WEBVTT

0:00:03.380000 --> 0:00:08.080000
 Hello everyone and welcome to the
 Evasion section of this course.

0:00:08.080000 --> 0:00:11.500000
 To kick things off, we're going to
 get started by taking a look or by

0:00:11.500000 --> 0:00:14.920000
 getting a formal introduction to evasion.


0:00:14.920000 --> 0:00:20.420000
 So this section of the course is going
 to be focused on evading security

0:00:20.420000 --> 0:00:24.460000
 mechanisms or security technologies
 that you typically find implemented

0:00:24.460000 --> 0:00:29.840000
 in production or real-world environments
 to protect web applications or

0:00:29.840000 --> 0:00:35.860000
 to at least filter what is going into
 the web applications from individual

0:00:35.860000 --> 0:00:40.220000
 clients. And this is where you have
 technologies like web application

0:00:40.220000 --> 0:00:42.600000
 firewalls as well as proxy.

0:00:42.600000 --> 0:00:46.700000
 So the objective here is firstly in this
 video to get a formal introduction

0:00:46.700000 --> 0:00:51.740000
 to some of these mechanisms and this
 will sort of give you an idea as

0:00:51.740000 --> 0:00:58.360000
 to how we have gotten to this particular
 point where we have web application

0:00:58.360000 --> 0:01:03.200000
 firewalls or proxies in addition
 to service side protection.

0:01:03.200000 --> 0:01:06.420000
 You typically see, so for
 example, input filtering.

0:01:06.420000 --> 0:01:10.920000
 So the objective here is to understand
 at least at a basic level what

0:01:10.920000 --> 0:01:14.460000
 this is all about and will be utilizing
 a couple of practical examples

0:01:14.460000 --> 0:01:17.240000
 in the next set of videos.

0:01:17.240000 --> 0:01:22.220000
 So in terms of web application security
 mechanisms, what are they?

0:01:22.220000 --> 0:01:24.800000
 Again, just going over
 them one more time.

0:01:24.800000 --> 0:01:29.680000
 So web application security mechanisms
 are sort of safeguards and measures

0:01:29.680000 --> 0:01:33.660000
 that are put in place to protect web
 applications from a wide range of

0:01:33.660000 --> 0:01:35.880000
 security threats and vulnerabilities.

0:01:35.880000 --> 0:01:41.180000
 These mechanisms are essential for ensuring
 the confidentiality, integrity,

0:01:41.180000 --> 0:01:45.540000
 and availability of web applications
 and their associated data.

0:01:45.540000 --> 0:01:50.720000
 In terms of the actual security mechanisms,
 you typically see that a web

0:01:50.720000 --> 0:01:52.860000
 application will have authentication.

0:01:52.860000 --> 0:01:57.100000
 So authentication mechanisms verify the
 identity of users and ensure that

0:01:57.100000 --> 0:02:01.180000
 they have the appropriate permissions
 to access specific resources within

0:02:01.180000 --> 0:02:02.740000
 the web application.

0:02:02.740000 --> 0:02:06.000000
 And some common authentication methods
 include usernames and passwords

0:02:06.000000 --> 0:02:11.780000
 or credentials, if you will, multi-factor
 authentication and or biometrics.

0:02:11.780000 --> 0:02:14.480000
 You then have authorization
 security, right?

0:02:14.480000 --> 0:02:18.340000
 So authorization security mechanisms
 determine what actions and resources

0:02:18.340000 --> 0:02:23.680000
 are allowed to access within the web application
 once they have been authenticated.

0:02:23.680000 --> 0:02:27.400000
 This includes defining roles, permissions,
 and access controls.

0:02:27.400000 --> 0:02:31.140000
 So we're sort of getting an idea as to
 what you typically see on the server

0:02:31.140000 --> 0:02:33.360000
 side or even on the client side, right?

0:02:33.360000 --> 0:02:36.500000
 And that's where you have input validation
 or input filtering, which we've

0:02:36.500000 --> 0:02:37.480000
 already explored.

0:02:37.480000 --> 0:02:41.560000
 So input validation or filtering is the
 process of verifying and sanitizing

0:02:41.560000 --> 0:02:45.840000
 data received from users or external
 sources to prevent malicious input

0:02:45.840000 --> 0:02:50.160000
 that could lead to the exploitation of
 vulnerabilities like SQL injection,

0:02:50.160000 --> 0:02:52.920000
 cross-site scripting,
 or command injection.

