WEBVTT

0:00:03.680000 --> 0:00:06.620000
 Hello everyone and welcome to this video.


0:00:06.620000 --> 0:00:10.520000
 In this video we're going to be taking
 a look at how to identify and exploit

0:00:10.520000 --> 0:00:15.720000
 a necessary vulnerability through the
 use of a practical lab here on the

0:00:15.720000 --> 0:00:21.820000
 INE platform. So this is going to be
 quite a complex lab and we're going

0:00:21.820000 --> 0:00:26.620000
 to be going beyond the standard just
 identifying exploit of vulnerability

0:00:26.620000 --> 0:00:31.520000
 but we're also going to take a look
 at how to chain vulnerabilities.

0:00:31.520000 --> 0:00:37.300000
 So SSRF is just going to be one aspect
 or one part of the overall exploitation

0:00:37.300000 --> 0:00:42.520000
 but hopefully this gives you a complete
 view not just of how you can leverage

0:00:42.520000 --> 0:00:47.920000
 or how you can exploit SSRF vulnerabilities
 but also get an understanding

0:00:47.920000 --> 0:00:50.860000
 as to the different forms.

0:00:50.860000 --> 0:00:57.560000
 You know, a SSRF vulnerability can
 present itself or you know also how

0:00:57.560000 --> 0:01:02.360000
 to combine one exploit or one vulnerability
 in order to take advantage

0:01:02.360000 --> 0:01:07.380000
 of another or you know vice versa but
 to cut things short, you know as

0:01:07.380000 --> 0:01:11.300000
 the title suggests, you know, we're going
 to be exploiting a SSRF vulnerability

0:01:11.300000 --> 0:01:16.500000
 to achieve our objective which in this
 case is remote code execution.

0:01:16.500000 --> 0:01:21.160000
 So as I mentioned this video has a
 lab associated with it, it's quite

0:01:21.160000 --> 0:01:25.620000
 lengthy, the lab has all the documentation
 or pretty much a walkthrough

0:01:25.620000 --> 0:01:29.460000
 of everything that I'm going to
 be going through right now.

0:01:29.460000 --> 0:01:33.260000
 And I would also like to point out
 that this lab will provide you with

0:01:33.260000 --> 0:01:37.040000
 access to a pre-configured Kali Linux
 system so you don't need to use

0:01:37.040000 --> 0:01:41.160000
 your own but I'm not going to
 take any more of your time.

0:01:41.160000 --> 0:01:45.660000
 I'm going to fire up my lab and I'll
 see you within the lab environment.

0:01:45.660000 --> 0:01:53.140000
 Alright so I am back within the lab environment
 and as you can see you'll

0:01:53.140000 --> 0:01:56.920000
 have access to a pre-configured
 Kali Linux system.

0:01:56.920000 --> 0:02:00.900000
 The first thing you want to do is just
 open up your browser and we're

0:02:00.900000 --> 0:02:04.600000
 just going to check if the target
 web application is running.

0:02:04.600000 --> 0:02:11.980000
 Now the host name of the target is
 demo.inie.local as it is documented

0:02:11.980000 --> 0:02:16.980000
 in the lab documentation so it's probably
 a smart thing if we are to you

0:02:16.980000 --> 0:02:23.080000
 know just ping demo.inie.local and see
 what the code is because in your

0:02:23.080000 --> 0:02:28.720000
 case or in your lab the IP will
 be different so demo.inie.local.

0:02:28.720000 --> 0:02:30.500000
 There we are so we get it.

0:02:30.500000 --> 0:02:34.260000
 This is the IP in my lab so just keep
 that in mind and we're now going

0:02:34.260000 --> 0:02:36.420000
 to perform a quick end map scan.

0:02:36.420000 --> 0:02:40.400000
 We'll perform a since scan, service version
 detection scan on the default

0:02:40.400000 --> 0:02:47.960000
 1000 ports that end map scans or you
 know within the default port profile

0:02:47.960000 --> 0:02:51.320000
 if you will or you know just a thousand
 of the most commonly used ports

0:02:51.320000 --> 0:02:56.320000
 I should say. But there we are that's
 done and right over here we can

0:02:56.320000 --> 0:03:01.400000
 see we have quite a lengthy service
 banner here but we have SSH running

0:03:01.400000 --> 0:03:05.240000
 Ubuntu or running on Ubuntu
 so we know that.

