WEBVTT

0:00:03.720000 --> 0:00:06.220000
 Hello everyone and welcome.

0:00:06.220000 --> 0:00:11.940000
 In this video we're going to be exploring
 PHP insecurity serialization.

0:00:11.940000 --> 0:00:16.340000
 And just as we did, you know, in the
 previous video when we're exploring

0:00:16.340000 --> 0:00:22.020000
 Java, insecurity serialization, and
 also the video prior to that one,

0:00:22.020000 --> 0:00:26.860000
 we're going to start off by getting an understanding
 of the actual serialization

0:00:26.860000 --> 0:00:32.300000
 and deserialization, you know, specific
 to the language or framework.

0:00:32.300000 --> 0:00:37.340000
 So, you know, before we touch on PHP
 and secure deserialization, let's

0:00:37.340000 --> 0:00:43.940000
 get started, you know, by understanding the
 PHP serialization and deserialization

0:00:43.940000 --> 0:00:49.620000
 process, right? So again, I know I've
 sort of been repetitive with the

0:00:49.620000 --> 0:00:55.040000
 term, you know, the definition of serialization,
 but I always, you know,

0:00:55.040000 --> 0:00:56.640000
 like reiterating it.

0:00:56.640000 --> 0:01:01.580000
 In the case of, you know, PHP serialization,
 this is the process of converting

0:01:01.580000 --> 0:01:08.420000
 a PHP object array, keep the array in mind
 or value into a string representation.

0:01:08.420000 --> 0:01:13.540000
 So again, not binary or not bit stream.

0:01:13.540000 --> 0:01:18.920000
 In this case, it's a string representation
 that can be stored, transmitted

0:01:18.920000 --> 0:01:21.600000
 or reused later.

0:01:21.600000 --> 0:01:26.540000
 The serialized string contains all
 the necessary information required

0:01:26.540000 --> 0:01:30.680000
 to reconstruct the original
 object or data structure.

0:01:30.680000 --> 0:01:36.260000
 And the function that allows you or
 that performs this in PHP is called

0:01:36.260000 --> 0:01:37.380000
 serialize, right?

0:01:37.380000 --> 0:01:42.100000
 So the serialize function handles serialization
 and the un-serialize function

0:01:42.100000 --> 0:01:44.540000
 handles deserialization.

0:01:44.540000 --> 0:01:49.080000
 The process is much simpler, you know,
 as a whole, or the functions are

0:01:49.080000 --> 0:01:54.040000
 much simpler than what we explored
 in the previous video with Java.

0:01:54.040000 --> 0:01:58.600000
 However, what is a bit more complex
 or what confuses a lot of people is

0:01:58.600000 --> 0:02:02.500000
 the actual serialized format, which
 is a string, but you know, it can

0:02:02.500000 --> 0:02:06.280000
 be a little bit difficult to understand
 exactly what's going on there.

0:02:06.280000 --> 0:02:10.560000
 So the serialization process is achieved
 using the serialized function

0:02:10.560000 --> 0:02:15.640000
 in PHP. And this the serialization
 process converts the object or data

0:02:15.640000 --> 0:02:20.760000
 structure into a string format that
 follows a strict syntax and we'll

0:02:20.760000 --> 0:02:23.120000
 take a look at this syntax shortly.

0:02:23.120000 --> 0:02:27.920000
 So the bottom line is that the serialized
 string or the output of serialization

0:02:27.920000 --> 0:02:30.620000
 will contain the object type.

0:02:30.620000 --> 0:02:35.540000
 So, you know, this identifies the data
 type is it an object array or scalar,

0:02:35.540000 --> 0:02:41.940000
 for example, length and metadata, you'll
 see numbers in PHP serialize

0:02:41.940000 --> 0:02:45.300000
 data. That's what it's referring to
 the length and, you know, metadata.

0:02:45.300000 --> 0:02:49.740000
 So this will include lengths of names,
 values or keys, and then properties

0:02:49.740000 --> 0:02:51.680000
 and values, which makes sense.

0:02:51.680000 --> 0:02:55.200000
 So all property names and their respective
 values are included in the

0:02:55.200000 --> 0:03:01.480000
 serialized form, or, you know, the actual
 serialized version of the data.

0:03:01.480000 --> 0:03:04.440000
 So that brings us now to the syntax.

0:03:04.440000 --> 0:03:08.180000
 So what I just said, I'm sort of explaining
 what all of that means.

