1
00:00:06,510 --> 00:00:08,100
- In this lesson, 8.5,

2
00:00:08,100 --> 00:00:11,250
we're gonna focus in
on application attacks.

3
00:00:11,250 --> 00:00:13,470
Now the objective of an application attack

4
00:00:13,470 --> 00:00:15,990
is to either manipulate the input,

5
00:00:15,990 --> 00:00:19,140
what is sent to the
processor, or the output.

6
00:00:19,140 --> 00:00:20,100
So one of those three,

7
00:00:20,100 --> 00:00:23,673
the input, what's
processed, or the output.

8
00:00:25,260 --> 00:00:29,010
So we want to always be
validating what is being input,

9
00:00:29,010 --> 00:00:31,020
what is being sent to the processor,

10
00:00:31,020 --> 00:00:33,000
or what's being output.

11
00:00:33,000 --> 00:00:35,460
The validation being
the process of enforcing

12
00:00:35,460 --> 00:00:39,480
and verifying the desired level
of compliance at all stages.

13
00:00:39,480 --> 00:00:43,230
Input validation is the process
of properly validating input

14
00:00:43,230 --> 00:00:45,300
from the client or the environment.

15
00:00:45,300 --> 00:00:48,030
And output validation is used to control

16
00:00:48,030 --> 00:00:50,220
what's returned to the screen.

17
00:00:50,220 --> 00:00:54,360
Application attacks can be very
powerful and very dangerous

18
00:00:54,360 --> 00:00:57,060
and yet there are some really simple

19
00:00:57,060 --> 00:00:58,590
straightforward things that we can do

20
00:00:58,590 --> 00:01:01,050
like input and output validation

21
00:01:01,050 --> 00:01:05,103
which will incredibly diminish
the success of an attack.

22
00:01:07,230 --> 00:01:10,290
So let's look at four
common application attacks.

23
00:01:10,290 --> 00:01:14,580
Injection, cross-site scripting,
cross-site request forgery,

24
00:01:14,580 --> 00:01:16,830
and directory traversal.

25
00:01:16,830 --> 00:01:19,860
An injection attack tricks an application

26
00:01:19,860 --> 00:01:23,460
into including unintended
commands in the data

27
00:01:23,460 --> 00:01:24,870
that's sent to an interpreter.

28
00:01:24,870 --> 00:01:27,540
An interpreter's just a fancy
way of saying the processor.

29
00:01:27,540 --> 00:01:31,860
And we see injection attacks
against operating systems,

30
00:01:31,860 --> 00:01:34,380
LDAP, lightweight
directory access protocol,

31
00:01:34,380 --> 00:01:36,660
and SQL databases.

32
00:01:36,660 --> 00:01:40,110
A cross-site scripting
attack known as an XSS attack

33
00:01:40,110 --> 00:01:42,300
is the injection of malicious code either

34
00:01:42,300 --> 00:01:45,630
into a web application or backend database

35
00:01:45,630 --> 00:01:47,970
that will execute scripts ultimately

36
00:01:47,970 --> 00:01:49,710
in the victim's browser.

37
00:01:49,710 --> 00:01:52,290
Now, there are two forms of a
cross-site scripting attack.

38
00:01:52,290 --> 00:01:54,090
There is persistent and reflective,

39
00:01:54,090 --> 00:01:56,283
and I'll go into that
detail in just a sec.

40
00:01:57,450 --> 00:01:59,460
Then we have a cross-site request forgery,

41
00:01:59,460 --> 00:02:01,620
known as a CSRF attack,

42
00:02:01,620 --> 00:02:03,180
which tricks a web browser into

43
00:02:03,180 --> 00:02:06,690
executing a malicious
action on a trusted site

44
00:02:06,690 --> 00:02:09,060
that the users already authenticated.

45
00:02:09,060 --> 00:02:11,310
The CSRF exploits that trust

46
00:02:11,310 --> 00:02:13,743
that the site has in the user's browser.

