WEBVTT

0:00:03.800000 --> 0:00:06.120000
 Hello everyone and welcome.

0:00:06.120000 --> 0:00:09.700000
 In this video we're going to be taking
 a look at, you know, identifying

0:00:09.700000 --> 0:00:13.740000
 and exploiting a very basic
 SSRF vulnerability.

0:00:13.740000 --> 0:00:17.120000
 And in order to demonstrate this, we
 don't really need a practical lab.

0:00:17.120000 --> 0:00:22.940000
 I've just set up a very quick lab on
 my calilinic system to demonstrate

0:00:22.940000 --> 0:00:28.380000
 that I just want to give you a feel for
 exactly what an SSRF vulnerability

0:00:28.380000 --> 0:00:33.460000
 is, you know, what it looks like in
 the context of a web application and

0:00:33.460000 --> 0:00:39.720000
 what the results or the outcomes of
 successful exploitation look like.

0:00:39.720000 --> 0:00:46.280000
 So as I mentioned, this will not be a,
 you know, this video does not have

0:00:46.280000 --> 0:00:47.680000
 a lab associated with it.

0:00:47.680000 --> 0:00:49.560000
 So I'm just doing it locally.

0:00:49.560000 --> 0:00:52.720000
 Don't worry that, you know, this really
 isn't crucial to your understanding.

0:00:52.720000 --> 0:01:00.560000
 This will all be contextualized in the
 next a lab that is on the INA platform.

0:01:00.560000 --> 0:01:04.700000
 But with that being said, I'm going to
 switch over onto my calilinic system,

0:01:04.700000 --> 0:01:07.320000
 not just walk you through
 this very simple web app.

0:01:07.320000 --> 0:01:09.800000
 So I'll see you there.

0:01:09.800000 --> 0:01:12.760000
 All right, so I'm back
 on my calilinic system.

0:01:12.760000 --> 0:01:15.980000
 As you can see, I've already
 opened up the web app here.

0:01:15.980000 --> 0:01:22.620000
 I'm already in the burp browser and
 I'm just running it on a VPS, but

0:01:22.620000 --> 0:01:26.760000
 you can see it's fairly simple,
 just called SSRF demonstration.

0:01:26.760000 --> 0:01:32.460000
 And in this case, the input is just
 again, the way the web app works is

0:01:32.460000 --> 0:01:37.760000
 fairly simple. You specify a URL and
 this particular page, if it's an

0:01:37.760000 --> 0:01:39.260000
 image, will render it.

0:01:39.260000 --> 0:01:44.080000
 So the way it's supposed to work is,
 for example, if I, you know, try

0:01:44.080000 --> 0:01:48.940000
 and make a request to INA.com with
 no specific resource specified, and

0:01:48.940000 --> 0:01:54.100000
 I just say fetch, it'll display the,
 you know, the image here, which in

0:01:54.100000 --> 0:01:56.600000
 this case appears to be HTML, right?

0:01:56.600000 --> 0:02:02.120000
 So if I go to the INA website and let's
 say I try and get the URL of a

0:02:02.120000 --> 0:02:06.460000
 particular image, this case SVG,
 let's see if it'll work.

0:02:06.460000 --> 0:02:08.060000
 Maybe, maybe not yet.

0:02:08.060000 --> 0:02:09.700000
 Probably not does not work there.

0:02:09.700000 --> 0:02:12.320000
 We probably need a PNG or something.

0:02:12.320000 --> 0:02:14.340000
 Let's see, that's a web P file.

0:02:14.340000 --> 0:02:15.980000
 Let's test this out.

0:02:15.980000 --> 0:02:19.720000
 So again, this is functionality you'd
 expect in a web app for whatever

0:02:19.720000 --> 0:02:22.700000
 reason, in this case, just
 dumps that content there.

0:02:22.700000 --> 0:02:26.440000
 Let me try my own website
 on my own blog here.

0:02:26.440000 --> 0:02:30.260000
 So let me just type that in like so.

0:02:30.260000 --> 0:02:37.900000
 All right, so I'll just try and grab
 one of my images from my website.

0:02:37.900000 --> 0:02:42.160000
 So I'll just say open image, and
 this is a PNG or it should be.

0:02:42.160000 --> 0:02:46.080000
 So I copy this. Let's put that in there.

0:02:46.080000 --> 0:02:48.760000
 Yeah, it is a PNG, but it's
 not being rendered.

0:02:48.760000 --> 0:02:51.980000
 Okay, regardless of that, I just wanted
 to show you what it would be look

0:02:51.980000 --> 0:02:55.240000
 at what, you know, this functionality
 would look like.

0:02:55.240000 --> 0:02:59.780000
 But now moving on to the attack, you
 know, to test it, what we can do

0:02:59.780000 --> 0:03:05.260000
 if you remember in the first, in the
 previous video, we can actually try

0:03:05.260000 --> 0:03:07.800000
 for some internal network reconnaissance.


0:03:07.800000 --> 0:03:10.020000
 So why don't we, you know,
 go ahead and do that.

0:03:10.020000 --> 0:03:17.580000
 So for example, you know, if I wanted
 to say HTTP, let's do local host.

0:03:17.580000 --> 0:03:21.860000
 So I'm just going to put
 in here local host.

0:03:21.860000 --> 0:03:25.740000
 So the actual port on which
 the web server is running.

0:03:25.740000 --> 0:03:27.900000
 So I'll just click on fetch.

0:03:27.900000 --> 0:03:28.800000
 Ah, there we go.

0:03:28.800000 --> 0:03:33.060000
 So we can see it does indeed, in this
 case, make a request to local host

0:03:33.060000 --> 0:03:38.340000
 remember. So that actually confirms
 that it's our vulnerability.