0:03:08.180000 --> 0:03:13.460000
 So this is an example of what you know,
 what PHP serialized data looks

0:03:13.460000 --> 0:03:15.660000
 like in terms of the syntax.

0:03:15.660000 --> 0:03:17.400000
 We'll take a look at a real example.

0:03:17.400000 --> 0:03:20.660000
 But it's very important that you understand
 exactly how it's organized.

0:03:20.660000 --> 0:03:24.380000
 So again, you may have seen this if you
 experienced with PHP serialization,

0:03:24.380000 --> 0:03:26.140000
 this is not going to be new.

0:03:26.140000 --> 0:03:28.320000
 You know, this is not new to you.

0:03:28.320000 --> 0:03:30.340000
 But I think it's important
 we go through it.

0:03:30.340000 --> 0:03:35.100000
 So firstly, and I'll just switch
 back and forth the object type.

0:03:35.100000 --> 0:03:39.060000
 So that's in this case, oh, in the case
 of this example, it's not always

0:03:39.060000 --> 0:03:43.940000
 going to be oh, but in this case, what
 it's telling us is, you know, oh,

0:03:43.940000 --> 0:03:48.880000
 essentially indicates the serialized
 type is an object.

0:03:48.880000 --> 0:03:50.580000
 Okay, and then you have the length.

0:03:50.580000 --> 0:03:53.680000
 So this is the length of the class name.

0:03:53.680000 --> 0:03:58.960000
 And then you then have the class name,
 you know, field, which is used

0:03:58.960000 --> 0:04:02.300000
 to specify the name of the
 class being serialized.

0:04:02.300000 --> 0:04:08.400000
 And then num properties here is the
 number of properties in the object.

0:04:08.400000 --> 0:04:12.980000
 And then the final section usually
 contains the property names and the

0:04:12.980000 --> 0:04:14.340000
 property values.

0:04:14.340000 --> 0:04:19.920000
 And you know, these two, you know, this
 is where you would have the, this

0:04:19.920000 --> 0:04:27.600000
 is where the properties, the property
 names and their respective values.

0:04:27.600000 --> 0:04:29.260000
 This is where they would be represented.

0:04:29.260000 --> 0:04:35.140000
 So this is a bit confusing, because
 you know, this is not when we get

0:04:35.140000 --> 0:04:38.880000
 to the example that has, you know,
 some sample data will start to make

0:04:38.880000 --> 0:04:45.760000
 sense. So let's, you know, take a look
 at an example here of, you know,

0:04:45.760000 --> 0:04:47.960000
 the actual serialization process.

0:04:47.960000 --> 0:04:51.720000
 So as you can see in this code here,
 which is just, you know, some basic

0:04:51.720000 --> 0:04:56.320000
 PHP code, the serialize function converts
 the PHP objects, arrays, or

0:04:56.320000 --> 0:04:58.780000
 values into a storeable string format.

0:04:58.780000 --> 0:05:03.320000
 So firstly, we have a class called
 user, and then public variable, so

0:05:03.320000 --> 0:05:08.500000
 name role, and then public function construct
 name role, it takes in name

0:05:08.500000 --> 0:05:12.800000
 and role. And then in here, you have
 this name is equal to name, this

0:05:12.800000 --> 0:05:14.300000
 role equals role.

0:05:14.300000 --> 0:05:17.120000
 And then you have the creation
 of the user object.

0:05:17.120000 --> 0:05:19.240000
 So user is equal to new user.

0:05:19.240000 --> 0:05:24.620000
 And then the, the values are passed
 through, or passed in here.

0:05:24.620000 --> 0:05:30.440000
 So Alice and admin, essentially representing
 name and role, and then the

0:05:30.440000 --> 0:05:35.420000
 serialization. So you can see a variable
 here, serialized is equal to,

0:05:35.420000 --> 0:05:39.800000
 and then you say, you call serialize
 or the serialize function, you tell

0:05:39.800000 --> 0:05:41.360000
 it what you want to serialize.

0:05:41.360000 --> 0:05:47.680000
 In this case, the value of user, right
 over here, the user object, and

0:05:47.680000 --> 0:05:52.160000
 then it just echoes, you know, serialized
 object and just displays, you

0:05:52.160000 --> 0:05:56.420000
 know, the actual object that was now
 in that has been serialized, or the

0:05:56.420000 --> 0:05:58.620000
 serialized format of the object.