0:03:05.240000 --> 0:03:10.100000
 We have what appears to be a web server
 running on port 5000 as well as

0:03:10.100000 --> 0:03:14.460000
 another HTTP web server you know Python
 based so most likely we're dealing

0:03:14.460000 --> 0:03:19.200000
 with a Python based web application or
 web server I should say application

0:03:19.200000 --> 0:03:25.160000
 server for that matter so 5000 and 8000
 so let's try and access demo.inie

0:03:25.160000 --> 0:03:32.220000
.local now and .local on port 5000 and
 right over here you can see sort

0:03:32.220000 --> 0:03:38.300000
 of our input or our first attack vector
 which is an XML validator so based

0:03:38.300000 --> 0:03:45.700000
 on what we had covered you know in the
 advanced injection attacks course

0:03:45.700000 --> 0:03:51.900000
 which you know essentially involved XML
 XML based attacks we talked about

0:03:51.900000 --> 0:03:58.720000
 standard XML injection but also XML
 external entities and we're going

0:03:58.720000 --> 0:04:05.040000
 to be leveraging or exploiting that
 first before we get into SSRF so the

0:04:05.040000 --> 0:04:09.960000
 bottom line is we have an XML validator
 so what's the next step well the

0:04:09.960000 --> 0:04:13.500000
 next step obviously is to you know
 create some sample XML because this

0:04:13.500000 --> 0:04:17.780000
 validates XML right and let's see what
 the output is so I'm going to create

0:04:17.780000 --> 0:04:24.320000
 a simple XML file or just some XML
 code that we can test out very very

0:04:24.320000 --> 0:04:30.720000
 simple and we can then you know
 try and see what output we get.

0:04:30.720000 --> 0:04:35.660000
 All right so I've created a very very
 small snippet here you can see it

0:04:35.660000 --> 0:04:39.620000
 has the correct formatting so XML version
 encoding and then we just have

0:04:39.620000 --> 0:04:43.960000
 just called the parent parent because
 if you remember in the in the other

0:04:43.960000 --> 0:04:48.840000
 course when we're talking about XML and
 you know how it's how it differentiates

0:04:48.840000 --> 0:04:53.860000
 itself from HTML one of those things
 was the fact that you know there's

0:04:53.860000 --> 0:04:57.880000
 no predefined tags so we have a parent
 we just need to follow the format

0:04:57.880000 --> 0:05:02.020000
 so parent child and then you know very
 basic so this is formatted correctly

0:05:02.020000 --> 0:05:06.360000
 of course so let's paste this in here
 and let's see what this tells us

0:05:06.360000 --> 0:05:12.700000
 aha excellent so it says the supplied
 XML is valid and then it looks like

0:05:12.700000 --> 0:05:17.940000
 it pretty much just displays it or
 reflects it back on the screen or I

0:05:17.940000 --> 0:05:21.820000
 should say reflected in the response but
 it's not rendered it just displays

0:05:21.820000 --> 0:05:26.420000
 exactly what we put in but not formatted
 obviously because its job is

0:05:26.420000 --> 0:05:32.420000
 just to validate it right so what if
 we take advantage of an XML entity

0:05:32.420000 --> 0:05:37.100000
 you know or at least test and see if
 that works well what we can do is

0:05:37.100000 --> 0:05:41.640000
 if you remember we'll just go to our
 previous snippet here so XML and

0:05:41.640000 --> 0:05:44.680000
 then in here where we define our entities
 we're just going to say doc

0:05:44.680000 --> 0:05:52.760000
 type and we are going to say replace
 and we then specify our entity so

0:05:52.760000 --> 0:05:59.800000
 the format should be simple like so
 we're just going to say entity so

0:05:59.800000 --> 0:06:04.040000
 and then description we're just going to
 say you know test entity or something

0:06:04.040000 --> 0:06:10.860000
 like this and then we are going to close
 the angle brackets and then close

0:06:10.860000 --> 0:06:17.840000
 this and angle brackets again so this
 should suffice what we're essentially

0:06:17.840000 --> 0:06:24.540000
 testing for is whether you know this
 parser is vulnerable to X X E or

0:06:24.540000 --> 0:06:31.780000
 X XML external entities not really external
 at this point but we can test

0:06:31.780000 --> 0:06:37.240000
 it out so I'm just going to paste this
 in here validate that and you can

0:06:37.240000 --> 0:06:43.120000
 see it tells us it's valid which is
 interesting and what we're looking

0:06:43.120000 --> 0:06:48.880000
 for is the description so test entity
 right over here you can see that

0:06:48.880000 --> 0:06:54.060000
 that is specified in the response you
 know in the XML entity so that pretty

0:06:54.060000 --> 0:06:57.600000
 much confirms that we you know this
 parser has an X X E vulnerability

0:06:57.600000 --> 0:07:02.640000
 so what can we do with this well we
 can you know try and reach out to

0:07:02.640000 --> 0:07:09.260000
 or leverage an external entity if you
 will or we can try and access the

0:07:09.260000 --> 0:07:14.320000
 contents of you know a specific file on
 the underlying system so for example

0:07:14.320000 --> 0:07:20.480000
 we can try and access the you know the proc
 net TCP file which will essentially

0:07:20.480000 --> 0:07:24.980000
 display on Linux you know it essentially
 on Linux systems this file contains

0:07:24.980000 --> 0:07:30.060000
 the you know information on the current
 TCP network connections so let's

0:07:30.060000 --> 0:07:35.360000
 go ahead and modify this and now instead
 of saying you know file so entity

0:07:35.360000 --> 0:07:41.580000
 we probably actually we can create a
 new one here and I'm just going to

0:07:41.580000 --> 0:07:47.860000
 create a new one all right so there
 we are in this case I've gotten rid

0:07:47.860000 --> 0:07:54.140000
 of you know some of the rest you know
 I've gone rid of the other tags

