WEBVTT

0:00:04.100000 --> 0:00:06.980000
 All right, so I'm back within
 my Cali Linux system.

0:00:06.980000 --> 0:00:11.240000
 And before we get started, I just want
 to highlight a couple of things.

0:00:11.240000 --> 0:00:15.500000
 Firstly, there's a couple of very useful
 resources online that I'd highly

0:00:15.500000 --> 0:00:19.540000
 recommend you take a look at the first
 or rather the only one is going

0:00:19.540000 --> 0:00:24.680000
 to be the HTML URL encoding
 reference on W3 schools.

0:00:24.680000 --> 0:00:29.360000
 That sort of explains what I just told
 you and gives you a very simple

0:00:29.360000 --> 0:00:32.580000
 example or a demo as to how it works.

0:00:32.580000 --> 0:00:38.280000
 So, you essentially put in text here and
 it shows you how this is essentially

0:00:38.280000 --> 0:00:40.300000
 parsed using URL encoding.

0:00:40.300000 --> 0:00:43.700000
 So, when you click on submit, you can
 see the same example where we have

0:00:43.700000 --> 0:00:48.000000
 PHP, the actual file or resource and
 then the inclusion of a parameter

0:00:48.000000 --> 0:00:50.240000
 called text and then the value here.

0:00:50.240000 --> 0:00:54.680000
 And you can see in this case, no URL encoding
 is required, but if we utilize

0:00:54.680000 --> 0:00:59.960000
 the space, so we can say, Alex is a
 bad pen tester, you know, just for

0:00:59.960000 --> 0:01:04.980000
 gags, you can see how that URL encoding
 is performed and just based on

0:01:04.980000 --> 0:01:09.260000
 what I explained to you, you can see
 that there is the utilization of

0:01:09.260000 --> 0:01:12.260000
 the percentage symbol and 20.

0:01:12.260000 --> 0:01:16.300000
 You can obviously utilize
 the char set website here.

0:01:16.300000 --> 0:01:20.560000
 So, for example, if I use a space and
 I click on convert, you can see

0:01:20.560000 --> 0:01:26.960000
 it automatically converts to %20, which
 is the ASCII, sorry, not the ASCII,

0:01:26.960000 --> 0:01:31.180000
 the hex, the hex position, Unicode
 hex position, which is 20.

0:01:31.180000 --> 0:01:36.960000
 So, just the percentage symbol followed
 by the Unicode hex position within,

0:01:36.960000 --> 0:01:39.000000
 for example, UTF-8.

0:01:39.000000 --> 0:01:42.140000
 But this is part of the
 US ASCII first 128.

0:01:42.140000 --> 0:01:46.640000
 So, just keep that in mind as you, you
 know, if you're dealing with, you

0:01:46.640000 --> 0:01:51.120000
 know, symbols or characters from different
 languages and scripts that

0:01:51.120000 --> 0:01:55.500000
 would then fall within the Unicode code
 point or within Unicode and not

0:01:55.500000 --> 0:02:01.800000
 within the first 128, which is part
 of Unicode for, you know, backwards

0:02:01.800000 --> 0:02:06.680000
 compatibility. In any case, the example
 that I want to start off with

0:02:06.680000 --> 0:02:13.480000
 is essentially enforcing URL
 encoding in using JavaScript.

0:02:13.480000 --> 0:02:19.280000
 So, I'll just open up a text editor
 here and I'll just use leafpad.

0:02:19.280000 --> 0:02:22.180000
 And this is going to be a very,
 very simple web application.

0:02:22.180000 --> 0:02:23.780000
 It's just going to be HTML file.

0:02:23.780000 --> 0:02:26.120000
 So, I'll just type it in here.

0:02:26.120000 --> 0:02:27.580000
 And again, you guys can follow along.

0:02:27.580000 --> 0:02:31.900000
 The reason why do this is so that you
 understand what's going on as I'm

0:02:31.900000 --> 0:02:35.140000
 typing. So, you know, we'll
 create the HTML tags now.

0:02:35.140000 --> 0:02:37.240000
 And that's very, very simple as you know.


0:02:37.240000 --> 0:02:40.320000
 So, we'll just say HTML like so.

0:02:40.320000 --> 0:02:44.100000
 And then we'll include the actual,
 the actual head here.

0:02:44.100000 --> 0:02:47.760000
 And I'll close the tags again just
 to keep things nice and simple.

0:02:47.760000 --> 0:02:50.540000
 So, body and we then have the body here.

0:02:50.540000 --> 0:02:54.000000
 And within the head, we have the title,
 which I'll just provide the title

0:02:54.000000 --> 0:03:00.260000
 of the website as a URL encode, you
 know, just keeping things nice and

0:03:00.260000 --> 0:03:04.760000
 simple. For the body, this is where we
 can start getting or taking a look

0:03:04.760000 --> 0:03:05.940000
 at some interesting stuff.

0:03:05.940000 --> 0:03:10.500000
 I'll just create an H1 and I'll just
 say, you know, URL encoding with

0:03:10.500000 --> 0:03:15.080000
 JS. Okay. And this is,
 we'll close the H1.

0:03:15.080000 --> 0:03:17.900000
 And from here, we can, the
 web application is simple.