0:05:58.620000 --> 0:06:04.280000
 So I want you to try and guess if we
 were to deserialize this particular

0:06:04.280000 --> 0:06:08.140000
 object, what the output would be.

0:06:08.140000 --> 0:06:12.300000
 And before we do that, we now have,
 it's a bit convoluted, but it sort

0:06:12.300000 --> 0:06:16.360000
 of explains the syntax that
 I was referring to earlier.

0:06:16.360000 --> 0:06:18.040000
 So let's try and analyze it.

0:06:18.040000 --> 0:06:21.260000
 So to begin with, we have, oh,
 here, what does that tell us?

0:06:21.260000 --> 0:06:25.580000
 It indicates the type, the serialized
 type is an object.

0:06:25.580000 --> 0:06:27.340000
 Then we have four, what does this mean?

0:06:27.340000 --> 0:06:32.700000
 Well, that's referring to the length
 of the class name, in this case,

0:06:32.700000 --> 0:06:34.880000
 user, okay, so the length.

0:06:34.880000 --> 0:06:38.520000
 And that's always specified
 as an, as an integer.

0:06:38.520000 --> 0:06:41.920000
 And then you have the user here,
 what's that referring to?

0:06:41.920000 --> 0:06:45.700000
 Well, if we go back here, you can see
 there's the user class, right over

0:06:45.700000 --> 0:06:47.440000
 here, that's what it's referring to.

0:06:47.440000 --> 0:06:50.160000
 So user, that's the name of the class.

0:06:50.160000 --> 0:06:52.340000
 And then two, what is that referring to?

0:06:52.340000 --> 0:06:55.180000
 Well, that's referring to the number
 of properties in the object.

0:06:55.180000 --> 0:06:58.760000
 And if we take a look at it, we can
 only see two properties, right?

0:06:58.760000 --> 0:07:00.940000
 That's where that's what that means.

0:07:00.940000 --> 0:07:06.820000
 And then you have the actual properties
 themselves right over here.

0:07:06.820000 --> 0:07:09.420000
 So you can see S4 name.

0:07:09.420000 --> 0:07:10.480000
 Okay, what does that mean?

0:07:10.480000 --> 0:07:16.780000
 Well, this property, the property
 name has four characters.

0:07:16.780000 --> 0:07:22.960000
 So you specify the data type, or, you
 know, pretty much the data type

0:07:22.960000 --> 0:07:27.140000
 here. So it's a string, the
 length, and then name, okay.

0:07:27.140000 --> 0:07:32.800000
 And then same for this one here, you
 have S5 Alice, the value of the name

0:07:32.800000 --> 0:07:34.880000
 is a string of length five.

0:07:34.880000 --> 0:07:39.400000
 So we have a property whose value is
 Alice, and you need to, you know,

0:07:39.400000 --> 0:07:42.760000
 what you're essentially seeing here
 is that, you know, all this info is

0:07:42.760000 --> 0:07:44.500000
 specified, what info?

0:07:44.500000 --> 0:07:49.160000
 Well, the data type, as well as
 the length, and then the value.

0:07:49.160000 --> 0:07:52.360000
 So you then have the other
 property, which is role.

0:07:52.360000 --> 0:07:59.260000
 So S4, that means string, you know,
 four, four characters, the property

0:07:59.260000 --> 0:08:03.700000
 name role here. And then, of course,
 finally, the value of the role is

0:08:03.700000 --> 0:08:06.960000
 string of length five,
 which is just admin.

0:08:06.960000 --> 0:08:13.680000
 So this is what the, what you're seeing
 here is the serialized version.

0:08:13.680000 --> 0:08:18.060000
 This is the serialized version
 of this particular object.

0:08:18.060000 --> 0:08:19.940000
 So that's pretty much it.

0:08:19.940000 --> 0:08:23.480000
 And you know, if you weren't aware
 of the syntax, this would be quite

0:08:23.480000 --> 0:08:25.260000
 difficult to understand.

0:08:25.260000 --> 0:08:30.920000
 The key thing to take note of, if I
 can point it out, is the, the type

0:08:30.920000 --> 0:08:32.440000
 right over here.

0:08:32.440000 --> 0:08:35.480000
 In this case, it's an object, but they
 can also be an array, for example,

0:08:35.480000 --> 0:08:39.260000
 in that case, can you guess what
 it will start with an A, right?

