WEBVTT

0:00:03.840000 --> 0:00:08.520000
 So I'll go back into my Chrome, the
 actual browser and just enter some

0:00:08.520000 --> 0:00:10.100000
 test data. All right.

0:00:10.100000 --> 0:00:11.960000
 So I'll just say test and submit that.

0:00:11.960000 --> 0:00:15.120000
 And I'll now send this to the intruder.

0:00:15.120000 --> 0:00:19.000000
 Okay. And within the intruder, we're
 just going to select the attack type

0:00:19.000000 --> 0:00:22.580000
 as sniper. So this is, you
 know, single payload set.

0:00:22.580000 --> 0:00:24.160000
 It works really well.

0:00:24.160000 --> 0:00:26.600000
 No payload positions have been selected.

0:00:26.600000 --> 0:00:33.340000
 And we know that the vulnerable parameter
 in this particular case is test.

0:00:33.340000 --> 0:00:38.080000
 And we're just going to highlight it like
 so and just add it as a position,

0:00:38.080000 --> 0:00:43.540000
 which means we're telling intruder that
 I want you to replace the payloads.

0:00:43.540000 --> 0:00:49.300000
 I want you to replace this particular
 position here with the payload list

0:00:49.300000 --> 0:00:50.620000
 that I provide you.

0:00:50.620000 --> 0:00:54.780000
 So you might be saying to yourself what
 payload list are you talking about?

0:00:54.780000 --> 0:00:59.360000
 Well, that's where sec lists come
 into play or comes into play.

0:00:59.360000 --> 0:01:02.600000
 So we now click on payloads
 and the payload set is one.

0:01:02.600000 --> 0:01:06.460000
 And we'll just use a simple, we'll use
 a simple list for the payload type

0:01:06.460000 --> 0:01:08.240000
 as for the payload settings.

0:01:08.240000 --> 0:01:12.020000
 So the simple list, we can just click
 on load and you want to navigate

0:01:12.020000 --> 0:01:24.640000
 to user, just navigate to sec lists.

0:01:24.640000 --> 0:01:27.340000
 So under user share, sec lists.

0:01:27.340000 --> 0:01:31.460000
 And I've gone alphabetically,
 you should see it here.

0:01:31.460000 --> 0:01:32.820000
 And there we are.

0:01:32.820000 --> 0:01:34.960000
 So I'll just double click on that.

0:01:34.960000 --> 0:01:36.560000
 And we're going to fuzzing.

0:01:36.560000 --> 0:01:41.880000
 And you can see that there are cross
 site scripting fuzzing lists here.

0:01:41.880000 --> 0:01:45.740000
 Now there's many options you can go for
 that have been created by different

0:01:45.740000 --> 0:01:49.620000
 individuals. The one I like using to
 begin with is just, you know, brute

0:01:49.620000 --> 0:01:53.940000
 logic. You can also then, you know,
 take a look at bypass strings, so

0:01:53.940000 --> 0:01:54.760000
 on and so forth.

0:01:54.760000 --> 0:02:00.400000
 These are extremely powerful
 fuzzing payload lists.

0:02:00.400000 --> 0:02:01.420000
 And you'll see why.

0:02:01.420000 --> 0:02:03.040000
 So I'll just click on open.

0:02:03.040000 --> 0:02:07.640000
 And you can see that this list contains
 a set of JavaScript or cross site

0:02:07.640000 --> 0:02:12.160000
 scripting payloads that can be used
 to bypass filters both on the client

0:02:12.160000 --> 0:02:20.420000
 side or on the building will keep that
 as you know, we actually want to

0:02:20.420000 --> 0:02:23.280000
 ensure that the payloads are encoded.

0:02:23.280000 --> 0:02:29.140000
 As for the settings what we want to
 make sure we do hear is just ensure

0:02:29.140000 --> 0:02:34.500000
 that burps we, it follows redirects
 because that's usually an issue and

0:02:34.500000 --> 0:02:37.800000
 once we're good to go, we just
 click on Start attack.

