WEBVTT

0:00:03.540000 --> 0:00:08.640000
 Hello everyone and welcome in this
 video, the course summary.

0:00:08.640000 --> 0:00:15.440000
 We're going to be getting a summary
 or taking a look back at what we've

0:00:15.440000 --> 0:00:20.740000
 covered in this course to again measure
 your progress or I should say

0:00:20.740000 --> 0:00:32.000000
 your progress and identify or get and
 of course your technical knowledge.

0:00:32.000000 --> 0:00:37.540000
 So pretty much we're just going to
 go get a recap of the key concepts

0:00:37.540000 --> 0:00:39.180000
 covered in this course.

0:00:39.180000 --> 0:00:44.900000
 This again has not changed from what
 we outlined in the course overview

0:00:44.900000 --> 0:00:50.120000
 video. So the idea was to take a look
 at data encoding or the fundamentals

0:00:50.120000 --> 0:00:54.800000
 of data encoding and then server side
 and client side filter evasion and

0:00:54.800000 --> 0:00:57.480000
 then of course WAF and
 proxy bypass technique.

0:00:57.480000 --> 0:01:03.580000
 So, you know, we covered this quite well
 I think in terms of the key concepts

0:01:03.580000 --> 0:01:07.740000
 given that there were just three
 I think we did fairly well.

0:01:07.740000 --> 0:01:11.000000
 And now of course we're going to take
 a look at the learning outcomes.

0:01:11.000000 --> 0:01:15.960000
 So the idea here is to actually verify
 whether again for me as the instructor

0:01:15.960000 --> 0:01:19.220000
 to verify whether I actually covered
 everything that I was supposed to

0:01:19.220000 --> 0:01:23.060000
 and for you as the student to actually
 verify that you know and are able

0:01:23.060000 --> 0:01:31.900000
 to do whatever was you know outlined
 or whatever is in alignment with

0:01:31.900000 --> 0:01:33.040000
 the learning outcomes.

0:01:33.040000 --> 0:01:36.040000
 So starting off by the end of the course
 you'll have a good understanding

0:01:36.040000 --> 0:01:39.720000
 of the importance of encoding on the web
 and its importance in the functionality

0:01:39.720000 --> 0:01:41.220000
 of web applications.

0:01:41.220000 --> 0:01:45.640000
 Indeed, we covered that quite well by
 taking a look at a couple of examples

0:01:45.640000 --> 0:01:50.120000
 and understanding where different types
 of encoding come into play especially

0:01:50.120000 --> 0:01:51.780000
 in the context of web apps.

0:01:51.780000 --> 0:01:57.760000
 So, you know data being data in transit
 and what type of encoding you

0:01:57.760000 --> 0:02:01.540000
 know is performed on the URL
 the reasons for that etc.

0:02:01.540000 --> 0:02:03.660000
 So I think we covered that quite well.

0:02:03.660000 --> 0:02:06.720000
 Secondly, you'll have a solid understanding
 of what content and input

0:02:06.720000 --> 0:02:10.220000
 filtering is how and why filtering
 is implemented in web applications

0:02:10.220000 --> 0:02:13.420000
 and how server side and client
 side filters can be bypassed.

0:02:13.420000 --> 0:02:17.140000
 And of course, we had a whole section
 dedicated to this and we're able

0:02:17.140000 --> 0:02:20.040000
 to cover that in quite a bit of detail.

0:02:20.040000 --> 0:02:25.180000
 And we obviously took a look at a couple
 of real world examples of how

0:02:25.180000 --> 0:02:28.800000
 this can be done through you
 know some lab exercises.

0:02:28.800000 --> 0:02:32.780000
 So again, I'm fairly happy
 with how that was covered.

0:02:32.780000 --> 0:02:35.640000
 Moving on, you'll have a solid understanding
 of the most common forms

0:02:35.640000 --> 0:02:38.720000
 of encoding on the web which is sort
 of related to the first learning

0:02:38.720000 --> 0:02:43.840000
 outcome of course how they work and
 how and why they're implemented.

0:02:43.840000 --> 0:02:47.940000
 So, you know HTML encoding, URL
 encoding and base 64 encoding.

0:02:47.940000 --> 0:02:50.620000
 Of course, we touched
 on this quite a bit.

