WEBVTT

0:00:03.820000 --> 0:00:09.080000
 Hello everyone and welcome to the final
 video within this section and

0:00:09.080000 --> 0:00:14.500000
 within this course where we will be wrapping
 up the process of performing

0:00:14.500000 --> 0:00:20.980000
 web service security testing specifically
 on soap based web services and

0:00:20.980000 --> 0:00:25.880000
 to tie everything off we're going to
 be taking a look at how to test for

0:00:25.880000 --> 0:00:30.680000
 command injection pretty much just factoring
 in what we've learned thus

0:00:30.680000 --> 0:00:35.800000
 far as you can see it's been pretty
 exciting and we'll be utilizing the

0:00:35.800000 --> 0:00:41.220000
 same lab that we have been during the
 actual practical videos or from

0:00:41.220000 --> 0:00:48.600000
 the point when we actually began enumerating
 or trying to find WSDL files.

0:00:48.600000 --> 0:00:54.980000
 So as you know this will be a practical
 video so this video a lot will

0:00:54.980000 --> 0:00:59.320000
 also utilize the lab we've used previously
 and if you're picking up from

0:00:59.320000 --> 0:01:03.260000
 where you left off from don't worry
 you can just proceed on we're now

0:01:03.260000 --> 0:01:07.640000
 going to be testing a different endpoint
 and what I'm going to do is switch

0:01:07.640000 --> 0:01:12.280000
 over into the lab environment
 and I'll see you there.

0:01:12.280000 --> 0:01:18.940000
 All right so I am back within the lab
 environment and as you know based

0:01:18.940000 --> 0:01:28.660000
 on what I did previously I am so we
 are going to be testing for command

0:01:28.660000 --> 0:01:32.560000
 injection and again the objective here
 is to now sort of contextualize

0:01:32.560000 --> 0:01:37.140000
 everything we've learned both theoretical
 and practical and just take

0:01:37.140000 --> 0:01:41.700000
 a look at one more example of a vulnerability
 we can exploit or identify

0:01:41.700000 --> 0:01:48.720000
 and exploit in a soap web service and
 in this particular case we're going

0:01:48.720000 --> 0:01:51.340000
 to navigate into or you want
 to navigate to demo.

0:01:51.340000 --> 0:01:56.160000
 I need local which will take you to Motilidae
 head over into web services

0:01:56.160000 --> 0:02:03.860000
 and into soap and navigate to command
 injection and DNS lookup okay so

0:02:03.860000 --> 0:02:08.220000
 when we navigate to this particular endpoint
 which is a web service lookup

0:02:08.220000 --> 0:02:15.400000
 DNS record we can see that we have the
 WSDL for this service as well as

0:02:15.400000 --> 0:02:20.820000
 the operation called lookup DNS which
 is fairly simple it just probably

0:02:20.820000 --> 0:02:26.580000
 performs a lookup on a website so if
 I click on it here you can see this

0:02:26.580000 --> 0:02:31.500000
 is how it works so the name is lookup
 DNS the binding is the following

0:02:31.500000 --> 0:02:36.400000
 the endpoint is displayed there as for
 the soap action it looks like we

0:02:36.400000 --> 0:02:41.460000
 need to specify it here the input we
 can take a look at by taking a look

0:02:41.460000 --> 0:02:45.140000
 at the sample request which we can actually
 copy and paste into burp repeater

0:02:45.140000 --> 0:02:54.020000
 we can see that under the actual operation
 here we can see lookup DNS

0:02:54.020000 --> 0:03:02.120000
 we have a parameter called target host
 and it is a string type so we just

0:03:02.120000 --> 0:03:09.960000
 put in an address or a website and it
 performs a DNS lookup on this and

0:03:09.960000 --> 0:03:18.180000
 this is a an endpoint or a service
 that could be vulnerable to command

0:03:18.180000 --> 0:03:22.580000
 injection if you're not familiar with
 command injection this was covered

0:03:22.580000 --> 0:03:26.680000
 in the testing for common attacks course
 within this learning path just

0:03:26.680000 --> 0:03:30.860000
 to go over it again this is a vulnerability
 that essentially allows for

0:03:30.860000 --> 0:03:36.440000
 the execution of system level commands
 and it's primarily caused by a

0:03:36.440000 --> 0:03:40.920000
 lack of input validation or sanitization
 and if we take a look at the

0:03:40.920000 --> 0:03:46.960000
 WSDL here you can see that we have the
 operation lookup DNS and this will

