
 like SQL injection, which again, you know,
 is a perennial OS top 10 threat.

0:07:01.920000 --> 0:07:03.840000
 Secondly, staying current.

0:07:03.840000 --> 0:07:07.420000
 This course pretty much addresses the
 growing popularity and adoption

0:07:07.420000 --> 0:07:12.580000
 of non-relational databases by equipping
 you with the skills required

0:07:12.580000 --> 0:07:14.540000
 to test no SQL databases.

0:07:14.540000 --> 0:07:19.900000
 So we didn't leave anything behind in
 terms of database testing, whether

0:07:19.900000 --> 0:07:26.820000
 they be relational databases or non
-relational databases like Mongo, for

0:07:26.820000 --> 0:07:30.360000
 example, then we have
 advanced techniques.

0:07:30.360000 --> 0:07:34.600000
 So, you know, this course equips you with
 an understanding of modern complex

0:07:34.600000 --> 0:07:38.640000
 multi-stage exploitation techniques
 like, you know, you're standard out

0:07:38.640000 --> 0:07:48.020000
 of band techniques, as well as you probably
 will run come across instances

0:07:48.020000 --> 0:07:51.180000
 of environments where
 they can be applied.

0:07:51.180000 --> 0:07:54.080000
 And then finally, diverse
 and comprehensive.

0:07:54.080000 --> 0:07:57.920000
 So that was one of my primary goals
 for this course was to go beyond the

0:07:57.920000 --> 0:08:02.840000
 standard injection vulnerabilities that,
 you know, are pretty much covered

0:08:02.840000 --> 0:08:08.140000
 from head to toe quite extensively, those
 being SQL injection vulnerabilities.

0:08:08.140000 --> 0:08:14.520000
 And I wanted to sort of explore some of the
 other injection based vulnerabilities

0:08:14.520000 --> 0:08:19.460000
 or attacks that, you know, sometimes
 you may not give enough credence

0:08:19.460000 --> 0:08:24.020000
 to, but are becoming increasingly
 relevant.

0:08:24.020000 --> 0:08:28.400000
 So this course reflects the diversity
 of modern application architectures

0:08:28.400000 --> 0:08:32.680000
 equipping you with the skills required
 to exploit secure, you know, directory

0:08:32.680000 --> 0:08:36.780000
 services and, of course,
 application frameworks.

0:08:36.780000 --> 0:08:40.940000
 And so now we have sort of the next
 steps or my recommendations for you

0:08:40.940000 --> 0:08:45.120000
 in terms of what to do next after this
 course in relation to this topic

0:08:45.120000 --> 0:08:49.120000
 specifically. So obviously the first
 thing I would recommend is apply

0:08:49.120000 --> 0:08:54.220000
 the concepts learned in this course
 and as well as others, you know, by

0:08:54.220000 --> 0:08:58.600000
 engaging in CTF challenges, bug bounty
 programs, of course, simulated

0:08:58.600000 --> 0:09:01.480000
 lab challenges, you know,
 for example, INE skills.

0:09:01.480000 --> 0:09:06.120000
 So now is a great place for you to actually
 test your skills and improve

0:09:06.120000 --> 0:09:11.320000
 them. I would also recommend that you
 explore, you know, the latest OS

0:09:11.320000 --> 0:09:16.340000
 guides, you know, the security testing
 guide, I should say, especially

0:09:16.340000 --> 0:09:19.240000
 those focused on injection based attacks.


0:09:19.240000 --> 0:09:23.480000
 And you know, this is important because
 you need to stay up to date on

0:09:23.480000 --> 0:09:30.140000
 the best practices and new vulnerabilities,
 you know, being added or being

0:09:30.140000 --> 0:09:37.960000
 cataloged in, you know, for example,
 the OASP web security testing guide.

0:09:37.960000 --> 0:09:42.660000
 I would also recommend that you explore
 some additional or some more advanced

0:09:42.660000 --> 0:09:47.320000
 injection vulnerabilities like SSI,
 X-BATH injection and format string

0:09:47.320000 --> 0:09:50.220000
 injection, just to name a few.

0:09:50.220000 --> 0:09:56.320000
 If you are, you know, if I've actually
 awoken your curiosity for injection

0:09:56.320000 --> 0:09:59.440000
 based attacks in this course, so those
 are some of the other ones I would

0:09:59.440000 --> 0:10:01.580000
 recommend you take a look at.

0:10:01.580000 --> 0:10:05.960000
 And of course, start applying your
 skills to bug bounty programs.

0:10:05.960000 --> 0:10:10.460000
 If you're not working as a web app
 investor to begin with, bug bounty

0:10:10.460000 --> 0:10:16.180000
 programs are the best place to actually,
 you know, test yourself and to

0:10:16.180000 --> 0:10:20.280000
 sort of ground yourself in, you know,
 generally speaking, what to expect

0:10:20.280000 --> 0:10:24.780000
 because you know, you are dealing with
 production, in most cases, production

0:10:24.780000 --> 0:10:26.840000
 web applications.

0:10:26.840000 --> 0:10:28.800000
 So, you know, bug crowd, a hacker one.

0:10:28.800000 --> 0:10:32.380000
 I would also highly recommend that
 you read reports on injection based

0:10:32.380000 --> 0:10:37.680000
 vulnerabilities to understand again
 how these vulnerabilities look like

0:10:37.680000 --> 0:10:42.380000
 in the wild and how they're exploited
 by fellow bug bounty hunters.

0:10:42.380000 --> 0:10:46.180000
 But with that being said, that brings
 us to the end of this course.

0:10:46.180000 --> 0:10:48.780000
 Thank you very much for watching.

0:10:48.780000 --> 0:10:53.660000
 And hopefully I'll see you in
 some of the other courses.

0:10:53.660000 --> 0:10:55.760000
 So really grateful you made it this far.

0:10:55.760000 --> 0:11:00.800000
 And as always, keep on learning and
 hopefully I'll see you again.

0:11:00.800000 --> 0:11:02.080000
 Thank you and bye.