0:02:50.620000 --> 0:02:55.640000
 And then of course, you know, this is
 sort of related to the second learning

0:02:55.640000 --> 0:02:59.980000
 outcome but more in a practical sense
 in this in the sense that you will

0:02:59.980000 --> 0:03:03.620000
 have the ability to detect and bypass
 common client side and server side

0:03:03.620000 --> 0:03:07.540000
 filters. So you know cross-site scripting
 filters, command injection etc.

0:03:07.540000 --> 0:03:13.280000
 And of course, in this case, we did explore
 that and we did do it practically,

0:03:13.280000 --> 0:03:17.280000
 you know, through the use of labs where
 we were targeting, you know, real

0:03:17.280000 --> 0:03:18.860000
 world web applications.

0:03:18.860000 --> 0:03:22.520000
 So, fairly comfortable with
 how that was covered.

0:03:22.520000 --> 0:03:25.500000
 And then finally, you know, you'll be
 able to bypass or evade rudimentary

0:03:25.500000 --> 0:03:29.260000
 forms of protection of filtering
 imposed by proxies or wafts.

0:03:29.260000 --> 0:03:35.360000
 And of course, we did explore that
 with a specific focus on, you know,

0:03:35.360000 --> 0:03:40.900000
 identification of an intermediary proxy
 or system that, you know, regardless

0:03:40.900000 --> 0:03:46.060000
 of whether it is a standard proxy like
 squid or a web application firewall,

0:03:46.060000 --> 0:03:51.300000
 the transmutation or transformation
 of requests and how to identify, you

0:03:51.300000 --> 0:03:56.200000
 know, that, you know, how to identify
 whether there is this intermediary

0:03:56.200000 --> 0:03:58.160000
 service or system.

0:03:58.160000 --> 0:04:01.560000
 And then secondly, how you can go about
 identifying the rules and then

0:04:01.560000 --> 0:04:06.840000
 bypassing them. So, yeah, fairly, you
 know, happy with how we covered

0:04:06.840000 --> 0:04:10.940000
 everything. And, you know, I think we
 covered everything with the depth

0:04:10.940000 --> 0:04:12.860000
 that was required.

0:04:12.860000 --> 0:04:17.020000
 And now we can take a look at some of
 the real world applications of what

0:04:17.020000 --> 0:04:18.680000
 you have learned in this course.

0:04:18.680000 --> 0:04:22.260000
 So starting off, you know,
 very, very important.

0:04:22.260000 --> 0:04:24.000000
 And I think most of you
 are aware of this.

0:04:24.000000 --> 0:04:28.760000
 Modern applications deploy security measures
 like input validation, blacklists,

0:04:28.760000 --> 0:04:32.040000
 whitelists, and of course web application
 firewalls to filter malicious

0:04:32.040000 --> 0:04:37.380000
 inputs. And the ability to bypass these
 mechanisms allows testers or you

0:04:37.380000 --> 0:04:41.040000
 to accurately, you know, simulate sophisticated
 attack scenarios used

0:04:41.040000 --> 0:04:45.540000
 by real world adversaries or, you know,
 to perform a thorough pen test

0:04:45.540000 --> 0:04:52.700000
 that is, that is sort of representative
 of what an organization may face,

0:04:52.700000 --> 0:04:58.040000
 you know, especially when you, when you
 think of, you know, the techniques

0:04:58.040000 --> 0:04:59.740000
 utilized by real world adversaries.

0:04:59.740000 --> 0:05:05.040000
 So it sort of adds depth and realism
 to your web app pen tests.

0:05:05.040000 --> 0:05:09.280000
 Secondly, you know, the ability to evade
 filters or bypass WAF rules allows

0:05:09.280000 --> 0:05:13.060000
 you to evaluate the robustness of an
 application security measures and

0:05:13.060000 --> 0:05:15.700000
 provide actionable recommendations
 for improvement.

0:05:15.700000 --> 0:05:22.140000
 So, you know, you're able to not only
 assess, you know, from a strictly,

0:05:22.140000 --> 0:05:26.860000
 you know, traditional security perspective,
 you know, the application

0:05:26.860000 --> 0:05:31.380000
 security, but the robustness of the,
 the application security measures.

0:05:31.380000 --> 0:05:35.380000
 So just going beyond testing, you know,
 specific elements within a web

0:05:35.380000 --> 0:05:38.980000
 app, you're now testing how robust
 the web application is.

0:05:38.980000 --> 0:05:42.320000
 And, you know, of course, how
 resistant it is to attacks.