0:02:52.920000 --> 0:02:55.480000
 You then have, of course, session management,
 which we've explored in

0:02:55.480000 --> 0:03:00.020000
 other courses. So session management mechanisms
 are responsible for creating,

0:03:00.020000 --> 0:03:03.540000
 managing, and securing
 user user sessions.

0:03:03.540000 --> 0:03:08.820000
 And they include measures like session
 timeouts, secure session cookies,

0:03:08.820000 --> 0:03:11.880000
 and protection against fixation attacks.

0:03:11.880000 --> 0:03:16.040000
 You then, of course, have, you know,
 additional protection that can be

0:03:16.040000 --> 0:03:20.420000
 implemented through the form of, let's
 say, browsers enforcing security

0:03:20.420000 --> 0:03:25.180000
 or, you know, server side, or rather
 the actual web server implementing

0:03:25.180000 --> 0:03:30.440000
 security features, like, you know, cross
-site request forgery protection.

0:03:30.440000 --> 0:03:34.860000
 So these mechanisms prevent attackers
 from tricking users into making

0:03:34.860000 --> 0:03:37.820000
 unauthorized requests to the
 application on their behalf.

0:03:37.820000 --> 0:03:41.300000
 And generally speaking, you'll typically
 see the implementation in the

0:03:41.300000 --> 0:03:46.460000
 form of tokens and anti-CSRF measures.

0:03:46.460000 --> 0:03:50.320000
 And then, of course, we have the security
 headers, which you'll most likely

0:03:50.320000 --> 0:03:52.740000
 see in any modern web application.

0:03:52.740000 --> 0:03:57.540000
 So HTTP security headers like content
 security policy, also known as CSP,

0:03:57.540000 --> 0:04:01.360000
 X content type options and X frame
 options are used to control how web

0:04:01.360000 --> 0:04:06.020000
 browsers should handle various aspects
 of web security and rendering.

0:04:06.020000 --> 0:04:07.840000
 You then, of course, have rate limiting.

0:04:07.840000 --> 0:04:11.400000
 So that's fairly standard to understand
 rate limiting mechanisms restrict

0:04:11.400000 --> 0:04:15.880000
 the number of requests a user or IP
 address can make to the application

0:04:15.880000 --> 0:04:18.020000
 within a specific time frame.

0:04:18.020000 --> 0:04:23.580000
 And this obviously helps prevent brute
 force attacks and or DDoS attempts.

0:04:23.580000 --> 0:04:26.140000
 That brings us to the defense mechanism.

0:04:26.140000 --> 0:04:29.580000
 So we've taken a look at, you
 know, security mechanisms.

0:04:29.580000 --> 0:04:34.540000
 In terms of proactive defense, web
 application defense mechanisms are

0:04:34.540000 --> 0:04:38.840000
 proactive tools and techniques that
 are used to design that are designed

0:04:38.840000 --> 0:04:43.300000
 to protect and defend web applications
 against various security threats

0:04:43.300000 --> 0:04:44.980000
 and vulnerabilities.

0:04:44.980000 --> 0:04:48.460000
 And these technologies are essential
 for safeguarding web applications

0:04:48.460000 --> 0:04:54.060000
 against attacks and ensuring the CIA triad
 in terms of the web applications

0:04:54.060000 --> 0:04:58.060000
 data and, you know, the actual
 integrity of the data.

0:04:58.060000 --> 0:05:01.920000
 So what are some common, you know,
 web application defense mechanisms

0:05:01.920000 --> 0:05:02.440000
 or technologies?

0:05:02.440000 --> 0:05:07.100000
 Well, that's where you have web application
 firewalls, also known as WAFS.

0:05:07.100000 --> 0:05:11.260000
 WAFS are security appliances or software
 solutions that sit between the

0:05:11.260000 --> 0:05:15.680000
 web application and the client, also
 the known as the browser to monitor

0:05:15.680000 --> 0:05:17.880000
 and filter incoming traffic.

0:05:17.880000 --> 0:05:22.180000
 They can detect and block common web application
 attacks such as SQL injection,

0:05:22.180000 --> 0:05:26.900000
 cross-site scripting or and application
 layer DDoS attacks.

0:05:26.900000 --> 0:05:31.540000
 You then have intrusion detection systems
 and intrusion prevention systems.