0:07:54.140000 --> 0:07:58.300000
 here so just keeping it simple so we
 still have locked type data but now

0:07:58.300000 --> 0:08:03.240000
 the entity is file system and then we're
 utilizing the file operator here

0:08:03.240000 --> 0:08:08.680000
 to get proc net TCP so this should
 give us some IP addresses they may

0:08:08.680000 --> 0:08:12.900000
 be encoded although we can probably
 take a look at how to decode this

0:08:12.900000 --> 0:08:18.840000
 stuff so validate there we go we can
 see it's valid and yeah this looks

0:08:18.840000 --> 0:08:23.760000
 like we can see the data tag here and
 local address and then yeah this

0:08:23.760000 --> 0:08:30.360000
 appeared to be base 64 encoded so we
 can pretty much at this point try

0:08:30.360000 --> 0:08:40.620000
 and decode these and we can actually
 utilize we can try and utilize a

0:08:40.620000 --> 0:08:50.240000
 script to do this for us so actually
 yeah we probably want to convert

0:08:50.240000 --> 0:08:54.580000
 into the hex to you know convert it
 from hex to let's say dot a decimal

0:08:54.580000 --> 0:09:00.560000
 notation so I'm going to use a Python
 script to do this for me so let

0:09:00.560000 --> 0:09:04.200000
 me just go ahead and create that here
 this should also be outlined in

0:09:04.200000 --> 0:09:10.840000
 the lab documentation all right there
 we are so this is it it's fairly

0:09:10.840000 --> 0:09:16.200000
 simple we have our imports here so we're
 importing socket and struct hex

0:09:16.200000 --> 0:09:20.340000
 IP is equal to we'll need to provide
 the you know the actual IP in hex

0:09:20.340000 --> 0:09:26.460000
 format and then address long is equal
 to int hex IP 16 right over here

0:09:26.460000 --> 0:09:35.780000
 and so I'm going to save this now on
 my desktop here to convert dot pi

0:09:35.780000 --> 0:09:43.200000
 all right there we go and we can open
 up our terminal let me go ahead

0:09:43.200000 --> 0:09:48.000000
 and navigate to my desktop and we're
 going to say python 3 convert dot

0:09:48.000000 --> 0:09:53.580000
 pi and we see we need to supply an IP
 address in hex so we can copy one

0:09:53.580000 --> 0:10:06.280000
 of these what about this one right over
 here so I'll go ahead and supply

0:10:06.280000 --> 0:10:11.320000
 this in here and we hit enter and you can
 see there we are so that's localhost

0:10:11.320000 --> 0:10:16.940000
 127 0 0 1 okay not really interesting
 but this is an example of what you

0:10:16.940000 --> 0:10:25.540000
 can do you know or what you can get as
 a result of successfully exploiting

0:10:25.540000 --> 0:10:29.780000
 an xx e vulnerability so let's try and
 find the other one here these all

0:10:29.780000 --> 0:10:38.180000
 seem to be empty what about this one
 let's see we probably want to try

0:10:38.180000 --> 0:10:45.440000
 as many as we can no that's not what
 we are looking for we have this value

0:10:45.440000 --> 0:10:51.320000
 here let's try this let's see what
 we have in here so python put that

0:10:51.320000 --> 0:10:59.320000
 in here on 92 24 23 is this the my IP
 address or is that the IP address

0:10:59.320000 --> 0:11:07.680000
 of the target web server 24 23 yes it
 looks like okay so that's that value

0:11:07.680000 --> 0:11:13.700000
 and let's see so if I go back in here
 that if that's localhost and that

0:11:13.700000 --> 0:11:25.940000
 means no let's see if I go in here what
 about this one okay I'm just trying

0:11:25.940000 --> 0:11:31.660000
 to find one specifically here want to
 mount this one let's go ahead and

0:11:31.660000 --> 0:11:39.600000
 try this one out here all right so 127
 0 0 11 anyway this is not really

0:11:39.600000 --> 0:11:43.560000
 that important just wanted to show you
 how you can again take advantage

0:11:43.560000 --> 0:11:47.160000
 of the xx e vulnerability how to dump
 you know a specific file or the

0:11:47.160000 --> 0:11:50.980000
 contents of a file how to make sense
 of it because you know formatting

0:11:50.980000 --> 0:12:00.160000
 is quite important and from this point
 now we can also you know we can

0:12:00.160000 --> 0:12:03.240000
 probably also try and convert the ports
 which you know I think is quite

0:12:03.240000 --> 0:12:13.400000
 important so obviously based on the
 port separated by colon so this is

0:12:13.400000 --> 0:12:20.240000
 hex here so we can actually use python
 just natively to convert that so

0:12:20.240000 --> 0:12:27.160000
 you know we're gonna say python 3 and
 I think we can just say you know

0:12:27.160000 --> 0:12:32.720000
 0x obviously in the correct format hit
 enter that's port 8 8 8 8 interesting

0:12:32.720000 --> 0:12:43.560000
 okay that's also running very let's
 see right over here what about this