0:02:37.800000 --> 0:02:39.620000
 Alright, so I'm currently
 in the community edition.

0:02:39.620000 --> 0:02:44.220000
 So that means that there is some throttling,
 but that'll work just fine.

0:02:44.220000 --> 0:02:45.440000
 And there we are.

0:02:45.440000 --> 0:02:51.040000
 So you can see that we have all the
 attempts here and we have the status

0:02:51.040000 --> 0:02:53.840000
 code redirects and the length.

0:02:53.840000 --> 0:02:58.540000
 What we want to focus on is the length
 here and more specifically looking

0:02:58.540000 --> 0:03:04.240000
 for variations or looking for differences
 in length in terms of, you know,

0:03:04.240000 --> 0:03:06.600000
 ones that look a little bit interesting.

0:03:06.600000 --> 0:03:13.120000
 Okay. Now we already know because we
 took a look at the, we actually took

0:03:13.120000 --> 0:03:18.540000
 a look at the medium security level
 source code, we already know what

0:03:18.540000 --> 0:03:21.320000
 is being filtered or sanitized.

0:03:21.320000 --> 0:03:25.960000
 And based on that, we pretty much already
 know what payloads will work.

0:03:25.960000 --> 0:03:31.240000
 All right. Now, if I click on a particular
 payload here, we can take a

0:03:31.240000 --> 0:03:34.640000
 look at the request and
 the response, right?

0:03:34.640000 --> 0:03:36.100000
 So we can see it here.

0:03:36.100000 --> 0:03:41.520000
 And if I render it, you can see
 that that look like it worked.

0:03:41.520000 --> 0:03:45.680000
 But you know, the burp suite render,
 rendering engine here will not render

0:03:45.680000 --> 0:03:51.700000
 a pop up. In this case, the payload
 is SVG on load alert one.

0:03:51.700000 --> 0:03:55.220000
 Okay, so I'm just going to open up
 in addition, I'm just going to open

0:03:55.220000 --> 0:03:57.520000
 up that particular payload list here.

0:03:57.520000 --> 0:04:00.040000
 So I'll just navigate to user.

0:04:00.040000 --> 0:04:03.200000
 And I'll go into share, there we are.

0:04:03.200000 --> 0:04:06.940000
 And I'll just search for set lists
 and we'll go into fuzzing and cross

0:04:06.940000 --> 0:04:10.880000
 that scripting. And I'll just open this
 up here so I can easily copy the

0:04:10.880000 --> 0:04:14.480000
 payload. So the one that
 looked like it worked.

0:04:14.480000 --> 0:04:17.120000
 And again, I'll show you how to identify
 which one worked, because that

0:04:17.120000 --> 0:04:20.600000
 can be quite difficult based on
 the web app you're testing.

0:04:20.600000 --> 0:04:23.920000
 But we'll go into Firefox here
 and we'll use this session.

0:04:23.920000 --> 0:04:28.580000
 So again, still on the medium security
 level, we're already able to bypass

0:04:28.580000 --> 0:04:33.260000
 it. But now assuming we didn't know anything
 about the server side filter

0:04:33.260000 --> 0:04:36.180000
 being used, let's see whether this works.


0:04:36.180000 --> 0:04:39.140000
 So I click on submit, and there we go.

0:04:39.140000 --> 0:04:43.100000
 Okay, so we know that that, you know,
 this particular payload works as

0:04:43.100000 --> 0:04:48.840000
 well, which is a heck of a lot better
 than, you know, using some of the

0:04:48.840000 --> 0:04:52.540000
 payloads I was using where I was just
 using my logic to, you know, make

0:04:52.540000 --> 0:04:54.360000
 the script tag uppercase.

0:04:54.360000 --> 0:04:59.100000
 And again, that was based on my knowledge
 of the server side filtering.

