WEBVTT

0:00:03.800000 --> 0:00:06.900000
 Types of Authentication Mechanisms.

0:00:06.900000 --> 0:00:11.500000
 In this video, we're going to be building
 on our analogy that we went

0:00:11.500000 --> 0:00:16.200000
 over. We went through in the previous
 video when we got the introduction

0:00:16.200000 --> 0:00:21.940000
 or reintroduction to authentication by taking
 a look at the types of authentication

0:00:21.940000 --> 0:00:26.520000
 mechanisms. We're now drilling deeper
 down into authentication.

0:00:26.520000 --> 0:00:32.200000
 We know what authentication is, but now we
 need to understand what authentication

0:00:32.200000 --> 0:00:37.780000
 mechanisms exist or what authentication
 mechanisms are typically utilized

0:00:37.780000 --> 0:00:42.860000
 by modern web applications specifically.

0:00:42.860000 --> 0:00:47.660000
 A bit of this will be a rehash or a recap
 of what probably stuff you already

0:00:47.660000 --> 0:00:53.680000
 know, but it'll also lay the groundwork
 or the skeleton or the outline

0:00:53.680000 --> 0:00:59.620000
 for the types of attacks that will
 be performing in this course.

0:00:59.620000 --> 0:01:04.780000
 Before we get into any of that, we
 need to, you know, what exactly is

0:01:04.780000 --> 0:01:06.680000
 an authentication mechanism?

0:01:06.680000 --> 0:01:12.100000
 Well, authentication mechanisms are
 methods or processes used to verify

0:01:12.100000 --> 0:01:17.360000
 the identity of a user or system attempting
 to access a web application

0:01:17.360000 --> 0:01:25.780000
 or a service. It could be an API,
 a web application, et cetera.

0:01:25.780000 --> 0:01:30.280000
 This by which the web application
 verifies the identity of a user.

0:01:30.280000 --> 0:01:35.520000
 That's the key word there
 or the key set of words.

0:01:35.520000 --> 0:01:41.160000
 Now these mechanisms ensure that only
 authorized users can gain access

0:01:41.160000 --> 0:01:45.360000
 to sensitive resources
 enhancing security.

0:01:45.360000 --> 0:01:50.360000
 So revisiting the analogy that I sort
 of introduced in the previous video

0:01:50.360000 --> 0:01:55.540000
 where I gave you the scenario or the
 premise of having a room that has

0:01:55.540000 --> 0:01:58.780000
 data that, you know, could
 be potentially useful.

0:01:58.780000 --> 0:02:03.660000
 So for example, a room with filing
 cabinets, computers really doesn't

0:02:03.660000 --> 0:02:08.340000
 matter. The bottom line is that whatever
 is in the room is valuable.

0:02:08.340000 --> 0:02:12.880000
 Now the room has a door and the door
 has a locking mechanism, which allows

0:02:12.880000 --> 0:02:14.480000
 it to be opened and closed.

0:02:14.480000 --> 0:02:20.580000
 And the door is the only means through
 which you can access the room.

0:02:20.580000 --> 0:02:26.700000
 So think of the door as a login form,
 for example, or even less not even

0:02:26.700000 --> 0:02:28.440000
 conflate the two just yet.

0:02:28.440000 --> 0:02:34.440000
 So the door is what at a fundamental
 level controls access.

0:02:34.440000 --> 0:02:40.560000
 Now it's very obvious, you know, if
 we sort of juxtapose this analogy

0:02:40.560000 --> 0:02:47.860000
 on top of or against web applications
 that this is sort of what the early

0:02:47.860000 --> 0:02:51.260000
 version of the internet or
 web applications were like.

0:02:51.260000 --> 0:02:58.060000
 And what they were missing was that
 the door itself needed an additional

0:02:58.060000 --> 0:03:03.240000
 layer of security or an enhancement,
 if you will, and that, you know,

0:03:03.240000 --> 0:03:08.540000
 typically would come in the form of a
 lock, right, a lock and key mechanism.

0:03:08.540000 --> 0:03:14.220000
 And that when I'm referring to the
 locking system, whether that be a,

0:03:14.220000 --> 0:03:24.540000
 you know, a standard that's what I mean
 when I, when I refer to authentication

0:03:24.540000 --> 0:03:30.920000
 mechanisms. So it's, you know, adding
 this layer of security or augmenting

0:03:30.920000 --> 0:03:37.440000
 the door, if you will, by now trying
 to incorporate a form of identity

0:03:37.440000 --> 0:03:44.120000
 verification. What that means is that
 presumably the only people who will

0:03:44.120000 --> 0:03:48.600000
 be allowed to access that room or can
 access that room are people who

0:03:48.600000 --> 0:03:50.920000
 are authorized to access that room.

