WEBVTT

0:00:09.400000 --> 0:00:14.840000
 Hello everyone and welcome to the Filte
 Evasion and WAF Bypass techniques

0:00:14.840000 --> 0:00:19.680000
 course. Before we get started with
 the course I always like providing

0:00:19.680000 --> 0:00:24.700000
 you, the student or learner with an
 overview of what we'll be covering

0:00:24.700000 --> 0:00:32.140000
 in this course. To give you an idea as to
 what to expect, the course prerequisites

0:00:32.140000 --> 0:00:37.300000
 as well as the learning outcomes or
 what you will know and what you'll

0:00:37.300000 --> 0:00:39.300000
 be able to do by the end of this course.

0:00:39.300000 --> 0:00:43.340000
 So this is a very important video because
 it again keeps you or prepares

0:00:43.340000 --> 0:00:48.360000
 you mentally by giving you a lay of the
 land in terms of the topics we'll

0:00:48.360000 --> 0:00:53.960000
 be covering and also acts as a way to
 again measure your progress at the

0:00:53.960000 --> 0:01:00.220000
 end of the course, specifically through
 the use of the learning outcomes

0:01:00.220000 --> 0:01:04.760000
 because at the end of the course in the
 course summary we will be revisiting

0:01:04.760000 --> 0:01:09.320000
 the learning outcomes or objectives
 to see whether I covered everything

0:01:09.320000 --> 0:01:12.940000
 that I was supposed to cover and more
 importantly for you whether you

0:01:12.940000 --> 0:01:24.880000
 know what you're supposed to be able to
 do but more importantly all aligned

0:01:24.880000 --> 0:01:28.200000
 to the learning outcomes
 that we'll define here.

0:01:28.200000 --> 0:01:31.700000
 So let's get some of the formalities
 out of the way.

0:01:31.700000 --> 0:01:34.300000
 Who am I? My name is Alexis Ahmed.

0:01:34.300000 --> 0:01:38.640000
 I'm the offensive security instructor
 or red team instructor here at INE

0:01:38.640000 --> 0:01:42.860000
 and also the red team leader senior
 pentester at Hackersploit.

0:01:42.860000 --> 0:01:47.120000
 So firstly let's take a look at some
 of the key concepts that we'll be

0:01:47.120000 --> 0:01:48.120000
 covering in this course.

0:01:48.120000 --> 0:01:53.660000
 We're going to start off by getting into
 data and coding or understanding

0:01:53.660000 --> 0:01:59.780000
 data and coding taking a look at the
 various encoding schemas of which

0:01:59.780000 --> 0:02:04.120000
 I'll actually explain in a few seconds
 or outline in a few seconds.

0:02:04.120000 --> 0:02:09.400000
 The idea is to essentially ensure that
 you have a good understanding of

0:02:09.400000 --> 0:02:14.500000
 data encoding specifically on the web
 or you know what you're likely to

0:02:14.500000 --> 0:02:18.540000
 encounter as being used
 by web applications.

0:02:18.540000 --> 0:02:22.760000
 We'll then move on to server side
 and client side filter evasion.

0:02:22.760000 --> 0:02:28.940000
 So you know the process of identifying
 you know the presence of a filter

0:02:28.940000 --> 0:02:32.760000
 whether it's client side or server
 side and then of course the various

0:02:32.760000 --> 0:02:45.860000
 evasion techniques that can be grounded
 you know through the use of through

0:02:45.860000 --> 0:02:51.200000
 the use or the implementation of set techniques
 in exploitation of vulnerabilities

0:02:51.200000 --> 0:02:56.860000
 you know that involve data being input
 you know examples of that would

0:02:56.860000 --> 0:02:59.800000
 be cross-site scripting
 SQL injection etc.

0:02:59.800000 --> 0:03:03.460000
 And then finally web application firewall
 and proxy bypass techniques

0:03:03.460000 --> 0:03:10.580000
 so how to identify or determine the presence
 of a web application firewall

0:03:10.580000 --> 0:03:16.040000
 or an intermediary system that is proxying
 traffic between yourself or

0:03:16.040000 --> 0:03:20.880000
 clients generally and the web application
 server or you know the actual

0:03:20.880000 --> 0:03:24.680000
 web server regardless of the fact we'll
 be exploring that how to identify

0:03:24.680000 --> 0:03:29.840000
 web application firewalls and then
 of course how to bypass them.

0:03:29.840000 --> 0:03:34.020000
 So at a high level those are the key
 concepts now sort of diving a little

0:03:34.020000 --> 0:03:37.880000
 bit deeper we're now going to take
 a look at the major topic.

0:03:37.880000 --> 0:03:42.440000
 So as I mentioned we'll cover the fundamentals
 of data encoding so you

0:03:42.440000 --> 0:03:47.660000
 know HTML encoding URL
 encoding base 64 etc.

