WEBVTT

0:00:04.100000 --> 0:00:09.600000
 Hello everyone and welcome to the Service
 Side Attacks course summary.

0:00:09.600000 --> 0:00:12.980000
 In this video we're going to be reviewing
 everything that we've covered

0:00:12.980000 --> 0:00:19.040000
 in this course to firstly identify or
 assess whether you know you indeed

0:00:19.040000 --> 0:00:24.060000
 or we did cover everything that we
 were supposed to cover that we laid

0:00:24.060000 --> 0:00:29.180000
 out in the course overview video where
 I introduced you to the various

0:00:29.180000 --> 0:00:37.320000
 topics both major or key as well as
 the prerequisites and the learning

0:00:37.320000 --> 0:00:41.980000
 outcomes. So we're trying to see whether
 we've covered everything and

0:00:41.980000 --> 0:00:45.660000
 more importantly whether you know what
 you're supposed to know by the

0:00:45.660000 --> 0:00:49.680000
 end of the course and you're able to
 do what I told you you'd be able

0:00:49.680000 --> 0:00:53.920000
 to do by the end of the course and those
 are of course the learning outcomes.

0:00:53.920000 --> 0:00:59.920000
 So let's get started firstly by you know
 getting a recap of the key concepts

0:00:59.920000 --> 0:01:01.760000
 which were fairly simple.

0:01:01.760000 --> 0:01:06.680000
 You know firstly get an understanding of
 the modern web application architecture

0:01:06.680000 --> 0:01:14.240000
 or what you're likely to come across
 as well as some of the more common

0:01:14.240000 --> 0:01:19.640000
 or I should say more prevalent web application
 architecture models from

0:01:19.640000 --> 0:01:22.860000
 layer to microservices etc.

0:01:22.860000 --> 0:01:27.140000
 Secondly, service side request forgery
 so you know the idea there was

0:01:27.140000 --> 0:01:30.960000
 to introduce you to SSRF if you weren't
 already familiar then show you

0:01:30.960000 --> 0:01:36.900000
 how to identify and exploit the vulnerability
 both you know both through

0:01:36.900000 --> 0:01:44.240000
 the use of a basic example or demo
 but also in an advanced form or in

0:01:44.240000 --> 0:01:50.120000
 an advanced example which was practical and
 you know how to chain vulnerabilities.

0:01:50.120000 --> 0:01:55.200000
 And then of course we have insecure
 discerilization and that pretty much

0:01:55.200000 --> 0:02:03.300000
 covers or you know give us an idea
 of what the major topics were which

0:02:03.300000 --> 0:02:05.360000
 I think we covered quite a bit.

0:02:05.360000 --> 0:02:08.500000
 And then of course we have the learning
 outcomes so we're sort of recapping

0:02:08.500000 --> 0:02:16.440000
 them they haven't so we're pretty much
 just using this as a way to benchmark

0:02:16.440000 --> 0:02:20.900000
 you know progress and to assess whether
 you know from my perspective whether

0:02:20.900000 --> 0:02:26.020000
 I covered everything I was supposed
 to to the extent that they correlate

0:02:26.020000 --> 0:02:29.840000
 or align with the learning outcomes
 both from a knowledge perspective

0:02:29.840000 --> 0:02:33.100000
 as well as a skill perspective.

0:02:33.100000 --> 0:02:38.840000
 So firstly understand modern web application
 architecture so by the end

0:02:38.840000 --> 0:02:42.080000
 of this course you should be able to
 describe the components and layers

0:02:42.080000 --> 0:02:45.920000
 of modern web application infrastructure
 architecture and explain the

0:02:45.920000 --> 0:02:49.680000
 role and interaction of the components
 that make up the web application

0:02:49.680000 --> 0:02:55.780000
 and of course we cover that in quite
 a bit of detail so I'm fairly happy

0:02:55.780000 --> 0:03:03.500000
 with the coverage of that or how we
 dealt with that particular outcome.