0:05:31.540000 --> 0:05:35.500000
 So these inspect network and application
 traffic and signs of suspicious

0:05:35.500000 --> 0:05:36.720000
 or malicious activity.

0:05:36.720000 --> 0:05:41.580000
 And they detect and alert
 on potential threats.

0:05:41.580000 --> 0:05:45.160000
 And then, you know, IPSs can actually
 go a step further and, you know,

0:05:45.160000 --> 0:05:53.940000
 block malicious traffic or anything that
 I'm not talking about a web proxy

0:05:53.940000 --> 0:05:56.820000
 like that. So I'm talking
 about an actual proxy.

0:05:56.820000 --> 0:06:00.960000
 So in the context of web applications,
 proxies refer to the intermediary

0:06:00.960000 --> 0:06:05.700000
 servers that facilitate communication
 between a user's browser and the

0:06:05.700000 --> 0:06:07.960000
 web server hosting the application.

0:06:07.960000 --> 0:06:11.440000
 These proxies can serve various purposes
 ranging from enhancing security

0:06:11.440000 --> 0:06:16.120000
 and privacy to optimizing performance
 and managing network traffic.

0:06:16.120000 --> 0:06:19.600000
 So you'll typically see that, you know,
 proxies can be a little bit difficult

0:06:19.600000 --> 0:06:23.020000
 to understand if you haven't
 implemented one yourself.

0:06:23.020000 --> 0:06:25.320000
 So the reason you'd implement a proxy.

0:06:25.320000 --> 0:06:29.140000
 So think of a proxy as a server that
 essentially acts as an intermediary

0:06:29.140000 --> 0:06:34.440000
 between any clients and the actual web server
 that's hosting the web application.

0:06:34.440000 --> 0:06:39.040000
 Now, one of the reasons you may want to
 do this is a good example is CloudFlare.

0:06:39.040000 --> 0:06:43.300000
 CloudFlare provides, you know, a proxy
 service where you can essentially

0:06:43.300000 --> 0:06:49.300000
 configure the DNS or your domain to point
 towards CloudFlare's proxy service

0:06:49.300000 --> 0:06:52.920000
 and CloudFlare would then direct the
 traffic to the actual web server.

0:06:52.920000 --> 0:06:57.860000
 This is typically done again to improve
 performance, but from the security

0:06:57.860000 --> 0:07:02.720000
 point of view, one of the benefits of
 a proxy is that it masks the actual

0:07:02.720000 --> 0:07:05.680000
 IP address of the web server itself.

0:07:05.680000 --> 0:07:09.540000
 So for example, if a website is being
 protected by CloudFlare, what you'll

0:07:09.540000 --> 0:07:14.980000
 typically see is if you perform, you know,
 a if you perform DNS enumeration

0:07:14.980000 --> 0:07:19.300000
 or you resolve the domain to the IP,
 you'll find that the IP address is

0:07:19.300000 --> 0:07:24.640000
 points to CloudFlare's proxy service,
 which means the actual IP address

0:07:24.640000 --> 0:07:29.760000
 of the web service unknown or essentially
 being masked by CloudFlare.

0:07:29.760000 --> 0:07:34.440000
 So proxies can be used for, you know,
 quite a lot of functionality in

0:07:34.440000 --> 0:07:39.500000
 terms of your, in terms of filtering
 and also optimizing performance of

0:07:39.500000 --> 0:07:41.020000
 your web application.

0:07:41.020000 --> 0:07:45.180000
 And from a security perspective, they
 really play a huge role in content

0:07:45.180000 --> 0:07:49.720000
 filtering based on, you know, a predefined
 set of rules, if you will.

0:07:49.720000 --> 0:07:53.280000
 And of course, we'll take a look at the
 differences between a web application

0:07:53.280000 --> 0:07:57.140000
 firewall and a proxy shortly,
 but just keep that in mind.

0:07:57.140000 --> 0:08:00.880000
 So now that we've got an understanding
 as to, you know, the common security

0:08:00.880000 --> 0:08:05.500000
 mechanisms that are implemented in
 web applications, and we've taken a

0:08:05.500000 --> 0:08:11.700000
 look at the defensive security solutions
 that can be put in place, we

0:08:11.700000 --> 0:08:16.060000
 can now get into, you know, get
 this introduction to evasion.

