WEBVTT

0:00:04.180000 --> 0:00:07.440000
 All right. So I'm currently
 in the lab environment.

0:00:07.440000 --> 0:00:11.220000
 And as you can see, you'll be provided
 with access to a preconfigured

0:00:11.220000 --> 0:00:12.380000
 Kali Linux system.

0:00:12.380000 --> 0:00:16.420000
 The target web application is
 running on demo.ini.local.

0:00:16.420000 --> 0:00:20.520000
 It is an intentionally vulnerable web
 application called, you know, X,

0:00:20.520000 --> 0:00:23.960000
 V, W, A or the extreme vulnerable
 web application.

0:00:23.960000 --> 0:00:27.100000
 Now you may be thinking to yourself,
 well, why are we not taking a look

0:00:27.100000 --> 0:00:32.080000
 at a more real or realistic example
 like we did in the previous video?

0:00:32.080000 --> 0:00:36.380000
 Well, again, it really doesn't matter
 in this particular context, because

0:00:36.380000 --> 0:00:41.240000
 the objective of this video is to,
 you know, primarily focus on object

0:00:41.240000 --> 0:00:46.620000
 injection, but more importantly, sort
 of give you an idea as to what the

0:00:46.620000 --> 0:00:52.040000
 serialized data would look like, or how
 to identify, if you will, serialization

0:00:52.040000 --> 0:00:56.720000
 in a web application, more specifically
 a PHP based web application.

0:00:56.720000 --> 0:01:03.420000
 So when you open up demo.ini.local, you
 know, you can click on the attacks

0:01:03.420000 --> 0:01:05.740000
 of vulnerabilities you
 want to try out here.

0:01:05.740000 --> 0:01:08.940000
 What we're focusing on is going
 to be PHP object injection.

0:01:08.940000 --> 0:01:11.640000
 So when you click on this, you can see
 it's going to, you know, sort of

0:01:11.640000 --> 0:01:14.140000
 give you an explanation.

0:01:14.140000 --> 0:01:18.960000
 I would say a very good summary of
 what I sort of outlined in the PHP

0:01:18.960000 --> 0:01:20.820000
 object injection section of the slides.

0:01:20.820000 --> 0:01:25.760000
 But when you're ready to just click here,
 and I want you to pay very close

0:01:25.760000 --> 0:01:28.240000
 attention to what is added to the URL.

0:01:28.240000 --> 0:01:33.860000
 So when we click here, we can see that
 some data is reflected back or

0:01:33.860000 --> 0:01:35.480000
 rendered on the web page.

0:01:35.480000 --> 0:01:39.200000
 So where is the web application
 getting this from?

0:01:39.200000 --> 0:01:42.860000
 Well, if we take a look at the URL, we
 can see something very interesting.

0:01:42.860000 --> 0:01:46.940000
 So we have a parameter called R, which
 is equal to, and there we are,

0:01:46.940000 --> 0:01:49.500000
 we have some serialized data.

0:01:49.500000 --> 0:01:54.420000
 So let's take a, now that you understand
 what PHP serialized data looks

0:01:54.420000 --> 0:01:56.800000
 like, let's take a closer look at this.

0:01:56.800000 --> 0:02:01.140000
 And, you know, I'm going to
 zoom in here a little bit.

0:02:01.140000 --> 0:02:03.040000
 And because this is quite important.

0:02:03.040000 --> 0:02:07.120000
 So if you remember what I mentioned,
 the object mapping, we have this

0:02:07.120000 --> 0:02:11.320000
 one does not start with, oh, it starts
 with a, which means it's an array,

0:02:11.320000 --> 0:02:16.900000
 right, consisting of two properties,
 right over here.

0:02:16.900000 --> 0:02:22.540000
 In this case, we can see
 we have integer zero.

0:02:22.540000 --> 0:02:29.880000
 So, you know, integer, and then we have
 string four, x v w a integer one,

0:02:29.880000 --> 0:02:34.340000
 string 33, and this right over here.

0:02:34.340000 --> 0:02:39.660000
 So that means that, you know, very simply,
 we can actually just say, let's

0:02:39.660000 --> 0:02:42.940000
 see, right over here, if I replace this,
 of course, it has to fit within,

0:02:42.940000 --> 0:02:45.100000
 we'll actually see if there's
 any validation.

