WEBVTT

0:00:03.580000 --> 0:00:06.840000
 Hello everyone and welcome to this video.


0:00:06.840000 --> 0:00:10.780000
 In this video, we're going to be kicking
 off the web service security

0:00:10.780000 --> 0:00:19.360000
 testing section by taking a look at WSDL
 disclosure and method enumeration.

0:00:19.360000 --> 0:00:24.980000
 So this is going to be a fully practical
 video or session where I will

0:00:24.980000 --> 0:00:30.820000
 be pretty much reiterating or now practically
 showing you what I've covered

0:00:30.820000 --> 0:00:35.180000
 in the previous videos and this will
 start to make a lot of sense.

0:00:35.180000 --> 0:00:38.920000
 So the bottom line is I'm an empiricist
 and I believe that you learn by

0:00:38.920000 --> 0:00:43.380000
 doing but the information that you have
 as you're doing what you're doing

0:00:43.380000 --> 0:00:48.440000
 will help contextualize everything
 that you can see in front of you.

0:00:48.440000 --> 0:00:53.800000
 So this video is going to be practical
 but we'll be exploring two different

0:00:53.800000 --> 0:00:58.720000
 aspects of my methodology that I
 outlined in the previous video.

0:00:58.720000 --> 0:01:03.740000
 We'll take a look at WSDL disclosure and
 what it looks like, what information

0:01:03.740000 --> 0:01:08.680000
 could possibly be exposed there and then
 we'll take a look at method enumeration

0:01:08.680000 --> 0:01:10.660000
 which will feed into the next video.

0:01:10.660000 --> 0:01:14.360000
 So to kick things off, before we get
 into the practical section, I need

0:01:14.360000 --> 0:01:19.060000
 to explain what WSDL disclosure is in
 the context of web service security

0:01:19.060000 --> 0:01:23.680000
 testing. So when dealing with web service
 security testing, accessing

0:01:23.680000 --> 0:01:27.580000
 the WSDL file is the first step.

0:01:27.580000 --> 0:01:31.760000
 Again, after you've identified the endpoint,
 we're not taking a look at

0:01:31.760000 --> 0:01:35.040000
 that because we're dealing with a lab
 environment so we cannot really

0:01:35.040000 --> 0:01:41.600000
 perform information gathering or OSINT
 to discover publicly accessible

0:01:41.600000 --> 0:01:45.280000
 web services that have WSDLs.

0:01:45.280000 --> 0:01:49.440000
 But this is usually the first step after
 identifying the web service or

0:01:49.440000 --> 0:01:51.340000
 even an API endpoint.

0:01:51.340000 --> 0:01:55.140000
 And what this will do is it'll give
 us the full list of operations and

0:01:55.140000 --> 0:02:00.240000
 types allowed by the server as well
 as the correct syntax to use, the

0:02:00.240000 --> 0:02:03.960000
 inputs, outputs and all the useful information
 we may need to run successful

0:02:03.960000 --> 0:02:09.320000
 attacks. Before we can enumerate the
 WSDL file for the soap web service,

0:02:09.320000 --> 0:02:13.180000
 we need to identify the soap web service
 and endpoints which again I'll

0:02:13.180000 --> 0:02:15.760000
 be doing in the context
 of the lab environment.

0:02:15.760000 --> 0:02:20.900000
 So do not take that as face value in
 terms of identifying the endpoint.

0:02:20.900000 --> 0:02:25.520000
 But in terms of WSDL disclosure, these
 are the techniques that apply or

0:02:25.520000 --> 0:02:27.620000
 work in the real world as well.

0:02:27.620000 --> 0:02:32.560000
 So once a soap service has been identified,
 another way to discover WSDL

0:02:32.560000 --> 0:02:37.480000
 files is by appending WSDL.WSDL or .

0:02:37.480000 --> 0:02:43.040000
 Sorry, question mark disco to
 the end of the service URL.

0:02:43.040000 --> 0:02:46.760000
 So let's say we have the endpoint here
 and I'll explain what the endpoint

0:02:46.760000 --> 0:02:49.820000
 is. So the endpoint is just a URL.

0:02:49.820000 --> 0:02:57.100000
 So it's HTTP soap dot site in this example,
 search engine W W S dot PHP.

0:02:57.100000 --> 0:03:02.420000
 So to that particular point where PHP
 ends, that is known as the endpoint.

0:03:02.420000 --> 0:03:16.140000
 Okay. Now you can append question mark WSDL
 to bring up the WSDL use interchangeably.

0:03:16.140000 --> 0:03:17.600000
 So just be aware of that.

0:03:17.600000 --> 0:03:24.140000
 And what the WSDL file will do or will
 provide you with is as I've mentioned

0:03:24.140000 --> 0:03:30.300000
 previously, give you a breakdown or
 a description, if you will, pretty

0:03:30.300000 --> 0:03:35.280000
 much a list of all operations and types
 allowed by the server, as well

0:03:35.280000 --> 0:03:40.120000
 as specify the correct syntax to use
 when utilizing a particular method.

0:03:40.120000 --> 0:03:43.280000
 And I know I'm going to keep
 calling it a method.

0:03:43.280000 --> 0:03:48.060000
 But what I'm referring to is an operation
 in the context of in the context

0:03:48.060000 --> 0:03:50.240000
 of WSDL and soap.