0:08:16.060000 --> 0:08:19.880000
 So evasion in web application security
 testing refers to the practice

0:08:19.880000 --> 0:08:24.560000
 of using various techniques and methods
 to bypass or circumvent security

0:08:24.560000 --> 0:08:29.280000
 mechanisms and controls put in place
 to protect a web application.

0:08:29.280000 --> 0:08:33.540000
 So the primary goal of evasion techniques
 is to deceive or to trick security

0:08:33.540000 --> 0:08:38.360000
 measures such as web application firewalls,
 intrusion detection systems,

0:08:38.360000 --> 0:08:41.600000
 input validation filters, which
 we've already taken a look at.

0:08:41.600000 --> 0:08:46.260000
 And I know the term, the terminology we've
 been using is slightly different.

0:08:46.260000 --> 0:08:51.660000
 So you can just think of bypassing as
 something very similar to evasion.

0:08:51.660000 --> 0:08:55.440000
 The only reason why we utilize the word
 evasion is because it's very closely

0:08:55.440000 --> 0:08:57.720000
 linked to web application firewalls.

0:08:57.720000 --> 0:09:02.180000
 So we've taken a look at, you know,
 bypassing or evading input filters.

0:09:02.180000 --> 0:09:06.700000
 But now we're focusing on evading some
 of the other defensive security

0:09:06.700000 --> 0:09:11.580000
 mechanisms that are put in place, you
 know, before your traffic actually

0:09:11.580000 --> 0:09:13.380000
 gets to the web application.

0:09:13.380000 --> 0:09:18.420000
 The point being is that we're turning
 our attention away from the, you

0:09:18.420000 --> 0:09:22.240000
 know, server side filtering, for example,
 and turning our attention to

0:09:22.240000 --> 0:09:27.640000
 the filters or the actual rule set
 that is running, let's say within a

0:09:27.640000 --> 0:09:31.960000
 web application firewall or within a
 proxy that, you know, prevents any

0:09:31.960000 --> 0:09:35.320000
 malicious traffic from even reaching
 the web application.

0:09:35.320000 --> 0:09:41.240000
 So the point is that these evasion or
 bypassing a web application firewall

0:09:41.240000 --> 0:09:45.980000
 is paramount to begin with because you'll
 not even be able to tell whether

0:09:45.980000 --> 0:09:50.800000
 the web application behind the web
 application firewall is vulnerable

0:09:50.800000 --> 0:09:54.860000
 to a particular, you know, vulnerability,
 because that traffic may be

0:09:54.860000 --> 0:09:58.940000
 being blocked. So it's very important
 that in the event you encounter

0:09:58.940000 --> 0:10:05.060000
 a proxy or a web application firewall
 that you are at least privy to some

0:10:05.060000 --> 0:10:07.200000
 techniques that can be
 used to bypass them.

0:10:07.200000 --> 0:10:11.220000
 So your traffic actually gets
 to the target web application.

0:10:11.220000 --> 0:10:14.280000
 And you know, you can essentially verify
 whether a vulnerability exists.

0:10:14.280000 --> 0:10:19.160000
 And if it does, you can then go ahead with
 and proceed with the exploitation.

0:10:19.160000 --> 0:10:24.240000
 So, you know, evasion techniques are
 just revolve around that where, you

0:10:24.240000 --> 0:10:28.200000
 know, you typically will be looking at
 bypassing web application firewall

0:10:28.200000 --> 0:10:30.340000
 rules or proxy rules.

0:10:30.340000 --> 0:10:34.100000
 So wafts and proxies are designed to
 filter out or even sanitize malicious

0:10:34.100000 --> 0:10:38.200000
 requests and prevent attacks like SQL
 injection or cross site scripting,

0:10:38.200000 --> 0:10:42.860000
 among many others, and evasion techniques
 may include or involve encoding,

0:10:42.860000 --> 0:10:47.900000
 obfuscation or fragmentation of malicious
 payloads to bypass the wafts

0:10:47.900000 --> 0:10:48.920000
 detection rules.

0:10:48.920000 --> 0:10:53.000000
 So in the context of web application
 firewalls or rather any firewall

0:10:53.000000 --> 0:10:57.120000
 for that matter, I am sure that most
 of you know that firewalls utilize

0:10:57.120000 --> 0:10:58.960000
 a rule set, right?