0:04:59.100000 --> 0:05:03.760000
 But with these payload lists.

0:05:03.760000 --> 0:05:11.820000
 And with the help of burp suite, we're
 able to easily identify payloads

0:05:11.820000 --> 0:05:13.040000
 that are working.

0:05:13.040000 --> 0:05:18.200000
 And the best way to identify which
 runs are working is not to look at

0:05:18.200000 --> 0:05:19.700000
 the status code.

0:05:19.700000 --> 0:05:28.960000
 Instead, it is to look at the length
 we have ones that follow a specific

0:05:28.960000 --> 0:05:32.320000
 pattern. But there is a little bit of
 an increment based on the size of

0:05:32.320000 --> 0:05:34.540000
 the payload, which makes sense.

0:05:34.540000 --> 0:05:38.960000
 Right. And what we're looking for our
 patterns where we have the same

0:05:38.960000 --> 0:05:39.760000
 type of results.

0:05:39.760000 --> 0:05:45.100000
 And, you know, in this case, most of
 these would have worked except for

0:05:45.100000 --> 0:05:49.240000
 this one here. And that's because, you
 know, for obvious reasons, we know

0:05:49.240000 --> 0:05:51.300000
 that the script tag is blocked.

0:05:51.300000 --> 0:05:55.240000
 So if we try and take a look at what was
 rendered here, you can see exactly

0:05:55.240000 --> 0:05:58.180000
 that because the script
 tag is being sanitized.

0:05:58.180000 --> 0:06:04.260000
 It's just displaying the text alert
 or just rendering it in HTML.

0:06:04.260000 --> 0:06:09.400000
 Not, it's not rendering it literally
 is just displaying the text.

0:06:09.400000 --> 0:06:16.060000
 As for the URL encoding technique used
 here, that looks like it may have

0:06:16.060000 --> 0:06:18.480000
 worked. Although, you know,
 we can't be too sure.

0:06:18.480000 --> 0:06:23.220000
 So it looks like lengths with
 5500 may not have worked.

0:06:23.220000 --> 0:06:25.980000
 But again, we can always
 try and confirm that.

0:06:25.980000 --> 0:06:34.200000
 And then when we get into the range
 of 5503 and 02, that also looks like

0:06:34.200000 --> 0:06:35.380000
 it did not work.

0:06:35.380000 --> 0:06:37.620000
 This one obviously did not work.

0:06:37.620000 --> 0:06:41.740000
 And we can keep going to refine, you
 know, a pattern that sort of points

0:06:41.740000 --> 0:06:45.880000
 towards the fact that this payload,
 you know, or these set of payloads

0:06:45.880000 --> 0:06:49.260000
 worked. So it looks like all
 of these did not work.

0:06:49.260000 --> 0:06:54.000000
 As long as we see that this included
 in the reflection, we know that that

0:06:54.000000 --> 0:06:54.860000
 one did not work.

0:06:54.860000 --> 0:06:57.320000
 And of course, this one
 looks like it did.

0:06:57.320000 --> 0:07:01.200000
 This one also looks like it did actually.


0:07:01.200000 --> 0:07:04.500000
 Hmm, I don't think that did.

0:07:04.500000 --> 0:07:06.940000
 But let's see this one here,
 this one looks interesting.

0:07:06.940000 --> 0:07:08.580000
 Yeah, that might have worked.

0:07:08.580000 --> 0:07:12.520000
 So if we take a look at the request
 here, we can actually see that.

0:07:12.520000 --> 0:07:17.260000
 And of course, if you just wanted to
 view it raw, you can just URL decode

0:07:17.260000 --> 0:07:20.480000
 it. So that's exactly what I'm going
 to do just to save a little bit of

0:07:20.480000 --> 0:07:23.560000
 time. And I'm going to close
 this particular attack.