0:03:50.240000 --> 0:03:52.460000
 But don't worry, it'll make sense.

0:03:52.460000 --> 0:03:54.860000
 And yeah, so that's how that can be done.


0:03:54.860000 --> 0:03:59.380000
 So the point is that once we find WSDL
 files, we can start inspecting

0:03:59.380000 --> 0:04:02.920000
 them and gather valuable information
 about the web service.

0:04:02.920000 --> 0:04:06.960000
 As you already know, this allows us
 to gather information information

0:04:06.960000 --> 0:04:12.680000
 such as operations, data
 syntax and much more.

0:04:12.680000 --> 0:04:16.460000
 And with that being said, ladies and
 gentlemen, we are finally here.

0:04:16.460000 --> 0:04:22.060000
 So this particular video will have
 a lab environment associated to it

0:04:22.060000 --> 0:04:28.340000
 or with it. And more importantly, all
 of the videos that will include

0:04:28.340000 --> 0:04:32.260000
 a practical session will be
 utilizing the same lab.

0:04:32.260000 --> 0:04:35.700000
 So within this section of the course,
 you may be a little bit worried

0:04:35.700000 --> 0:04:37.900000
 because you may only see one lab.

0:04:37.900000 --> 0:04:40.140000
 Don't worry, that's by design.

0:04:40.140000 --> 0:04:43.260000
 The reason there's only one lab is because
 we're going to be using that

0:04:43.260000 --> 0:04:45.920000
 one lab for all of the demonstrations.

0:04:45.920000 --> 0:04:49.360000
 So the name of the lab
 is just web services.

0:04:49.360000 --> 0:04:50.940000
 Okay. And that's pretty much it.

0:04:50.940000 --> 0:04:54.360000
 It has documentation on pretty much most
 of what I'm going to be highlighting

0:04:54.360000 --> 0:04:57.820000
 here. And all you need to
 do is just fire it up.

0:04:57.820000 --> 0:05:01.520000
 It'll provide you with access
 to a calilinic system.

0:05:01.520000 --> 0:05:03.780000
 So you don't need to utilize your own.

0:05:03.780000 --> 0:05:07.200000
 And with that being said, I'm going
 to fire up my lab environment and

0:05:07.200000 --> 0:05:09.000000
 switch over into it.

0:05:09.000000 --> 0:05:11.820000
 And we can get started.

0:05:11.820000 --> 0:05:16.540000
 All right. So I'm currently
 within the lab environment.

0:05:16.540000 --> 0:05:20.120000
 And as you can see, you will be provided
 with access to a calilinic system.

0:05:20.120000 --> 0:05:25.200000
 And in order to get started, the target
 web application, or if you will,

0:05:25.200000 --> 0:05:32.560000
 web service is running on a URL or
 a domain called demo.ini.local.

0:05:32.560000 --> 0:05:37.060000
 And in this case, we are going to
 be utilizing OASP Motilide 2.

0:05:37.060000 --> 0:05:40.520000
 Now, don't worry, you may be saying to
 yourself, what's the point of using

0:05:40.520000 --> 0:05:42.980000
 something that's deliberately vulnerable?


0:05:42.980000 --> 0:05:47.260000
 You know, what if we wanted to see
 this real world implementation?

0:05:47.260000 --> 0:05:51.180000
 Well, in that case, it will pretty
 much serve the same purpose.

0:05:51.180000 --> 0:05:55.320000
 The reason I'm using Motilide 2, by
 the way, which actually has a web

0:05:55.320000 --> 0:05:57.520000
 service if you're not familiar with it.

0:05:57.520000 --> 0:06:01.960000
 The reason I'm using it is because it will
 highlight and pretty much practically

0:06:01.960000 --> 0:06:06.380000
 encapsulates all that I
 have taught thus far.

0:06:06.380000 --> 0:06:09.520000
 And you'll actually see it come, you'll
 actually see yourself discover

0:06:09.520000 --> 0:06:15.060000
 stuff. So what we want to do is navigate,
 you want to navigate to demo

0:06:15.060000 --> 0:06:20.720000
.ini.local. And from this point on,
 we can pretty much just go into web

0:06:20.720000 --> 0:06:23.300000
 services here and soap.

0:06:23.300000 --> 0:06:27.820000
 And we want to go to the username
 enumeration endpoint.

0:06:27.820000 --> 0:06:32.260000
 So this is, in essence, the web
 service or API endpoints.

0:06:32.260000 --> 0:06:34.280000
 I'm going to click on that here.

0:06:34.280000 --> 0:06:35.260000
 And here we are.

0:06:35.260000 --> 0:06:40.100000
 So when we navigate to the web service
 endpoint, you can see it, the endpoint

0:06:40.100000 --> 0:06:44.600000
 is demo.ini.local under a folder
 called web services.

0:06:44.600000 --> 0:06:50.520000
 Soap w and the name of the endpoint
 is ws user account.php.

0:06:50.520000 --> 0:06:54.220000
 Okay. So now you can see
 we're on this page.

0:06:54.220000 --> 0:06:57.080000
 We don't get any funny
 output, which is fine.

0:06:57.080000 --> 0:07:01.620000
 And you can see right over here, it
 says that ws user account view the

0:07:01.620000 --> 0:07:03.800000
 wstl for the service.