47
00:02:14,580 --> 00:02:17,113
Our fourth attack is
a directory traversal.

48
00:02:17,113 --> 00:02:20,760
A directory traversal attack
uses specially crafted input

49
00:02:20,760 --> 00:02:24,000
that includes dot dot slash sequences

50
00:02:24,000 --> 00:02:27,030
to traverse a directory and access files

51
00:02:27,030 --> 00:02:30,300
or directories that are
outside of the intended scope.

52
00:02:30,300 --> 00:02:31,320
Now down on the bottom here,

53
00:02:31,320 --> 00:02:34,320
you can see a link to an owasp site.

54
00:02:34,320 --> 00:02:37,290
Owasp has a really good
article and an explanation

55
00:02:37,290 --> 00:02:38,610
of a directory traversal.

56
00:02:38,610 --> 00:02:40,500
So if you're interested and
you want more information,

57
00:02:40,500 --> 00:02:41,703
that's the place to go.

58
00:02:43,230 --> 00:02:45,390
So let's go through each
one of those attacks.

59
00:02:45,390 --> 00:02:47,070
We're gonna go through
an injection attack.

60
00:02:47,070 --> 00:02:48,330
We're gonna go through a persistent

61
00:02:48,330 --> 00:02:50,400
and reflective cross-site scripting,

62
00:02:50,400 --> 00:02:53,673
and we'll go through a cross-site
request forgery attack.

63
00:02:55,140 --> 00:02:56,880
So here's what I want you to imagine.

64
00:02:56,880 --> 00:02:59,310
I want you to imagine
that you're an attacker.

65
00:02:59,310 --> 00:03:03,450
And what you wanna do is you
wanna extract some information

66
00:03:03,450 --> 00:03:05,910
from an organization's database.

67
00:03:05,910 --> 00:03:08,670
And you're thinking,
okay how do I do that?

68
00:03:08,670 --> 00:03:10,170
Well you as the attacker say,

69
00:03:10,170 --> 00:03:12,240
hmm let me go look at their website.

70
00:03:12,240 --> 00:03:14,580
Are there any forms on their website?

71
00:03:14,580 --> 00:03:15,960
And like wow, yeah, there is.

72
00:03:15,960 --> 00:03:18,690
There's a form to request a white paper.

73
00:03:18,690 --> 00:03:20,040
Well, that would be interesting

74
00:03:20,040 --> 00:03:22,740
because anybody who's
requesting the white paper is

75
00:03:22,740 --> 00:03:25,620
either a client or maybe
wants to be a client.

76
00:03:25,620 --> 00:03:27,870
And if I'm the attacker and I can

77
00:03:27,870 --> 00:03:30,570
get that potential client
information out of there,

78
00:03:30,570 --> 00:03:33,600
I can use that in a
social engineering attack

79
00:03:33,600 --> 00:03:35,670
going after those clients.

80
00:03:35,670 --> 00:03:37,650
So I look at the form,
you know the website,

81
00:03:37,650 --> 00:03:39,210
and I say yep, there's a form, right?

82
00:03:39,210 --> 00:03:41,790
That form to request the white paper.

83
00:03:41,790 --> 00:03:43,980
Now maybe the form is just very simple.

84
00:03:43,980 --> 00:03:46,530
It's saying what's your
first name, your last name,

85
00:03:46,530 --> 00:03:48,870
your phone number, and your postal code.

86
00:03:48,870 --> 00:03:50,910
Well, if there was input validation

87
00:03:50,910 --> 00:03:52,320
the first name might be restricted

88
00:03:52,320 --> 00:03:54,810
to let's say, 16 characters all alpha.

89
00:03:54,810 --> 00:03:59,250
Maybe the last name is 18
or 20 characters, all alpha.

90
00:03:59,250 --> 00:04:01,920
The phone number is
probably a country code,

91
00:04:01,920 --> 00:04:04,770
an area code, three
numbers, and four numbers,

92
00:04:04,770 --> 00:04:06,000
but all numeric.