0:03:03.500000 --> 0:03:07.720000
 Secondly recognize service side vulnerability
 so understand what service

0:03:07.720000 --> 0:03:11.640000
 side attacks are and how they exploit weaknesses
 in the back end infrastructure

0:03:11.640000 --> 0:03:15.040000
 of course that's very closely linked
 with the first learning outcome but

0:03:15.040000 --> 0:03:19.200000
 quite important in understanding you
 know what vulnerabilities exist in

0:03:19.200000 --> 0:03:24.440000
 each layer of you know web applications
 architecture but more importantly

0:03:24.440000 --> 0:03:29.520000
 which ones are more which ones are more
 prevalent to the web server layer

0:03:29.520000 --> 0:03:33.800000
 and application server layer and of
 course in that context or with that

0:03:33.800000 --> 0:03:38.020000
 in mind I think we we covered that
 quite well and I give you you know

0:03:38.020000 --> 0:03:43.500000
 very thorough examples both textual
 and visual using you know that way

0:03:43.500000 --> 0:03:48.700000
 it did by diagrams to explain this
 and then of course we have SSRF so

0:03:48.700000 --> 0:03:52.720000
 by the end of this course you should
 be able to define or you know define

0:03:52.720000 --> 0:03:59.720000
 and explain SSRF its causes so what
 causes the vulnerability the attack

0:03:59.720000 --> 0:04:04.060000
 anatomy so you should understand from
 a technical or theoretical perspective

0:04:04.060000 --> 0:04:09.240000
 you know how a necessary a necessary vulnerability
 is identified and exploited

0:04:09.240000 --> 0:04:14.860000
 as well as the variations right and
 then furthermore by the end of the

0:04:14.860000 --> 0:04:19.560000
 course you should demonstrate you know
 practical exploitation or ability

0:04:19.560000 --> 0:04:24.820000
 to identify and exploit SSRF vulnerabilities
 including blind and advanced

0:04:24.820000 --> 0:04:29.640000
 techniques we're really focused on
 the advanced side in terms of blind

0:04:29.640000 --> 0:04:33.540000
 it was more so theoretical but regardless
 of that fact you know we had

0:04:33.540000 --> 0:04:39.560000
 a basic example and a more advanced
 example or you know lab if you will

0:04:39.560000 --> 0:04:45.180000
 that sort of covered SSRF at least in
 my opinion quite well so you know

0:04:45.180000 --> 0:04:49.860000
 that particular learning outcome deals
 with both knowledge and skill so

0:04:49.860000 --> 0:04:53.280000
 I think we covered that quite well
 and then of course we have insecure

0:04:53.280000 --> 0:04:58.080000
 deserialization so by the end of the
 course you should be able to explain

0:04:58.080000 --> 0:05:01.620000
 what insecure deserialization is and
 how it can lead to vulnerabilities

0:05:01.620000 --> 0:05:06.180000
 like RCE for example but the key there
 is to understand what serialization

0:05:06.180000 --> 0:05:11.700000
 is what deserialization is why serialization
 is performed in web applications

0:05:11.700000 --> 0:05:17.980000
 and more importantly how these types
 of or how insecure deserialization

0:05:17.980000 --> 0:05:23.620000
 can lead to you know vulnerabilities
 like RCE and then of course finally

0:05:23.620000 --> 0:05:29.760000
 exploit language specific deserialization
 vulnerabilities so by the end

0:05:29.760000 --> 0:05:33.780000
 of the course you should be able to
 identify and exploit deserialization

0:05:33.780000 --> 0:05:37.980000
 vulnerabilities in Java PHP and .NET applications
 or I should say frameworks

0:05:37.980000 --> 0:05:43.660000
 but again we covered that in quite a bit
 of detail all of which was practical

0:05:43.660000 --> 0:05:50.500000
 which you know was augmented by the
 technical or theoretical aspects or

0:05:50.500000 --> 0:05:55.340000
 you know the sections of the videos
 but the bottom line is we covered

0:05:55.340000 --> 0:06:01.520000
 each of these we covered exploit you know
 language specific deserialization