0:10:58.960000 --> 0:11:03.900000
 So a set of rules that essentially,
 you know, tell the web application

0:11:03.900000 --> 0:11:07.260000
 firewall, you know, what to
 block out or what to keep.

0:11:07.260000 --> 0:11:11.300000
 So web application firewalls do not
 sanitize or filter, they just block

0:11:11.300000 --> 0:11:13.200000
 based on a rule set.

0:11:13.200000 --> 0:11:17.560000
 Proxies are slightly different in that
 they have different rules for,

0:11:17.560000 --> 0:11:22.900000
 you know, different aspects of, you know,
 the the actual filtering process

0:11:22.900000 --> 0:11:27.940000
 and can be used to filter or can be used
 to block access, you know, depending

0:11:27.940000 --> 0:11:29.420000
 on what is required.

0:11:29.420000 --> 0:11:31.720000
 So proxies are very, very common.

0:11:31.720000 --> 0:11:35.540000
 In fact, most sites, I think you can
 say are, you know, protected or are

0:11:35.540000 --> 0:11:39.500000
 shielded by some form of proxy regardless
 as to whether, you know, it's

0:11:39.500000 --> 0:11:43.080000
 something like Cloudflare or even a
 caching proxy like squared, which

0:11:43.080000 --> 0:11:45.140000
 will actually be exploring.

0:11:45.140000 --> 0:11:48.560000
 And then of course, if there is an intrusion
 detection system like PHP,

0:11:48.560000 --> 0:11:54.480000
 IDS or PHP IDs, depending on how you
 pronounce it, you typically also

0:11:54.480000 --> 0:11:58.820000
 want to, you know, evade detection
 by these systems.

0:11:58.820000 --> 0:12:04.460000
 But the primary focus around here will
 be the primary focus will be, you

0:12:04.460000 --> 0:12:09.080000
 know, taking a look at bypassing or
 evading web application firewalls.

0:12:09.080000 --> 0:12:13.220000
 We then of course have circumventing
 input validation filters or input

0:12:13.220000 --> 0:12:17.280000
 filters in general, which we've already
 taken a look at at least at a

0:12:17.280000 --> 0:12:21.640000
 basic level, but many web applications
 employ input validation filters

0:12:21.640000 --> 0:12:24.340000
 to block potentially malicious input.

0:12:24.340000 --> 0:12:27.960000
 And evasion may involve crafting input
 that seems legitimate, but can

0:12:27.960000 --> 0:12:30.640000
 exploit vulnerabilities
 in the application.

0:12:30.640000 --> 0:12:33.380000
 And then of course, you want to avoid
 rate limiting and authentication

0:12:33.380000 --> 0:12:37.860000
 controls. So attackers will typically
 utilize evasion techniques to avoid

0:12:37.860000 --> 0:12:42.500000
 triggering rate limiting mechanisms or to
 bypass authentication and authorization

0:12:42.500000 --> 0:12:48.440000
 controls. So you're performing a brute
 force attack and there is a proxy

0:12:48.440000 --> 0:12:53.020000
 or a web application firewall or some
 mechanism that is going to, you

0:12:53.020000 --> 0:12:57.260000
 know, block your traffic based on a
 predefined rule is very common with

0:12:57.260000 --> 0:13:01.520000
 web application firewalls or proxies
 where if a certain amount of requests

0:13:01.520000 --> 0:13:05.700000
 are made within a certain a certain amount
 of time, your IP will be blocked

0:13:05.700000 --> 0:13:07.100000
 for let's say an hour.

0:13:07.100000 --> 0:13:10.360000
 And that's usually to protect against,
 you know, brute force attacks or

0:13:10.360000 --> 0:13:16.060000
 any type of denial of service type of
 attack or, you know, a type of attack

0:13:16.060000 --> 0:13:21.180000
 that is likely to be malicious just
 based on the irregular nature of the

0:13:21.180000 --> 0:13:25.480000
 traffic or the amount of attempts being
 made attempts being the number

0:13:25.480000 --> 0:13:31.820000
 of requests. So in one of the main,
 one of the main aspects or sources

0:13:31.820000 --> 0:13:36.100000
 of confusion whenever I discuss this topic
 is, what's the difference between

0:13:36.100000 --> 0:13:37.940000
 a WAF and a proxy?

0:13:37.940000 --> 0:13:42.760000
 And this is fairly simple on the surface
 level, so WAF is designed to

0:13:42.760000 --> 0:13:48.120000
 provide, you know, or to defend a web
 application against attacks, right?