93
00:04:06,000 --> 00:04:07,950
And maybe a postal code is either

94
00:04:07,950 --> 00:04:12,180
five or maybe with a dash
eight and it's alpha numeric,

95
00:04:12,180 --> 00:04:13,800
but no special symbols.

96
00:04:13,800 --> 00:04:16,470
Maybe it's also even asking
for an email address.

97
00:04:16,470 --> 00:04:19,530
So an email address we
know could be fairly long.

98
00:04:19,530 --> 00:04:20,850
It could be alpha numeric,

99
00:04:20,850 --> 00:04:22,560
but the only special characters allowed

100
00:04:22,560 --> 00:04:25,290
should be a period and an at sign.

101
00:04:25,290 --> 00:04:28,590
So with input validation,
we put those parameters,

102
00:04:28,590 --> 00:04:31,200
we mean the developers
would put those parameters

103
00:04:31,200 --> 00:04:33,030
in the form and say that's the only thing

104
00:04:33,030 --> 00:04:34,833
you can put in that form.

105
00:04:36,390 --> 00:04:38,310
But the attacker goes
to the form and says,

106
00:04:38,310 --> 00:04:40,980
I wonder if they have input validation.

107
00:04:40,980 --> 00:04:42,360
Turns out they don't.

108
00:04:42,360 --> 00:04:44,970
So instead of putting in a
first name or a last name

109
00:04:44,970 --> 00:04:47,250
or any of the other fields
what they're supposed to be,

110
00:04:47,250 --> 00:04:49,080
the attacker sends the attack string,

111
00:04:49,080 --> 00:04:52,950
in this case just a SQL
query in the form data.

112
00:04:52,950 --> 00:04:55,650
Well that information gets forwarded

113
00:04:55,650 --> 00:04:56,970
to the backend database.

114
00:04:56,970 --> 00:04:59,430
So the application
forwards that attack string

115
00:04:59,430 --> 00:05:01,080
to the backend database.

116
00:05:01,080 --> 00:05:03,390
The backend trusts the front end.

117
00:05:03,390 --> 00:05:05,730
So the database runs the query

118
00:05:05,730 --> 00:05:08,910
and returns the results to
the front end application,

119
00:05:08,910 --> 00:05:10,950
which might be a list of everyone

120
00:05:10,950 --> 00:05:12,990
who has requested that white paper.

121
00:05:12,990 --> 00:05:15,240
Now, if there was output validation,

122
00:05:15,240 --> 00:05:16,980
the only thing the
application could return

123
00:05:16,980 --> 00:05:18,498
to the user would be,

124
00:05:18,498 --> 00:05:20,730
thanks for requesting the white paper,

125
00:05:20,730 --> 00:05:24,180
or information not complete,

126
00:05:24,180 --> 00:05:26,100
or please enter again, right?

127
00:05:26,100 --> 00:05:27,900
Just a few very discreet things.

128
00:05:27,900 --> 00:05:29,760
But if there's no output validation,

129
00:05:29,760 --> 00:05:32,490
whatever the database
returned to the application

130
00:05:32,490 --> 00:05:34,680
can be returned to the user,

131
00:05:34,680 --> 00:05:36,960
or in this case to you, our attacker.

132
00:05:36,960 --> 00:05:39,900
So the application presents
the results to the attacker,

133
00:05:39,900 --> 00:05:42,510
and that is a very simple illustration

134
00:05:42,510 --> 00:05:44,493
of a SQL injection attack.

135
00:05:45,810 --> 00:05:47,640
Next let's look at cross-site scripting.

136
00:05:47,640 --> 00:05:49,320
Cross-site scripting has two versions,

137
00:05:49,320 --> 00:05:51,810
persistent and reflective.