0:06:01.520000 --> 0:06:07.320000
 vulnerabilities Java PHP and .NET so
 I think we covered that quite well

0:06:07.320000 --> 0:06:13.100000
 and those are the linear outcomes overall
 I think we did well both you

0:06:13.100000 --> 0:06:18.560000
 guys as well as myself I think based
 on what I had laid out you know and

0:06:18.560000 --> 0:06:22.600000
 this is exactly what was in the course
 overview nothing has changed and

0:06:22.600000 --> 0:06:26.500000
 what we ended up doing I think in many
 aspects we sort of went over what

0:06:26.500000 --> 0:06:31.880000
 we were supposed to cover but that's
 always a good thing so that brings

0:06:31.880000 --> 0:06:36.020000
 us now to you know some real world
 applications of what you've learned

0:06:36.020000 --> 0:06:40.080000
 in this course because it's not enough
 for me to say that you know they're

0:06:40.080000 --> 0:06:43.600000
 the linear outcomes and you know you
 should know this and you should be

0:06:43.600000 --> 0:06:50.400000
 able to do that it's how this course
 has improved you as a web application

0:06:50.400000 --> 0:06:55.680000
 penetration tester and where these
 where this knowledge and skills can

0:06:55.680000 --> 0:07:00.700000
 be applied so or where they're relevant
 so firstly the reason this is

0:07:00.700000 --> 0:07:04.660000
 this course is important or what you've
 learned is important is the prevalence

0:07:04.660000 --> 0:07:09.560000
 in real world applications right what am
 I referring to here well vulnerabilities

0:07:09.560000 --> 0:07:14.080000
 like SSRF you know is commonly found
 in applications integrating third

0:07:14.080000 --> 0:07:19.100000
-party APIs or processing user supplied
 URLs and has been highlighted in

0:07:19.100000 --> 0:07:22.600000
 vulnerability disclosures affecting
 major cloud providers you know like

0:07:22.600000 --> 0:07:26.880000
 AWS Google cloud there've been quite
 a few breaches of late that have

0:07:26.880000 --> 0:07:32.200000
 been as a direct result of a SSRF vulnerability
 which was later which

0:07:32.200000 --> 0:07:39.860000
 was later extended you know into which was
 later extended by other vulnerabilities

0:07:39.860000 --> 0:07:45.460000
 as we saw in the advanced or SSRF to RSE
 video where you chain vulnerabilities

0:07:45.460000 --> 0:07:54.500000
 and of course it goes without saying
 that the ORSP 2021 SSRF is actually

0:07:54.500000 --> 0:08:00.220000
 classified as a major vulnerability category
 it is ranked last but regardless

0:08:00.220000 --> 0:08:13.660000
 of the fact it is quite you know it
 secondly you know so why this course

0:08:13.660000 --> 0:08:17.800000
 or what you've learned is so important really
 revolves around the sophisticated

0:08:17.800000 --> 0:08:22.120000
 exploitation techniques that were demonstrated
 so this course provides

0:08:22.120000 --> 0:08:26.180000
 you with the skills required to facilitate
 advanced attacks that are rarely

0:08:26.180000 --> 0:08:30.580000
 stand alone as you as we you know we've
 been able to see or go through

0:08:30.580000 --> 0:08:35.600000
 in this course and you know often used
 as entry points for advanced attack

0:08:35.600000 --> 0:08:40.120000
 chains for example you know this is
 not to say that we covered this very

0:08:40.120000 --> 0:08:45.180000
 example but this is one of them so you
 know leveraging SSRF to gain access

0:08:45.180000 --> 0:08:50.800000
 or to communicate with the internal API
 and then utilizing that to elevate

0:08:50.800000 --> 0:08:55.660000
 your privileges so you know these advanced
 attack chains that involve

0:08:55.660000 --> 0:09:00.280000
 exploitation not just of one vulnerability
 but in order to get your foot

0:09:00.280000 --> 0:09:04.620000
 in the door you in this particular case
 would be exploitative vulnerability

0:09:04.620000 --> 0:09:09.540000
 like SSRF or deserialization that can
 then lead to other things but the

