WEBVTT

0:00:03.700000 --> 0:00:06.120000
 Hello everyone and welcome.

0:00:06.120000 --> 0:00:09.540000
 In this video we're going to be taking
 a look at how to bypass or evade

0:00:09.540000 --> 0:00:13.040000
 squid proxy browser-based restrictions.

0:00:13.040000 --> 0:00:17.620000
 So this video is going to include or
 involve the utilization of a live

0:00:17.620000 --> 0:00:19.860000
 lab for the demonstration.

0:00:19.860000 --> 0:00:23.640000
 And in this case what we're taking
 a look at is how to bypass a proxy

0:00:23.640000 --> 0:00:29.180000
 browser-based restrictions, typically
 implemented for axis control.

0:00:29.180000 --> 0:00:33.340000
 So the first thing that obviously I
 want to cover is squid proxy with

0:00:33.340000 --> 0:00:36.780000
 regards to what it is
 and its feature set.

0:00:36.780000 --> 0:00:43.060000
 So squid, as it's known colloquially,
 is a widely utilized open source

0:00:43.060000 --> 0:00:45.860000
 proxy server and web cache daemon.

0:00:45.860000 --> 0:00:50.300000
 And it primarily operates as a proxy
 server which means it acts as an

0:00:50.300000 --> 0:00:54.880000
 intermediary between client devices like
 your browser or even widely speaking

0:00:54.880000 --> 0:00:59.700000
 computers or smartphones and web servers,
 consequently facilitating requests

0:00:59.700000 --> 0:01:01.540000
 and responses between them.

0:01:01.540000 --> 0:01:07.620000
 So in the context of web application
 it will come before or essentially

0:01:07.620000 --> 0:01:09.980000
 shields a web application.

0:01:09.980000 --> 0:01:13.660000
 So that means that all traffic going
 to the web application or rather

0:01:13.660000 --> 0:01:16.320000
 the web server go through squid.

0:01:16.320000 --> 0:01:20.180000
 And squid is very robust in terms of
 what you can do in terms of filtering

0:01:20.180000 --> 0:01:21.420000
 or axis control.

0:01:21.420000 --> 0:01:25.200000
 So squid is commonly deployed in network
 environments to improve performance,

0:01:25.200000 --> 0:01:30.660000
 enhance security or manage internet
 access and is also implemented on

0:01:30.660000 --> 0:01:35.840000
 the web for exactly what I've stated
 among many other reasons or many

0:01:35.840000 --> 0:01:37.560000
 other pieces of functionality.

0:01:37.560000 --> 0:01:41.920000
 So going into some of the features here
 you can see that the primary utilization

0:01:41.920000 --> 0:01:45.580000
 of the squid proxy is caching.

0:01:45.580000 --> 0:01:49.240000
 So squid can cache frequently
 requested web content locally.

0:01:49.240000 --> 0:01:53.520000
 When a client requests a web page or
 object that squid is cached it serves

0:01:53.520000 --> 0:01:56.600000
 the content from its cache instead of
 fetching it from the original web

0:01:56.600000 --> 0:02:00.180000
 server. Very similar to
 what cloud flare does.

0:02:00.180000 --> 0:02:04.040000
 You then have access control which is
 what we'll be taking a look at in

0:02:04.040000 --> 0:02:05.540000
 the practical demo.

0:02:05.540000 --> 0:02:09.660000
 So squid provides robust access control
 mechanisms administrators can

0:02:09.660000 --> 0:02:13.300000
 configure rules to control what clients
 are allowed to access specific

0:02:13.300000 --> 0:02:17.720000
 websites or you know particular domain
 or a particular area within a web

0:02:17.720000 --> 0:02:19.520000
 application like an admin panel.

0:02:19.520000 --> 0:02:21.560000
 You then have content filtering.

0:02:21.560000 --> 0:02:25.600000
 So squid can be used for content filtering
 and blocking access to specific

0:02:25.600000 --> 0:02:28.780000
 websites or categories of websites.