138
00:05:51,810 --> 00:05:54,210
In a persistent cross-site scripting,

139
00:05:54,210 --> 00:05:55,830
the goal will be for the attacker

140
00:05:55,830 --> 00:05:58,080
to identify a vulnerable webpage

141
00:05:58,080 --> 00:05:59,940
that their victims go to,

142
00:05:59,940 --> 00:06:03,120
because ultimately what
they want is a script

143
00:06:03,120 --> 00:06:06,420
that's going to execute
in the victim's browser.

144
00:06:06,420 --> 00:06:10,470
So the attacker is going to
identify a vulnerable webpage.

145
00:06:10,470 --> 00:06:13,050
The attacker will inject
a malicious string

146
00:06:13,050 --> 00:06:15,663
or script into that webpage.

147
00:06:16,500 --> 00:06:18,420
The victim clicks on the URL

148
00:06:18,420 --> 00:06:22,140
and injects the script into the webpage.

149
00:06:22,140 --> 00:06:26,100
The webpage sends that script
right back to the victim.

150
00:06:26,100 --> 00:06:28,020
The script downloads and executes

151
00:06:28,020 --> 00:06:30,690
in the victim's browser and voila,

152
00:06:30,690 --> 00:06:32,970
the victim's system is compromised.

153
00:06:32,970 --> 00:06:36,840
The once again, right, if
we had input validation,

154
00:06:36,840 --> 00:06:39,120
the attacker in both the reflective

155
00:06:39,120 --> 00:06:41,460
and the persistent would
never be allowed to

156
00:06:41,460 --> 00:06:45,060
inject that script into the webpage.

157
00:06:45,060 --> 00:06:47,190
Next up is CSRF,

158
00:06:47,190 --> 00:06:49,470
or cross site request forgery.

159
00:06:49,470 --> 00:06:51,330
In this case, the attacker is going

160
00:06:51,330 --> 00:06:53,400
to forge a malicious request

161
00:06:53,400 --> 00:06:55,830
and embed it in a hyperlink with the goal

162
00:06:55,830 --> 00:06:59,433
of exploiting the trust that
a site has in a browser.

163
00:07:00,750 --> 00:07:02,850
So the attacker is going
to send the request

164
00:07:02,850 --> 00:07:05,643
to a user logged into a targeted website.

165
00:07:06,690 --> 00:07:08,190
The user clicks on the hyperlink

166
00:07:08,190 --> 00:07:10,470
which sends a request
to the targeted website.

167
00:07:10,470 --> 00:07:13,260
Now how could that happen if
they're already logged in?

168
00:07:13,260 --> 00:07:14,670
Well, probably in a popup

169
00:07:14,670 --> 00:07:16,740
would be one of the most common ways,

170
00:07:16,740 --> 00:07:18,900
the user is already logged in.

171
00:07:18,900 --> 00:07:20,280
A popup occurs,

172
00:07:20,280 --> 00:07:22,200
click here to do our survey.

173
00:07:22,200 --> 00:07:23,520
Say yes or no.

174
00:07:23,520 --> 00:07:24,960
They click that, right?

175
00:07:24,960 --> 00:07:28,620
That sends the request
to the targeted website.

176
00:07:28,620 --> 00:07:30,480
The website validates
the request is coming

177
00:07:30,480 --> 00:07:32,610
from the trusted sender.

178
00:07:32,610 --> 00:07:36,090
The website executes whatever
the malicious request is.

179
00:07:36,090 --> 00:07:40,530
And again, we've got a compromise
or a malicious outcome.

180
00:07:40,530 --> 00:07:42,930
So it's important that you can recognize

181
00:07:42,930 --> 00:07:45,300
injection, cross-site scripting,

182
00:07:45,300 --> 00:07:48,450
cross-site request forgery,
and directory traversal.

183
00:07:48,450 --> 00:07:52,410
And recognize that really the
foundation of all of those

184
00:07:52,410 --> 00:07:55,200
is having weak or insufficient

185
00:07:55,200 --> 00:07:59,250
or even non-existent input
and output validation.