0:03:38.340000 --> 0:03:42.980000
 But you can see that we can
 also try different ports.

0:03:42.980000 --> 0:03:48.020000
 So for example, we can try port 22,
 which is not going to work actually

0:03:48.020000 --> 0:03:49.620000
 looks like it does.

0:03:49.620000 --> 0:03:52.700000
 They are failed to establish here.

0:03:52.700000 --> 0:03:55.360000
 So there we are, we can actually
 do some pinging.

0:03:55.360000 --> 0:03:59.360000
 And you know, we can try a
 plethora of other checks.

0:03:59.360000 --> 0:04:05.040000
 But what if we try and utilize
 the file option?

0:04:05.040000 --> 0:04:08.760000
 So we know we can say file this sort
 of simulates what you'd see in a

0:04:08.760000 --> 0:04:11.680000
 PHP based web application.

0:04:11.680000 --> 0:04:14.920000
 So we can use the file
 option right over here.

0:04:14.920000 --> 0:04:17.360000
 So let me just say file.

0:04:17.360000 --> 0:04:20.920000
 And we try and access a local
 file right over here.

0:04:20.920000 --> 0:04:24.360000
 So local file access or
 inclusion, if you will.

0:04:24.360000 --> 0:04:26.920000
 And then we specify what we want to read.


0:04:26.920000 --> 0:04:30.620000
 So a good idea is probably the
 Etsy password file on Linux.

0:04:30.620000 --> 0:04:34.440000
 If the underlying server is indeed
 Linux, we hit get and look at this

0:04:34.440000 --> 0:04:41.300000
 interesting. And that pretty much is
 SSRF, you know, very basic example.

0:04:41.300000 --> 0:04:45.060000
 The bottom line is you want to find
 an application input that, you know,

0:04:45.060000 --> 0:04:48.480000
 or a piece of the web applications functionality
 that allows you to specify

0:04:48.480000 --> 0:04:53.120000
 a URL. And you essentially test firstly
 to see if you can, you know, reach

0:04:53.120000 --> 0:04:59.480000
 external web servers or websites external
 IPs, if you will, and then internal

0:04:59.480000 --> 0:05:03.960000
 and try and see whether what happens
 with, you know, specific file when

0:05:03.960000 --> 0:05:09.620000
 that is being fetched from an external
 web server, and whether it's rendered,

0:05:09.620000 --> 0:05:11.800000
 whether it can be executed by the server.


0:05:11.800000 --> 0:05:14.740000
 In this case, it was just
 displaying them raw.

0:05:14.740000 --> 0:05:18.640000
 And then we tested local host, and you
 know, it looked like we can communicate

0:05:18.640000 --> 0:05:19.940000
 with some stuff.

0:05:19.940000 --> 0:05:24.240000
 And then finally, you know, file inclusion
 or, you know, the ability to

0:05:24.240000 --> 0:05:27.740000
 read local files on this server,
 which is actually quite helpful.

0:05:27.740000 --> 0:05:30.700000
 So very, very interesting.

0:05:30.700000 --> 0:05:32.260000
 This is not command injection.

0:05:32.260000 --> 0:05:35.960000
 So I can say, for example, you know,
 LS right over here, you can see it's

0:05:35.960000 --> 0:05:38.600000
 going to say, it has a schema.

0:05:38.600000 --> 0:05:42.920000
 And you can see, it says,
 maybe you meant this.

0:05:42.920000 --> 0:05:46.780000
 If I go into burp suite, and I take
 a look at the requests here, where

0:05:46.780000 --> 0:05:53.160000
 we made a request for, I'll just pick
 one here, for example, assets, you

0:05:53.160000 --> 0:05:57.980000
 can see to I need to actually
 pull all, all other assets.

0:05:57.980000 --> 0:06:02.980000
 And you can see when we made a, we tried
 to access local host port 5000,

0:06:02.980000 --> 0:06:07.900000
 it's the value is specified as a parameter
 in the body of the request,

0:06:07.900000 --> 0:06:09.360000
 and not in the URL.

0:06:09.360000 --> 0:06:11.860000
 So this is also URL encoded.

0:06:11.860000 --> 0:06:14.540000
 And you can see that right over here.

0:06:14.540000 --> 0:06:18.600000
 And then, you know, the web app just
 renders it, but this would be basic

0:06:18.600000 --> 0:06:21.960000
 and not blind. That's very
 important to keep in mind.

0:06:21.960000 --> 0:06:25.480000
 But yeah, I just wanted to show you what
 it looks like, very, very basic.

0:06:25.480000 --> 0:06:30.880000
 But as I mentioned, SSRF really comes
 in handy as part of, you know, larger

0:06:30.880000 --> 0:06:36.620000
 complex, you know, attack chain, or when
 you're chaining multiple vulnerabilities.

0:06:36.620000 --> 0:06:38.760000
 And that's what we'll be looking
 at in the next video.

0:06:38.760000 --> 0:06:42.360000
 But with that being said, that's going to
 be it for the practical demonstration

0:06:42.360000 --> 0:06:45.540000
 section of this video.

0:06:45.540000 --> 0:06:49.200000
 All right, so that was some
 basic SSRF exploitation.

0:06:49.200000 --> 0:06:52.260000
 And there's really nothing much to add.

0:06:52.260000 --> 0:06:54.520000
 Don't worry, you'll get
 a chance to try it out.

0:06:54.520000 --> 0:06:57.260000
 And that's what we'll be doing in the
 next videos I've been mentioning

0:06:57.260000 --> 0:07:01.220000
 repeatedly. So with that being said,
 that's going to be it for this video.

0:07:01.220000 --> 0:07:03.320000
 And I will be seeing you
 in the next video.