0:03:17.900000 --> 0:03:22.780000
 It's just going to take an input in
 an input box or text field, if you

0:03:22.780000 --> 0:03:27.360000
 will. And it's then we're going to create
 a button that will perform the

0:03:27.360000 --> 0:03:30.520000
 encoding in with JavaScript.

0:03:30.520000 --> 0:03:35.580000
 We're not going to send it anywhere
 or to the web server for processing.

0:03:35.580000 --> 0:03:39.860000
 But what we're going to do instead is
 just display the encoded text back

0:03:39.860000 --> 0:03:42.760000
 similar to what W3 schools did there.

0:03:42.760000 --> 0:03:47.640000
 So we'll start off by creating a label
 and the label is just going to

0:03:47.640000 --> 0:03:51.440000
 be four is equal to, and the label we're
 going to give it a unique name

0:03:51.440000 --> 0:03:55.160000
 of text input, which because we
 will be referencing this here.

0:03:55.160000 --> 0:03:58.560000
 And we're just going to say
 enter text to encode.

0:03:58.560000 --> 0:04:03.040000
 So just prompting the user to,
 you know, enter the text.

0:04:03.040000 --> 0:04:05.900000
 So we'll just close the label there.

0:04:05.900000 --> 0:04:09.300000
 And let me make sure I, you
 know, type in the tags here.

0:04:09.300000 --> 0:04:12.660000
 And from this point, we can now create
 the actual input, which is going

0:04:12.660000 --> 0:04:14.620000
 to be a type text.

0:04:14.620000 --> 0:04:17.160000
 So it's going to accept text here.

0:04:17.160000 --> 0:04:20.300000
 And then the ID is going to be what
 we referenced earlier, which is just

0:04:20.300000 --> 0:04:23.780000
 text input. So unique
 identifier for that.

0:04:23.780000 --> 0:04:27.960000
 The placeholder for this is just going
 to be, you know, enter text, for

0:04:27.960000 --> 0:04:33.300000
 example, right? And we'll close that
 input tag there or the input element.

0:04:33.300000 --> 0:04:36.900000
 We're then going to create a button,
 which is of type button, you know,

0:04:36.900000 --> 0:04:38.020000
 self-explanatory.

0:04:38.020000 --> 0:04:40.840000
 We've ever developed an HTML on click.

0:04:40.840000 --> 0:04:45.540000
 So this is now when we refer to a
 particular JavaScript function.

0:04:45.540000 --> 0:04:48.340000
 So in this case, we're just
 going to call the function.

0:04:48.340000 --> 0:04:50.720000
 We've not yet developed the function,
 but we're going to call it encode

0:04:50.720000 --> 0:04:53.920000
 text and then just reference it there.

0:04:53.920000 --> 0:04:59.680000
 So essentially providing this button
 with an action and the action will

0:04:59.680000 --> 0:05:01.980000
 be facilitated by JavaScript.

0:05:01.980000 --> 0:05:05.420000
 So we're going to just call
 this button encode like so.

0:05:05.420000 --> 0:05:08.020000
 And I'm just going to close
 the button tag there.

0:05:08.020000 --> 0:05:13.260000
 OK, now we can pretty much create a,
 you know, paragraph here and just

0:05:13.260000 --> 0:05:15.200000
 say encoded text.

0:05:15.200000 --> 0:05:18.540000
 So we're essentially reflecting back
 or displaying the encoded text that

0:05:18.540000 --> 0:05:21.520000
 was input by the user.

0:05:21.520000 --> 0:05:24.040000
 So we'll just close the
 paragraph tag here.

0:05:24.040000 --> 0:05:25.880000
 Don't think we need much in there.

0:05:25.880000 --> 0:05:30.280000
 So encoded text and then we'll create
 the paragraph tag here with an ID

0:05:30.280000 --> 0:05:33.720000
 is equal to encoded text.

0:05:33.720000 --> 0:05:40.840000
 So again, the function in this gap,
 we'll just say encoded text.

0:05:40.840000 --> 0:05:45.420000
 There we are. And we'll just close that
 there and we'll close the paragraph

0:05:45.420000 --> 0:05:50.360000
 tag like so. We'll now create
 the JavaScript snippet here.

0:05:50.360000 --> 0:05:52.740000
 So script and script.

0:05:52.740000 --> 0:05:55.760000
 So this is client side enforcement
 of URL encoding.

0:05:55.760000 --> 0:06:00.420000
 So we'll, you know, we can
 actually just say function.

0:06:00.420000 --> 0:06:04.980000
 And we already specified the name, but
 we'll just call this encode text

0:06:04.980000 --> 0:06:08.100000
 because we have referenced it here.

0:06:08.100000 --> 0:06:11.720000
 And the function is going
 to be very simple.

0:06:11.720000 --> 0:06:14.700000
 So we'll just open up the
 curly braces in here.

0:06:14.700000 --> 0:06:16.760000
 We will say variable,
 create a new variable.

0:06:16.760000 --> 0:06:21.180000
 We'll just call it input text because
 again, we are referencing it here.

0:06:21.180000 --> 0:06:27.120000
 And then we'll say document
 dot get element by ID.

0:06:27.120000 --> 0:06:30.140000
 So we're just going to reference that
 element by its ID, which we already

0:06:30.140000 --> 0:06:33.200000
 created right over here
 called text input.

0:06:33.200000 --> 0:06:38.100000
 So text input and dot value.