0:05:42.320000 --> 0:05:46.140000
 So I think that's, you know, very, very
 good point or, you know, one of

0:05:46.140000 --> 0:05:49.500000
 the applications there, the knowledge
 and skills you've acquired in this

0:05:49.500000 --> 0:05:53.480000
 course. And then finally, you know,
 vulnerabilities like SQL injection,

0:05:53.480000 --> 0:05:56.980000
 cross-site scripting, and SSRF may not
 be exploitable with simple payloads

0:05:56.980000 --> 0:06:03.160000
 due to filters. And, you know, learning
 or being able to evade, you know,

0:06:03.160000 --> 0:06:08.080000
 essentially having the knowledge of
 how to evade filters will help you

0:06:08.080000 --> 0:06:11.880000
 circumvent these protections because,
 again, they're quite prevalent.

0:06:11.880000 --> 0:06:16.180000
 And, of course, you know, the result
 of this is successful exploitation.

0:06:16.180000 --> 0:06:20.020000
 So, you know, if I was to narrow it down,
 I would say, you know, the real

0:06:20.020000 --> 0:06:22.580000
-world applications of the knowledge
 and skills you have learned in this

0:06:22.580000 --> 0:06:27.940000
 course really revolve around the fact
 that, you know, filter evasion and

0:06:27.940000 --> 0:06:32.640000
 web bypassing a sort of quite
 relevant or quite prevalent.

0:06:32.640000 --> 0:06:38.280000
 I would say relevant first in terms of
 the fact that a lot of these mechanisms

0:06:38.280000 --> 0:06:43.120000
 are in place in modern web applications.

0:06:43.120000 --> 0:06:46.780000
 And in terms of the prevalence, you
 know, which I just pointed out, or

0:06:46.780000 --> 0:06:50.860000
 the relevance, you know, they're sort
 of related because a lot of web

0:06:50.860000 --> 0:06:54.040000
 applications utilize filtering
 or web application files.

0:06:54.040000 --> 0:06:55.820000
 So that's a good reason.

0:06:55.820000 --> 0:07:01.320000
 Or, you know, one of the benefits
 of actually knowing this stuff.

0:07:01.320000 --> 0:07:07.300000
 And secondly, you know, you know, sort
 of going beyond the relevance,

0:07:07.300000 --> 0:07:09.000000
 we talk about the prevalence.

0:07:09.000000 --> 0:07:11.320000
 As I said, they're sort of related.

0:07:11.320000 --> 0:07:17.440000
 But in terms of my point and what I mean
 by prevalence, you know, it goes

0:07:17.440000 --> 0:07:21.460000
 sort of beyond the fact that let's say
 many web applications or many websites

0:07:21.460000 --> 0:07:23.920000
 are using, you know, the
 security measures.

0:07:23.920000 --> 0:07:29.840000
 But also what we learned in this course
 is very important or should have

0:07:29.840000 --> 0:07:34.360000
 helped you in understanding, you know,
 the nuances or the different, the

0:07:34.360000 --> 0:07:37.420000
 different types of filtering, for example,
 that you're likely to encounter

0:07:37.420000 --> 0:07:40.680000
 and sort of build that
 into your methodology.

0:07:40.680000 --> 0:07:43.140000
 So those are the real world applications.


0:07:43.140000 --> 0:07:46.520000
 And then of course, I have some recommendations
 for you here, first of

0:07:46.520000 --> 0:07:51.400000
 which is to research and practice bypassing
 popular wafts like mod security,

0:07:51.400000 --> 0:07:53.280000
 cloud flare, emperver.

0:07:53.280000 --> 0:07:57.780000
 And then of course, explore waft bypass
 techniques specifically like payload

0:07:57.780000 --> 0:08:03.480000
 manipulation, traffic shaping, and using
 alternative encoding or non standard

0:08:03.480000 --> 0:08:09.860000
 requests. And with that being said,
 that's the, the end of the course

0:08:09.860000 --> 0:08:12.680000
 summary video. And that brings
 us to the end of this course.

0:08:12.680000 --> 0:08:16.660000
 I would like to thank you very much
 for making it this far or completing

0:08:16.660000 --> 0:08:20.940000
 the course. And hopefully you
 found the course useful.

0:08:20.940000 --> 0:08:28.300000
 And again, hopefully you'll find use
 for the knowledge and skills you

0:08:28.300000 --> 0:08:32.220000
 build. With that being said, I'm
 going to bid you farewell.

0:08:32.220000 --> 0:08:35.260000
 And hopefully I'll be seeing
 you in the next course.