0:07:03.800000 --> 0:07:06.080000
 Click on an operation to view its detail.


0:07:06.080000 --> 0:07:10.740000
 So what is displayed here, where it's
 displaying the actual method or

0:07:10.740000 --> 0:07:16.780000
 operation, this is known as abstract
 ws dl, right, where it's essentially

0:07:16.780000 --> 0:07:22.120000
 giving you a high level overview of what
 types of operations you can run.

0:07:22.120000 --> 0:07:27.240000
 Now, as I pointed out in the slides, when
 it comes down to ws dl disclosure,

0:07:27.240000 --> 0:07:30.000000
 this here, generally speaking,
 will not be displayed.

0:07:30.000000 --> 0:07:34.520000
 So generally speaking, web app developers
 don't want just anyone reading

0:07:34.520000 --> 0:07:39.420000
 the ws dl to understand what this web
 service can be used for, as well

0:07:39.420000 --> 0:07:42.860000
 as, you know, the various methods or
 operations as they are called in

0:07:42.860000 --> 0:07:44.520000
 the context of soap.

0:07:44.520000 --> 0:07:50.500000
 You know, they want to pretty much
 just give you enough to do what is

0:07:50.500000 --> 0:07:55.900000
 legitimately required in terms of the
 functionality of this web service.

0:07:55.900000 --> 0:07:59.620000
 So the bottom line is let's not
 rely on this hyperlink here.

0:07:59.620000 --> 0:08:04.300000
 We can test out the techniques provided,
 you know, that I provided in

0:08:04.300000 --> 0:08:09.380000
 the slides where we can append
 ws dl, okay, and I hit enter.

0:08:09.380000 --> 0:08:14.140000
 And in this case, it brings
 up the ws dl in XML format.

0:08:14.140000 --> 0:08:20.900000
 So within the ws dl, you can see that
 right over here, we have the actual

0:08:20.900000 --> 0:08:24.700000
 definitions. So firstly,
 we have the types.

0:08:24.700000 --> 0:08:27.520000
 So you can actually see
 that right over here.

0:08:27.520000 --> 0:08:32.320000
 So firstly, do you remember what
 the types element was used for?

0:08:32.320000 --> 0:08:37.980000
 Well, the types element is used to define
 the XML schema data types that

0:08:37.980000 --> 0:08:39.500000
 are used by the web service.

0:08:39.500000 --> 0:08:41.040000
 So let's try and understand it.

0:08:41.040000 --> 0:08:42.200000
 So you can see types.

0:08:42.200000 --> 0:08:49.460000
 Okay. XML schema target namespace
 ws user account.

0:08:49.460000 --> 0:08:52.360000
 Okay, that's the target namespace.

0:08:52.360000 --> 0:08:54.480000
 And by the way, you can
 expand and collapse.

0:08:54.480000 --> 0:09:04.560000
 We can see the soap encoding.

0:09:04.560000 --> 0:09:09.440000
 So this is just the XML schemas schema
 data types to be used by the web

0:09:09.440000 --> 0:09:14.120000
 service. We then have the
 message element here.

0:09:14.120000 --> 0:09:18.560000
 The message element, if you remember,
 defines the data elements for each

0:09:18.560000 --> 0:09:23.140000
 operation. So in this case, under the
 message element, what is being defined

0:09:23.140000 --> 0:09:28.320000
 as the data element being defined
 is called username.

0:09:28.320000 --> 0:09:32.580000
 Okay. So things are starting to click
 now, now that you're actually starting

0:09:32.580000 --> 0:09:35.720000
 to see the value of the theoretical
 side of things.

0:09:35.720000 --> 0:09:41.340000
 We then have, if we take a look at this
 closely other message elements,

0:09:41.340000 --> 0:09:43.840000
 defining other data elements.

0:09:43.840000 --> 0:09:48.340000
 So you can see in this case, we have
 the message has a name of get user

0:09:48.340000 --> 0:09:55.520000
 response. And in this case, the part
 name is return type xsd dot XML.

0:09:55.520000 --> 0:10:00.160000
 Okay. And then we have, you know, create
 user response, so on and so forth.

0:10:00.160000 --> 0:10:05.340000
 So these are message elements, again,
 just to reiterate message elements,

0:10:05.340000 --> 0:10:08.120000
 define the data elements
 for each operation.

0:10:08.120000 --> 0:10:12.740000
 Now, if we scroll to the bottom where
 we start dealing with operations,

0:10:12.740000 --> 0:10:15.680000
 we can see something very
 interesting here.

0:10:15.680000 --> 0:10:21.480000
 So we can see that right over
 here, it says port type.

0:10:21.480000 --> 0:10:28.560000
 Okay. Now, let's see whether you right
 now can tell me what port type

0:10:28.560000 --> 0:10:31.760000
 tells us about wsd l.

0:10:31.760000 --> 0:10:35.560000
 I'll give you two seconds.

0:10:35.560000 --> 0:10:39.720000
 All right. So what this tells us, if you
 go back, and this is why I differentiated

0:10:39.720000 --> 0:10:46.240000
 the two versions of wsd l, this tells
 us that the version of wsd l being

0:10:46.240000 --> 0:10:52.140000
 used here is 1.1, because remember, in
 2.0, port type is not used anymore

0:10:52.140000 --> 0:10:54.480000
 to define operations.