0:07:23.560000 --> 0:07:25.920000
 There we are, we'll go into the decoder.

0:07:25.920000 --> 0:07:28.600000
 And I'll replace that now
 with the one I copied.

0:07:28.600000 --> 0:07:34.460000
 And this is pretty much it pretty weird
 for a for a cross side scripting

0:07:34.460000 --> 0:07:37.200000
 payload. But in reality, it really isn't.


0:07:37.200000 --> 0:07:42.600000
 So we can easily, you know, pretty much
 pick one directly from the list.

0:07:42.600000 --> 0:07:48.580000
 But again, assuming we didn't know
 what type of filtering was in place

0:07:48.580000 --> 0:07:52.700000
 on the server side, you know, we would
 if we were to do this manually,

0:07:52.700000 --> 0:07:54.040000
 this would take a lot of time.

0:07:54.040000 --> 0:07:58.500000
 So always utilize automation
 tools like burp.

0:07:58.500000 --> 0:08:04.620000
 And now let's take a look at maybe one
 more that probably will work here.

0:08:04.620000 --> 0:08:07.320000
 Like, for example, iframe should work.

0:08:07.320000 --> 0:08:10.600000
 And we'll go back into Firefox here.

0:08:10.600000 --> 0:08:12.540000
 And I'll just paste that in there.

0:08:12.540000 --> 0:08:15.060000
 And there we are fantastic.

0:08:15.060000 --> 0:08:18.080000
 So it also embedded the iframe.

0:08:18.080000 --> 0:08:23.640000
 What we'll do now is let's set the
 difficulty level to the highest in

0:08:23.640000 --> 0:08:27.020000
 terms of the one that is functioning.

0:08:27.020000 --> 0:08:31.580000
 And to do that, I'm just going
 to go into the proxy.

0:08:31.580000 --> 0:08:34.500000
 And I'm just going to disable intercept
 here for a few seconds.

0:08:34.500000 --> 0:08:37.640000
 And we'll go into DVWA security.

0:08:37.640000 --> 0:08:40.200000
 Remember, we can go to impossible.

0:08:40.200000 --> 0:08:43.760000
 Because again, that is pretty much
 almost perfect at that point.

0:08:43.760000 --> 0:08:45.080000
 I'll only go to high.

0:08:45.080000 --> 0:08:47.520000
 And we'll click on submit.

0:08:47.520000 --> 0:08:54.740000
 And now what we will do is we will go
 into the reflected process scripting

0:08:54.740000 --> 0:08:55.780000
 reflected page here.

0:08:55.780000 --> 0:08:57.780000
 And we'll not take a look
 at the source code.

0:08:57.780000 --> 0:09:00.260000
 So I don't know what the filter is.

0:09:00.260000 --> 0:09:03.920000
 Okay. So if I say if I use what I use
 previously, which was an uppercase

0:09:03.920000 --> 0:09:07.160000
 script tag, and I say, you know, alert.

0:09:07.160000 --> 0:09:12.420000
 And I say one, you know,
 script, there we are.

0:09:12.420000 --> 0:09:16.060000
 You'll see that that did not work.

0:09:16.060000 --> 0:09:20.400000
 All right. So we're dealing with much
 better filtering, input filtering

0:09:20.400000 --> 0:09:23.560000
 on the service idea, which
 is, you know, pretty cool.

0:09:23.560000 --> 0:09:27.700000
 So now that we have an idea as to how
 this is working, I'll go into burp,

0:09:27.700000 --> 0:09:31.720000
 enable intercept, and we'll just repeat
 the process that we did previously.

0:09:31.720000 --> 0:09:35.740000
 Right. So we'll go in here and just
 say, you know, test, right, click

0:09:35.740000 --> 0:09:42.120000
 on submit. Is anything changed in terms
 of the structure of the get request,

0:09:42.120000 --> 0:09:47.280000
 not really. So we'll send
 this into the intruder.