0:03:50.920000 --> 0:03:57.040000
 And the authorized personnel have keys
 that essentially grant them that

0:03:57.040000 --> 0:04:03.740000
 access. So revisiting what I have listed
 out in the slides, these mechanisms

0:04:03.740000 --> 0:04:10.120000
 ensure that only authorized users can
 gain access to sensitive resources.

0:04:10.120000 --> 0:04:17.400000
 So previously, the, the secure or the,
 the room with all the data only

0:04:17.400000 --> 0:04:23.740000
 had a door. The door didn't have a locking
 mechanism or a way to essentially

0:04:23.740000 --> 0:04:26.940000
 prevent unauthorized personnel
 from accessing it.

0:04:26.940000 --> 0:04:31.780000
 And what that means or what that meant
 is that, well, yes, a closed door

0:04:31.780000 --> 0:04:36.080000
 would prevent some people
 from not accessing it.

0:04:36.080000 --> 0:04:40.820000
 However, pretty much anyone with the
 intent or the will to find out what's

0:04:40.820000 --> 0:04:45.680000
 in the room would easily be able to
 twist the handle and open the door,

0:04:45.680000 --> 0:04:50.480000
 get in and, you know, do whatever they
 wanted to or with the data that's

0:04:50.480000 --> 0:04:52.240000
 stored in that room.

0:04:52.240000 --> 0:04:58.380000
 When you introduce a locking mechanism
 or a security mechanism, so it

0:04:58.380000 --> 0:05:05.140000
 could be a standard, you know, key lock
 mechanism or, for example, biometric

0:05:05.140000 --> 0:05:07.200000
 lock or whatever.

0:05:07.200000 --> 0:05:13.100000
 Now only the individuals who have the
 key or who have been provided, who's

0:05:13.100000 --> 0:05:18.840000
 fingerprints or biometrics have been
 logged as authorized or, you know,

0:05:18.840000 --> 0:05:23.360000
 users who have access will be
 able to access that room.

0:05:23.360000 --> 0:05:28.320000
 So I know I'm using a very convoluted
 analogy here, but I think it's very

0:05:28.320000 --> 0:05:32.980000
 important that you understand what, when
 I refer to mechanisms, what exactly

0:05:32.980000 --> 0:05:37.720000
 I mean. And this is very important
 because the mechanisms that you'll

0:05:37.720000 --> 0:05:41.340000
 find out in the wild or in the
 real world are going to differ.

0:05:41.340000 --> 0:05:44.240000
 So you're going to have your
 standard login forms, right?

0:05:44.240000 --> 0:05:45.960000
 So that's username and password.

0:05:45.960000 --> 0:05:50.560000
 That's essentially your door with a
 key lock, for example, where, you

0:05:50.560000 --> 0:05:55.600000
 know, you put in your username, which is
 really not secure, but your password

0:05:55.600000 --> 0:06:00.360000
 is what actually allows you in, or, you
 know, prevents you from accessing

0:06:00.360000 --> 0:06:07.880000
 the room or a particular website or a resource
 on a website or web application.

0:06:07.880000 --> 0:06:13.300000
 And you'll see that there've been augmentations
 made or you'll find these

0:06:13.300000 --> 0:06:19.440000
 variations in authentication mechanisms in
 the form of two-factor authentication,

0:06:19.440000 --> 0:06:23.680000
 where, you know, they're adding this
 additional layer of security to the

0:06:23.680000 --> 0:06:29.000000
 door to essentially ensure the same
 thing that only authorized personnel

0:06:29.000000 --> 0:06:31.940000
 can access what's behind the door.

0:06:31.940000 --> 0:06:36.320000
 So in the next couple of slides, we'll
 explore some of the key types of

0:06:36.320000 --> 0:06:41.060000
 authentication mechanisms used
 in modern web applications.

0:06:41.060000 --> 0:06:45.240000
 And to kick things off, we have the
 most basic, which I mentioned.

0:06:45.240000 --> 0:06:50.640000
 This is the password-based authentication
 mechanism, where users provide

0:06:50.640000 --> 0:06:54.480000
 a username and a password
 to verify their identity.

0:06:54.480000 --> 0:06:58.900000
 Fairly simple. The most basic, you know,
 implemented everywhere, not just

0:06:58.900000 --> 0:07:03.560000
 on web applications or websites, but
 your own computer, when you start

0:07:03.560000 --> 0:07:05.080000
 it up, you need to log in.