0:03:47.660000 --> 0:03:51.880000
 among many others that I haven't listed
 here but just to give you an idea

0:03:51.880000 --> 0:03:54.740000
 of what to expect that's what we'll
 be doing there and then we'll get

0:03:54.740000 --> 0:04:00.200000
 into the fundamentals or I should say
 the you know getting an understanding

0:04:00.200000 --> 0:04:04.600000
 of the inner workings of input filtering
 and how filtering is implemented

0:04:04.600000 --> 0:04:07.560000
 both on the client side server side etc.

0:04:07.560000 --> 0:04:12.060000
 The idea here is to give you this you know
 this overview so that you understand

0:04:12.060000 --> 0:04:17.660000
 or you start to get a clearer picture
 of where the vulnerabilities or

0:04:17.660000 --> 0:04:22.080000
 where you know filters can be bypassed
 if you will or evaded and then

0:04:22.080000 --> 0:04:25.620000
 we'll take a look at client side and
 filter side filter evasion which

0:04:25.620000 --> 0:04:30.340000
 I already mentioned and you know we'll
 be taking a look at very specific

0:04:30.340000 --> 0:04:34.300000
 cases that involve cross-site scripting
 vulnerabilities, SQL injection

0:04:34.300000 --> 0:04:36.560000
 vulnerabilities etc.

0:04:36.560000 --> 0:04:41.180000
 and then finally WAF and proxy bypass
 techniques which I also outlined.

0:04:41.180000 --> 0:04:45.840000
 So that brings us to the learning outcomes
 so what you will know and what

0:04:45.840000 --> 0:04:48.340000
 you should be able to do
 by the end of the course.

0:04:48.340000 --> 0:04:51.680000
 So firstly you'll have a good understanding
 of the importance of encoding

0:04:51.680000 --> 0:04:56.260000
 on the web and its importance in the
 functionality of web applications.

0:04:56.260000 --> 0:05:00.020000
 You will have a solid understanding
 of what content and input filtering

0:05:00.020000 --> 0:05:04.220000
 is, how and why filtering is implemented
 in web applications and how server

0:05:04.220000 --> 0:05:07.320000
 side and client side filters
 can be bypassed.

0:05:07.320000 --> 0:05:10.780000
 You'll have a solid understanding of
 the most common forms of encoding

0:05:10.780000 --> 0:05:16.620000
 on the web, how they work and how and
 why they're implemented so think

0:05:16.620000 --> 0:05:21.160000
 of HTML encoding, URL encoding
 and base 64 encoding.

0:05:21.160000 --> 0:05:25.120000
 You will have the ability to detect
 and bypass common client side and

0:05:25.120000 --> 0:05:28.460000
 server side filters so you know cross
-site scripting filters, command

0:05:28.460000 --> 0:05:31.420000
 injection, SQL injection etc.

0:05:31.420000 --> 0:05:35.160000
 And finally you'll be able to bypass or
 evade rudimentary forms of protection

0:05:35.160000 --> 0:05:39.140000
 or filtering imposed by proxies
 or web application firewall.

0:05:39.140000 --> 0:05:43.860000
 So you know that's it or there you
 go that's you know what you should

0:05:43.860000 --> 0:05:47.680000
 expect in terms of you know knowledge
 you should have acquired and the

0:05:47.680000 --> 0:05:50.400000
 skills you should have acquired by
 the end of the course and this sort

0:05:50.400000 --> 0:05:56.820000
 of sets a benchmark for us or for you
 to measure yourself or to measure

0:05:56.820000 --> 0:05:59.380000
 your progress at the end of the course.

0:05:59.380000 --> 0:06:03.260000
 So those are the learning outcomes and
 then of course we have the course

0:06:03.260000 --> 0:06:07.640000
 pre-recursite so what do you need to
 know or what you should be able to

0:06:07.640000 --> 0:06:09.680000
 do before getting into this course.

0:06:09.680000 --> 0:06:16.100000
 But you know basically you know you
 just need a familiarity with HTTP,

0:06:16.100000 --> 0:06:20.100000
 HTTPS so you know how the protocol
 works, the headers etc.

0:06:20.100000 --> 0:06:23.620000
 You should also be familiar or should
 have experience in using proxies

0:06:23.620000 --> 0:06:27.440000
 like ZAP or Android burps suite really
 doesn't matter as long as you're

0:06:27.440000 --> 0:06:32.820000
 comfortable with intercepting traffic
 or requests and you know modifying

0:06:32.820000 --> 0:06:37.280000
 them you know you should be good and
 also I'd recommend having a basic

0:06:37.280000 --> 0:06:40.060000
 familiarity or understanding
 of JavaScript.

0:06:40.060000 --> 0:06:44.480000
 This is not really that important
 but is highly recommended.

0:06:44.480000 --> 0:06:48.060000
 With that being said I don't I don't
 want to take too much time I'm really

0:06:48.060000 --> 0:06:52.200000
 excited to get started with this course
 and I'll be seeing you in the

0:06:52.200000 --> 0:06:53.620000
 first section of the course.