0:08:39.260000 --> 0:08:43.160000
 So hopefully, you're starting to actually
 understand this and then pay

0:08:43.160000 --> 0:08:46.220000
 attention to the length, but more importantly,
 the name of the class,

0:08:46.220000 --> 0:08:47.740000
 that's usually quite important.

0:08:47.740000 --> 0:08:50.540000
 So hopefully that makes sense.

0:08:50.540000 --> 0:08:54.340000
 Now, what happens when we un-serialize,
 which is a question that I asked

0:08:54.340000 --> 0:09:00.540000
 before we took a look at the actual,
 the actual serialized format there.

0:09:00.540000 --> 0:09:05.260000
 Well, the un-serialized function
 reconstructs the original object.

0:09:05.260000 --> 0:09:08.740000
 So this is an example of a PHP script
 that would, you know, de-serialize

0:09:08.740000 --> 0:09:11.360000
 it, or un-serialize it, if you will.

0:09:11.360000 --> 0:09:16.460000
 And, you know, I'd ask the question, what
 would be the output of de-serializing,

0:09:16.460000 --> 0:09:18.100000
 you know, that particular object?

0:09:18.100000 --> 0:09:23.580000
 And it would be name, Alice, rule, admin,
 pretty much these values right

0:09:23.580000 --> 0:09:27.580000
 over here. So that's
 as simple as it gets.

0:09:27.580000 --> 0:09:33.300000
 And you can see what we, what we were
 un-serializing here was the serialized

0:09:33.300000 --> 0:09:34.660000
 data we have here.

0:09:34.660000 --> 0:09:36.420000
 It's exactly the same.

0:09:36.420000 --> 0:09:37.880000
 And it just gives us this.

0:09:37.880000 --> 0:09:40.220000
 The bottom line is that
 nothing has changed.

0:09:40.220000 --> 0:09:42.040000
 Everything has been preserved.

0:09:42.040000 --> 0:09:46.920000
 Now, you can, you know, this script
 is playing around with how the data

0:09:46.920000 --> 0:09:52.400000
 is, how the data is being
 presented or represented.

0:09:52.400000 --> 0:09:56.200000
 So you can see I'm sort of adding a string
 here, so name and concatenating

0:09:56.200000 --> 0:09:59.120000
 it with user, the user variable.

0:09:59.120000 --> 0:10:03.900000
 Likewise, the, the same for the rule.

0:10:03.900000 --> 0:10:07.180000
 But that's pretty much it in a nutshell.

0:10:07.180000 --> 0:10:11.180000
 And now, you know, let's sort of
 summarize the entire process.

0:10:11.180000 --> 0:10:15.020000
 So first thing that I want to point
 out is object inspection.

0:10:15.020000 --> 0:10:18.380000
 So PHP inspects the object class
 name properties and values.

0:10:18.380000 --> 0:10:19.740000
 And then you have your type mapping.

0:10:19.740000 --> 0:10:22.240000
 So each data type is encoded.

0:10:22.240000 --> 0:10:28.000000
 So O represents object s string
 i integer b Boolean array.

0:10:28.000000 --> 0:10:33.400000
 So whenever you see any of these type mapping
 within serialize, PHP serialized

0:10:33.400000 --> 0:10:37.160000
 data, just know that they're referring
 to an object string integer Boolean

0:10:37.160000 --> 0:10:40.140000
 or an array. And then length tracking.

0:10:40.140000 --> 0:10:44.120000
 So the length of strings and arrays is
 calculated to ensure precise encoding

0:10:44.120000 --> 0:10:48.840000
 and also to ensure that when deserialized,
 there's nothing added, nothing

0:10:48.840000 --> 0:10:54.720000
 funny added like, you know,
 like white space, etc.

0:10:54.720000 --> 0:10:57.580000
 And then of course, serialization
 string generation.

0:10:57.580000 --> 0:11:00.860000
 So the object is transformed into the
 serialized string format, combining

0:11:00.860000 --> 0:11:03.420000
 all metadata property names and values.

0:11:03.420000 --> 0:11:08.280000
 That's as simple as it is, you know,
 whole lot simpler than, than Java

0:11:08.280000 --> 0:11:09.380000
 in terms of the process.

0:11:09.380000 --> 0:11:13.780000
 Of course, you know, the serialized
 data is usually quite difficult to

0:11:13.780000 --> 0:11:16.780000
 understand, but hopefully
 you understand it now.

0:11:16.780000 --> 0:11:21.080000
 And now that brings us to PHP
 in secure deserialization.