0:12:43.560000 --> 0:12:55.340000
 one okay 0x trying that out 22 so that's
 SSH this is a local host let's

0:12:55.340000 --> 0:13:06.440000
 try and find another one here let's see
 0 0 0 okay this one might be interesting

0:13:06.440000 --> 0:13:11.180000
 actually wait hold on a second that's
 the TCP port range there I can see

0:13:11.180000 --> 0:13:20.580000
 I have this one here quite interesting
 but if we go back up there probably

0:13:20.580000 --> 0:13:27.080000
 should be others like port 5000 8000
 etc which have probably missed but

0:13:27.080000 --> 0:13:31.440000
 this is on a you know different system
 that we you know we may not have

0:13:31.440000 --> 0:13:35.720000
 access to these ports in any case so this
 is you know sort of the internals

0:13:35.720000 --> 0:13:41.460000
 now of the of the web application or
 the application server and you know

0:13:41.460000 --> 0:13:45.920000
 some of the other components that it
 can access so we can go ahead just

0:13:45.920000 --> 0:13:54.740000
 try one more like this one here um three
 five eight seven one okay interesting

0:13:54.740000 --> 0:14:00.240000
 and yeah so we can you know you can pretty
 much enumerate this info again

0:14:00.240000 --> 0:14:04.640000
 this is not really the focus but one
 of the things you might have realized

0:14:04.640000 --> 0:14:10.860000
 is that there is an SSRF vulnerability
 that you know essentially is inherent

0:14:10.860000 --> 0:14:22.180000
 to the you know the I would say in
 this case external entity and well

0:14:22.180000 --> 0:14:30.480000
 how do we take advantage of it well
 what we can do is we can let's say

0:14:30.480000 --> 0:14:37.920000
 create a dtd file and you know I explain
 what that is and then utilize

0:14:37.920000 --> 0:14:44.140000
 the XML validated to see whether it
 actually you know fetches or reaches

0:14:44.140000 --> 0:14:49.880000
 out to the to the address of the external
 entity which you know will essentially

0:14:49.880000 --> 0:14:55.320000
 be a web server that we are hosting
 that web server will contain the dtd

0:14:55.320000 --> 0:15:01.060000
 file because again external entity
 needs to point to something usually

0:15:01.060000 --> 0:15:08.040000
 it's a dtd file now in case you've
 forgotten a dtd file dtd stands for

0:15:08.040000 --> 0:15:12.320000
 document type definition and what it
 does is it just defines the structure

0:15:12.320000 --> 0:15:18.260000
 and you know the legal elements and
 attributes of an XML document and

0:15:18.260000 --> 0:15:24.760000
 pretty much you know in terms of why
 it's used is it's typically used

0:15:24.760000 --> 0:15:30.260000
 by web applications to verify you know
 XML data is valid so we can essentially

0:15:30.260000 --> 0:15:37.920000
 utilize you know the the XML external
 entity to fetch a dtd that then

0:15:37.920000 --> 0:15:44.000000
 defines you know what we can actually
 do in or via XML if that makes sense

0:15:44.000000 --> 0:15:53.080000
 so from this point on what we could
 do is let's go ahead and we probably

0:15:53.080000 --> 0:15:56.760000
 want to create a dtd file so let's start
 there I'm just going to create

0:15:56.760000 --> 0:16:04.340000
 a simple one here I'm just going to
 create a new file okay and there we

0:16:04.340000 --> 0:16:08.520000
 are I've just created a quick dtd file
 as I said this is something already

0:16:08.520000 --> 0:16:15.040000
 explained in another course but what
 this will do as you can see right

0:16:15.040000 --> 0:16:21.560000
 over here file contents all entity all
 and then entity file contents start

0:16:21.560000 --> 0:16:25.800000
 etc it will essentially allow us to
 read specific files from the file

0:16:25.800000 --> 0:16:31.740000
 system and in this case you know the
 file system is local host port 8888

0:16:31.740000 --> 0:16:37.440000
 right over here that was the open port
 we found and we're going to want

0:16:37.440000 --> 0:16:40.720000
 to save this and I'm just going to
 save it on my desktop here and I'm

0:16:40.720000 --> 0:16:45.740000
 just going to call it evil dot dtd okay
 so we're going to save that there

0:16:45.740000 --> 0:16:51.320000
 we are then going to need to set up
 a web server to host the dtd file

0:16:51.320000 --> 0:16:55.900000
 so I'll just exit from the Python interpreter
 here and I'm just going

0:16:55.900000 --> 0:17:02.500000
 to say python 3 m http dot server we'll
 go and use port 8080 so it's going

0:17:02.500000 --> 0:17:07.240000
 to host it because I saved the dtd file
 on my desktop and now we're going

0:17:07.240000 --> 0:17:12.220000
 to just create an XML query that will
 then input into the validator that

0:17:12.220000 --> 0:17:19.540000
 will essentially reach out using XML
 external entity to our our web server

0:17:19.540000 --> 0:17:23.340000
 that we're running on the calilinic
 system that's hosting the evil dot

0:17:23.340000 --> 0:17:31.080000
 dtd file and essentially tell it to
 use that dtd file and yeah so I'm