0:07:05.080000 --> 0:07:08.120000
 Typically, you're going to,
 you know, use a password.

0:07:08.120000 --> 0:07:11.080000
 And you can start to understand that,
 for example, on Windows, you now

0:07:11.080000 --> 0:07:15.000000
 have different authentication mechanisms,
 where you can use a PIN code

0:07:15.000000 --> 0:07:18.320000
 or you can use facial recognition.

0:07:18.320000 --> 0:07:22.000000
 Or if you have a fingerprint scanner,
 you know, if you're on a Mac OS

0:07:22.000000 --> 0:07:27.600000
 system, you still, when you start up
 your Mac OS system, you still need

0:07:27.600000 --> 0:07:31.700000
 to provide your password before, you
 know, biometric authentication can

0:07:31.700000 --> 0:07:36.480000
 be enabled, you know, on system
 wake-ups or, you know, whatever.

0:07:36.480000 --> 0:07:39.060000
 But that's the most basic one.

0:07:39.060000 --> 0:07:43.980000
 You then have an augmented version of that,
 which is multi-factor authentication,

0:07:43.980000 --> 0:07:48.720000
 where you're combining two or
 more independent credentials.

0:07:48.720000 --> 0:07:52.240000
 And the keyword there is independent,
 so they're not linked to each other.

0:07:52.240000 --> 0:07:56.180000
 So it's not like, you know, providing
 another password, although that

0:07:56.180000 --> 0:07:59.500000
 is generally considered multi-factor
 authentication, but you're trying

0:07:59.500000 --> 0:08:01.720000
 to keep them as distinct as possible.

0:08:01.720000 --> 0:08:09.220000
 So, you know, this could be something like
 a password and or a PIN, something

0:08:09.220000 --> 0:08:13.040000
 that you have. So something that you
 know, something that you have, what

0:08:13.040000 --> 0:08:19.860000
 would you, would a person or an individual
 or an identity typically have

0:08:19.860000 --> 0:08:22.460000
 besides a password.

0:08:22.460000 --> 0:08:27.260000
 So, you know, something like a smartphone
 that only you have access to.

0:08:27.260000 --> 0:08:30.760000
 And that's where you have your two
-factor authentication codes.

0:08:30.760000 --> 0:08:33.860000
 So, you know, security tokens, etc.

0:08:33.860000 --> 0:08:35.860000
 And then something that you are.

0:08:35.860000 --> 0:08:39.380000
 And this is where we have biometric verification,
 like, you know, fingerprint

0:08:39.380000 --> 0:08:41.400000
 or facial recognition.

0:08:41.400000 --> 0:08:46.180000
 So you can probably already start to
 understand that they're all trying

0:08:46.180000 --> 0:08:49.520000
 to do, all of these mechanisms are
 trying to do the same thing.

0:08:49.520000 --> 0:08:53.100000
 They're just, you know, some are much
 more secure than the others, but

0:08:53.100000 --> 0:08:58.600000
 we couldn't have gotten this far without
 the initial password-based authentication

0:08:58.600000 --> 0:09:05.480000
 mechanism. You then have two-factor
 authentication, classic, or what we

0:09:05.480000 --> 0:09:08.200000
 now refer to as two-factor
 authentication.

0:09:08.200000 --> 0:09:13.860000
 So this is a type or a subset of multi
-factor authentication, but, you

0:09:13.860000 --> 0:09:18.780000
 know, that requires exactly two factors
 for authentication, often a password

0:09:18.780000 --> 0:09:24.580000
 and a one-time code that's sent typically
 via SMS or an authenticate app

0:09:24.580000 --> 0:09:28.960000
 where you configure two-factor authentication
 on a device that only you

0:09:28.960000 --> 0:09:33.760000
 have access to. And when you log in
 with a username and password, you'll

0:09:33.760000 --> 0:09:37.700000
 be prompted to enter the two-factor
 authentication code, either through

0:09:37.700000 --> 0:09:42.200000
 your authenticator app on your phone,
 or you'll be sent in a message.

0:09:42.200000 --> 0:09:46.020000
 Again, a message will be sent to your
 number that only you will have access

0:09:46.020000 --> 0:09:53.420000
 to. But as you probably know, with
 these SIM swap attacks, and attack

0:09:53.420000 --> 0:10:00.880000
 is being able to essentially your phone
 number, the safest option at this

0:10:00.880000 --> 0:10:03.380000
 point is the authenticator app.