0:02:45.100000 --> 0:02:50.020000
 But let's say, you know, PHP is not nice.


0:02:50.020000 --> 0:02:52.060000
 Something stupid like this.

0:02:52.060000 --> 0:02:54.740000
 Okay, so why is this not happening?

0:02:54.740000 --> 0:02:58.980000
 Well, it's not happening because again,
 it does not match the original

0:02:58.980000 --> 0:03:03.500000
 object. So when we click here, you
 can see that there, if I get rid of

0:03:03.500000 --> 0:03:07.300000
 this, if we delete it, let's see, yeah,
 there we are, it pretty much does

0:03:07.300000 --> 0:03:09.020000
 not display anything there.

0:03:09.020000 --> 0:03:11.340000
 Um, but there you go.

0:03:11.340000 --> 0:03:14.020000
 So that is our serialized data.

0:03:14.020000 --> 0:03:17.760000
 And now we get into the
 actual object injection.

0:03:17.760000 --> 0:03:25.540000
 Now, before we get into object injection,
 just to prove to you, you know,

0:03:25.540000 --> 0:03:30.460000
 that my description of what this represents
 is correct, which I'm assuming

0:03:30.460000 --> 0:03:35.040000
 you did as well, let's utilize the
 PHP, let's utilize PHP here on the

0:03:35.040000 --> 0:03:36.800000
 Kali Linux system interactively.

0:03:36.800000 --> 0:03:39.960000
 So I'm going to say PHP,
 so interactive mode.

0:03:39.960000 --> 0:03:42.140000
 And then I'll just say var dump.

0:03:42.140000 --> 0:03:45.320000
 And we can say, un-serialize.

0:03:45.320000 --> 0:03:46.900000
 This is how simple it is.

0:03:46.900000 --> 0:03:50.920000
 So un-serialize and then in here, I'll
 just put in what we copied, like

0:03:50.920000 --> 0:03:55.920000
 so, make sure to close the single quote
 and then double and then the semicolon

0:03:55.920000 --> 0:03:57.780000
 hit enter. There we are.

0:03:57.780000 --> 0:03:59.160000
 So you can see it's not an object.

0:03:59.160000 --> 0:04:04.240000
 It's an array consisting of two right over
 here to, I wouldn't say properties,

0:04:04.240000 --> 0:04:10.260000
 but in this case, you know, these,
 these would be, you know, so we can

0:04:10.260000 --> 0:04:12.060000
 see we have zero and one.

0:04:12.060000 --> 0:04:16.420000
 Now, because this is an array, these
 are not really, you know, there's

0:04:16.420000 --> 0:04:17.860000
 no class or anything like that.

0:04:17.860000 --> 0:04:21.500000
 These are just the array values here.

0:04:21.500000 --> 0:04:24.260000
 And they're, you know,
 they're both strings.

0:04:24.260000 --> 0:04:26.660000
 So one of them is X, V, W, A, etc.

0:04:26.660000 --> 0:04:30.580000
 So I just wanted to show you that you can
 actually perform the deserialization

0:04:30.580000 --> 0:04:35.740000
 or un-serialization process yourself.

0:04:35.740000 --> 0:04:41.460000
 Now, what we can try and do is because
 we sort of understand how this

0:04:41.460000 --> 0:04:45.860000
 works is we can create our own serialized
 data that we can then inject

0:04:45.860000 --> 0:04:49.080000
 in the URL there in the R parameter.

0:04:49.080000 --> 0:04:56.100000
 And we can sort of, you know, we can
 utilize because we sort of, you know,

0:04:56.100000 --> 0:04:58.280000
 have an understanding of how this works.

0:04:58.280000 --> 0:05:04.000000
 You know, what we can do is, you know,
 actually, I think we would need

0:05:04.000000 --> 0:05:09.360000
 to actually understand what exactly
 this particular page does before we

0:05:09.360000 --> 0:05:13.140000
 try anything. Because at this point,
 I think I'm quite unsure.

0:05:13.140000 --> 0:05:16.660000
 So we say, actually, no, what I
 don't, I don't want to do that.

0:05:16.660000 --> 0:05:21.420000
 What I want to do is just
 inspect here for a second.

0:05:21.420000 --> 0:05:25.980000
 So firstly, let me just bring
 this up here slightly.