0:17:31.080000 --> 0:17:34.840000
 just going to create that quick snippet
 now it's going to be slightly

0:17:34.840000 --> 0:17:41.000000
 different all right there we are just
 set it up you can see in this case

0:17:41.000000 --> 0:17:47.020000
 now doc type data entity dtd system
 goes essentially you know we'll make

0:17:47.020000 --> 0:17:55.000000
 a request to our evil dot dtd and then
 over here dtd all essentially and

0:17:55.000000 --> 0:18:01.440000
 you can see data is just the file contents
 so in this particular case

0:18:01.440000 --> 0:18:05.360000
 again if you're following along make sure
 you replace this with your calilinic's

0:18:05.360000 --> 0:18:12.440000
 IP because it will be different and
 now we can actually we can actually

0:18:12.440000 --> 0:18:19.480000
 just input this now before we actually
 do anything before we run this

0:18:19.480000 --> 0:18:22.920000
 in the validator I want to explain a
 couple of things that I might have

0:18:22.920000 --> 0:18:30.780000
 rushed that I might have rushed through
 all right so first things first

0:18:30.780000 --> 0:18:36.980000
 you know this right over here the first
 you know the first payload or

0:18:36.980000 --> 0:18:43.120000
 this particular XML code will essentially
 load the contents of the evil

0:18:43.120000 --> 0:18:48.180000
 dot dtd file that we're hosting and
 then of course this will be passed

0:18:48.180000 --> 0:18:53.160000
 by the back end now the evil dot dtd
 file that we created essentially

0:18:53.160000 --> 0:18:58.420000
 contains the entity that sends a request
 to you know local host port 888

0:18:58.420000 --> 0:19:04.220000
 this is executed on the target server
 and as a result of that if I just

0:19:04.220000 --> 0:19:14.920000
 go to evil dot dtd you can see what
 it does is it essentially it embeds

0:19:14.920000 --> 0:19:19.720000
 it in the cdata section because you can
 see that right over here so cdata

0:19:19.720000 --> 0:19:25.460000
 now what is cdata even though this has
 been explained before cdata sections

0:19:25.460000 --> 0:19:29.700000
 you know can essentially be used to block
 escape literal text when placing

0:19:29.700000 --> 0:19:36.380000
 you know restricted or disallowed characters
 you know with entity references

0:19:36.380000 --> 0:19:44.420000
 and you know that's a security feature
 that we're sort of trying to avoid

0:19:44.420000 --> 0:19:48.800000
 you can learn more about you know the
 cdata sections I can obviously you

0:19:48.800000 --> 0:19:53.080000
 know walk you through a little bit more
 but you know quite simply cdata

0:19:53.080000 --> 0:19:57.680000
 sections can be used to block escape literal
 text when replacing prohibited

0:19:57.680000 --> 0:20:08.500000
 characters you know with entity references
 when that is actually undesirable

0:20:08.500000 --> 0:20:13.100000
 so cdata sections can appear inside
 you know element content and allow

0:20:13.100000 --> 0:20:19.260000
 angular brackets and you know the ampersand
 character for example to appear

0:20:19.260000 --> 0:20:31.660000
 so that's why when we explored XML attacks
 in one in the advanced injection

0:20:31.660000 --> 0:20:36.560000
 attacks course the prohibited characters
 are the angular brackets so less

0:20:36.560000 --> 0:20:41.020000
 than greater than ampersand single quote
 double quote so what this does

0:20:41.020000 --> 0:20:49.420000
 right over here or I should say what
 what the evil dot dtd file does if

0:20:49.420000 --> 0:20:58.020000
 I can just open it again um there we
 go open it here is what what it does

0:20:58.020000 --> 0:21:03.560000
 is it essentially ensures that the response
 contains restricted characters

0:21:03.560000 --> 0:21:09.440000
 and those characters will get embedded
 into the cdata section which is

0:21:09.440000 --> 0:21:13.520000
 something we want and as a result you
 know the XML validator or parser

0:21:13.520000 --> 0:21:18.780000
 will not raise any errors with the you
 know the actual syntax or anything

0:21:18.780000 --> 0:21:22.900000
 like that so what we can go ahead and
 do now is just validate the XML

0:21:22.900000 --> 0:21:26.940000
 here and there you are you can see
 XML is valid and that's because of

0:21:26.940000 --> 0:21:32.880000
 what we just did you know we essentially
 embedded you can see contents

0:21:32.880000 --> 0:21:41.720000
 of evil dot dtd right over here in
 the cdata in the cdata section and

0:21:41.720000 --> 0:21:46.560000
 you know it's not going to be treated
 literally so if we take a look at

0:21:46.560000 --> 0:21:53.240000
 the response we can see we have a html
 here which is interesting and what

0:21:53.240000 --> 0:21:58.080000
 appears to be a directory listing on
 the web server so let's actually

0:21:58.080000 --> 0:22:02.540000
 save this and i'm just going to stop at
 the html tag right over here actually

0:22:02.540000 --> 0:22:08.820000
 hold on that we can see flag one very
 interesting and then another doc