0:13:48.120000 --> 0:13:53.860000
 Now proxy doesn't really have any, you
 know, primary or underlying objective.

0:13:53.860000 --> 0:13:55.360000
 It's used for a lot of things.

0:13:55.360000 --> 0:13:58.820000
 So within this particular table, I
 sort of lay out these differences.

0:13:58.820000 --> 0:14:03.020000
 So on the left hand side, you can see
 that I have the features and then

0:14:03.020000 --> 0:14:08.720000
 on the right, the two, the two technologies,
 the WAF and proxy, the differences

0:14:08.720000 --> 0:14:12.120000
 between the two with regards to the
 or in relation to the feature and

0:14:12.120000 --> 0:14:13.320000
 question or outline.

0:14:13.320000 --> 0:14:18.360000
 So the primary purpose you can see for
 a WAF is web application security

0:14:18.360000 --> 0:14:22.820000
 for a proxy. They're much more versatile
 and are not necessarily security

0:14:22.820000 --> 0:14:25.980000
 focused. You then have traffic handling.

0:14:25.980000 --> 0:14:29.400000
 In terms of WAFs, they analyze
 and filter web traffic.

0:14:29.400000 --> 0:14:32.700000
 And in terms of proxies, they can pretty
 much do the same, but they act

0:14:32.700000 --> 0:14:36.860000
 really as an intermediary for various
 purposes that could be for caching,

0:14:36.860000 --> 0:14:44.440000
 for filtering. Again, it has no specific
 objective or underlying focus.

0:14:44.440000 --> 0:14:49.500000
 For the actual security focus, what
 this refers to is, you know, what

0:14:49.500000 --> 0:14:54.420000
 is typically performed from the perspective
 of an attacker to these security

0:14:54.420000 --> 0:14:56.920000
 mechanisms or these defensive mechanisms.


0:14:56.920000 --> 0:15:02.700000
 So in the context of the WAF, you see it's
 highly specialized in web application

0:15:02.700000 --> 0:15:06.940000
 security. In terms of the proxy, again,
 they're not designed for that.

0:15:06.940000 --> 0:15:10.320000
 So that means that they have
 a much broader use case.

0:15:10.320000 --> 0:15:13.500000
 And again, you can do more
 research on proxies.

0:15:13.500000 --> 0:15:16.680000
 They really have quite a few use cases.

0:15:16.680000 --> 0:15:21.780000
 In terms of the rule sets, WAFs utilize
 predefined rule sets, security

0:15:21.780000 --> 0:15:24.720000
 rule sets to be more specific.

0:15:24.720000 --> 0:15:27.880000
 And in the case of proxies, you know,
 rule sets and policies are much

0:15:27.880000 --> 0:15:29.300000
 more flexible and varied.

0:15:29.300000 --> 0:15:30.960000
 So what does this mean?

0:15:30.960000 --> 0:15:34.880000
 It means that with the web application
 firewall, like mod security, for

0:15:34.880000 --> 0:15:38.500000
 example, the rule sets will
 be very static, right?

0:15:38.500000 --> 0:15:42.560000
 They'll not be undergoing changes or,
 you know, changing them is, no,

0:15:42.560000 --> 0:15:45.680000
 I wouldn't say it's difficult, but
 you really don't want to be messing

0:15:45.680000 --> 0:15:50.200000
 around with rulesets, especially if
 you're using, you know, the ORs, mod

0:15:50.200000 --> 0:15:53.520000
 security core ruleset or something,
 or even additional rule sets.

0:15:53.520000 --> 0:15:57.540000
 But the way proxies are designed, they're
 designed to be much more robust

0:15:57.540000 --> 0:16:02.900000
 with regards to the with regards to filtering
 or, you know, even a validation

0:16:02.900000 --> 0:16:08.520000
 of, let's say, incoming requests based on
 predefined parameters or configuration

0:16:08.520000 --> 0:16:13.340000
 options. The point is that you can
 tell a proxy to block requests that

0:16:13.340000 --> 0:16:17.900000
 are coming from any user or any client
 that is using Firefox as their

0:16:17.900000 --> 0:16:20.380000
 browser. So they're robust in that sense.


0:16:20.380000 --> 0:16:24.780000
 They can, they really are designed
 to essentially filter traffic.