0:05:25.980000 --> 0:05:32.680000
 And then I'll just scroll to this particular
 model or just expand that.

0:05:32.680000 --> 0:05:35.200000
 No, this is the one here.

0:05:35.200000 --> 0:05:39.120000
 So what we want is this one here.

0:05:39.120000 --> 0:05:43.840000
 So there we go. We can see
 there's a form group text.

0:05:43.840000 --> 0:05:45.820000
 So this is rendered directly back.

0:05:45.820000 --> 0:05:51.340000
 Okay. We can see right over here the,
 you know, where it's getting it

0:05:51.340000 --> 0:05:57.520000
 from the href. Okay, so now
 we can close this up.

0:05:57.520000 --> 0:06:03.440000
 And if I say, you know, view page source
 right over here, we can see,

0:06:03.440000 --> 0:06:06.740000
 let's see if we can find something here.

0:06:06.740000 --> 0:06:09.860000
 So that's there, the nav
 bar, side bar there.

0:06:09.860000 --> 0:06:11.440000
 Actually, it's just a nav bar.

0:06:11.440000 --> 0:06:13.800000
 Then we have the model here.

0:06:13.800000 --> 0:06:20.900000
 And right over here, we can see, so
 the model model content, hold on.

0:06:20.900000 --> 0:06:23.640000
 Okay, no, that's just that there.

0:06:23.640000 --> 0:06:26.320000
 What I'm looking for is
 this right over here.

0:06:26.320000 --> 0:06:30.580000
 So we have that reference there.

0:06:30.580000 --> 0:06:33.460000
 Okay, submit, click here button primary.

0:06:33.460000 --> 0:06:35.600000
 It just sends this in here.

0:06:35.600000 --> 0:06:41.940000
 Now, let's take a look at the let's
 take a look at the source code of

0:06:41.940000 --> 0:06:45.580000
 this web application, because
 I think it's quite important.

0:06:45.580000 --> 0:06:48.100000
 So I'm just going to navigate
 to a GitHub repo.

0:06:48.100000 --> 0:06:51.280000
 This GitHub repo has also been
 added to the lab documentation.

0:06:51.280000 --> 0:06:52.960000
 So just give me a second.

0:06:52.960000 --> 0:06:56.300000
 All right, so I've just copied
 it from the GitHub repo.

0:06:56.300000 --> 0:07:00.520000
 Again, link is been, you know,
 added to the lab documentation.

0:07:00.520000 --> 0:07:05.140000
 And this is specific to this
 PHP object injection page.

0:07:05.140000 --> 0:07:10.200000
 So if we take a look at, you know, this
 particular page, you can see what's

0:07:10.200000 --> 0:07:13.700000
 not included when you view the source,
 obviously is the PHP code.

0:07:13.700000 --> 0:07:19.120000
 So we can see right over here, class
 PHP object injection, public inject,

0:07:19.120000 --> 0:07:22.740000
 okay, and then the construct function
 or method is this is not really

0:07:22.740000 --> 0:07:28.660000
 a magic method. But this is what
 sort of initiates serialization.

0:07:28.660000 --> 0:07:35.420000
 So we then we can see the wake up function,
 which is, or, you know, in

0:07:35.420000 --> 0:07:38.580000
 in PHP parlance, it would be called
 a method, not a function, but it's

0:07:38.580000 --> 0:07:39.680000
 pretty much the same thing.

0:07:39.680000 --> 0:07:42.440000
 But either wake up method
 right over here.

0:07:42.440000 --> 0:07:47.160000
 Okay. And we can see there's
 just a direct injection.

0:07:47.160000 --> 0:07:51.520000
 And more importantly, we can see, and
 this is sort of the vulnerability,

0:07:51.520000 --> 0:07:59.660000
 the eval. You know, we can actually see
 that the inject parameter is directly

0:07:59.660000 --> 0:08:05.020000
 passed to eval, which, and if you know,
 a little bit about evil in PHP,

0:08:05.020000 --> 0:08:11.520000
 what this does is it pretty much evaluates
 the given whatever is specified

0:08:11.520000 --> 0:08:16.980000
 as PHP. So the, you know, in this particular
 case, the parameter would

0:08:16.980000 --> 0:08:24.140000
 be value, the parameter would be evaluated
 and pretty much as a, you know,