0:11:21.080000 --> 0:11:24.340000
 So now that we have an understanding
 of what, you know, the serialization

0:11:24.340000 --> 0:11:27.000000
 and deserialization process looks like.

0:11:27.000000 --> 0:11:33.480000
 Now let's touch on, you know, targeting
 or exploiting insecure deserialization

0:11:33.480000 --> 0:11:35.640000
 vulnerabilities in PHP based web apps.

0:11:35.640000 --> 0:11:41.240000
 So insecure deserialization in PHP occurs
 when user supplied serialized

0:11:41.240000 --> 0:11:45.180000
 data is deserialized without
 proper validation.

0:11:45.180000 --> 0:11:49.820000
 This can lead to unintended behavior,
 such as remote code execution or

0:11:49.820000 --> 0:11:54.080000
 code execution flat out data manipulation
 or object injection.

0:11:54.080000 --> 0:11:57.400000
 And we'll talk a little bit about object
 injection because that's quite

0:11:57.400000 --> 0:12:00.440000
 important. And how does this work?

0:12:00.440000 --> 0:12:05.020000
 Well, a PHP application accepts serialized
 data from untrusted sources.

0:12:05.020000 --> 0:12:09.020000
 This could be cookies,
 forms or HTTP requests.

0:12:09.020000 --> 0:12:13.080000
 The application utilizes the unserialized
 function to reconstruct objects

0:12:13.080000 --> 0:12:15.260000
 without verifying the data's integrity.

0:12:15.260000 --> 0:12:21.360000
 This is again quite similar to what
 we're exploring or, you know, one

0:12:21.360000 --> 0:12:26.980000
 of the causes that we saw in the Java
 insecure deserialization video.

0:12:26.980000 --> 0:12:31.580000
 And then finally, an attacker craft
 a malicious serialized string that

0:12:31.580000 --> 0:12:35.820000
 triggers unintended functionality
 during deserialization.

0:12:35.820000 --> 0:12:40.060000
 So you're pretty much just looking
 for an input, whatever that may be,

0:12:40.060000 --> 0:12:44.540000
 where serialized data is specified or
 where you can, you know, essentially

0:12:44.540000 --> 0:12:46.700000
 specify serialized data.

0:12:46.700000 --> 0:12:50.600000
 The reason that's important is because
 you want your either targeting

0:12:50.600000 --> 0:12:53.800000
 the serialized data itself.

0:12:53.800000 --> 0:13:00.100000
 So you can reverse engineer it, you know,
 change it and then send it back

0:13:00.100000 --> 0:13:05.720000
 or your targeting, like we saw in the previous
 video with Java, the serialization

0:13:05.720000 --> 0:13:08.300000
 deserialization mechanism.

0:13:08.300000 --> 0:13:11.020000
 So, you know, there's a lot of things
 you could be targeting in terms

0:13:11.020000 --> 0:13:12.100000
 of vulnerabilities.

0:13:12.100000 --> 0:13:16.980000
 But generally speaking, you're targeting,
 you know, you're targeting instances

0:13:16.980000 --> 0:13:21.460000
 where, you know, there's no verification
 during the unserialization or

0:13:21.460000 --> 0:13:22.940000
 deserialization.

0:13:22.940000 --> 0:13:37.000000
 There's no verification of the unserialized
 being too lax or not restricting

0:13:37.000000 --> 0:13:41.100000
 stuff or, you know, just passing in
 whatever was being was input by the

0:13:41.100000 --> 0:13:47.280000
 user, etc, etc. So what are the primary
 causes of insecure deserialization

0:13:47.280000 --> 0:13:51.460000
 in PHP? Well, firstly, just like, again,
 all the other examples we've

0:13:51.460000 --> 0:13:53.700000
 seen, blind trust in user input.

0:13:53.700000 --> 0:13:58.640000
 So accepting serialized data from untrusted
 sources without verification,

0:13:58.640000 --> 0:14:00.680000
 misuse of the unserialized function.

0:14:00.680000 --> 0:14:04.300000
 So using the unserialized function directly
 on user supply data without

0:14:04.300000 --> 0:14:08.820000
 doing anything to it or validating
 it, vulnerable magic methods, which

0:14:08.820000 --> 0:14:10.480000
 we'll get into shortly.

0:14:10.480000 --> 0:14:17.620000
 So exploiting magic methods like wake
 up or destruct for malicious code

0:14:17.620000 --> 0:14:20.540000
 execution and then lack
 of input validation.