0:16:24.780000 --> 0:16:26.660000
 I think that's the best
 way of putting it.

0:16:26.660000 --> 0:16:30.700000
 And they can filter traffic based on
 predefined rules, which are very

0:16:30.700000 --> 0:16:34.040000
 robust in terms of, you know,
 what you can configure.

0:16:34.040000 --> 0:16:39.200000
 So you can pretty much control access
 as with a lot of granularity or

0:16:39.200000 --> 0:16:43.880000
 specificity. In terms of the deployment
 location, that's fairly simple.

0:16:43.880000 --> 0:16:47.440000
 WAFs are typically deployed in
 front of web applications.

0:16:47.440000 --> 0:16:50.860000
 And proxies, the same can be done, but
 you'll typically see that they're

0:16:50.860000 --> 0:16:54.500000
 deployed in various locations
 within a network.

0:16:54.500000 --> 0:16:58.420000
 In terms of targeted threats, you know,
 web applications will protect

0:16:58.420000 --> 0:17:02.160000
 against common web application threats
 like SQL injection, cross-site

0:17:02.160000 --> 0:17:04.200000
 scripting attacks, so on and so forth.

0:17:04.200000 --> 0:17:08.540000
 The bottom line with WAFs is a web application
 firewall is only as good

0:17:08.540000 --> 0:17:11.780000
 as the rule set that is, it is utilizing.


0:17:11.780000 --> 0:17:15.580000
 In terms of targeted threats for proxies,
 you can see that it, you know,

0:17:15.580000 --> 0:17:18.980000
 pretty much provides some of the features
 that you do not get with the

0:17:18.980000 --> 0:17:24.420000
 WAF. So content filtering, geo-blocking,
 so blocking an entire region.

0:17:24.420000 --> 0:17:29.740000
 And in certain cases, many third party
 or commercial web application firewalls

0:17:29.740000 --> 0:17:40.460000
 provide this proxying service that,
 you know, allows you or gives you

0:17:40.460000 --> 0:17:46.380000
 to see an implementation of both or an
 implementation where a web application

0:17:46.380000 --> 0:17:48.440000
 is utilizing a proxy.

0:17:48.440000 --> 0:17:52.880000
 A web application firewall is very
 rare, is very rare to see that, as

0:17:52.880000 --> 0:17:57.460000
 I said, most of these services are now
 being provided as an all-in-one.

0:17:57.460000 --> 0:18:00.840000
 So think of CloudFlare, which provides,
 you know, proxying a content delivery

0:18:00.840000 --> 0:18:05.780000
 network as well as, you know, a web
 application firewall features.

0:18:05.780000 --> 0:18:09.600000
 You then have the use cases, so
 fairly simple to understand.

0:18:09.600000 --> 0:18:14.260000
 WAFs are specifically designed for web
 application security and proxies

0:18:14.260000 --> 0:18:18.540000
 have multiple use cases, including,
 you know, caching, load balancing,

0:18:18.540000 --> 0:18:19.600000
 so on and so forth.

0:18:19.600000 --> 0:18:24.220000
 So proxies, you know, are much more
 robust and don't have a defined use

0:18:24.220000 --> 0:18:28.540000
 case or, you know, defined piece of functionality
 or role that they play.

0:18:28.540000 --> 0:18:37.380000
 They just make your web a distributed
 infrastructure.

0:18:37.380000 --> 0:18:41.200000
 They help, you know, provide
 load balancing.

0:18:41.200000 --> 0:18:46.740000
 They can essentially fill the traffic
 based on, as I mentioned earlier,

0:18:46.740000 --> 0:18:52.100000
 pre-configured or predefined
 rules that you want.

0:18:52.100000 --> 0:18:55.540000
 And, you know, that also extends to additional
 protection like geo-blocking

0:18:55.540000 --> 0:18:58.280000
 or even IP blocking.

0:18:58.280000 --> 0:19:02.420000
 With that being said, now that we've
 gotten an introduction to evasion

0:19:02.420000 --> 0:19:08.480000
 as a process, we can now take a look at
 some practical examples, specifically

0:19:08.480000 --> 0:19:13.160000
 with these defensive mechanisms like,
 you know, proxies or web application

0:19:13.160000 --> 0:19:17.360000
 firewall. So with that being said, that's
 going to be it for this video

0:19:17.360000 --> 0:19:19.840000
 and I'll be seeing you in the next video.