0:22:08.820000 --> 0:22:13.600000
 type here actually hold on we might
 want to start right over here so doc

0:22:13.600000 --> 0:22:20.280000
 type html let's see we have directory
 listing and a flag ah interesting

0:22:20.280000 --> 0:22:25.140000
 okay so i'm just going to copy this
 here i'm going to save it as an html

0:22:25.140000 --> 0:22:29.080000
 file so we can see what it looks like
 so i'll just save it and we're just

0:22:29.080000 --> 0:22:37.240000
 going to call this listing dot html and
 now we're going to save that there

0:22:37.240000 --> 0:22:41.520000
 and we're going to try and open this
 up in Firefox let's see what we're

0:22:41.520000 --> 0:22:46.900000
 able to find so just open up listing
 and there we are we can see directory

0:22:46.900000 --> 0:22:54.560000
 listing again by leveraging the xxe vulnerability
 and again taking advantage

0:22:54.560000 --> 0:23:00.600000
 of the ssrf functionality afforded to
 us there in or as part of the larger

0:23:00.600000 --> 0:23:12.780000
 xxe vulnerability or attack we can
 actually you know read the you know

0:23:12.780000 --> 0:23:16.780000
 files from the file directory here
 now of course i'll try and explain

0:23:16.780000 --> 0:23:22.240000
 this a little bit more but you know we
 didn't specify any particular directory

0:23:22.240000 --> 0:23:26.700000
 because we weren't aware of that so if
 i go back in here to our dt default

0:23:26.700000 --> 0:23:32.360000
 you can see it just says just the file
 system specified is just local

0:23:32.360000 --> 0:23:36.680000
 osp08888 so it appears there's a web
 server that's hosting these folders

0:23:36.680000 --> 0:23:42.660000
 or files obviously this is the html response
 so if we click on it we won't

0:23:42.660000 --> 0:23:46.320000
 get anything but this is obviously
 a folder and then we have flag one

0:23:46.320000 --> 0:23:51.940000
 so how can we now leverage or utilize
 what we have just learned and this

0:23:51.940000 --> 0:23:56.380000
 is you know now standard ssrf if you
 will how can we leverage this to

0:23:56.380000 --> 0:24:01.760000
 access let's say the contents of flag
 one well we can obviously or we

0:24:01.760000 --> 0:24:11.540000
 should be able to do this by modifying
 the dt d file and specify the resource

0:24:11.540000 --> 0:24:15.440000
 that we're looking for so you know if
 i go back in here and i say instead

0:24:15.440000 --> 0:24:22.760000
 of just local host 888 in terms of the
 actual system that we are trying

0:24:22.760000 --> 0:24:27.500000
 to interact with or you know it's obviously
 local host in this case but

0:24:27.500000 --> 0:24:34.880000
 we can just say flag one right over
 here and uh let's save this now and

0:24:34.880000 --> 0:24:41.200000
 now if we go back um yeah that that
 should suffice we can actually now

0:24:41.200000 --> 0:24:47.240000
 just make um i'll just close this tab
 right over here we just need to

0:24:47.240000 --> 0:24:53.860000
 change this uh XML and that's evil
 dot dt d yeah that should work just

0:24:53.860000 --> 0:24:57.780000
 fine so let's validate it and there
 we are we can see that because it's

0:24:57.780000 --> 0:25:01.740000
 embedded in the cdata section we actually
 get the flag so that's the value

0:25:01.740000 --> 0:25:04.380000
 of flag one now i'm not going to be
 going through the process of getting

0:25:04.380000 --> 0:25:08.880000
 flag two or i will take you to the point
 where you can get it but uh yeah

0:25:08.880000 --> 0:25:12.280000
 i just wanted to show you how that works
 now obviously the most important

0:25:12.280000 --> 0:25:17.620000
 file that we're looking for or directory
 is the ssh directory so we can

0:25:17.620000 --> 0:25:22.060000
 actually modify our dt d file and instead
 of saying flag one we can just

0:25:22.060000 --> 0:25:28.560000
 say ssh because it's a directory we'll
 close that there and um yeah i

0:25:28.560000 --> 0:25:33.320000
 don't think we need to modify anything
 there but uh yeah we can actually

0:25:33.320000 --> 0:25:39.060000
 just run it because our web server
 is still going um sorry evil dot dt

0:25:39.060000 --> 0:25:44.440000
 d uh did we save that let me just make
 sure i've saved this there we go

0:25:44.440000 --> 0:25:50.480000
 let's try that again there we go and
 now authorized keys we can see we

0:25:50.480000 --> 0:25:57.200000
 have idrsa um we can actually save this
 response but we have idrsa private

0:25:57.200000 --> 0:26:04.540000
 key and public key um yeah that's pretty
 much it so how can we actually

0:26:04.540000 --> 0:26:08.100000
 get the contents of these files because
 you know we can actually use them

0:26:08.100000 --> 0:26:13.920000
 to SSH into the system that's sort of
 the key here so what we can do now

0:26:13.920000 --> 0:26:21.780000
 is we have authorized keys idrsa and
 idrsa.pub so let's try and get the