0:02:28.780000 --> 0:02:33.360000
 This is more so this is in the context
 of web application security can

0:02:33.360000 --> 0:02:38.280000
 be seen as a web application firewall
 where you can block entire URLs

0:02:38.280000 --> 0:02:43.440000
 within the web application from being
 accessed completely or you can filter

0:02:43.440000 --> 0:02:48.920000
 any requests being made to a particular
 resource or anything like that.

0:02:48.920000 --> 0:02:51.900000
 So it's very robust as
 you can already tell.

0:02:51.900000 --> 0:02:56.000000
 With that being said now that you have
 an idea as to what squid is let's

0:02:56.000000 --> 0:02:59.540000
 take a look at the practical demonstration
 where we'll be utilizing a

0:02:59.540000 --> 0:03:03.580000
 live lab. So you can start up the lab
 by clicking or by launching it.

0:03:03.580000 --> 0:03:07.640000
 The lab can be found under this video
 or it should be associated with

0:03:07.640000 --> 0:03:11.520000
 this video and once you start it up
 it will provide you with pretty much

0:03:11.520000 --> 0:03:12.440000
 everything you need.

0:03:12.440000 --> 0:03:14.480000
 You don't need your own calilinic system.


0:03:14.480000 --> 0:03:17.840000
 It will provide you with a terminal
 based interface and from that point

0:03:17.840000 --> 0:03:19.120000
 on you know we can get started.

0:03:19.120000 --> 0:03:22.060000
 So I'm going to start up the
 lab and we can get started.

0:03:22.060000 --> 0:03:24.060000
 So I'll see you there.

0:03:24.060000 --> 0:03:28.780000
 Alright so I am currently in the lab
 environment and to get started the

0:03:28.780000 --> 0:03:33.740000
 first order of business is to check our
 current IP address for the system

0:03:33.740000 --> 0:03:35.280000
 that we're currently on.

0:03:35.280000 --> 0:03:38.800000
 That can be done by typing in I have
 config and we want to take a look

0:03:38.800000 --> 0:03:41.220000
 at the interface Ethernet 1.

0:03:41.220000 --> 0:03:44.380000
 So in your case the IP address
 will be different.

0:03:44.380000 --> 0:03:45.880000
 So keep that in mind.

0:03:45.880000 --> 0:03:49.560000
 The only thing that will remain the
 same is that this system or the lab

0:03:49.560000 --> 0:03:53.760000
 that you're currently working in
 will have an IP address of 2.

0:03:53.760000 --> 0:03:58.460000
 So it's going to be the second IP address
 within the subnet and in your

0:03:58.460000 --> 0:04:03.060000
 case you just need to copy this here
 and you know for example in our case

0:04:03.060000 --> 0:04:06.280000
 we can then you know perform a quick
 end map scan on it and you can see

0:04:06.280000 --> 0:04:07.760000
 we don't have anything running on it.

0:04:07.760000 --> 0:04:13.620000
 Now the way this lab is configured
 specifically the squid proxy server

0:04:13.620000 --> 0:04:19.160000
 it has been configured to essentially
 restrict access to a particular

0:04:19.160000 --> 0:04:26.600000
 web server and in this case the web server
 that it has been that has been

0:04:26.600000 --> 0:04:31.660000
 configured to restrict access to is
 one that is running on local host

0:04:31.660000 --> 0:04:35.380000
 on port 80. Now we don't have a web server
 running on local host but that's

0:04:35.380000 --> 0:04:37.540000
 not the point right.

0:04:37.540000 --> 0:04:41.660000
 So squid proxy can be configured to
 forward request which is typically

0:04:41.660000 --> 0:04:44.220000
 its default configuration on the web.

0:04:44.220000 --> 0:04:49.740000
 So in this case what we're just assuming
 is based on the example of the

0:04:49.740000 --> 0:04:53.020000
 demonstration that I'll go through we're
 just assuming that we're trying

0:04:53.020000 --> 0:04:58.920000
 to access a website that is then being
 proxied or the requests of which

0:04:58.920000 --> 0:05:01.780000
 are being proxied through the
 actual squid proxy server.