0:08:24.140000 --> 0:08:28.760000
 it'll pretty much be executed or treated
 like PHP code in the context

0:08:28.760000 --> 0:08:33.300000
 of PHP. I know that evil sort of is unique
 to different languages or there's

0:08:33.300000 --> 0:08:37.680000
 instances or their languages that use a,
 you know, similar sort of terminology,

0:08:37.680000 --> 0:08:45.520000
 but in PHP, it'll just treat it as it'll
 just treat it as PHP code, which

0:08:45.520000 --> 0:08:51.480000
 means we can actually just utilize this
 knowledge of, you know, the actual

0:08:51.480000 --> 0:08:54.780000
 web application itself and how the
 serialization is taking place.

0:08:54.780000 --> 0:08:58.040000
 Of course, I understand that this is
 not always going to be the case,

0:08:58.040000 --> 0:09:02.040000
 but there's something very important
 that I'm trying to point out here.

0:09:02.040000 --> 0:09:07.760000
 Now, if we take a look at this here,
 so yeah, this is the D serial, there

0:09:07.760000 --> 0:09:12.760000
 we are, we can see our one on serialized
 request, no validation at all.

0:09:12.760000 --> 0:09:19.380000
 So what we can do is we can actually
 create a small PHP file to create

0:09:19.380000 --> 0:09:24.260000
 our payload or our serialized data, if
 you will, and what we will utilize

0:09:24.260000 --> 0:09:29.380000
 is, you know, we'll take advantage of
 the fact that, you know, the, the

0:09:29.380000 --> 0:09:35.960000
 inject parameter is being, the inject
 parameter is directly passed to

0:09:35.960000 --> 0:09:41.320000
 evil. And as a result of that,
 we can execute system commands.

0:09:41.320000 --> 0:09:45.520000
 So we would pretty much just
 follow the same formula here.

0:09:45.520000 --> 0:09:50.780000
 So actually, we can pretty much just
 copy this here, but we need to do

0:09:50.780000 --> 0:09:52.120000
 a couple of things.

0:09:52.120000 --> 0:09:54.740000
 Actually, it's better if we
 just write it from scratch.

0:09:54.740000 --> 0:09:59.620000
 So I'll just open up my terminal exit
 from interactive mode here, I'll

0:09:59.620000 --> 0:10:01.300000
 navigate to my desktop.

0:10:01.300000 --> 0:10:06.360000
 And we'll just call this object dot PHP,
 feel free to use any editor you're

0:10:06.360000 --> 0:10:07.460000
 comfortable with.

0:10:07.460000 --> 0:10:14.940000
 And we'll just say, you know, just
 create or specify our PHP tag here,

0:10:14.940000 --> 0:10:19.380000
 if I can actually type and let me make
 sure I close the tag, because I'm

0:10:19.380000 --> 0:10:21.580000
 notorious for not doing that.

0:10:21.580000 --> 0:10:23.720000
 So in here, we're going
 to create a class.

0:10:23.720000 --> 0:10:29.080000
 And this is, let's see PHP, we can
 just use the same name there.

0:10:29.080000 --> 0:10:31.980000
 So let me just go back here.

0:10:31.980000 --> 0:10:40.460000
 So PHP object injection, and we'll
 then open up that there.

0:10:40.460000 --> 0:10:46.000000
 So now in here, we're going
 to say, public, inject.

0:10:46.000000 --> 0:10:51.320000
 That's going to be equal to this is
 where we specify our system command.

0:10:51.320000 --> 0:10:54.980000
 So to verify that there is, you know,
 insecure deserialization, we're

0:10:54.980000 --> 0:10:59.300000
 just going to execute a very simple
 Linux system command like ID, just

0:10:59.300000 --> 0:11:04.900000
 to get the user ID right on, and
 we'll then close this up here.

0:11:04.900000 --> 0:11:10.780000
 And that there. Okay, so now we're
 going to create our object.

0:11:10.780000 --> 0:11:18.280000
 So in this particular case, let's see,
 we'll just say OBJ is equal to

0:11:18.280000 --> 0:11:27.980000
 new PHP, or just call PHP, the class
 here so PHP object injection, and

0:11:27.980000 --> 0:11:35.520000
 will not pass anything there will denser
 save our dump and serialize object,

0:11:35.520000 --> 0:11:37.520000
 right? That makes sense.