0:10:54.480000 --> 0:11:00.280000
 So in this particular case, we now know
 we are dealing with wsd l version

0:11:00.280000 --> 0:11:05.520000
 1.1. So port type, just going back to the
 definition, describes the operations

0:11:05.520000 --> 0:11:08.800000
 that can be performed and
 the messages involved.

0:11:08.800000 --> 0:11:12.700000
 So we now know that, you know, the operations
 element specifies, you know,

0:11:12.700000 --> 0:11:13.500000
 pretty much the method.

0:11:13.500000 --> 0:11:19.040000
 So in this case, the operation is name,
 sorry, operation name is get user.

0:11:19.040000 --> 0:11:21.500000
 And right over here, the documentation
 is provided.

0:11:21.500000 --> 0:11:26.500000
 So it says that this particular operation
 or method fetches user information

0:11:26.500000 --> 0:11:34.880000
 is user exists. So fetches user information,
 if the user exists, else

0:11:34.880000 --> 0:11:36.980000
 returns error message.

0:11:36.980000 --> 0:11:41.900000
 Okay. So that's fairly vague, but it
 still tells us what this method does.

0:11:41.900000 --> 0:11:48.200000
 So get user, that was publicly exposed
 right over here does that.

0:11:48.200000 --> 0:11:53.280000
 If we now take a look at another method
 or operation called create user,

0:11:53.280000 --> 0:11:57.420000
 that's self explanatory, this allows
 us to create a new user account.

0:11:57.420000 --> 0:12:01.740000
 So in this case, the web service allows
 for this functionality, meaning

0:12:01.740000 --> 0:12:06.460000
 that a client can essentially
 perform these actions.

0:12:06.460000 --> 0:12:08.280000
 Okay, that's what this means.

0:12:08.280000 --> 0:12:15.120000
 We also have another operation
 name here called update user.

0:12:15.120000 --> 0:12:20.120000
 And in this case, it says if the account
 exists, update the existing user

0:12:20.120000 --> 0:12:22.820000
 account, otherwise create
 a new user account.

0:12:22.820000 --> 0:12:27.580000
 Now, one other thing I want you to pay
 attention to if you remember, remember

0:12:27.580000 --> 0:12:43.020000
 what the purpose of soap was, specifically
 the format and encode the requests

0:12:43.020000 --> 0:12:44.780000
 and responses, right?

0:12:44.780000 --> 0:12:48.540000
 And that's why you have all of this
 additional information here, which

0:12:48.540000 --> 0:12:55.080000
 is in essence, or in essence will be
 included in the actual request or

0:12:55.080000 --> 0:12:59.260000
 response. And I'll show you how
 to go about invoking a request.

0:12:59.260000 --> 0:13:03.120000
 But you can see right over here, it tells
 you the endpoint, which we already

0:13:03.120000 --> 0:13:09.140000
 know about, but, but remember, based
 on what's being documented here,

0:13:09.140000 --> 0:13:11.420000
 it is utilizing HTTP.

0:13:11.420000 --> 0:13:13.680000
 So it is soap over HTTP.

0:13:13.680000 --> 0:13:19.000000
 And more importantly, in order to utilize
 this operation or method, we

0:13:19.000000 --> 0:13:21.440000
 need to send a post request.

0:13:21.440000 --> 0:13:25.680000
 And again, we'll revisit what we covered
 in the theoretical section.

0:13:25.680000 --> 0:13:28.760000
 But in a practical sense,
 and it'll all click.

0:13:28.760000 --> 0:13:33.540000
 So the bottom line is that this is
 WSDL disclosure, essentially trying

0:13:33.540000 --> 0:13:38.180000
 to find the WSDL file that'll tell
 us more about how this web service

0:13:38.180000 --> 0:13:42.340000
 or in the case of APIs,
 how the API works.

0:13:42.340000 --> 0:13:47.780000
 So if we go back now, you can see that
 we can again take into account

0:13:47.780000 --> 0:13:51.100000
 what is provided publicly
 and click on get user.

0:13:51.100000 --> 0:13:56.160000
 And now when you click on this here,
 this is additional documentation.

0:13:56.160000 --> 0:14:00.800000
 It will essentially open up this dialog
 box that will then provide you

0:14:00.800000 --> 0:14:08.600000
 with the following information, essentially
 taking the XML, the XML contained

0:14:08.600000 --> 0:14:14.160000
 within the WSDL file that I just showed
 you and converting it into a readable

0:14:14.160000 --> 0:14:19.400000
 format so that you can also understand,
 you know, what you can also understand

0:14:19.400000 --> 0:14:23.840000
 what was being displayed, or it essentially
 converts the XML into a readable

0:14:23.840000 --> 0:14:29.100000
 format. So you can see in the case
 of the get user method, the binding

0:14:29.100000 --> 0:14:34.240000
 is WS user account binding, and then
 the end point is the following soap

0:14:34.240000 --> 0:14:39.100000
 action is URL, WS user account get user.

0:14:39.100000 --> 0:14:44.060000
 So the bottom line we wanted to invoke
 a request on the end point, we

0:14:44.060000 --> 0:14:46.020000
 would need to specify the following.

0:14:46.020000 --> 0:14:49.180000
 And then the style is RPC.