0:05:01.780000 --> 0:05:06.320000
 So the IP address of the squid proxy
 server is going to be the third IP

0:05:06.320000 --> 0:05:10.320000
 within the subnet nor again remember
 your subnet will be different but

0:05:10.320000 --> 0:05:14.300000
 all you need to do is just copy the ethernet
 one IP address or inet address

0:05:14.300000 --> 0:05:19.480000
 and just change the two here to a three
 and that's the IP address of the

0:05:19.480000 --> 0:05:20.760000
 squid proxy server.

0:05:20.760000 --> 0:05:24.980000
 So we can confirm that by saying end
 map I'll just paste in what I copied

0:05:24.980000 --> 0:05:28.700000
 and change the two to a three and you
 can see it says right over here

0:05:28.700000 --> 0:05:35.480000
 on that IP address that the on
 port 31 28 we have squid HTTP.

0:05:35.480000 --> 0:05:41.260000
 Alright so if we try and make a request
 so I'll say curl H or we'll just

0:05:41.260000 --> 0:05:46.480000
 say curl X and we want to ensure that
 it's going through the squid proxy

0:05:46.480000 --> 0:05:50.980000
 server we will then need to specify
 its IP so I'll just paste in what

0:05:50.980000 --> 0:05:56.400000
 I copy change the two to a three and
 the port is 31 28 we're now sending

0:05:56.400000 --> 0:06:00.740000
 our request through the proxy server
 and we want to access the web server

0:06:00.740000 --> 0:06:08.160000
 on 127.0.0.1 on port 80 specifically
 so this is the website we're trying

0:06:08.160000 --> 0:06:12.360000
 to access the only reason why I'm performing
 it manually is because again

0:06:12.360000 --> 0:06:16.680000
 we're not in the context of you know
 utilizing a web browser here and

0:06:16.680000 --> 0:06:24.940000
 secondly you know we haven't we don't
 have the domain to this IP or the

0:06:24.940000 --> 0:06:29.560000
 IP address of the squid proxy server
 regardless of that the squid proxy

0:06:29.560000 --> 0:06:34.920000
 server has been configured to direct
 requests coming in to this particular

0:06:34.920000 --> 0:06:42.840000
 web server here and it'll only allow access
 based on a browser on a browser

0:06:42.840000 --> 0:06:48.060000
 restriction so what that means is that
 I lonely accept requests coming

0:06:48.060000 --> 0:06:55.260000
 from a particular client or let's see
 we get an error access denied response

0:06:55.260000 --> 0:07:00.420000
 here coming through squid so you can
 see it says the following enter the

0:07:00.420000 --> 0:07:05.040000
 following error was encountered while
 trying to retrieve the URL and it

0:07:05.040000 --> 0:07:08.780000
 says access denied so we're looking
 at the access control functionality

0:07:08.780000 --> 0:07:12.540000
 within squid so access control configuration
 prevents your request from

0:07:12.540000 --> 0:07:16.080000
 being allowed at this time please contact
 your service provider so on

0:07:16.080000 --> 0:07:21.460000
 and so forth so the only way to access
 the website running on local host

0:07:21.460000 --> 0:07:29.880000
 port 80 or 127.0.0.1 is to access it
 via Firefox now the reason we're

0:07:29.880000 --> 0:07:33.560000
 in a terminal based environment is to
 show you how this can be done using

0:07:33.560000 --> 0:07:37.320000
 a tool like curl but ideally if you're
 using something like chrome you'd

0:07:37.320000 --> 0:07:41.640000
 not be able to access that particular
 web server so what we would need

0:07:41.640000 --> 0:07:45.800000
 to do is we can utilize curl and we
 can specify a custom request header

0:07:45.800000 --> 0:07:50.260000
 and within the new request header is
 going to be the user agent header