0:11:37.520000 --> 0:11:42.280000
 And we'll now at this point,
 just close that up there.

0:11:42.280000 --> 0:11:43.840000
 And that should be good.

0:11:43.840000 --> 0:11:47.980000
 So this will create our serialized payload
 for us that will just execute

0:11:47.980000 --> 0:11:54.280000
 the command ID, because of the fact that
 the inject parameter or whatever

0:11:54.280000 --> 0:11:57.100000
 data is stored is directly
 passed to eval.

0:11:57.100000 --> 0:12:04.400000
 So we can now save this, and we just
 need to say PHP object dot PHP, and

0:12:04.400000 --> 0:12:06.500000
 it'll do the serialization for us.

0:12:06.500000 --> 0:12:09.640000
 And there we are, you can now see
 this is the serialized data.

0:12:09.640000 --> 0:12:10.980000
 It's now object.

0:12:10.980000 --> 0:12:25.620000
 And then right over here, we have name,
 and then just has one, just has

0:12:25.620000 --> 0:12:31.860000
 one parameter here, which is just,
 you know, system ID, we'll just run

0:12:31.860000 --> 0:12:33.280000
 the ID command, right?

0:12:33.280000 --> 0:12:37.320000
 So we just need to copy this to test
 it and see, hopefully because the

0:12:37.320000 --> 0:12:42.320000
 eval method of function is being used,
 it'll, the value of the user ID

0:12:42.320000 --> 0:12:43.940000
 will be reflected on the web page.

0:12:43.940000 --> 0:12:47.600000
 So we just go back to the web page
 here, and we replace the original,

0:12:47.600000 --> 0:12:51.500000
 you know, value of the parameter R.

0:12:51.500000 --> 0:12:53.740000
 So we just hit enter.

0:12:53.740000 --> 0:12:54.820000
 And there we go.

0:12:54.820000 --> 0:13:00.120000
 Yeah. Insecure this serialization in
 PHP, you can see the use IDs now,

0:13:00.120000 --> 0:13:03.600000
 you know, it's telling us the use
 ID, which makes sense is www data.

0:13:03.600000 --> 0:13:09.100000
 So you know, this is RCE or command
 execution, if you will, arbitrary

0:13:09.100000 --> 0:13:13.740000
 as if you will, but that
 is pretty interesting.

0:13:13.740000 --> 0:13:18.600000
 So let's go directly to, there's a
 couple of other examples that I'll

0:13:18.600000 --> 0:13:20.140000
 list out in the lab documentation.

0:13:20.140000 --> 0:13:24.200000
 But let's go directly to
 gaining a reverse shell.

0:13:24.200000 --> 0:13:26.700000
 It should be fairly simple.

0:13:26.700000 --> 0:13:32.080000
 We're just going to, I'm just going to,
 we pretty much just need to modify

0:13:32.080000 --> 0:13:33.640000
 the object here.

0:13:33.640000 --> 0:13:36.900000
 So object.php that we're using
 to generate our payload.

0:13:36.900000 --> 0:13:41.920000
 But now, instead of just saying ID,
 we are going to utilize a reverse

0:13:41.920000 --> 0:13:48.320000
 shell. So we're going to say bin, bash,
 and then we'll say see, let's

0:13:48.320000 --> 0:13:56.520000
 see. Yeah, we would need
 to say bash interactive.

0:13:56.520000 --> 0:14:06.720000
 So bash i. And then yeah, we would
 just, let's go ahead and, you know,

0:14:06.720000 --> 0:14:08.360000
 just redirect that.

0:14:08.360000 --> 0:14:12.960000
 And so redirect there.

0:14:12.960000 --> 0:14:15.780000
 And what are we redirecting there?

0:14:15.780000 --> 0:14:18.780000
 So standard output, that should be fine.

0:14:18.780000 --> 0:14:27.380000
 So dev, TCP. And then our Kali Linux
 IP, so I'll open up a new tab here.

0:14:27.380000 --> 0:14:29.180000
 So I have config.

0:14:29.180000 --> 0:14:31.200000
 In your case, it will be different.

0:14:31.200000 --> 0:14:32.620000
 So keep that in mind.