0:06:38.100000 --> 0:06:42.980000
 So append dot value and then create another
 variable called encoded text,

0:06:42.980000 --> 0:06:44.620000
 which we already referenced earlier.

0:06:44.620000 --> 0:06:46.920000
 And then encode URI.

0:06:46.920000 --> 0:06:49.700000
 So this is the JavaScript
 function that does it.

0:06:49.700000 --> 0:06:53.400000
 So component. So encode URI component.

0:06:53.400000 --> 0:06:55.860000
 And then we specify what
 we want to encode.

0:06:55.860000 --> 0:07:00.480000
 So input text is what we want to encode.

0:07:00.480000 --> 0:07:03.820000
 And we'll then specify
 or just print it out.

0:07:03.820000 --> 0:07:09.500000
 So document dot get element by ID.

0:07:09.500000 --> 0:07:15.900000
 In here, we're just going
 to say encoded text.

0:07:15.900000 --> 0:07:19.340000
 Dot text content because
 we need to display it.

0:07:19.340000 --> 0:07:25.480000
 And then that's going to be equal to encoded
 text, which is being displayed

0:07:25.480000 --> 0:07:27.720000
 early on in the paragraph there.

0:07:27.720000 --> 0:07:32.320000
 So that's pretty much it really
 in terms of what we need to do.

0:07:32.320000 --> 0:07:37.620000
 So we'll just close that up there and
 we make sure that we've closed all

0:07:37.620000 --> 0:07:40.800000
 the other tags. And let's say this,
 I'm going to save it on my desktop

0:07:40.800000 --> 0:07:44.700000
 as URL encode dot HTML.

0:07:44.700000 --> 0:07:47.020000
 Because there's no inclusion of PHP.

0:07:47.020000 --> 0:07:50.000000
 And now I can open this up in my web browser
 and it's going to work really,

0:07:50.000000 --> 0:07:53.960000
 really simply because all the processing
 is done on the client side.

0:07:53.960000 --> 0:07:57.200000
 So there we are URL encoding
 with JavaScript.

0:07:57.200000 --> 0:08:00.220000
 So we just put in the text that
 we want to encode here.

0:08:00.220000 --> 0:08:05.360000
 And this particular web app will perform
 the URL encoding automatically.

0:08:05.360000 --> 0:08:10.680000
 So the point is that when we say, for
 example, Alexis here, encode, you

0:08:10.680000 --> 0:08:14.580000
 can see just displays back, you
 know, what was specified.

0:08:14.580000 --> 0:08:18.300000
 If it does have the inclusion of special
 characters or spaces like Alexis

0:08:18.300000 --> 0:08:21.180000
 is a bad pen tester.

0:08:21.180000 --> 0:08:26.600000
 We encode that. You can see it pretty
 much highlights what would be the

0:08:26.600000 --> 0:08:28.300000
 URL encoding that would be performed.

0:08:28.300000 --> 0:08:31.480000
 And of course, you can utilize something
 like burpsweet to intercept and

0:08:31.480000 --> 0:08:34.540000
 see that that is indeed
 what is being passed.

0:08:34.540000 --> 0:08:38.680000
 But again, remember, there
 is no web server here.

0:08:38.680000 --> 0:08:40.480000
 The reason for that is self explanatory.

0:08:40.480000 --> 0:08:42.520000
 I'm just opening up the HTML file.

0:08:42.520000 --> 0:08:45.640000
 So we can actually try that as well.

0:08:45.640000 --> 0:08:49.280000
 So I'll just open up a terminal
 here and we'll use Python.

0:08:49.280000 --> 0:08:53.620000
 So pseudo Python three, just to start
 up a very simple HTTP web servers

0:08:53.620000 --> 0:08:58.820000
 pseudo Python three module
 HTTP dot server port 80.

0:08:58.820000 --> 0:09:01.360000
 And I'll put in my password here.

0:09:01.360000 --> 0:09:05.900000
 And looks like I'm already using
 or Apache is already using this.

0:09:05.900000 --> 0:09:10.060000
 So system CTL stop Apache to
 and just run this again.

0:09:10.060000 --> 0:09:15.780000
 There we are. So now I just need
 to navigate to local host 001.

0:09:15.780000 --> 0:09:19.280000
 There we are. And you are in code HTML.

0:09:19.280000 --> 0:09:24.220000
 So if I now say Alexis
 is a bad pen tester.

0:09:24.220000 --> 0:09:27.780000
 Like so encode that there.

0:09:27.780000 --> 0:09:31.840000
 You know, still nothing being done because
 it's not being sent anywhere.

0:09:31.840000 --> 0:09:36.040000
 But if we were to send this, you know,
 let's say to a back end that was

0:09:36.040000 --> 0:09:40.180000
 using PHP, then we would be able to
 see that somewhat represented in the

0:09:40.180000 --> 0:09:48.680000
 URL here. So the point is that when
 this is being done now, at least on

0:09:48.680000 --> 0:09:52.200000
 the based on the way it's currently
 developed, because it's reflecting

0:09:52.200000 --> 0:09:55.400000
 back what is currently encoded.

0:09:55.400000 --> 0:09:57.640000
 Java cross L scripting will not work.

0:09:57.640000 --> 0:10:01.840000
 Now that's not because URL encoding
 is a security feature.