0:26:21.780000 --> 0:26:27.580000
 private SSH key or keys if there's more
 than one we'll do that by modifying

0:26:27.580000 --> 0:26:33.340000
 our dt dt file here and uh we'll say
 SSH and then in here we have idrsa

0:26:33.340000 --> 0:26:40.300000
 right and we'll save this in here and
 uh now we don't need to modify our

0:26:40.300000 --> 0:26:45.380000
 payload or XML here so we just click
 on it and there we go so we have

0:26:45.380000 --> 0:26:49.220000
 it but we need to you know this is not
 formatted correctly so we'll need

0:26:49.220000 --> 0:26:54.400000
 to format this but we can see begin
 RSA private key and rsa private key

0:26:54.400000 --> 0:26:58.140000
 and i don't know if these are two separate
 ones now it just looks like

0:26:58.140000 --> 0:27:02.020000
 it's duplicated but you know that's
 fine so i'm just going to save this

0:27:02.020000 --> 0:27:06.880000
 and i'll show you how we can format
 it so i just copied that there and

0:27:06.880000 --> 0:27:12.060000
 the problem with this is um you know it's
 missing new lines it's not formatted

0:27:12.060000 --> 0:27:15.960000
 correctly now while we can automate this
 i'm just going to save this first

0:27:15.960000 --> 0:27:25.980000
 um and um we're just going to call it
 idrsa just keep the names as they

0:27:25.980000 --> 0:27:32.540000
 are so idrsa so that's the private
 now we can actually utilize said um

0:27:32.540000 --> 0:27:37.420000
 to automate the process for us of you
 know sort of formatting it correctly

0:27:37.420000 --> 0:27:44.000000
 or to restore it if you will by just
 going to go into my desktop here

0:27:44.000000 --> 0:27:51.660000
 and you know with said we can essentially
 say said uh e and we then say

0:27:51.660000 --> 0:28:00.600000
 starts with um you know begin private
 begin rsa private key so let's let

0:28:00.600000 --> 0:28:06.440000
 me just take a look at this here so
 uh what we're looking for is this

0:28:06.440000 --> 0:28:14.460000
 so begin and then i'm just going to
 copy that exactly as it is so there

0:28:14.460000 --> 0:28:24.680000
 we are and we're going to say new line
 um but we also have a few more

0:28:24.680000 --> 0:28:30.780000
 that we need to provide here and uh
 sorry said e just a moment is that

0:28:30.780000 --> 0:28:39.880000
 formatted correctly uh yeah we need
 to include a backslash here new line

0:28:39.880000 --> 0:28:49.540000
 just enter hold on a second so uh said
 e s yeah that should be fine and

0:28:49.540000 --> 0:28:56.020000
 then private key uh yeah my bad that
 should be the ampersand is in here

0:28:56.020000 --> 0:29:04.840000
 and then and uh close this there and uh
 this will be a new line so backslash

0:29:04.840000 --> 0:29:14.180000
 my bad and then we can say e um same
 thing but now the end private key

0:29:14.180000 --> 0:29:24.680000
 so i'm just going to copy that now
 right over here as it is copy that

0:29:24.680000 --> 0:29:38.660000
 there okay and we're now going to say
 and we probably also want to specify

0:29:38.660000 --> 0:29:46.300000
 what we are filtering for uh and um
 just i'll explain what this does in

0:29:46.300000 --> 0:29:59.380000
 a second once i have finalized it so
 we'll say s um let's see and i will

0:29:59.380000 --> 0:30:07.700000
 say 64 in here so 64 actually that's
 in curly braces limit that there

0:30:07.700000 --> 0:30:27.080000
 and um actually hold on we probably want
 to specify that in there so yeah

0:30:27.080000 --> 0:30:30.540000
 and then we'll just specify now on
 the final line the name of the file

0:30:30.540000 --> 0:30:37.240000
 which in our case we called ID RSA there
 we are formats it perfectly as

0:30:37.240000 --> 0:30:46.660000
 you'd expect um and uh you can just
 compare it to the uh actually yeah

0:30:46.660000 --> 0:30:52.400000
 there we are so we can actually ID RSA
 and we can probably then save that

0:30:52.400000 --> 0:30:59.400000
 there um so what did the said command
 do well uh first things first uh

0:30:59.400000 --> 0:31:04.560000
 you can see it adds a new line after
 begin RSA private key or that string

0:31:04.560000 --> 0:31:10.960000
 it adds a new line before you know the
 end RSA private key string um and

0:31:10.960000 --> 0:31:14.700000
 then of course for all other string blocks
 it adds a new line after every

0:31:14.700000 --> 0:31:20.740000
 64 characters um and uh we now want to
 save it so you know saving it should

0:31:20.740000 --> 0:31:26.880000
 be as simple as just saying um we're
 just going to say uh we'll just call

0:31:26.880000 --> 0:31:34.300000
 it clean or we can call it fixed i think
 fixed um ID RSA something like

0:31:34.300000 --> 0:31:43.040000
 this now we are much that's formatted
 correctly uh what we can do now