0:09:09.540000 --> 0:09:14.260000
 bottom line is that these are you know
 vulnerabilities that exist or are

0:09:14.260000 --> 0:09:23.480000
 native I should say to the application
 server layer so that's the second

0:09:23.480000 --> 0:09:27.960000
 one and then of course I think this
 is quite important you know custom

0:09:27.960000 --> 0:09:33.660000
 tooling this course provides you with
 practical knowledge and experience

0:09:33.660000 --> 0:09:37.240000
 in developing custom payloads and tools
 that are required for the successful

0:09:37.240000 --> 0:09:41.780000
 exploitation of vulnerabilities like
 for example insecure deserialization

0:09:41.780000 --> 0:09:47.340000
 of course we went beyond that we're taking
 a look at SSRF etc but I think

0:09:47.340000 --> 0:09:51.620000
 we covered quite a bit of you know
 custom resource development if you

0:09:51.620000 --> 0:09:55.360000
 will you know generating payloads to
 meet our requirements or to meet

0:09:55.360000 --> 0:10:01.480000
 our needs so on and so forth so these
 are you know what I would consider

0:10:01.480000 --> 0:10:06.120000
 to be the key takeaways in terms of your
 skill set as a web app pen tester

0:10:06.120000 --> 0:10:09.480000
 from this course and hopefully you concur
 of course there's many others

0:10:09.480000 --> 0:10:14.820000
 that I could have listed but if I was
 to if I was to you know stick to

0:10:14.820000 --> 0:10:23.940000
 the core of what I believe are the key
 takeaways or you know what is to

0:10:23.940000 --> 0:10:29.040000
 be a memory primarily so what are the
 next steps what are my recommendations

0:10:29.040000 --> 0:10:34.400000
 to you in terms of what you should do
 after this course not just in relation

0:10:34.400000 --> 0:10:39.700000
 to the certificate or the certification
 but also widely speaking you know

0:10:39.700000 --> 0:10:44.840000
 in terms of your career or you know this
 particular type of vulnerabilities

0:10:44.840000 --> 0:10:53.760000
 specifically so first thing I would
 recommend you do is to extend your

0:10:53.760000 --> 0:10:59.280000
 vulnerabilities like ssti I would also
 recommend that you practice chaining

0:10:59.280000 --> 0:11:03.100000
 vulnerabilities for real world scenarios
 such as you know which we did

0:11:03.100000 --> 0:11:07.000000
 but take a look at a few other examples
 maybe even in bug bounty reports

0:11:07.000000 --> 0:11:12.300000
 that essentially revolve or involve combining
 SSRF with privilege escalation

0:11:12.300000 --> 0:11:17.420000
 for example or insecure discerilization
 with remote code execution so

0:11:17.420000 --> 0:11:22.420000
 I want you to get a feel for some of
 the more advanced attack chains or

0:11:22.420000 --> 0:11:26.280000
 attacks that involve exploitation of
 not just one but you know more than

0:11:26.280000 --> 0:11:31.620000
 one server side vulnerability that
 can then give you access to some of

0:11:31.620000 --> 0:11:36.740000
 the internal mechanisms or
 services the APIs etc.

0:11:36.740000 --> 0:11:41.620000
 I would also recommend that you practice
 building custom payloads for

0:11:41.620000 --> 0:11:45.900000
 complex environments such as deserialization
 in less documented frameworks

0:11:45.900000 --> 0:11:52.760000
 we sort of focused on the primary
 ones you know PHP, Java, .NET etc.

0:11:52.760000 --> 0:11:56.760000
 but I would also recommend exploring you
 know some of the other less documented

0:11:56.760000 --> 0:12:03.580000
 frameworks and then finally you know
 really probably the best piece of

0:12:03.580000 --> 0:12:07.060000
 advice I can give you is to start applying
 your skills to bug bounty programs

0:12:07.060000 --> 0:12:13.160000
 such as hacker one bug crowd more importantly
 read reports on SSRF vulnerabilities

0:12:13.160000 --> 0:12:19.140000
 that were discovered how they were
 exploited what type of access they

0:12:19.140000 --> 0:12:25.700000
 you know essentially led to or ended
 up you know providing the attack

0:12:25.700000 --> 0:12:27.940000
 after exploitation etc.