0:09:47.280000 --> 0:09:50.600000
 And we'll close the previous
 attacks here.

0:09:50.600000 --> 0:09:53.620000
 And there we are.

0:09:53.620000 --> 0:09:58.660000
 And we'll just select this particular parameter
 value as the payload position

0:09:58.660000 --> 0:10:01.180000
 point. Just click on add.

0:10:01.180000 --> 0:10:05.400000
 And the payloads will just load the standard
 process scripting brute logic

0:10:05.400000 --> 0:10:07.960000
 payload list. There we are.

0:10:07.960000 --> 0:10:11.540000
 Make sure URL payload
 encoding is enabled.

0:10:11.540000 --> 0:10:16.820000
 As for the settings, again, we want
 to make sure that if there is a that

0:10:16.820000 --> 0:10:22.780000
 perpsuit follows redirections, and
 we will then click on start attack.

0:10:22.780000 --> 0:10:26.760000
 Right. I'm also quite curious to see
 whether we'll get any successful

0:10:26.760000 --> 0:10:29.760000
 weather will get any successful
 payloads here.

0:10:29.760000 --> 0:10:33.840000
 So what I'm going to do is I'm going
 to wait for this to complete.

0:10:33.840000 --> 0:10:37.180000
 So they're just, you know,
 113 payloads to try out.

0:10:37.180000 --> 0:10:40.900000
 And we'll then see which ones work.

0:10:40.900000 --> 0:10:44.660000
 And once we've tested them and confirmed
 that they do work, and we were

0:10:44.660000 --> 0:10:48.880000
 able to bypass the filter, the server
 side filter, I will then reveal

0:10:48.880000 --> 0:10:50.380000
 the source code.

0:10:50.380000 --> 0:10:53.020000
 And that'll tell us exactly
 what was going on.

0:10:53.020000 --> 0:10:56.840000
 And that'll give you a better idea as
 to, you know, why a payload worked

0:10:56.840000 --> 0:10:59.240000
 over another one.

0:10:59.240000 --> 0:11:02.260000
 All right. So in two days, almost done.

0:11:02.260000 --> 0:11:06.420000
 Actually, we are at 111,
 actually 112 now.

0:11:06.420000 --> 0:11:10.300000
 Let's take a look at
 which payload worked.

0:11:10.300000 --> 0:11:13.440000
 So, you know, we can easily just scroll
 and view the actual response.

0:11:13.440000 --> 0:11:16.600000
 It looked like this one
 worked, the SVG on load.

0:11:16.600000 --> 0:11:18.420000
 So let's try that out.

0:11:18.420000 --> 0:11:21.260000
 Again, I'm just looking at
 what was rendered back.

0:11:21.260000 --> 0:11:22.860000
 It may not work.

0:11:22.860000 --> 0:11:28.280000
 We're going to Firefox and we'll
 change the dvwa security level.

0:11:28.280000 --> 0:11:30.600000
 I'll set it to high.

0:11:30.600000 --> 0:11:34.460000
 There we go. And we're going to
 reflect it cross that scripting.

0:11:34.460000 --> 0:11:36.960000
 And I'm just going to
 paste that in there.

0:11:36.960000 --> 0:11:38.120000
 And there we go.

0:11:38.120000 --> 0:11:41.700000
 So it looks like high security level
 can still be bypassed with a simple

0:11:41.700000 --> 0:11:47.080000
 payload in the set lists, cross that
 scripting payload list, specifically

0:11:47.080000 --> 0:11:50.220000
 the one called cross that
 scripting brute logic.

0:11:50.220000 --> 0:11:54.520000
 But let's see which other ones exist
 here, because I'm sure we'll have

0:11:54.520000 --> 0:11:55.680000
 a couple of other ones.