0:14:49.180000 --> 0:14:55.140000
 In terms of the actual encoding, we
 can see it's encoded, namespace is

0:14:55.140000 --> 0:14:56.700000
 there encoding style.

0:14:56.700000 --> 0:15:02.780000
 In terms of the output, we can see the
 output to be used is encoded right

0:15:02.780000 --> 0:15:06.540000
 over here, the parts return XSD dot XML.

0:15:06.540000 --> 0:15:10.600000
 And now it'll also attach
 a sample request.

0:15:10.600000 --> 0:15:13.380000
 So this is again designed
 to teach you this process.

0:15:13.380000 --> 0:15:19.860000
 But in terms of manually invoking the
 actual request or invoking a method

0:15:19.860000 --> 0:15:24.520000
 or operation, if you will, that is
 also possible, as we'll see in the

0:15:24.520000 --> 0:15:29.220000
 next video. But you can see that this
 is what a request looks like.

0:15:29.220000 --> 0:15:35.960000
 So post, then the end point here, the version
 of HTTP, and then any additional

0:15:35.960000 --> 0:15:41.980000
 information. And then remember, when I'd highlighted
 the web service implementation

0:15:41.980000 --> 0:15:49.640000
 specifically talking about, you know,
 how soap works, the actual, the

0:15:49.640000 --> 0:15:55.760000
 actual payload is specified here in the
 body of the request in XML format.

0:15:55.760000 --> 0:16:00.120000
 So firstly, we have the soap environment,
 you know, the soap environment

0:16:00.120000 --> 0:16:03.340000
 element here, which specifies
 the envelope.

0:16:03.340000 --> 0:16:11.020000
 And then of course, we have XMLNS soap
 environment, which is the schema.

0:16:11.020000 --> 0:16:13.760000
 And then it points to the actual URL.

0:16:13.760000 --> 0:16:18.040000
 And then of course, we have the
 soap environment header body.

0:16:18.040000 --> 0:16:20.940000
 And then, you know, we can pretty much
 see what the request looks like.

0:16:20.940000 --> 0:16:29.820000
 And in here, we can actually see that
 for the, for the operation get user,

0:16:29.820000 --> 0:16:32.060000
 a parameter needs to be specified.

0:16:32.060000 --> 0:16:35.340000
 And in this case, the parameter
 name is username.

0:16:35.340000 --> 0:16:37.900000
 And the XSD type is string.

0:16:37.900000 --> 0:16:41.660000
 And then the use name is
 specified as follows.

0:16:41.660000 --> 0:16:45.680000
 So what this means with this particular
 method, just to think through

0:16:45.680000 --> 0:16:50.120000
 it, again, clearly, is this
 is how we can check.

0:16:50.120000 --> 0:16:57.300000
 This is how we can, based on the way
 this particular, based on the way

0:16:57.300000 --> 0:17:02.420000
 this particular method works, this
 will get the user information for a

0:17:02.420000 --> 0:17:04.640000
 particular user if they exist.

0:17:04.640000 --> 0:17:08.920000
 Okay. Now, you can already tell that
 a vulnerability exists here and a

0:17:08.920000 --> 0:17:12.140000
 simple vulnerability is we can utilize
 something like the burp suite in

0:17:12.140000 --> 0:17:18.420000
 truder and try and fuzz for user names
 to see whether we can find additional

0:17:18.420000 --> 0:17:22.540000
 users. But that's a very basic type
 of attack, or, you know, basic type

0:17:22.540000 --> 0:17:26.940000
 of enumeration. But generally speaking,
 this here will not be provided

0:17:26.940000 --> 0:17:28.880000
 to you this dialogue box or this prompt.

0:17:28.880000 --> 0:17:34.380000
 Generally speaking, when you click
 on a soap API endpoint, it will not

0:17:34.380000 --> 0:17:36.620000
 provide you with anything on the page.

0:17:36.620000 --> 0:17:40.080000
 It'll just provide you with some random
 output telling you that this is

0:17:40.080000 --> 0:17:45.880000
 an endpoint in terms of also disclosing
 or finding the WSDL file, you

0:17:45.880000 --> 0:17:48.260000
 need to utilize a technique like this.

0:17:48.260000 --> 0:17:52.620000
 And you need to based on what was specified
 in the WSDL file, you need

0:17:52.620000 --> 0:17:58.040000
 to understand what all of this means
 and how to create requests or invoke

0:17:58.040000 --> 0:18:02.080000
 requests tied to specific
 methods or operations.

0:18:02.080000 --> 0:18:04.720000
 So we've learned quite
 a lot in this video.

0:18:04.720000 --> 0:18:08.140000
 We have learned firstly
 about WSDL disclosure.

0:18:08.140000 --> 0:18:11.980000
 We've also learned about methods or operations
 as they are known or referred

0:18:11.980000 --> 0:18:18.360000
 to as how they work and an example as
 to how to invoke a request in the

0:18:18.360000 --> 0:18:22.420000
 format of a soap, a soap request.

0:18:22.420000 --> 0:18:25.420000
 In this particular case, you know, XML.

0:18:25.420000 --> 0:18:30.380000
 And obviously, we generally speaking
 understand what's going on, you know,

0:18:30.380000 --> 0:18:31.760000
 at a very basic level.

0:18:31.760000 --> 0:18:36.200000
 So we also have a couple of other operations
 here like create user, which

0:18:36.200000 --> 0:18:38.040000
 again is self explanatory.