0:14:32.620000 --> 0:14:35.920000
 So then in here, I'll
 just paste that there.

0:14:35.920000 --> 0:14:39.780000
 And we want to connect to
 port, let's say 1234.

0:14:39.780000 --> 0:14:41.640000
 We also need to set up
 our net cat listener.

0:14:41.640000 --> 0:14:43.880000
 Hopefully, I don't forget.

0:14:43.880000 --> 0:14:50.580000
 And then we're going to say redirect
 here to standard output should be

0:14:50.580000 --> 0:14:53.100000
 fine. So we'll just say one.

0:14:53.100000 --> 0:14:58.960000
 And then we will close
 that up there, like so.

0:14:58.960000 --> 0:15:03.360000
 Yeah, so we had 123.

0:15:03.360000 --> 0:15:06.440000
 So close the first one second.

0:15:06.440000 --> 0:15:12.800000
 And let's see one, two, how many
 single quotes did I open here?

0:15:12.800000 --> 0:15:16.940000
 Yeah, so that's one, two.

0:15:16.940000 --> 0:15:20.260000
 Let's see. Did I create any?

0:15:20.260000 --> 0:15:22.200000
 Yeah, so that would just be two.

0:15:22.200000 --> 0:15:25.100000
 Make sure I'm closing them correctly.

0:15:25.100000 --> 0:15:27.780000
 So yeah, close that.

0:15:27.780000 --> 0:15:30.700000
 And then double quote close that.

0:15:30.700000 --> 0:15:34.020000
 And then right over here, yeah, we
 don't need to change anything here.

0:15:34.020000 --> 0:15:35.500000
 So we write and quit.

0:15:35.500000 --> 0:15:36.760000
 And then PHP object.

0:15:36.760000 --> 0:15:40.360000
 And now we have our sterilized payload.

0:15:40.360000 --> 0:15:42.380000
 So let's see if this works.

0:15:42.380000 --> 0:15:47.420000
 So I will, I'll just copy this.

0:15:47.420000 --> 0:15:49.900000
 And we'll actually see if it works.

0:15:49.900000 --> 0:15:53.680000
 So I'm a bit doubtful here.

0:15:53.680000 --> 0:15:58.680000
 Actually, in this case,
 we'll only be copying.

0:15:58.680000 --> 0:16:04.680000
 Yeah, that's, we'll just be copying that.


0:16:04.680000 --> 0:16:06.700000
 So let's go ahead and try it.

0:16:06.700000 --> 0:16:08.320000
 Actually, let me set up my listener.

0:16:08.320000 --> 0:16:12.400000
 So net cat lvp 1234.

0:16:12.400000 --> 0:16:18.260000
 And before I do that, let me just verify
 that I did indeed set it as 1234.

0:16:18.260000 --> 0:16:23.420000
 Yes, I did. So run that there.

0:16:23.420000 --> 0:16:27.320000
 And then we go ahead and, you know,
 perform our injection here object

0:16:27.320000 --> 0:16:31.520000
 injection. We hit enter and oh boy.

0:16:31.520000 --> 0:16:33.960000
 Mm. That didn't look like it worked.

0:16:33.960000 --> 0:16:34.980000
 Why is it not working?

0:16:34.980000 --> 0:16:42.400000
 Well, as I suspected, the reason this
 is not working is because the payload,

0:16:42.400000 --> 0:16:47.100000
 the serialized payload contains the escape,
 you know, characters, I think,

0:16:47.100000 --> 0:16:56.260000
 you know, encoding.

0:16:56.260000 --> 0:17:00.720000
 So actually it might be a good
 time to burst out burp.

0:17:00.720000 --> 0:17:03.380000
 So let me go ahead and open up burp here.


0:17:03.380000 --> 0:17:06.800000
 And I'll get back to you when
 I've got it up and running.

0:17:06.800000 --> 0:17:09.060000
 Actually, I think we
 should be good to go.

0:17:09.060000 --> 0:17:15.960000
 I think we also want to configure
 Firefox to proxy traffic to burp.

0:17:15.960000 --> 0:17:22.100000
 Luckily for us, we have Foxy proxy with
 all a burp suite for burp suite

0:17:22.100000 --> 0:17:25.500000
 or zap profile. So we don't
 need to do anything there.