0:14:20.540000 --> 0:14:23.620000
 So not verifying or sanitizing
 serialized input.

0:14:23.620000 --> 0:14:33.680000
 So what are these PHP are special methods
 prefixed with a double underscore

0:14:33.680000 --> 0:14:37.740000
 that are automatically called during
 certain object operations.

0:14:37.740000 --> 0:14:41.360000
 In the context of deserialization, the
 following magic methods are sort

0:14:41.360000 --> 0:14:43.140000
 of critical or important.

0:14:43.140000 --> 0:14:46.980000
 So you have wake up, this is automatically
 invoked during deserialization

0:14:46.980000 --> 0:14:50.800000
 and it's often used to re initialize
 object properties.

0:14:50.800000 --> 0:14:55.080000
 You then have destruct, you know, this
 is called when an object is destroyed.

0:14:55.080000 --> 0:14:58.880000
 So at the end of a script, two string,
 this is invoked when an object

0:14:58.880000 --> 0:15:03.020000
 is treated as a string, very important,
 and then sleep invoked during

0:15:03.020000 --> 0:15:07.780000
 serialization to clean up or prepare
 object properties and then call,

0:15:07.780000 --> 0:15:08.920000
 which is quite dangerous.

0:15:08.920000 --> 0:15:11.700000
 So triggered when an undefined
 method is called.

0:15:11.700000 --> 0:15:16.860000
 Now, quick note here, attackers exploit
 magic methods by embedding malicious

0:15:16.860000 --> 0:15:19.400000
 logic in the serialized payload.

0:15:19.400000 --> 0:15:23.600000
 When the application unserializes the
 payload, magic methods, magic methods

0:15:23.600000 --> 0:15:26.780000
 like wake up or destruct
 execute automatically.

0:15:26.780000 --> 0:15:30.620000
 So you're trying to leverage some of
 these magic methods, you know, to

0:15:30.620000 --> 0:15:35.240000
 do something that the web app is not designed
 to do or, you know, potentially

0:15:35.240000 --> 0:15:41.620000
 malicious. And that brings us now to
 a specific, you know, very, very

0:15:41.620000 --> 0:15:46.640000
 specific aspect of insecure deserialization
 in PHP and that's PHP object

0:15:46.640000 --> 0:15:50.160000
 injection. So what is
 PHP object injection?

0:15:50.160000 --> 0:15:57.120000
 Well, this is an attack vector that
 arises when user input is passed to

0:15:57.120000 --> 0:16:01.340000
 by manipulating that's the keyword serialized
 objects attackers can exploit

0:16:01.340000 --> 0:16:05.620000
 vulnerable magic methods to execute
 arbitrary code, modify application

0:16:05.620000 --> 0:16:08.820000
 behavior or access sensitive data.

0:16:08.820000 --> 0:16:12.740000
 So this is an example of PHP object
 injection where you we're using the

0:16:12.740000 --> 0:16:19.260000
 same PHP code. And actually it has a few
 modifications, but this is vulnerable

0:16:19.260000 --> 0:16:21.000000
 to, you know, object injection.

0:16:21.000000 --> 0:16:24.580000
 And I've sort of highlighted through
 a comment what exactly is vulnerable.

0:16:24.580000 --> 0:16:28.160000
 And you can see what is vulnerable is
 the fact that data is being passed

0:16:28.160000 --> 0:16:32.380000
 directly to the unserialized function
 or method, if you will.

0:16:32.380000 --> 0:16:33.220000
 So very, very simple.

0:16:33.220000 --> 0:16:37.840000
 We have a class called user, you know,
 public name, public role, and then

0:16:37.840000 --> 0:16:40.860000
 public function destruct.

0:16:40.860000 --> 0:16:47.260000
 If this, you know, role is equal to admin,
 echo access granted admin privileges.

0:16:47.260000 --> 0:16:53.840000
 If I set, you know, data from the get
 request, so you variable called

0:16:53.840000 --> 0:16:57.640000
 data is equal to the data from the
 get request and then user is equal

0:16:57.640000 --> 0:16:59.880000
 to unserialized data.

0:16:59.880000 --> 0:17:06.360000
 And the bottom line is, you know, if
 we can somehow inject some malicious

0:17:06.360000 --> 0:17:13.260000
 or inject our malicious serialized data
 as part of the get request, this

0:17:13.260000 --> 0:17:14.580000
 is again very basic.