0:10:01.840000 --> 0:10:07.880000
 It's just how the web application is
 using what data is sent or what data

0:10:07.880000 --> 0:10:10.080000
 is being input using this input field.

0:10:10.080000 --> 0:10:13.780000
 So if I say encode, you can see
 it's just encoding it, right?

0:10:13.780000 --> 0:10:17.460000
 In preparation to be sent
 somewhere, for example.

0:10:17.460000 --> 0:10:23.640000
 So the point is, is that typically what
 would happen is it would be encoded

0:10:23.640000 --> 0:10:26.880000
 and then it's sent to the server
 side where it would be decoded.

0:10:26.880000 --> 0:10:30.800000
 And the decoded value would then be
 utilized for whatever it's supposed

0:10:30.800000 --> 0:10:31.960000
 to be utilized for.

0:10:31.960000 --> 0:10:36.240000
 So for example, if it was checking for
 a user's ID or a username and password,

0:10:36.240000 --> 0:10:39.120000
 it would interact with the
 relational database.

0:10:39.120000 --> 0:10:45.340000
 And that's the actual birth or the,
 the, that's what gives rise to SQL

0:10:45.340000 --> 0:10:47.740000
 injection vulnerabilities, for example.

0:10:47.740000 --> 0:10:52.360000
 So the point is that we can take a look
 at a much more realistic example

0:10:52.360000 --> 0:10:54.900000
 that utilizes PHP.

0:10:54.900000 --> 0:11:00.520000
 So it'll use the same logic where we
 will be essentially putting in or

0:11:00.520000 --> 0:11:03.900000
 will provide the user with the ability
 to put in input using an input

0:11:03.900000 --> 0:11:06.120000
 field and then click on submit.

0:11:06.120000 --> 0:11:09.140000
 The bottom line is that the server side
 would then perform the encoding

0:11:09.140000 --> 0:11:13.580000
 and then I'll show you what typically
 happens in terms of decoding and

0:11:13.580000 --> 0:11:17.660000
 the fact that this should never be treated
 as a security feature because

0:11:17.660000 --> 0:11:21.440000
 it all depends on how the back end,
 you know, will handle what has been

0:11:21.440000 --> 0:11:25.660000
 input. This just ensures that whatever
 has been input is sent in the correct

0:11:25.660000 --> 0:11:30.280000
 format because, you know, at the end,
 it could be decoded either way.

0:11:30.280000 --> 0:11:35.240000
 So I'll create a new file here and I'll
 just use this as a sort of a template,

0:11:35.240000 --> 0:11:37.720000
 what we created earlier.

0:11:37.720000 --> 0:11:43.120000
 And now the only thing that needs to change
 really, we don't need to change

0:11:43.120000 --> 0:11:49.240000
 the actual. Do we need
 to change anything?

0:11:49.240000 --> 0:11:53.340000
 Yes, the only thing we would need to
 change now is going to be around

0:11:53.340000 --> 0:11:55.820000
 the actual form here.

0:11:55.820000 --> 0:11:59.300000
 So here we will now need
 to specify a form.

0:11:59.300000 --> 0:12:04.240000
 So I'm going to say form method
 is going to be equal to get.

0:12:04.240000 --> 0:12:05.880000
 We're using a get method here.

0:12:05.880000 --> 0:12:12.180000
 The action is just null and now this
 would essentially fall under that

0:12:12.180000 --> 0:12:13.060000
 particular form.

0:12:13.060000 --> 0:12:15.260000
 So I'll close the form tag here.

0:12:15.260000 --> 0:12:19.720000
 And now within this particular form,
 the label, we don't need to change

0:12:19.720000 --> 0:12:24.000000
 anything here. In terms of the input,
 that's going to be text, the ID,

0:12:24.000000 --> 0:12:26.280000
 text, input, text is fine.

0:12:26.280000 --> 0:12:28.720000
 We need to provide it with a name.

0:12:28.720000 --> 0:12:33.600000
 So I'm just going to say name
 is equal to input text, right?

0:12:33.600000 --> 0:12:35.520000
 Placeholder can remain.

0:12:35.520000 --> 0:12:38.780000
 The button is going to be of type submit.


0:12:38.780000 --> 0:12:42.660000
 We're not using JavaScript,
 so we don't need that there.

0:12:42.660000 --> 0:12:43.980000
 And we can get rid of that there.

0:12:43.980000 --> 0:12:51.220000
 And now we also do not need
 the paragraph tags there.

0:12:51.220000 --> 0:12:54.780000
 And for JavaScript, we're
 not using JavaScript.

0:12:54.780000 --> 0:12:55.880000
 We're using PHP.

0:12:55.880000 --> 0:12:58.220000
 So I'll just create the PHP tag here.

0:12:58.220000 --> 0:13:03.200000
 So I'll just say PHP and I'll close
 the tag here at the bottom.

0:13:03.200000 --> 0:13:06.400000
 So just there PHP.

0:13:06.400000 --> 0:13:09.720000
 And now we need to create the actual
 PHP code that will perform the URL

0:13:09.720000 --> 0:13:17.940000
 encoding. So I will say if and we'll
 say I said and we'll specify that

0:13:17.940000 --> 0:13:23.660000
 the value is coming from a parameter
 in the actual get request.

0:13:23.660000 --> 0:13:28.540000
 So we'll say get like so.

0:13:28.540000 --> 0:13:31.720000
 And in here, we'll say input text.