0:11:55.680000 --> 0:11:58.580000
 And one of the reasons why I want to
 do this is to try and understand,

0:11:58.580000 --> 0:12:02.540000
 you know, what type of filtering might
 be going on, just looking at it

0:12:02.540000 --> 0:12:03.680000
 from the outside, right?

0:12:03.680000 --> 0:12:08.160000
 So in this one, in this particular
 case, it looks, it looks like this

0:12:08.160000 --> 0:12:11.400000
 one didn't work based on the output,
 but let's try and see some of the

0:12:11.400000 --> 0:12:15.740000
 other ones. So yeah, we can see that
 that filtered it quite well.

0:12:15.740000 --> 0:12:21.860000
 So what looks like is going on here,
 and I'm going to note it down to

0:12:21.860000 --> 0:12:26.460000
 see how right or how wrong I am is
 double quotes are being filtered or

0:12:26.460000 --> 0:12:32.780000
 sanitized, because any that includes
 double quotes are being sanitized.

0:12:32.780000 --> 0:12:40.600000
 And then more so, you can see that there,
 let's see, yeah, actually not

0:12:40.600000 --> 0:12:47.020000
 sanitized, I would say, but
 that did not work there.

0:12:47.020000 --> 0:12:50.040000
 That displayed that there.

0:12:50.040000 --> 0:12:57.920000
 So what looks like is going on here
 is we may have, because this worked.

0:12:57.920000 --> 0:12:59.640000
 So that's not an issue.

0:12:59.640000 --> 0:13:04.500000
 So I'm not sure the greater than
 less than is the issue here.

0:13:04.500000 --> 0:13:10.120000
 Let's keep going to see whether we have
 or can pick up any other successful

0:13:10.120000 --> 0:13:13.380000
 ones. So this one did not work.

0:13:13.380000 --> 0:13:19.220000
 Let's see. Okay, so that
 did not work as well.

0:13:19.220000 --> 0:13:22.380000
 So what exactly is being filtered here?

0:13:22.380000 --> 0:13:24.020000
 What's going on in the background?

0:13:24.020000 --> 0:13:26.400000
 Not sure. Not sure.

0:13:26.400000 --> 0:13:32.060000
 Not sure. Okay, so this particular
 case that did not work as well.

0:13:32.060000 --> 0:13:40.920000
 And if we go and click on the length
 here, just to see some anomalies,

0:13:40.920000 --> 0:13:44.480000
 we can see that that did not work.

0:13:44.480000 --> 0:13:54.300000
 All right. So I think the less than,
 if I'm not mistaken, actually the

0:13:54.300000 --> 0:13:57.580000
 greater than symbol might be filtered.

0:13:57.580000 --> 0:14:00.940000
 Let's just take note of what
 I'm picking up here.

0:14:00.940000 --> 0:14:03.620000
 And we'll then verify it
 with the source code.

0:14:03.620000 --> 0:14:14.280000
 So actually less than might be the case.

0:14:14.280000 --> 0:14:18.280000
 But we will see because this is
 can become very, very difficult.

0:14:18.280000 --> 0:14:21.420000
 It's most likely less than.

0:14:21.420000 --> 0:14:27.080000
 And I don't think the double
 quotes is an issue here.

0:14:27.080000 --> 0:14:29.880000
 Do we have any success here?

0:14:29.880000 --> 0:14:35.480000
 Script for sure is being filtered.

0:14:35.480000 --> 0:14:38.220000
 Probably even uppercase script.

0:14:38.220000 --> 0:14:44.360000
 So if we say, you know, script alert
 one, which I think we did already.

0:14:44.360000 --> 0:14:49.240000
 Yeah. Okay, so we know that
 that is also being filtered.

0:14:49.240000 --> 0:14:52.780000
 But if we take a look at some of the
 other results, and of course, I'll

0:14:52.780000 --> 0:14:57.240000
 not waste too much time on this, but
 what I'm looking for are anomalies

0:14:57.240000 --> 0:15:00.380000
 in terms of the length here.