0:17:14.580000 --> 0:17:19.300000
 It'll automatically get, you know,
 unserialized or deserialized.

0:17:19.300000 --> 0:17:23.560000
 So the, what happens in terms of exploitation
 is the attacker craft say

0:17:23.560000 --> 0:17:25.260000
 malicious serialized payload.

0:17:25.260000 --> 0:17:28.680000
 So in this case, this would be the PHP
 file or script that the attacker

0:17:28.680000 --> 0:17:33.260000
 creates. So you can see class user,
 public name, evil user, public role

0:17:33.260000 --> 0:17:37.720000
 admin, and then echo URL and
 code serialize new user.

0:17:37.720000 --> 0:17:40.620000
 So this is what the serialized
 payload would look like.

0:17:40.620000 --> 0:17:43.700000
 So you have object right over here.

0:17:43.700000 --> 0:17:49.420000
 So name of the class, you know, how
 many, how many properties here so

0:17:49.420000 --> 0:17:54.420000
 name, evil user, role, admin, and of
 course their lengths are specified

0:17:54.420000 --> 0:17:58.660000
 here. So you can already see how easy
 it is to understand exactly what

0:17:58.660000 --> 0:18:01.960000
 PHP serialized data looks like.

0:18:01.960000 --> 0:18:05.360000
 And consequently, what your payload
 looks like to actually see if you've

0:18:05.360000 --> 0:18:08.380000
 made any mistakes quite important.

0:18:08.380000 --> 0:18:11.320000
 And the bottom line is that the attacker
 sends the serialized payload

0:18:11.320000 --> 0:18:15.600000
 via get. So you can see in this case,
 there's a resource called, you know,

0:18:15.600000 --> 0:18:20.700000
 just von.php. This is an example parameter
 data is equal to that's where

0:18:20.700000 --> 0:18:24.900000
 it's injected. And then the unserialized
 function reconstructs the object.

0:18:24.900000 --> 0:18:28.780000
 But more importantly, the magic method
 we saw in the code there, the destruct

0:18:28.780000 --> 0:18:33.420000
 magic method is triggered, essentially
 granting the attacker admin privileges.

0:18:33.420000 --> 0:18:39.200000
 And if we revisit what, you know, if
 we revisit where I sort of specified

0:18:39.200000 --> 0:18:44.160000
 these magic methods or functions, if
 you will, you can see that right

0:18:44.160000 --> 0:18:48.360000
 over here, destruct, you know, called
 when the object is destroyed, for

0:18:48.360000 --> 0:18:52.380000
 example, at the end of a script, and
 we'll get into what, you know, what

0:18:52.380000 --> 0:18:58.920000
 they can be used for, or what you can
 actually gain, or what you get,

0:18:58.920000 --> 0:19:05.520000
 you know, as by leveraging or taking
 advantage of magic methods.

0:19:05.520000 --> 0:19:11.060000
 So there we are, that's, you know, sort
 of all the theoretical knowledge

0:19:11.060000 --> 0:19:16.420000
 I think you need in order to understand
 firstly, the PHP serialization

0:19:16.420000 --> 0:19:20.660000
 and deserialization process, understand,
 you know, what serialized PHP

0:19:20.660000 --> 0:19:33.820000
 or PHP serialized data looks like,
 what the deserialization or in the

0:19:33.820000 --> 0:19:37.400000
 cure deserialization is all
 about, so on and so forth.

0:19:37.400000 --> 0:19:39.320000
 But now it's time to put it into context.


0:19:39.320000 --> 0:19:43.140000
 So in order to do that, we're going
 to be leveraging a live lab on the

0:19:43.140000 --> 0:19:47.120000
 INA platform. So this video has a lab
 associated with it is going to be

0:19:47.120000 --> 0:19:49.120000
 the lab just below this video.

0:19:49.120000 --> 0:19:53.700000
 And the lab will provide you with access
 to a preconfigured calilinic

0:19:53.700000 --> 0:19:58.420000
 system, the lab also is documented very,
 very well, and pretty much follows

0:19:58.420000 --> 0:20:01.300000
 the methodology that I'll
 be walking you through.

0:20:01.300000 --> 0:20:04.660000
 But with that being said, I'm going
 to fire up my lab informant and I'll

0:20:04.660000 --> 0:20:06.660000
 see you in the lab in
 a couple of seconds.