0:10:03.380000 --> 0:10:07.420000
 You then have token-based authentication,
 something that will be covering

0:10:07.420000 --> 0:10:11.720000
 quite a bit in this course, and
 that essentially uses tokens.

0:10:11.720000 --> 0:10:15.580000
 Now, we'll dive deeper into these authentication
 mechanisms, you know,

0:10:15.580000 --> 0:10:17.980000
 in terms of how they work, etc.

0:10:17.980000 --> 0:10:25.520000
 But some examples of these are your
 standard JSON web tokens, or JWTs,

0:10:25.520000 --> 0:10:28.460000
 as they're called, or OAuth tokens.

0:10:28.460000 --> 0:10:33.820000
 These are issued upon successful logins,
 and are used for subsequent requests,

0:10:33.820000 --> 0:10:37.780000
 reducing the need to repeatedly
 enter credentials.

0:10:37.780000 --> 0:10:42.680000
 Now, you're probably already guessing
 that as we now start to get into

0:10:42.680000 --> 0:10:49.660000
 authentication mechanisms, like token
-based authentication, that these

0:10:49.660000 --> 0:10:56.720000
 authentication mechanisms are not really
 suited in some cases for certain

0:10:56.720000 --> 0:11:01.060000
 types of environments over the
 others, or over others, right?

0:11:01.060000 --> 0:11:04.460000
 And again, I'm not going to dive too
 deep into this, but the important

0:11:04.460000 --> 0:11:06.920000
 thing is that you get this overview.

0:11:06.920000 --> 0:11:11.040000
 You then have your single
 sign-on or SSO, right?

0:11:11.040000 --> 0:11:16.080000
 And this authentication mechanism allows
 users to log in once and gain

0:11:16.080000 --> 0:11:20.940000
 access to multiple applications or services
 without needing to re-enter

0:11:20.940000 --> 0:11:26.160000
 credentials, often using protocols
 like SAML or OAuth.

0:11:26.160000 --> 0:11:31.480000
 Again, we'll dive into that at a later
 stage, but moving on, we also have

0:11:31.480000 --> 0:11:34.960000
 the classic one-time passwords or OTP.

0:11:34.960000 --> 0:11:39.680000
 So this is a temporary password that
 is sent to the user via SMS or email

0:11:39.680000 --> 0:11:41.560000
 for a single login session.

0:11:41.560000 --> 0:11:47.740000
 So you've typically seen this with some
 online websites or services that

0:11:47.740000 --> 0:11:52.940000
 typically use OTP codes in
 addition to your password.

0:11:52.940000 --> 0:11:59.700000
 So if you try to log in, you'll typically
 get an email with a code that

0:11:59.700000 --> 0:12:04.480000
 you need to essentially copy and paste,
 or you need to use to essentially

0:12:04.480000 --> 0:12:05.780000
 verify identity.

0:12:05.780000 --> 0:12:10.440000
 And this is a bit different than two
-factor authentication, because an

0:12:10.440000 --> 0:12:16.880000
 additional medium is now being added, and
 that, of course, is email, whereby,

0:12:16.880000 --> 0:12:21.060000
 you know, instead of your authenticator
 app and your phone number, you

0:12:21.060000 --> 0:12:22.440000
 can also use emails.

0:12:22.440000 --> 0:12:24.500000
 All the codes can be sent
 to you via email.

0:12:24.500000 --> 0:12:30.400000
 This is very, very common with
 a lot of SaaS services online.

0:12:30.400000 --> 0:12:32.240000
 But there you go.

0:12:32.240000 --> 0:12:37.120000
 So that's OTP. And with that being said,
 that's going to be it for this

0:12:37.120000 --> 0:12:41.120000
 video. I just wanted to give you
 an overview of what to expect.

0:12:41.120000 --> 0:12:46.180000
 I'm sure a lot of you have already come
 across these, not just at a personal

0:12:46.180000 --> 0:12:51.480000
 level when using the internet, but
 also as a penetration tester.

0:12:51.480000 --> 0:12:55.380000
 And as we progress within this section,
 you'll sort of get an understanding

0:12:55.380000 --> 0:13:00.220000
 of exactly what we'll be doing in terms
 of which of these authentication

0:13:00.220000 --> 0:13:04.340000
 mechanisms we're going to be testing,
 what types of vulnerabilities we're

0:13:04.340000 --> 0:13:08.040000
 going to be looking for, and of
 course, how to exploit them.

0:13:08.040000 --> 0:13:11.040000
 But with that being said, that's
 going to be it for this video.

0:13:11.040000 --> 0:13:13.480000
 And I will be seeing you
 in the next video.