186
00:07:59,250 --> 00:08:00,630
All right that my friends takes us

187
00:08:00,630 --> 00:08:02,250
to a three second challenge.

188
00:08:02,250 --> 00:08:03,630
Are you ready?

189
00:08:03,630 --> 00:08:05,970
The process of validating
the output of a process

190
00:08:05,970 --> 00:08:08,073
before it is returned to the recipient.

191
00:08:09,150 --> 00:08:10,833
One, two, three.

192
00:08:12,120 --> 00:08:14,103
That's gonna be output validation.

193
00:08:15,540 --> 00:08:16,373
Number two.

194
00:08:16,373 --> 00:08:19,773
An attack that uses
dot-dot-slash sequences.

195
00:08:21,030 --> 00:08:22,650
One, two, three.

196
00:08:22,650 --> 00:08:24,753
That's gonna be a directory traversal.

197
00:08:26,100 --> 00:08:28,440
Number three, injection
of a malicious code

198
00:08:28,440 --> 00:08:31,110
into a vulnerable web
application that will execute

199
00:08:31,110 --> 00:08:32,673
in a victim's browser.

200
00:08:33,600 --> 00:08:35,463
One, two, three.

201
00:08:36,510 --> 00:08:38,910
That's gonna be persistent
cross-site scripting.

202
00:08:40,350 --> 00:08:41,430
Number four.

203
00:08:41,430 --> 00:08:44,370
Tricking an application into
including unauthorized commands

204
00:08:44,370 --> 00:08:46,353
in the data sent to an interpreter.

205
00:08:47,460 --> 00:08:49,950
One, two, three.

206
00:08:49,950 --> 00:08:51,900
That's injection.

207
00:08:51,900 --> 00:08:53,490
And lastly, number five.

208
00:08:53,490 --> 00:08:56,400
Injection of malicious
code into a web application

209
00:08:56,400 --> 00:08:58,440
that initiates at the client side

210
00:08:58,440 --> 00:09:02,190
and ultimately executes
in the victim's browser.

211
00:09:02,190 --> 00:09:04,830
One, two, three.

212
00:09:04,830 --> 00:09:08,010
And that's gonna be reflective
cross-site scripting.

213
00:09:08,010 --> 00:09:10,680
All right, let's do a
security-in-action together.

214
00:09:10,680 --> 00:09:13,383
Put that knowledge into
play about injection.

215
00:09:14,370 --> 00:09:15,930
The results of a security assessment

216
00:09:15,930 --> 00:09:18,180
for your organization's
pre-production website

217
00:09:18,180 --> 00:09:20,310
documents injection flaws.

218
00:09:20,310 --> 00:09:22,230
The outsourced website developers

219
00:09:22,230 --> 00:09:23,640
are minimizing the finding.

220
00:09:23,640 --> 00:09:25,410
Ah, not such a big deal.

221
00:09:25,410 --> 00:09:27,600
The marketing department's
pushing really hard

222
00:09:27,600 --> 00:09:30,480
to get this site published ASAP.

223
00:09:30,480 --> 00:09:33,540
The website owner,
claims she has no budget

224
00:09:33,540 --> 00:09:34,860
to address any problems.

225
00:09:34,860 --> 00:09:37,260
Matter of fact maybe
they're already over budget.

226
00:09:37,260 --> 00:09:38,790
Executive management turns to you

227
00:09:38,790 --> 00:09:40,500
and is asking you for guidance.

228
00:09:40,500 --> 00:09:42,420
What are you gonna tell them?

229
00:09:42,420 --> 00:09:45,150
So we got this security assessment done

230
00:09:45,150 --> 00:09:46,920
on this pre-production website.

231
00:09:46,920 --> 00:09:48,870
So the website's not out there yet.

232
00:09:48,870 --> 00:09:52,740
And it says, oh man you
got some injection flaws.

233
00:09:52,740 --> 00:09:55,170
So we go to the developers
and the developers say,

234
00:09:55,170 --> 00:09:56,760
oh, nah that's not a big deal.