0:18:38.040000 --> 0:18:42.440000
 It allows us to create a new user
 and it shows you how to do it.

0:18:42.440000 --> 0:18:44.800000
 So very, very simple here.

0:18:44.800000 --> 0:18:48.360000
 And we can actually take a look
 at how this can be done.

0:18:48.360000 --> 0:18:53.360000
 So while this may sort of exceed the
 scope of what I wanted to cover,

0:18:53.360000 --> 0:18:56.300000
 let's take a look at what
 this looks like, right?

0:18:56.300000 --> 0:19:06.680000
 So based on proxy here in Firefox,
 and I'll click on the burp suite or

0:19:06.680000 --> 0:19:10.460000
 zap profile, because we want to
 intercept our requests now.

0:19:10.460000 --> 0:19:14.900000
 And I will go into web application
 analysis and burp suite.

0:19:14.900000 --> 0:19:19.060000
 And I'll show you exactly how to go about,
 you know, invoking a particular

0:19:19.060000 --> 0:19:22.740000
 request, you know, that's
 tied to an operation here.

0:19:22.740000 --> 0:19:26.740000
 So I'll go and start burp suite up.

0:19:26.740000 --> 0:19:32.140000
 All right, so burp suite is up and running,
 and I'll go into user options,

0:19:32.140000 --> 0:19:35.360000
 just so I can increase
 the font size here.

0:19:35.360000 --> 0:19:39.260000
 And I increase that there, the interface
 should dynamically update to

0:19:39.260000 --> 0:19:41.020000
 the new version of burp.

0:19:41.020000 --> 0:19:42.960000
 And I'll change that to the dark mode.

0:19:42.960000 --> 0:19:47.580000
 And in terms of the HTTP message display,
 I'll also increase this to something

0:19:47.580000 --> 0:19:51.980000
 that is readable by you guys, just
 so that everything is clear.

0:19:51.980000 --> 0:19:55.600000
 So I'll change that to 28, because I
 believe it's that important actually

0:19:55.600000 --> 0:20:00.500000
 will stick to 24, and because
 of XML and wrapping.

0:20:00.500000 --> 0:20:04.860000
 So we have burp suite up and running
 now, and I'll go into the repeater.

0:20:04.860000 --> 0:20:08.740000
 All right, the reason I'm going into
 the repeater is because, and I'm

0:20:08.740000 --> 0:20:10.920000
 going to get rid of the inspector here.

0:20:10.920000 --> 0:20:12.920000
 I don't really need that at the moment.

0:20:12.920000 --> 0:20:15.660000
 The reason I'm going to the repeater
 is because we're already provided

0:20:15.660000 --> 0:20:20.620000
 with instructions on how to create
 the how to invoke the request.

0:20:20.620000 --> 0:20:29.020000
 So what was documented.

0:20:29.020000 --> 0:20:33.220000
 So for example, what we can do is, you
 know, we can, on this particular

0:20:33.220000 --> 0:20:37.760000
 end point, we can say, you can utilize
 the pound symbol here to invoke

0:20:37.760000 --> 0:20:41.940000
 it from our web browser, because
 this is soap over HTTP.

0:20:41.940000 --> 0:20:48.120000
 I can go ahead and say, as documented
 here in the dialogue box, we can

0:20:48.120000 --> 0:20:54.220000
 pretty much just in this particular case,
 just say get user, so get user,

0:20:54.220000 --> 0:20:57.020000
 and I hit enter.

0:20:57.020000 --> 0:21:01.220000
 That will, in this particular case does
 not look like it's invoked that

0:21:01.220000 --> 0:21:06.200000
 because the soap action can
 be invoked directly here.

0:21:06.200000 --> 0:21:09.880000
 If we take a look at the post, yeah.

0:21:09.880000 --> 0:21:14.540000
 Okay, so we would need to do it using
 a post or not a get, which is why

0:21:14.540000 --> 0:21:15.460000
 it didn't work here.

0:21:15.460000 --> 0:21:18.960000
 So we need to go into burp
 suite and manually do it.

0:21:18.960000 --> 0:21:24.700000
 So I'm going to copy this particular
 sample request for get user.

0:21:24.700000 --> 0:21:27.840000
 All right, and we're just going
 to modify it accordingly.

0:21:27.840000 --> 0:21:31.300000
 And there's a couple of modifications
 we need to do to the URI.

0:21:31.300000 --> 0:21:36.500000
 And then we need to set the actual target
 address, which is demo.ini.local,

0:21:36.500000 --> 0:21:41.880000
 because that's here is specified
 as as local host.

0:21:41.880000 --> 0:21:45.480000
 So I'll go into burp suite into the
 repeater, and I'll paste pretty much

0:21:45.480000 --> 0:21:49.460000
 what I copied. So the first thing is
 we know the endpoint is not in the

0:21:49.460000 --> 0:21:51.420000
 does not have motility.

0:21:51.420000 --> 0:21:54.120000
 The URI here does not have motility.

0:21:54.120000 --> 0:21:59.060000
 It's just web services, soap,
 ws user account.php.

0:21:59.060000 --> 0:22:02.900000
 And in here, you know, we leave the
 default Jeremy to see whether that

0:22:02.900000 --> 0:22:05.960000
 user exists. And we want
 to monitor the output.