0:12:27.940000 --> 0:12:31.960000
 I would also recommend that you practice
 creating detailed reports specific

0:12:31.960000 --> 0:12:35.700000
 I would say in general but in this
 in the case of this course specific

0:12:35.700000 --> 0:12:40.960000
 to SSRF deserialization why is that
 important why is reading and writing

0:12:40.960000 --> 0:12:46.060000
 reports important well it's important
 because it gives you a feel not

0:12:46.060000 --> 0:12:52.180000
 just for you know the methodology used
 by other web app investors and

0:12:52.180000 --> 0:12:57.780000
 you know bug bounty hunters like yourself
 but it also gives you an understanding

0:12:57.780000 --> 0:13:03.320000
 of the nomenclature that is used in reporting
 these types of vulnerabilities

0:13:03.320000 --> 0:13:10.720000
 how to report them correctly how to
 you know how to utilize or what POC

0:13:10.720000 --> 0:13:17.440000
 to utilize in different cases so on and
 so forth and I would also recommend

0:13:17.440000 --> 0:13:23.340000
 that you actually learn a little bit more
 about remediating these vulnerabilities

0:13:23.340000 --> 0:13:34.400000
 because you know any good report regardless
 whether it's a web you know

0:13:34.400000 --> 0:13:40.940000
 extremely extremely useful and it shows
 a lot of you know it tells a client

0:13:40.940000 --> 0:13:45.420000
 or a company a lot about you and your
 professionalism when you actually

0:13:45.420000 --> 0:13:50.760000
 propose actionable remediation steps
 for server-side vulnerabilities you

0:13:50.760000 --> 0:13:53.940000
 know specific to this course but in
 general I always sort of maintain

0:13:53.940000 --> 0:13:58.640000
 that next step as you've probably seen
 in other courses in this learning

0:13:58.640000 --> 0:14:04.640000
 path and that is really take a look
 or focus or turn your attention to

0:14:04.640000 --> 0:14:13.600000
 the vulnerabilities covered in this course
 and how they are how they work

0:14:13.600000 --> 0:14:17.620000
 or how they've been exploited in real
 world applications and the best

0:14:17.620000 --> 0:14:21.920000
 way you can do that is by reading reports
 you know then performing hunting

0:14:21.920000 --> 0:14:26.240000
 yourself improving your methodology understanding
 a little bit more about

0:14:26.240000 --> 0:14:31.460000
 again what you're likely to to come across
 how to test for let's say blind

0:14:31.460000 --> 0:14:39.440000
 SSRF etc so that that is what I can
 say or these are my recommendations

0:14:39.440000 --> 0:14:44.400000
 you know for you in terms of what you
 should do next and of course this

0:14:44.400000 --> 0:14:49.360000
 is just localized to this course but
 this is what I recommend you focus

0:14:49.360000 --> 0:14:53.800000
 on with that being said that brings
 us to the end of this course I would

0:14:53.800000 --> 0:14:58.000000
 like to thank you very much for making
 it this far if you have hopefully

0:14:58.000000 --> 0:15:02.860000
 you found value in the course you know
 we'll obviously be working to improve

0:15:02.860000 --> 0:15:08.480000
 the course over time and add in a few
 more goodies and labs etc but I

0:15:08.480000 --> 0:15:13.020000
 really enjoyed developing this course
 and hopefully you enjoyed watching

0:15:13.020000 --> 0:15:17.240000
 it and found value in it definitely
 you know go through the labs more

0:15:17.240000 --> 0:15:27.460000
 than just once keep on practicing and
 follow my namely surface side attacks

0:15:27.460000 --> 0:15:33.280000
 with that being said I will be I bid
 you farewell and hopefully I'll be

0:15:33.280000 --> 0:15:34.540000
 seeing you in the next course.