0:31:43.040000 --> 0:31:48.260000
 is uh so we've gotten the private SSH
 key but and we don't know who it

0:31:48.260000 --> 0:31:53.340000
 belongs to so in order to use a SSH
 key if you've never used one before

0:31:53.340000 --> 0:31:58.820000
 we are we need to find the corresponding
 username or email for the key

0:31:58.820000 --> 0:32:06.160000
 right uh you know we need to find a
 valid username regardless but uh in

0:32:06.160000 --> 0:32:11.400000
 this case i saw that we had a public
 key so the public key always contains

0:32:11.400000 --> 0:32:15.520000
 or typically contains the email of the
 user or the account name and then

0:32:15.520000 --> 0:32:22.300000
 followed by the host name so um what
 we can do now is just modify the

0:32:22.300000 --> 0:32:35.620000
 gtd file uh dtd file i should say um
 um so we'll change ID RSA to in this

0:32:35.620000 --> 0:32:40.220000
 case ID RSA dot power by believe it
 was uh what it was called here from

0:32:40.220000 --> 0:32:45.400000
 the listening uh no that that was uh
 the private key but in the previous

0:32:45.400000 --> 0:32:49.020000
 one we'll see it's probably dot power but
 shouldn't expect it to be different

0:32:49.020000 --> 0:32:57.500000
 um and then we can just run this again
 and now um hold on now we didn't

0:32:57.500000 --> 0:33:01.200000
 save the dtd file always forget to do
 that so let's go ahead and run this

0:33:01.200000 --> 0:33:08.740000
 now so validate again and now yes SSH
 uh there we go uh do we have any

0:33:08.740000 --> 0:33:14.960000
 it should be at the end so david that
 is insecurecorp.com um and so we

0:33:14.960000 --> 0:33:27.680000
 can probably infer that the username
 is um yeah we probably also want

0:33:27.680000 --> 0:33:33.120000
 to save this i'm wondering whether we
 need any formatting here we don't

0:33:33.120000 --> 0:33:38.020000
 need uh you know we actually don't need
 the public key so because we have

0:33:38.020000 --> 0:33:43.600000
 the private so in essence what we can
 do is just say uh let's see we're

0:33:43.600000 --> 0:33:48.640000
 gonna say SSH i and specify the private
 key there and we're gonna say

0:33:48.640000 --> 0:33:54.600000
 david or try and use david yeah we'll
 just say david.demo.ini.local so

0:33:54.600000 --> 0:34:02.620000
 the host name and let's hit enter and
 uh there we go uh password hmm what's

0:34:02.620000 --> 0:34:12.020000
 the password ah hmm wait hold on a
 second fixed ID yeah that should be

0:34:12.020000 --> 0:34:19.840000
 fine uh unless we don't have any permission
 set so let's just set that

0:34:19.840000 --> 0:34:26.040000
 right now there we are and we get access
 to the user david and uh consequently

0:34:26.040000 --> 0:34:32.380000
 remote code execution so uh that's pretty
 much it uh you can see there's

0:34:32.380000 --> 0:34:36.540000
 quite an advanced demo that leverages
 uh more than one vulnerability we

0:34:36.540000 --> 0:34:41.080000
 started off you know with uh by exploiting
 external entities and then

0:34:41.080000 --> 0:34:45.640000
 you know explored server service for
 request forgery in terms of making

0:34:45.640000 --> 0:34:52.000000
 a request to an external server uh resource
 that was essentially malicious

0:34:52.000000 --> 0:34:59.380000
 the dtd file was malicious um in that
 it allowed for us to view um you

0:34:59.380000 --> 0:35:04.280000
 know specific data stored on the system
 and as a result of that we're

0:35:04.280000 --> 0:35:09.500000
 able to access SSH keys um or you know
 the SSH key for a user account

0:35:09.500000 --> 0:35:13.480000
 on the underlying server that we then
 leverage to gain access to the server

0:35:13.480000 --> 0:35:17.520000
 and uh you know there's pretty much
 it that is remote command execution

0:35:17.520000 --> 0:35:21.560000
 and with that being said that brings us to
 the end of the practical demonstration

0:35:21.560000 --> 0:35:27.740000
 section of this video all right so that
 was um how to identify and exploit

0:35:27.740000 --> 0:35:32.820000
 an SSRF vulnerability in sort of a realistic
 con uh context and of course

0:35:32.820000 --> 0:35:36.220000
 in this particular demonstration there's
 a bit more advanced in that and

0:35:36.220000 --> 0:35:41.020000
 it involved us chaining multiple vulnerabilities
 uh definitely go through

0:35:41.020000 --> 0:35:44.420000
 the lab pretty much all the steps i
 went through are documented in the

0:35:44.420000 --> 0:35:48.520000
 lab documentation test it out go through
 it more than once try and play

0:35:48.520000 --> 0:35:52.840000
 try and play with a couple of things
 uh you know specifically you know

0:35:52.840000 --> 0:35:57.520000
 modifying the dtd file just to see what
 else you can do uh but with that

0:35:57.520000 --> 0:36:00.780000
 being said that's going to be it for
 this video and i'll be seeing you