0:03:46.960000 --> 0:03:51.800000
 return the results of the DNS lookup
 and you know we can pretty much just

0:03:51.800000 --> 0:03:56.860000
 copy the sample request and do what we
 did previously so we can just click

0:03:56.860000 --> 0:04:02.640000
 on the sample request for the lookup
 DNS operation which is going to be

0:04:02.640000 --> 0:04:09.000000
 a post so always pay attention to that
 and I'm not going to go into web

0:04:09.000000 --> 0:04:14.900000
 application analysis and I'll open up
 burp suite here and we want to make

0:04:14.900000 --> 0:04:18.960000
 sure we modify the endpoint or the
 URI there within the actual request

0:04:18.960000 --> 0:04:23.220000
 header because we you can see that
 we don't have motility as a folder

0:04:23.220000 --> 0:04:28.180000
 there or is not part of the path if
 you will so I'll just expand this

0:04:28.180000 --> 0:04:33.140000
 and I'll go into my user options one
 more time we'll go into display and

0:04:33.140000 --> 0:04:38.180000
 for the font size for the interface
 I'll go for 16 and we'll change this

0:04:38.180000 --> 0:04:42.220000
 to dark because I really like that
 and I'm assuming most of you to do

0:04:42.220000 --> 0:04:49.000000
 as well we'll go for 24 and now we'll go
 into the repeater as we did previously

0:04:49.000000 --> 0:04:53.340000
 I'll just close up the inspector there
 and we'll paste this in here first

0:04:53.340000 --> 0:05:00.460000
 order of business is getting rid of
 this here and we then need to if we

0:05:00.460000 --> 0:05:05.060000
 take a look at the sample address google
.com yeah we'll use the default

0:05:05.060000 --> 0:05:10.300000
 there and I'll just resize this ever
 so slightly and we'll now be prompted

0:05:10.300000 --> 0:05:15.480000
 to specify the target by burp suite
 solid send and that is just demo.ini

0:05:15.480000 --> 0:05:22.260000
.local and the port is just going to
 be port 80 solid okay and we'll then

0:05:22.260000 --> 0:05:29.060000
 send it now and there we are we get a
 200 okay which means operation does

0:05:29.060000 --> 0:05:35.320000
 exist and was executed and in this case
 you can see that the results there's

0:05:35.320000 --> 0:05:39.740000
 nothing in the results the reason for
 that is because this lab is not

0:05:39.740000 --> 0:05:44.500000
 connected to the internet so for example
 if I went into you know I have

0:05:44.500000 --> 0:05:49.700000
 config and I copied my Kali Linux IP
 and I tried to perform a DNS lookup

0:05:49.700000 --> 0:05:53.460000
 on it it should work because this is
 on the local network and they should

0:05:53.460000 --> 0:06:01.040000
 be a DNS server locally so I'll just
 paste that in there for some reason

0:06:01.040000 --> 0:06:06.640000
 it's not pasting we had that is very
 weird so let me just try and copy

0:06:06.640000 --> 0:06:13.940000
 it again so there we are I'll just copy
 and we'll go back in here in case

0:06:13.940000 --> 0:06:18.620000
 I need that and I'll just replace it
 with the IP there and we hit send

0:06:18.620000 --> 0:06:24.400000
 we should get some form of a result here
 okay so nothing very interesting

0:06:24.400000 --> 0:06:29.280000
 so whenever dealing with command injection
 vulnerabilities or input vulnerabilities

0:06:29.280000 --> 0:06:33.640000
 we typically want to find a way to
 terminate whatever is coming before

0:06:33.640000 --> 0:06:40.360000
 it right or you know terminate the query
 or command or whatever is coming

0:06:40.360000 --> 0:06:44.920000
 before it in the case of SQL injection
 we know that the easiest way to

0:06:44.920000 --> 0:06:54.180000
 do that is through a single or opens
 us opens up the availability or the

0:06:54.180000 --> 0:07:00.420000
 possibility to to essentially put our
 SQL our malicious SQL injection

0:07:00.420000 --> 0:07:06.320000
 payload after the after the single quote
 in the case of command injection

0:07:06.320000 --> 0:07:11.660000
 based on how these types of web services
 and even web applications work

0:07:11.660000 --> 0:07:15.860000
 they are taking in a command that is
 then executed at the system level

0:07:15.860000 --> 0:07:21.040000
 so by the underlying server which is
 most likely Linux and the way this

0:07:21.040000 --> 0:07:27.680000
 is done or the way the way commands are
 terminated in the shell is through