0:13:31.720000 --> 0:13:34.600000
 OK, so that's the actual
 name of the parameter.

0:13:34.600000 --> 0:13:39.080000
 And from this point on, let's
 just close that up there.

0:13:39.080000 --> 0:13:41.820000
 We'll now create the curly braces here.

0:13:41.820000 --> 0:13:45.240000
 So this is where we are defining
 the actual function.

0:13:45.240000 --> 0:13:49.000000
 So we'll create a new variable
 called input text, right?

0:13:49.000000 --> 0:13:52.220000
 And we'll not perform the URL encoding
 beforehand because I want to highlight

0:13:52.220000 --> 0:13:55.860000
 something. So we'll say get.

0:13:55.860000 --> 0:14:04.160000
 Input text and I'm going
 to close that up there.

0:14:04.160000 --> 0:14:09.940000
 And now we are just going to say echo
 H to just reflect back whatever

0:14:09.940000 --> 0:14:15.140000
 is input. So no URL encoding being
 done and we'll just change this to

0:14:15.140000 --> 0:14:19.000000
 PHP. OK, so encoded text.

0:14:19.000000 --> 0:14:21.840000
 So this is now more so
 server side encoding.

0:14:21.840000 --> 0:14:32.200000
 And we'll just say.

0:14:32.200000 --> 0:14:37.100000
 Input input and we then put in
 the value of the variable.

0:14:37.100000 --> 0:14:41.000000
 We just reference the variable here
 that stores the actual value that

0:14:41.000000 --> 0:14:43.520000
 was input. So input text.

0:14:43.520000 --> 0:14:48.960000
 And from that point on, yeah, we can
 just close the H1, sorry, the H2

0:14:48.960000 --> 0:14:54.040000
 here. And we can then close that
 tag there and there we are.

0:14:54.040000 --> 0:14:57.700000
 OK, so this will work
 pretty much the same.

0:14:57.700000 --> 0:15:04.060000
 We'll save this as URL encode dot PHP
 and we need to have a functional

0:15:04.060000 --> 0:15:08.680000
 web server that supports PHP as the
 backend or server side language.

0:15:08.680000 --> 0:15:13.240000
 What that means is that we need to copy
 this into the directory, the Apache

0:15:13.240000 --> 0:15:15.660000
 to default directory or root.

0:15:15.660000 --> 0:15:17.540000
 So I'll say pseudo.

0:15:17.540000 --> 0:15:23.160000
 Copy URL encode dot PHP to var www HTML.

0:15:23.160000 --> 0:15:26.940000
 And now I can say pseudo system CTL.

0:15:26.940000 --> 0:15:35.380000
 Start Apache to OK, so now we'll just
 navigate back to local host and

0:15:35.380000 --> 0:15:38.420000
 we'll just navigate to
 URL encode dot PHP.

0:15:38.420000 --> 0:15:39.880000
 OK, there we are.

0:15:39.880000 --> 0:15:43.860000
 Now I already performed a few tests
 here, so I'm just going to clear the

0:15:43.860000 --> 0:15:46.840000
 recent history just so it doesn't
 interfere with the demo.

0:15:46.840000 --> 0:15:48.980000
 So URL encoding with PHP.

0:15:48.980000 --> 0:15:50.100000
 How does this work?

0:15:50.100000 --> 0:15:53.120000
 Remember, no URL encoding
 has been implemented.

0:15:53.120000 --> 0:15:59.240000
 So if I say Alexis, you can see it should
 just display that back actually.

0:15:59.240000 --> 0:16:02.060000
 For some reason, it doesn't do that.

0:16:02.060000 --> 0:16:07.660000
 We are saying echo input
 is equal to input text.

0:16:07.660000 --> 0:16:10.380000
 And yes, I did not close that tag there.

0:16:10.380000 --> 0:16:13.780000
 So always remember to check your syntax
 and I'll just say pseudo remove

0:16:13.780000 --> 0:16:19.620000
 var www HTML. URL encode dot PHP
 and replace it with a new one.

0:16:19.620000 --> 0:16:26.600000
 So pseudo copy. URL encode
 dot PHP for www HTML.

0:16:26.600000 --> 0:16:28.820000
 Now let's reload.

0:16:28.820000 --> 0:16:33.140000
 OK, so I say encode.

0:16:33.140000 --> 0:16:39.260000
 There we are. So input is Alexis and
 you can now see the parameter name

0:16:39.260000 --> 0:16:41.140000
 is input text and the value is Alexis.

0:16:41.140000 --> 0:16:46.720000
 So now what happens when we start including
 spaces like Alexis a bad pen

0:16:46.720000 --> 0:16:50.340000
 tester. You can see it
 just reflects it back.

0:16:50.340000 --> 0:16:54.540000
 We can now an attacker could potentially
 say, you know, script alert.

0:16:54.540000 --> 0:16:59.460000
 So very, very similar to HTML encoding
 in terms of potential issues, but

0:16:59.460000 --> 0:17:02.260000
 you can see we're able
 to execute JavaScript.

0:17:02.260000 --> 0:17:06.020000
 The only reason that's the case again,
 remember, this all comes down to

0:17:06.020000 --> 0:17:09.740000
 how the web application is developed
 or configured to work.