0:07:50.260000 --> 0:07:55.140000
 and in here we can just say firefox and
 now we're making the same request

0:07:55.140000 --> 0:07:59.340000
 to the web server running on local host
 port 80 going through the squid

0:07:59.340000 --> 0:08:04.760000
 proxy server and now it should actually
 you know provide us with access

0:08:04.760000 --> 0:08:10.600000
 and in this case let's see what it
 says here so we've said curl h user

0:08:10.600000 --> 0:08:17.920000
 agent and yep I forgot to as you can
 see it says congratulations you've

0:08:17.920000 --> 0:08:23.160000
 successfully completed the challenge so
 this sort of highlights or outlines

0:08:23.160000 --> 0:08:28.680000
 how robust a web proxy can be so just
 to reiterate or to go over it because

0:08:28.680000 --> 0:08:33.780000
 you might be confused in this example
 just think of this here as the domain

0:08:33.780000 --> 0:08:37.880000
 you want to access again it's an IP
 address because you know we don't

0:08:37.880000 --> 0:08:42.840000
 have DNS and we haven't resolved it
 to a particular you know we haven't

0:08:42.840000 --> 0:08:47.420000
 resolved this IP address to a particular
 domain and in reality what would

0:08:47.420000 --> 0:08:51.780000
 be happening is through your DNS server
 you would have configured your

0:08:51.780000 --> 0:08:57.820000
 domain to point to the IP address of
 your own squid proxy server the squid

0:08:57.820000 --> 0:09:02.140000
 proxy server would then be configured to
 route all requests to this particular

0:09:02.140000 --> 0:09:08.120000
 IP or domain and generally speaking once
 that is done if a client or someone

0:09:08.120000 --> 0:09:12.820000
 across the world try to access your
 domain via their browser it would

0:09:12.820000 --> 0:09:17.840000
 go through the squid proxy server first
 and then in this case access control

0:09:17.840000 --> 0:09:26.460000
 has been implemented based on the clients
 the clients agent right so the

0:09:26.460000 --> 0:09:31.640000
 user agent and it essentially prevents
 access to that website if you are

0:09:31.640000 --> 0:09:36.680000
 coming from a web browser that is not
 Firefox so once we were able to

0:09:36.680000 --> 0:09:40.700000
 essentially make a request with the
 user agent header set to Firefox you

0:09:40.700000 --> 0:09:44.120000
 can see that it allowed us to access that
 domain so it's a very rudimentary

0:09:44.120000 --> 0:09:48.360000
 example that demonstrates the access
 control functionality afforded to

0:09:48.360000 --> 0:09:53.260000
 you by a you know proxy server so that
 is going to conclude the practical

0:09:53.260000 --> 0:09:58.800000
 demonstration side of this video all
 right so that was an example of how

0:09:58.800000 --> 0:10:03.780000
 to evade or bypass some rudimentary
 you know browser based restrictions

0:10:03.780000 --> 0:10:08.080000
 implemented through a proxy server or
 a proxy for lack of a better word

0:10:08.080000 --> 0:10:13.160000
 in this case the proxy server being
 squid and that brings us to the end

0:10:13.160000 --> 0:10:18.300000
 of this course so I'd like to thank
 you very much for getting to this

0:10:18.300000 --> 0:10:22.660000
 point and hopefully you learned a lot
 about how web applications work

0:10:22.660000 --> 0:10:27.480000
 and how the web works with regards to
 encoding you know how to identify

0:10:27.480000 --> 0:10:33.220000
 bypass client and server side filters
 as well as you know getting the

0:10:33.220000 --> 0:10:37.900000
 introduction to web application firewalls
 proxies etc and of course how

0:10:37.900000 --> 0:10:42.860000
 to you know perform some rudimentary
 bypass or evasion on a proxy server

0:10:42.860000 --> 0:10:48.080000
 that was restricting access based on
 the browser being used to make the

0:10:48.080000 --> 0:10:51.680000
 request with that being said that's
 going to be it for this video and