0:07:27.680000 --> 0:07:33.640000
 the use of a semicolon typically right
 or even an ampersand and in order

0:07:33.640000 --> 0:07:38.680000
 to test it what we can do is utilize
 a semicolon here and just click on

0:07:38.680000 --> 0:07:43.640000
 send and as you can see here no results
 return but remember we need to

0:07:43.640000 --> 0:07:48.260000
 put in a system command after this so
 I can put in the id command to display

0:07:48.260000 --> 0:07:52.980000
 the current user if executed successfully
 you can see there we are we've

0:07:52.980000 --> 0:07:58.000000
 successfully exploited the the command
 injection vulnerability and as

0:07:58.000000 --> 0:08:02.680000
 you can see here now the use id is dot
 dot data so remember we still have

0:08:02.680000 --> 0:08:07.740000
 to get the third flag so let me see
 if I can list out the contents of

0:08:07.740000 --> 0:08:13.480000
 our current directory so right now we
 are currently okay I'll just list

0:08:13.480000 --> 0:08:19.520000
 it out the files in here but if I say
 pwd and I print the current working

0:08:19.520000 --> 0:08:25.140000
 directory you can see we are currently
 in app web services soap okay so

0:08:25.140000 --> 0:08:30.540000
 let's see what is in the app folder
 here and this is one of the um one

0:08:30.540000 --> 0:08:34.540000
 of the impacts of command injection
 is we can get remote code execution

0:08:34.540000 --> 0:08:39.220000
 and now we are not only interacting with
 the web service or web application

0:08:39.220000 --> 0:08:50.740000
 we now can play with files on the list
 all um we'll say app okay let's

0:08:50.740000 --> 0:08:54.180000
 see if this works whether it passes
 that correctly there we are so we

0:08:54.180000 --> 0:09:00.520000
 can see that there and this displays all
 contents in the um motility directory

0:09:00.520000 --> 0:09:05.220000
 or where motility is being hosted and
 from this point on you know we can

0:09:05.220000 --> 0:09:09.120000
 um pretty much look for anything sensitive
 that we would like to exfiltrate

0:09:09.120000 --> 0:09:14.300000
 so for example uh you know we can take
 a look at what I'm really curious

0:09:14.300000 --> 0:09:20.200000
 to see is setup database uh because
 and I'll explain this so I'll just

0:09:20.200000 --> 0:09:26.920000
 say cat and we'll get the name of the
 file so setup um actually that is

0:09:26.920000 --> 0:09:33.860000
 set hyphen up hyphen um database.php
 I'm just trying to see whether we

0:09:33.860000 --> 0:09:37.280000
 have any database credentials that we
 can then use to gain access to the

0:09:37.280000 --> 0:09:44.540000
 MySQL database but let's send here
 and um okay so setting up database

0:09:44.540000 --> 0:09:52.220000
 do we have an inclusion of uh credentials
 let's see let's see so there

0:09:52.220000 --> 0:09:59.740000
 we are database username um hmm interesting
 okay so that's trying to connect

0:09:59.740000 --> 0:10:06.920000
 yeah so that just sets it up what I'll
 do is I'll my previous command

0:10:06.920000 --> 0:10:12.680000
 uh just to list out the contents of
 the app directory and in here we can

0:10:12.680000 --> 0:10:17.640000
 look for any configuration file that
 could contain you know uh passwords

0:10:17.640000 --> 0:10:23.740000
 or anything like that but more importantly
 I was looking for the um I

0:10:23.740000 --> 0:10:29.860000
 was looking for the flag uh that um
 that we were supposed to get so we

0:10:29.860000 --> 0:10:34.460000
 got the second flag and the third I'm
 sorry the first and second flag

0:10:34.460000 --> 0:10:38.960000
 but not the third flag which is actually
 our objective here so I'm not

0:10:38.960000 --> 0:10:42.300000
 really sure where it's stored we can
 probably run a find command or a

0:10:42.300000 --> 0:10:48.440000
 locate command to try and see where that
 is um in terms of its uh storage

0:10:48.440000 --> 0:10:53.780000
 um and obviously I think that that's
 probably the best option here we'll

0:10:53.780000 --> 0:11:00.080000
 just say find um let's see we'll say
 find and uh we'll say you know i

0:11:00.080000 --> 0:11:05.260000
 name and we'll use a rejects here so
 flag anything with flag and then

0:11:05.260000 --> 0:11:12.360000
 redirect that to dev null and uh now
 from this point on we don't uh it