0:22:05.960000 --> 0:22:10.400000
 So if we try and click on send now
 burp suite will do something really

0:22:10.400000 --> 0:22:15.240000
 cool for us. It'll tell us, hey, you
 need to configure the details of

0:22:15.240000 --> 0:22:17.420000
 the server to which the
 request will be sent.

0:22:17.420000 --> 0:22:21.600000
 That's because it's not included here
 in this particular sample request.

0:22:21.600000 --> 0:22:25.140000
 So all we need to do is
 just say demo.ini.local.

0:22:25.140000 --> 0:22:29.020000
 And the port is running on is port 80,
 because there's no SSL certificate.

0:22:29.020000 --> 0:22:30.900000
 So I'll just hit OK now.

0:22:30.900000 --> 0:22:36.880000
 And now I will click on send and let's
 see what the response looks like.

0:22:36.880000 --> 0:22:41.280000
 All right, so the response
 is fairly easy to decipher.

0:22:41.280000 --> 0:22:46.240000
 We can see the X soap server header
 here tells us that the soap server

0:22:46.240000 --> 0:22:49.660000
 being used is called new soap 0.95.

0:22:49.660000 --> 0:22:52.620000
 Keep this in mind because you can also
 search for vulnerabilities affecting

0:22:52.620000 --> 0:22:56.300000
 the soap server in and of itself.

0:22:56.300000 --> 0:23:08.840000
 Now in this case, new soap is not the
 former Google search on the new

0:23:08.840000 --> 0:23:13.660000
 soap is pretty much just a PHP toolkit,
 a soap toolkit for PHP.

0:23:13.660000 --> 0:23:19.780000
 So it essentially facilitates soap,
 you know, soap communication.

0:23:19.780000 --> 0:23:24.340000
 And in this case, the other header that
 we can see here is the set cookie,

0:23:24.340000 --> 0:23:28.940000
 which is fine because it's just setting
 a PHP session ID to again, track

0:23:28.940000 --> 0:23:35.500000
 our session. And in this particular case,
 let's see here in the response,

0:23:35.500000 --> 0:23:39.900000
 we can see that what is
 provided in the output.

0:23:39.900000 --> 0:23:44.160000
 And again, we can get the same information,
 I think actually doesn't highlight

0:23:44.160000 --> 0:23:52.760000
 the response. But right over here,
 the output will contain XSD XML.

0:23:52.760000 --> 0:23:56.300000
 Yeah, so fetches user information if
 the user exists, else returns an

0:23:56.300000 --> 0:24:01.440000
 error message. So we really didn't know
 what it was going to respond in

0:24:01.440000 --> 0:24:04.560000
 terms of additional information
 regarding a user.

0:24:04.560000 --> 0:24:08.660000
 So in this case, it looks like
 the username Jeremy exists.

0:24:08.660000 --> 0:24:11.040000
 And the response is the following.

0:24:11.040000 --> 0:24:14.560000
 So pay attention to the XML
 response right over here.

0:24:14.560000 --> 0:24:16.020000
 I know it begins at the top.

0:24:16.020000 --> 0:24:21.400000
 By the way, I verified the fact that,
 you know, I verified the fact right

0:24:21.400000 --> 0:24:29.160000
 over here that that we were dealing
 with with WSDL version 1.1.

0:24:29.160000 --> 0:24:33.140000
 And you can see that also you're taking
 a look at the elements in the

0:24:33.140000 --> 0:24:35.600000
 response, but that's besides the point.

0:24:35.600000 --> 0:24:42.160000
 So in the actual body of the XML response,
 you can see right over here

0:24:42.160000 --> 0:24:47.840000
 that we have, we have the accounts element,
 which says, prints out a message

0:24:47.840000 --> 0:24:50.260000
 that says results for Jeremy.

0:24:50.260000 --> 0:24:52.580000
 So you can see the right over here.

0:24:52.580000 --> 0:24:57.380000
 And then under the account element, we
 have the username, which is specified.

0:24:57.380000 --> 0:24:58.820000
 And then the signature.

0:24:58.820000 --> 0:25:06.320000
 Okay. So it looks like the, in this particular
 case, the get user operation,

0:25:06.320000 --> 0:25:15.200000
 if the user is valid, will display the
 username itself of that user, as

0:25:15.200000 --> 0:25:16.160000
 well as their signature.

0:25:16.160000 --> 0:25:19.620000
 In this case, the signature doesn't
 make sense, you know, hacking lingo

0:25:19.620000 --> 0:25:21.940000
 1337 as you understand.

0:25:21.940000 --> 0:25:24.720000
 But that's how we know
 that a user exists.

0:25:24.720000 --> 0:25:27.240000
 Now, let's try and see what
 that error looks like.

0:25:27.240000 --> 0:25:28.960000
 So I'll try and put in my name.

0:25:28.960000 --> 0:25:30.540000
 Of course, I know I don't exist.

0:25:30.540000 --> 0:25:32.300000
 But let's see what it says.

0:25:32.300000 --> 0:25:34.680000
 Does the user Alexis exist?

0:25:34.680000 --> 0:25:37.400000
 Hmm, it says right over here.

0:25:37.400000 --> 0:25:40.380000
 The user Alexis does not exist.

0:25:40.380000 --> 0:25:42.880000
 And oh, boy, what is this?