0:15:00.380000 --> 0:15:02.860000
 So that still has a bit of an issue.

0:15:02.860000 --> 0:15:07.920000
 These ones might look or look
 like they might work.

0:15:07.920000 --> 0:15:13.180000
 So X on X equals one, one
 one that is visible.

0:15:13.180000 --> 0:15:16.240000
 That is clearly visible.

0:15:16.240000 --> 0:15:21.460000
 If we go in here, let's take a look
 at some of the other one script for

0:15:21.460000 --> 0:15:23.640000
 sure is being blocked.

0:15:23.640000 --> 0:15:25.260000
 What about the form?

0:15:25.260000 --> 0:15:29.660000
 The form tag? Yeah, that's
 also being filtered.

0:15:29.660000 --> 0:15:35.360000
 It looks like if I just expand
 this, it looks like here.

0:15:35.360000 --> 0:15:39.360000
 Type is also being taken out.

0:15:39.360000 --> 0:15:44.020000
 So not really sure their
 body on load alert.

0:15:44.020000 --> 0:15:46.300000
 This one looks like it's working.

0:15:46.300000 --> 0:15:48.100000
 So I'm just going to go into the request.


0:15:48.100000 --> 0:15:55.740000
 And again, we can easily just, you
 know, modify the, by minimize this

0:15:55.740000 --> 0:15:58.180000
 and go back into burp suite here.

0:15:58.180000 --> 0:16:05.780000
 I'm going to the proxy if we just change
 this here and set that like so

0:16:05.780000 --> 0:16:07.920000
 and just for that there.

0:16:07.920000 --> 0:16:09.200000
 Yep, that worked.

0:16:09.200000 --> 0:16:10.860000
 So that particular payload works.

0:16:10.860000 --> 0:16:17.040000
 So we've been able to bypass all levels
 of security, except obviously

0:16:17.040000 --> 0:16:24.700000
 impossible. But still, what I wanted to
 show you is how you can, the different

0:16:24.700000 --> 0:16:28.460000
 ways you can approach it, obviously
 the most realistic and most likely

0:16:28.460000 --> 0:16:33.480000
 scenario is that you're pretty much going
 into this with a black box approach

0:16:33.480000 --> 0:16:37.760000
 where you don't know any, you don't know
 anything about the type of filtering

0:16:37.760000 --> 0:16:40.880000
 that's being used on the server side.

0:16:40.880000 --> 0:16:46.220000
 And as a result, you can always rely
 on the ever helpful burp suite and

0:16:46.220000 --> 0:16:50.320000
 the sec lists, fuzzing payload lists
 specifically for the vulnerability

0:16:50.320000 --> 0:16:52.360000
 you're trying to test for.

0:16:52.360000 --> 0:16:56.600000
 And this also works for SQL injection,
 which I believe I covered in the

0:16:56.600000 --> 0:16:58.160000
 SQL injection course.

0:16:58.160000 --> 0:17:01.740000
 And now let's take a look at the actual
 source code before we close up

0:17:01.740000 --> 0:17:03.760000
 the practical section.

0:17:03.760000 --> 0:17:09.300000
 So if we click on source
 here, okay, all right.

0:17:09.300000 --> 0:17:13.240000
 So we're now, we can now see that there's
 the use of the function called

0:17:13.240000 --> 0:17:16.360000
 preg replace, which is interesting.

0:17:16.360000 --> 0:17:18.780000
 Let's try and see what this is all about.


0:17:18.780000 --> 0:17:21.360000
 So this is a PHP function.

0:17:21.360000 --> 0:17:24.100000
 So this is quite interesting.

0:17:24.100000 --> 0:17:29.720000
 I've only seen this used quite a few
 times in terms of the implementation,

0:17:29.720000 --> 0:17:32.740000
 but yeah, perform a regular expression
 search and replace.

0:17:32.740000 --> 0:17:33.920000
 So this is sanitization.