0:17:09.740000 --> 0:17:14.760000
 So what's happening is input is sent
 to the web server and then the back

0:17:14.760000 --> 0:17:19.580000
 end or server side language reflects
 it back to the client in the form

0:17:19.580000 --> 0:17:22.480000
 of HTML, which is then
 rendered on the page.

0:17:22.480000 --> 0:17:27.440000
 So in this particular case, based on
 how this basic web app works, because

0:17:27.440000 --> 0:17:31.180000
 it's just doing a simple reflection, it
 makes sense that it would be vulnerable

0:17:31.180000 --> 0:17:33.660000
 to reflected cross-site scripting.

0:17:33.660000 --> 0:17:38.800000
 But there is no interaction with the
 database, which means that again,

0:17:38.800000 --> 0:17:43.180000
 depending on all the web application
 works, you know, the inclusion of,

0:17:43.180000 --> 0:17:47.480000
 let's say, a SQL injection payload
 here would not work.

0:17:47.480000 --> 0:17:50.720000
 So the point I'm trying to make is it's
 very important that you understand

0:17:50.720000 --> 0:17:55.740000
 how the value of the parameter being
 passed in the URL is being used.

0:17:55.740000 --> 0:18:01.180000
 It's not really, it's not important
 to understand URL encoding, more so

0:18:01.180000 --> 0:18:03.420000
 understanding what's being
 done with that data.

0:18:03.420000 --> 0:18:07.720000
 If it's being reflected back, that means
 that, you know, you're most likely

0:18:07.720000 --> 0:18:11.240000
 dealing with a vulnerability
 like cross-site scripting.

0:18:11.240000 --> 0:18:14.720000
 If it's being used, like, let's say
 for authentication, so let's say,

0:18:14.720000 --> 0:18:20.520000
 you know, a URL in code.php, you know,
 question mark, username equals

0:18:20.520000 --> 0:18:23.720000
 Alexis and password equals password.

0:18:23.720000 --> 0:18:28.680000
 In one of those parameters is where I
 could inject a SQL injection payload.

0:18:28.680000 --> 0:18:32.620000
 Now, again, as I said, URL encoding
 does not make a security difference

0:18:32.620000 --> 0:18:33.900000
 because you'll see why.

0:18:33.900000 --> 0:18:40.060000
 So let's implement the, let's implement
 URL encoding with PHP, right?

0:18:40.060000 --> 0:18:43.460000
 So we have the input text variable,
 which is going to be equal to the

0:18:43.460000 --> 0:18:46.960000
 value of the input text parameter.

0:18:46.960000 --> 0:18:49.440000
 So now let's say encode text.

0:18:49.440000 --> 0:18:53.300000
 Let's create a new variable called
 encode text is going to be equal to

0:18:53.300000 --> 0:18:59.200000
 the PHP function called URL encode, which
 automates URL encoding and then

0:18:59.200000 --> 0:19:05.520000
 we'll pass in input, input text right
 over here and we'll close that up

0:19:05.520000 --> 0:19:10.160000
 there. So now what's happening is whatever
 is being input as the value

0:19:10.160000 --> 0:19:13.500000
 of the input text parameter is being
 saved in a variable called input

0:19:13.500000 --> 0:19:18.580000
 text. Okay. We then create another variable
 called encode text that performs

0:19:18.580000 --> 0:19:24.840000
 URL encoding using the URL encode PHP
 function on whatever was input or

0:19:24.840000 --> 0:19:29.140000
 whatever the value of the
 input text parameter was.

0:19:29.140000 --> 0:19:34.120000
 And then from this point on, it's all
 up to the web application developer

0:19:34.120000 --> 0:19:39.540000
 in terms of what they're going to do
 with the, um, with the value of the

0:19:39.540000 --> 0:19:40.940000
 input text parameter.

0:19:40.940000 --> 0:19:46.820000
 Irregardless of whether it's been URL
 encoded typically in the event that

0:19:46.820000 --> 0:19:51.200000
 it is being used, like for example, to,
 you know, uh, check or authenticate

0:19:51.200000 --> 0:19:55.680000
 with, uh, you know, whatever data is
 in a, in a relational database, this

0:19:55.680000 --> 0:19:57.740000
 is typically also decoded.

0:19:57.740000 --> 0:20:03.460000
 All right. So the reason it's
 decoded is very, very simple.

0:20:03.460000 --> 0:20:04.720000
 You'll see why right now.

0:20:04.720000 --> 0:20:09.080000
 So I'll change the output here, the
 H2 output to, to display the value

0:20:09.080000 --> 0:20:11.660000
 of the encode text, a variable.

0:20:11.660000 --> 0:20:13.700000
 So encode text there.

0:20:13.700000 --> 0:20:15.920000
 And now I'm just going
 to replace this here.

0:20:15.920000 --> 0:20:19.720000
 So I'll just say pseudo remove, just
 remove the original one and copy

0:20:19.720000 --> 0:20:21.720000
 the modified version.

0:20:21.720000 --> 0:20:24.620000
 And now I'll just get rid of
 that there and let's refresh.

0:20:24.620000 --> 0:20:30.020000
 So now if I say Alexis is a bad pen tester,
 this is what will be received

0:20:30.020000 --> 0:20:31.760000
 on the server side.

0:20:31.760000 --> 0:20:34.080000
 Again, URL encoded.