0:25:42.880000 --> 0:25:44.820000
 What is this here?

0:25:44.820000 --> 0:25:45.420000
 Very interesting.

0:25:45.420000 --> 0:25:50.580000
 For some reason, a curly bracket was
 included in the output or what was

0:25:50.580000 --> 0:25:55.120000
 reflected back. Hmm, maybe something
 to explore in the next video.

0:25:55.120000 --> 0:26:01.480000
 But you can already start to see that,
 you know, the vulnerabilities you

0:26:01.480000 --> 0:26:06.560000
 can identify in terms of input vulnerabilities
 and the exploitation is

0:26:06.560000 --> 0:26:09.940000
 exactly the same as that
 of a web application.

0:26:09.940000 --> 0:26:13.680000
 So in this case, it's most likely that
 it's interacting with the database,

0:26:13.680000 --> 0:26:16.940000
 right? Because it's checking
 to see where the user exists.

0:26:16.940000 --> 0:26:21.880000
 There might be some sort of a SQL statement
 here, maybe even a NoSQL statement.

0:26:21.880000 --> 0:26:23.360000
 Who knows? Who knows?

0:26:23.360000 --> 0:26:28.880000
 But taking a look at the the XML here
 in the request, you can see based

0:26:28.880000 --> 0:26:33.780000
 on what we copied, if we take a look
 at it here, we can see there we are.

0:26:33.780000 --> 0:26:36.780000
 So soap environment header, the body.

0:26:36.780000 --> 0:26:40.500000
 So as you if you've utilized XML before,
 you know, it pretty much uses

0:26:40.500000 --> 0:26:45.060000
 very similar tags to that of HTML,
 in terms of a location of specific

0:26:45.060000 --> 0:26:50.640000
 data. So in the body, we have the we
 have the operation or as I like to

0:26:50.640000 --> 0:26:54.780000
 call it the method get user and then
 soap environment encoding style is

0:26:54.780000 --> 0:26:57.520000
 set to none. So it's not being encoded.

0:26:57.520000 --> 0:26:59.200000
 That's a vulnerability right there.

0:26:59.200000 --> 0:27:03.400000
 I can tell you that right now, at will
 it actually is been encoded, but

0:27:03.400000 --> 0:27:06.520000
 utilizing the default
 XML encoding schema.

0:27:06.520000 --> 0:27:11.080000
 But my point will be made because this
 can actually you can actually specify

0:27:11.080000 --> 0:27:13.140000
 a type of encoding.

0:27:13.140000 --> 0:27:17.520000
 There's no input validation, but you
 can see usename xsi type is equal

0:27:17.520000 --> 0:27:21.700000
 to string. All right, so that means
 usenames are to be provided in the

0:27:21.700000 --> 0:27:23.520000
 form of a string.

0:27:23.520000 --> 0:27:29.340000
 So that's how you can go about, you
 know, identifying the wsdl file, of

0:27:29.340000 --> 0:27:33.360000
 course, identifying the end the endpoint,
 taking a look and deciphering

0:27:33.360000 --> 0:27:35.480000
 the documentation of the web service.

0:27:35.480000 --> 0:27:40.980000
 And then of course, utilizing a tool
 like burp suite to pretty much play

0:27:40.980000 --> 0:27:46.040000
 around with the with the web service
 itself or to perform tests.

0:27:46.040000 --> 0:27:50.020000
 Now, what I'm going to do within burp
 suite, I'm just going to turn off

0:27:50.020000 --> 0:27:52.800000
 the burp suite profile
 here within foxy proxy.

0:27:52.800000 --> 0:27:58.280000
 We also have other, we also have other
 operations that you can try out,

0:27:58.280000 --> 0:28:00.620000
 like create user update user.

0:28:00.620000 --> 0:28:05.480000
 The key thing that motility is trying
 to tell you here is that these are

0:28:05.480000 --> 0:28:08.980000
 the legitimate operations allowed.

0:28:08.980000 --> 0:28:12.600000
 Okay, so this means that these are the
 operations that the web developer

0:28:12.600000 --> 0:28:18.900000
 pretty much had in mind, or has in
 mind for standard users to use.

0:28:18.900000 --> 0:28:24.100000
 And in the next video, we'll be exploring
 the process of finding an invoking

0:28:24.100000 --> 0:28:27.880000
 hidden operations or hidden methods.

0:28:27.880000 --> 0:28:32.240000
 And yeah, so I think this was a good
 foray or intro into how everything

0:28:32.240000 --> 0:28:33.920000
 clicks together.

0:28:33.920000 --> 0:28:37.560000
 And of course, you know, you can definitely
 play around with some of the

0:28:37.560000 --> 0:28:40.480000
 other end points provided
 to you by motility.

0:28:40.480000 --> 0:28:44.380000
 And that is going to conclude the practical
 demonstration side of this

0:28:44.380000 --> 0:28:50.480000
 video. All right, so hopefully that's
 gotten you excited to begin exploring

0:28:50.480000 --> 0:28:55.060000
 the other techniques or the other phases
 of my methodology and now your

0:28:55.060000 --> 0:28:59.460000
 methodology. And with that being said,
 that's going to be it for this

0:28:59.460000 --> 0:29:02.300000
 video. And I'll be seeing
 you in the next video.