0:11:12.360000 --> 0:11:21.280000
 should process uh special characters
 um okay so flags flags let me let

0:11:21.280000 --> 0:11:26.560000
 me just drag this to the side and we
 are looking for let's see we have

0:11:26.560000 --> 0:11:35.020000
 any flags here no flags I can only see
 none of these related but we can

0:11:35.020000 --> 0:11:43.540000
 see these are all in the proc directory
 uh okay very interesting um but

0:11:43.540000 --> 0:11:51.840000
 we know that this is working um this
 is interesting because we should

0:11:51.840000 --> 0:11:55.720000
 oh there we are there we are flag three
 is under app I can't believe I

0:11:55.720000 --> 0:12:04.740000
 didn't see it so if I just say um in
 here ls al app that's weird the fact

0:12:04.740000 --> 0:12:08.600000
 that I didn't see it the first time because
 there is sorted alphabetically

0:12:08.600000 --> 0:12:13.260000
 so you know if I say oh there we are
 so it does exist so now we can just

0:12:13.260000 --> 0:12:20.920000
 say cat and app and we'll say flag three
 and we'll then hit send and uh

0:12:20.920000 --> 0:12:26.380000
 there we are so we get the flag the third
 flag here and that consequently

0:12:26.380000 --> 0:12:32.880000
 concludes uh the motility web service
 challenges there are of course other

0:12:32.880000 --> 0:12:38.120000
 ones you can take a look at and more
 specifically uh we do have um if

0:12:38.120000 --> 0:12:43.900000
 we go back to motility right over here
 they are the uh rest web services

0:12:43.900000 --> 0:12:47.880000
 which you can check out for yourself
 rest is arguably much more simpler

0:12:47.880000 --> 0:12:52.520000
 to utilize so for example when I go
 to the end point here the rest end

0:12:52.520000 --> 0:12:58.540000
 point uh you can see that now this works
 over hdpn parameters are passed

0:12:58.540000 --> 0:13:04.900000
 in the url it looks like um you can
 see that uh yeah so post creates a

0:13:04.900000 --> 0:13:10.920000
 new account put so as I mentioned in
 the web services in a web service

0:13:10.920000 --> 0:13:16.320000
 implementations video in the intro section
 uh rest or restful api is utilized

0:13:16.320000 --> 0:13:20.620000
 methods uh to perform certain actions
 on an end point the bottom line

0:13:20.620000 --> 0:13:25.000000
 is that this is the end point here uh
 and you pass in parameters in this

0:13:25.000000 --> 0:13:30.040000
 particular implementation uh in the url
 and then utilize different methods

0:13:30.040000 --> 0:13:35.880000
 to either create a new account uh update
 an account with regards to maybe

0:13:35.880000 --> 0:13:41.160000
 updating a password or deleting the account
 use the delete method so definitely

0:13:41.160000 --> 0:13:46.720000
 give this a go try out get started
 with um with other web services in

0:13:46.720000 --> 0:13:52.480000
 this case you can definitely try out
 the rest our web services here and

0:13:52.480000 --> 0:13:56.960000
 uh that is going to conclude the practical
 demonstration side of this

0:13:56.960000 --> 0:14:03.580000
 video all right so that was how to test
 for command injection vulnerabilities

0:14:03.580000 --> 0:14:09.500000
 on a dope web service end point and
 uh that brings us to the end of the

0:14:09.500000 --> 0:14:13.960000
 course um I know you guys wanted to
 take a look at more our web service

0:14:13.960000 --> 0:14:17.880000
 stuff I can almost feel it uh through
 your screen but as I said don't

0:14:17.880000 --> 0:14:23.180000
 worry this is going to set you up uh
 I think uh for the next stage which

0:14:23.180000 --> 0:14:27.620000
 is again exploring other web service
 implementation types whether it be

0:14:27.620000 --> 0:14:32.060000
 you know through restful apis and now
 you can finally turn your attention

0:14:32.060000 --> 0:14:37.960000
 to apis the primary objective here was
 to give you that first foray into

0:14:37.960000 --> 0:14:42.100000
 web services and apis because as you
 saw they pretty much work the same

0:14:42.100000 --> 0:14:47.940000
 once you understand web services like
 so restful apis are a piece of cake

0:14:47.940000 --> 0:14:52.500000
 so you know I know that you even be
 able to learn that on your own uh

0:14:52.500000 --> 0:14:56.240000
 but with that being said that brings
 us to the end of this video and I'll