0:17:33.920000 --> 0:17:36.580000
 This is classic sanitization.

0:17:36.580000 --> 0:17:41.180000
 So what is being searched
 for and replaced.

0:17:41.180000 --> 0:17:46.200000
 So we can see what is being searched
 for is the forward slash less than

0:17:46.200000 --> 0:17:47.900000
 was I right there?

0:17:47.900000 --> 0:17:50.460000
 Yes, I was in terms of that.

0:17:50.460000 --> 0:17:59.200000
 The asterisk dot asterisk and
 then script in and of itself.

0:17:59.200000 --> 0:18:07.320000
 And of course, we can always utilize
 the ever helpful rejects 101 to try

0:18:07.320000 --> 0:18:10.140000
 and see what exactly is going on here.

0:18:10.140000 --> 0:18:14.260000
 So you can see matches the character
 with the index that is provided.

0:18:14.260000 --> 0:18:18.300000
 So this is case sensitive,
 which makes sense here.

0:18:18.300000 --> 0:18:22.980000
 The first capturing group matches any
 character, except for line terminators

0:18:22.980000 --> 0:18:29.520000
 matches the previous token between
 zero and an unlimited time.

0:18:29.520000 --> 0:18:32.460000
 The second capturing group
 matches any character.

0:18:32.460000 --> 0:18:34.500000
 Yeah, that makes sense.

0:18:34.500000 --> 0:18:40.540000
 And then of course, the global pattern
 flags, case sensitive match, ignore

0:18:40.540000 --> 0:18:45.460000
 case of, yeah, okay, so fairly simple
 in terms of what is going on.

0:18:45.460000 --> 0:18:49.980000
 And you can see that in this particular
 case, this payload here would

0:18:49.980000 --> 0:18:52.560000
 have been detected the standard one.

0:18:52.560000 --> 0:18:56.960000
 And you know, I really like rejects
 101 for this, because it pretty much

0:18:56.960000 --> 0:18:59.000000
 explains what's going on.

0:18:59.000000 --> 0:19:03.900000
 And you know, and allows you to be a
 paste in your payloads here to see

0:19:03.900000 --> 0:19:05.060000
 which one would be detected.

0:19:05.060000 --> 0:19:07.320000
 So fairly useful.

0:19:07.320000 --> 0:19:10.620000
 With that being said, that is going to
 conclude the practical demonstration

0:19:10.620000 --> 0:19:12.720000
 side of this video.

0:19:12.720000 --> 0:19:18.620000
 All right, so that was how to bypass
 or rather identify and then bypass

0:19:18.620000 --> 0:19:21.840000
 server side filters.

0:19:21.840000 --> 0:19:25.940000
 And specifically, we took a look at how
 to do this for cross-site scripting

0:19:25.940000 --> 0:19:27.280000
 vulnerabilities.

0:19:27.280000 --> 0:19:32.840000
 And obviously, the highlight of the
 practical demonstration was on how

0:19:32.840000 --> 0:19:38.020000
 to leverage tools like burp suite and
 of course, resources like sec lists

0:19:38.020000 --> 0:19:43.940000
 to automate the process of, you know,
 identifying payloads, regardless

0:19:43.940000 --> 0:19:47.760000
 as to whether they're cross-site scripting
 payloads or SQL injection payloads

0:19:47.760000 --> 0:19:55.180000
 that can be used to bypass the server
 side filters as we did manually

0:19:55.180000 --> 0:19:59.460000
 when we're talking about bypassing
 the client side filters.

0:19:59.460000 --> 0:20:01.340000
 So hopefully you found that useful.

0:20:01.340000 --> 0:20:03.740000
 Please do take a look at sec lists.

0:20:03.740000 --> 0:20:07.060000
 It is an extremely useful resource.

0:20:07.060000 --> 0:20:10.160000
 And with that being said, that is
 going to be it for this video.