0:20:34.080000 --> 0:20:35.760000
 So I just hit enter.

0:20:35.760000 --> 0:20:38.720000
 And for some reason that
 button does not work.

0:20:38.720000 --> 0:20:44.660000
 So button is type button and, uh, actually
 no, that's supposed to be submit

0:20:44.660000 --> 0:20:46.940000
 because we're submitting.

0:20:46.940000 --> 0:20:49.400000
 Uh, let me replace that because
 that should work.

0:20:49.400000 --> 0:20:52.180000
 And I'll just copy the new one there.

0:20:52.180000 --> 0:20:55.200000
 So I say Alexis is a bad pen tester.

0:20:55.200000 --> 0:20:59.520000
 And now you can see that a PHP
 is performing the URL encoding.

0:20:59.520000 --> 0:21:01.540000
 So pretty much works the same.

0:21:01.540000 --> 0:21:08.520000
 If I now say script, alert one
 and I say script, there we are.

0:21:08.520000 --> 0:21:12.140000
 That's weird. It should actually do that.


0:21:12.140000 --> 0:21:14.980000
 But they, they can see this
 is what it would be sent.

0:21:14.980000 --> 0:21:19.180000
 This is how the, um, the actual value
 of the parameter would be sent and,

0:21:19.180000 --> 0:21:22.120000
 uh, how it would be received
 on the web server side.

0:21:22.120000 --> 0:21:25.900000
 Now, if as I said, this is used being
 used for authentication or a parameter

0:21:25.900000 --> 0:21:30.020000
 value is being used for authentication
 or they some check with the database,

0:21:30.020000 --> 0:21:33.900000
 the web application will typically
 decode the value.

0:21:33.900000 --> 0:21:39.940000
 And that's what causes most of the SQL
 injection vulnerabilities or even,

0:21:39.940000 --> 0:21:41.980000
 uh, you know, cross-site scripting.

0:21:41.980000 --> 0:21:51.780000
 So for example, what if we say, um,
 we say something like a welcome user

0:21:51.780000 --> 0:21:56.220000
 or just say welcome and we
 display the decoded value.

0:21:56.220000 --> 0:21:58.380000
 Now we would need to decode
 it on the server side.

0:21:58.380000 --> 0:22:04.220000
 So we can say decoded text, a new variable
 is equal to URL decode, uh,

0:22:04.220000 --> 0:22:06.000000
 decode URL decode.

0:22:06.000000 --> 0:22:12.240000
 And we say in here, uh, encoded,
 uh, encode text, right?

0:22:12.240000 --> 0:22:18.460000
 And, uh, we now displayed instead
 of encode text, the decoded text.

0:22:18.460000 --> 0:22:22.540000
 Okay. So let's say it was being reflected
 for whatever reason back.

0:22:22.540000 --> 0:22:24.240000
 That's what causes the issues.

0:22:24.240000 --> 0:22:29.380000
 And the reason I'm doing this is to
 show you that URL encoding is only

0:22:29.380000 --> 0:22:35.400000
 used for the transmission of, uh,
 uh, of information within the URL.

0:22:35.400000 --> 0:22:39.980000
 It has nothing to do with protecting
 the web application against, you

0:22:39.980000 --> 0:22:43.380000
 know, injection attacks like cross
-site scripting or SQL injection.

0:22:43.380000 --> 0:22:50.300000
 So now, um, if I refresh the page here,
 you can now see, you say, Alexis,

0:22:50.300000 --> 0:22:52.620000
 it's just going to reflect it back.

0:22:52.620000 --> 0:22:58.160000
 If I now say script and use this here
 and just click on encode, you can

0:22:58.160000 --> 0:23:00.840000
 see that that's the input, but
 it actually should decode.

0:23:00.840000 --> 0:23:05.220000
 And that's because I did not,
 uh, copy the modified version.

0:23:05.220000 --> 0:23:09.160000
 If I bring this back, you can now see
 it's vulnerable to SQL injection.

0:23:09.160000 --> 0:23:13.100000
 Now the key thing I want you to notice
 and the best way to demonstrate

0:23:13.100000 --> 0:23:18.000000
 this is to utilize burp suite because
 I still want to show you that URL

0:23:18.000000 --> 0:23:20.560000
 encoding is being performed.

0:23:20.560000 --> 0:23:24.920000
 Um, and it all depends on how the backend
 handles what has been sent.

0:23:24.920000 --> 0:23:28.340000
 It's been sent in the correct
 format to avoid issues.

0:23:28.340000 --> 0:23:33.000000
 URL encoding is there to ensure that
 this data is sent, again, regardless

0:23:33.000000 --> 0:23:41.800000
 of what is to ensure that
 data is sent correctly.

0:23:41.800000 --> 0:23:43.240000
 That's the key thing to note.

0:23:43.240000 --> 0:23:47.540000
 So I'll open up burp suite and I'll show
 you that it's still being performed.

0:23:47.540000 --> 0:23:51.300000
 And regardless of whether this web
 application was using URL encoding

0:23:51.300000 --> 0:23:55.880000
 or not, it will still be vulnerable
 to cross-site scripting because of

0:23:55.880000 --> 0:24:03.280000
 how the backend handles or how the server
 side handles what has been sent.

0:24:03.280000 --> 0:24:06.620000
 So I'm in burp. I'm just going to open
 up the burp browser here because

0:24:06.620000 --> 0:24:07.440000
 it's much simpler.