0:17:25.500000 --> 0:17:26.980000
 What's this about?

0:17:26.980000 --> 0:17:29.540000
 Burp suite is out of data.

0:17:29.540000 --> 0:17:35.760000
 Interesting. Anyway, let's go ahead
 and try and run that again.

0:17:35.760000 --> 0:17:38.560000
 Intercept is indeed on.

0:17:38.560000 --> 0:17:42.880000
 So object injection.

0:17:42.880000 --> 0:17:47.600000
 Oh, so we would need to
 do a URL and code here.

0:17:47.600000 --> 0:17:51.460000
 But let's go ahead and do it now.

0:17:51.460000 --> 0:17:55.500000
 So let's see right over here.

0:17:55.500000 --> 0:17:59.020000
 So control you would want work.

0:17:59.020000 --> 0:18:00.980000
 Do we have on it, catalyst now running?

0:18:00.980000 --> 0:18:04.720000
 Yes, we do. Let's for that.

0:18:04.720000 --> 0:18:10.320000
 Okay, nothing. So looks like we
 may need to do it one more time.

0:18:10.320000 --> 0:18:14.620000
 Hit enter. We're just going to encode it.


0:18:14.620000 --> 0:18:17.380000
 Actually, you know what?

0:18:17.380000 --> 0:18:19.500000
 I think I'm doing this incorrectly.

0:18:19.500000 --> 0:18:24.960000
 What I'll do is let me go back in here,
 copy this, because we just want

0:18:24.960000 --> 0:18:26.260000
 to pass it directly.

0:18:26.260000 --> 0:18:31.300000
 So there's no real need in
 utilizing the intercept.

0:18:31.300000 --> 0:18:34.480000
 So in fact, I'll just disable
 intercept there.

0:18:34.480000 --> 0:18:36.180000
 And I'll disable this.

0:18:36.180000 --> 0:18:37.920000
 We don't need burp suite.

0:18:37.920000 --> 0:18:40.440000
 So actually we do need it right now.

0:18:40.440000 --> 0:18:44.780000
 So I'll go into the decoder
 and paste that in there.

0:18:44.780000 --> 0:18:48.760000
 I'm going to say encode as URL encode.

0:18:48.760000 --> 0:18:50.560000
 That's what we want.

0:18:50.560000 --> 0:18:53.340000
 So copy that there.

0:18:53.340000 --> 0:18:59.700000
 So control C. And then in here, we're
 just going to get rid of that there.

0:18:59.700000 --> 0:19:04.500000
 Hit enter. And now take
 a look at our listener.

0:19:04.500000 --> 0:19:05.900000
 Boom. There we go.

0:19:05.900000 --> 0:19:07.360000
 We go to reversal.

0:19:07.360000 --> 0:19:09.080000
 We can confirm that.

0:19:09.080000 --> 0:19:11.800000
 And there we have home index, etc.

0:19:11.800000 --> 0:19:13.080000
 And that's pretty much it.

0:19:13.080000 --> 0:19:18.520000
 So that is PHP object injection, more
 specifically, you know, in this

0:19:18.520000 --> 0:19:22.320000
 particular case, that would fall under
 PHP and security serialization,

0:19:22.320000 --> 0:19:25.520000
 because it, you know, heavily involved
 object injection is just referring

0:19:25.520000 --> 0:19:28.780000
 to a technique. And you know, the fact
 that you're actually injecting

0:19:28.780000 --> 0:19:33.660000
 it in directly. But that being said,
 that brings us to the end of the

0:19:33.660000 --> 0:19:36.740000
 practical demonstration
 section of this video.

0:19:36.740000 --> 0:19:41.480000
 All right. So that was PHP
 in security serialization.

0:19:41.480000 --> 0:19:44.320000
 And hopefully found it valuable.

0:19:44.320000 --> 0:19:45.580000
 Definitely go through the lab.

0:19:45.580000 --> 0:19:49.900000
 I added a couple of examples in there
 that can, you know, sort of give

0:19:49.900000 --> 0:19:52.880000
 you a better idea of the types of payloads
 you can create or what you

0:19:52.880000 --> 0:19:56.720000
 can do. But with that being said, that's
 going to be it for this video.

0:19:56.720000 --> 0:19:59.180000
 And I will be seeing you
 in the next video.