235
00:09:56,760 --> 00:09:59,190
They're really minimizing the finding.

236
00:09:59,190 --> 00:10:01,320
But the marketing department
says, listen, we're late.

237
00:10:01,320 --> 00:10:03,330
We gotta get this out ASAP.

238
00:10:03,330 --> 00:10:05,850
The website owner says I've got no money,

239
00:10:05,850 --> 00:10:10,260
I have no budget whatsoever
to fix this problem.

240
00:10:10,260 --> 00:10:12,240
Management says what do we do?

241
00:10:12,240 --> 00:10:14,130
So put me on pause, jot down some notes,

242
00:10:14,130 --> 00:10:16,630
come on back with your
response when you're ready.

243
00:10:18,240 --> 00:10:21,300
Well, injection is a really
serious flaw that can result

244
00:10:21,300 --> 00:10:24,180
in unauthorized access, data exfiltration,

245
00:10:24,180 --> 00:10:25,620
and data corruption.

246
00:10:25,620 --> 00:10:28,380
And the business impact
can be really significant.

247
00:10:28,380 --> 00:10:31,500
Reputational, financial,
and compliance damage.

248
00:10:31,500 --> 00:10:33,780
So we wanna start with really emphasizing

249
00:10:33,780 --> 00:10:34,953
that to management.

250
00:10:36,270 --> 00:10:37,650
It is the responsibility

251
00:10:37,650 --> 00:10:41,160
of the website developers
to deliver secure code.

252
00:10:41,160 --> 00:10:43,530
It's sort of inherent in the relationship.

253
00:10:43,530 --> 00:10:45,900
But hopefully this was
specified in the contract

254
00:10:45,900 --> 00:10:48,120
because if it wasn't they perhaps are

255
00:10:48,120 --> 00:10:49,720
gonna charge you more to fix it.

256
00:10:51,120 --> 00:10:52,530
The bottom line,

257
00:10:52,530 --> 00:10:55,530
doesn't matter that we're
behind time or over budget.

258
00:10:55,530 --> 00:10:57,630
The site should definitely not go live

259
00:10:57,630 --> 00:10:59,670
until this flaw is addressed.

260
00:10:59,670 --> 00:11:04,260
Again, because the business
impact of unauthorized access,

261
00:11:04,260 --> 00:11:08,310
data exfiltration and data
corruption is really significant.

262
00:11:08,310 --> 00:11:11,010
Reputational damage, financial damage,

263
00:11:11,010 --> 00:11:13,080
and potentially compliance damage.

264
00:11:13,080 --> 00:11:14,850
So you wanna do everything you can

265
00:11:14,850 --> 00:11:18,300
to convince executive management
to say absolutely not.

266
00:11:18,300 --> 00:11:19,620
And you probably wanna point out

267
00:11:19,620 --> 00:11:21,750
that wait a minute, we went through

268
00:11:21,750 --> 00:11:23,880
the process of doing a security assessment

269
00:11:23,880 --> 00:11:25,860
just to find out these kind of things.

270
00:11:25,860 --> 00:11:28,650
Why wouldn't we pay attention

271
00:11:28,650 --> 00:11:30,510
to what our security assessment is saying?

272
00:11:30,510 --> 00:11:33,330
That's the reason we did
a security assessment.

273
00:11:33,330 --> 00:11:36,960
So having this very convincing
conversation or discussion,

274
00:11:36,960 --> 00:11:38,960
definitely my friend security-in-action.

275
00:11:40,200 --> 00:11:41,910
You know it's not a very big word cloud

276
00:11:41,910 --> 00:11:42,930
but there's a lot here.

277
00:11:42,930 --> 00:11:45,330
And make sure that you
really understand each

278
00:11:45,330 --> 00:11:46,980
of these type of attacks.

279
00:11:46,980 --> 00:11:48,930
When you're ready, come on
over to the next lesson.

280
00:11:48,930 --> 00:11:50,130
I'll be waiting for you.