0:24:07.440000 --> 0:24:09.820000
 And I'm just going to copy the URL here.

0:24:09.820000 --> 0:24:15.500000
 So just this right over here just
 to show you that it does work.

0:24:15.500000 --> 0:24:20.640000
 But what I want to focus on specifically,
 make sure intercept is on is,

0:24:20.640000 --> 0:24:23.740000
 um, yeah, so nothing there yet.

0:24:23.740000 --> 0:24:28.440000
 Let's put in that same script
 here and click on encode.

0:24:28.440000 --> 0:24:30.900000
 You can see that is still being encoded.

0:24:30.900000 --> 0:24:35.420000
 And this site or this web application
 is still vulnerable to cross-site

0:24:35.420000 --> 0:24:39.240000
 scripting. So if I send it to the repeat
 and hit send, you can now see

0:24:39.240000 --> 0:24:44.300000
 under the render, it should render
 the JavaScript if not, and chromium

0:24:44.300000 --> 0:24:46.840000
 it should be, should have
 given us the same results.

0:24:46.840000 --> 0:24:50.600000
 So I'll go back into burp and just
 afford that request there.

0:24:50.600000 --> 0:24:54.160000
 And you can see it is vulnerable
 to cross-site scripting.

0:24:54.160000 --> 0:24:59.480000
 The key point here, URL encoding
 is not sanitizing input.

0:24:59.480000 --> 0:25:03.700000
 It just ensures that data reaches the
 destination in the correct format,

0:25:03.700000 --> 0:25:08.480000
 taking into account that specific characters,
 letters or symbols need

0:25:08.480000 --> 0:25:12.000000
 to be encoded in order to
 be interpreted correctly.

0:25:12.000000 --> 0:25:15.620000
 So it's just a formatting thing that
 ensures whatever is sent reaches

0:25:15.620000 --> 0:25:17.440000
 the web server correctly.

0:25:17.440000 --> 0:25:22.140000
 Whatever the web server does with it
 is again, how the actual back end

0:25:22.140000 --> 0:25:24.260000
 of the web application was developed.

0:25:24.260000 --> 0:25:28.760000
 And this is very common with in cases
 where parameters are being used

0:25:28.760000 --> 0:25:32.480000
 to interact or where the web server
 or the back end is using whatever

0:25:32.480000 --> 0:25:37.000000
 has been input to perform checks
 against or with a database.

0:25:37.000000 --> 0:25:39.900000
 And in that case, it is
 almost always decoded.

0:25:39.900000 --> 0:25:44.940000
 Whatever is URL encoded is almost always
 URL-decoded because you cannot

0:25:44.940000 --> 0:25:52.240000
 send whatever was URL encoded to a SQL
 database server to be checked against

0:25:52.240000 --> 0:25:53.520000
 a particular value.

0:25:53.520000 --> 0:26:00.320000
 So this is generally speaking how URL encoding
 works and that's the importance

0:26:00.320000 --> 0:26:03.040000
 of it in terms of web applications.

0:26:03.040000 --> 0:26:07.920000
 The key takeaway here is again, this
 is not a security feature, it's just

0:26:07.920000 --> 0:26:13.480000
 used to again ensure data reaches
 its destination correctly.

0:26:13.480000 --> 0:26:17.420000
 The back end of the web application
 or whatever is running on the web

0:26:17.420000 --> 0:26:22.100000
 server will pretty much do whatever
 it wants with that data and that's

0:26:22.100000 --> 0:26:23.540000
 what you're looking for.

0:26:23.540000 --> 0:26:28.400000
 You just need to understand that most
 web applications will rely on the

0:26:28.400000 --> 0:26:31.360000
 web browser to perform
 URL encoding for them.

0:26:31.360000 --> 0:26:35.020000
 But in certain cases, you may come across
 situations where it is in full

0:26:35.020000 --> 0:26:39.380000
 state they're using JavaScript or PHP.

0:26:39.380000 --> 0:26:42.580000
 With that being said, that is going to
 conclude the practical demonstration

0:26:42.580000 --> 0:26:44.480000
 side of this video.

0:26:44.480000 --> 0:26:48.640000
 All right, so that was URL
 encoding in a nutshell.

0:26:48.640000 --> 0:26:50.160000
 Very, very simple to understand.

0:26:50.160000 --> 0:26:54.940000
 Again, the key thing I wanted to highlight
 is never think of URL encoding

0:26:54.940000 --> 0:26:56.540000
 as a security feature.

0:26:56.540000 --> 0:27:02.160000
 We're now going to take a look at we're
 going to be exploring the security

0:27:02.160000 --> 0:27:07.900000
 features implemented or security techniques
 implemented in the filtering

0:27:07.900000 --> 0:27:09.200000
 section of the course.

0:27:09.200000 --> 0:27:13.420000
 But before we get to that section, we're
 going to touch on the last video

0:27:13.420000 --> 0:27:18.560000
 within the encoding section, which
 is going to be on base 64 encoding.

0:27:18.560000 --> 0:27:21.700000
 And that's what we're going to be
 looking at in the next video.

0:27:21.700000 --> 0:27:24.060000
 With that being said, that's going
 to be it for this video.

0:27:24.060000 --> 0:27:26.560000
 And I'll be seeing you in the next video.


