0:00 Music 0:08 There are different attack chains related to attack on humans. 0:15 So there are technical and human attacks, obviously. 0:21 So technical is when you're hacking Wi-Fi, you're hacking LAN, you are getting the software information, system information, and much more. 0:30 But for human, you can collect information from LinkedIn, Twitter, social media. 0:35 You can do OSINT and a lot of other stuff. 0:38 So what is OSINT, right? 0:42 Ossent. 0:43 Let me show you what is Ossent. 0:49 What exactly is interesting for us? 0:54 Let's analyze, for example, just full company. 1:02 So like this. 1:05 So now I am running 112 audits against website. 1:14 112 audits. 1:16 You can do it manually or you can do it automatically. 1:20 So here, this is example. 1:23 We went to the website, which is called urskan.io. 1:31 And that website is providing us with information about all the IPs which we used. 1:40 It is basically showing us the technologies which we used. 1:46 Here you can also see the information, but all the stuff you can collect. 1:52 From sub tabs here if they will pop up here. 1:58 But in reality, you can just see. 2:02 This is a subdomain which was collected. 2:05 So how this data is collected? 2:07 This data is collected from the third party websites. 2:11 So it goes to Google and collects the information. 2:14 It goes to the Wayback Machine, which is on this website. 2:20 Let me just show you so you understand. 2:23 Way back machine. 2:24 Way back machine. 2:30 Way back. 2:30 Machine. 2:31 Way back machine. 2:35 So you just go here, you input your website, and you can see how it looked before. 2:46 And why do we need this information? 2:48 We need this information because potentially you can collect information which is not there anymore. 2:58 This is historical data. 3:00 So you can just click, for example, how it looks maybe. 3:08 One month ago. 3:10 You see something is wrong with the Wayback Machine, but usually this website works. 3:18 Yeah, now I can click and it will show me how this website works. 3:25 So, yeah. 3:28 It will show that stuff. 3:30 What else interesting? 3:31 You can also collect the DNS information, information about where this website was hosted. 3:41 Also, this is very interesting stuff. 3:44 It went to GitHub and collected me all the names. 3:51 Related to a company name. 3:54 So it assumed that if I'm using CQR with company, it should go to GitHub. 4:01 and find that specific name. 4:04 So let me show you some real example. 4:10 It will be secret. 4:15 Password. 4:17 I'll just show you. 4:18 So potentially, you can go to code and you can search the name of your company and put the secret. 4:27 So if they have the GitHub repo, you will be able to find it. 4:38 So you just put AWS. 4:41 Secret key. 4:44 Why it's in here? 4:46 Okay. 4:49 So let's just spend a few minutes here. 4:55 Potentially, we will be able to find some keys. 5:00 Like this. 5:01 So this is environment which can have those keys. 5:07 And if we are doing the research about company, we can find their GitHub, you see, for example, this is test, test, test. 5:18 So this is like test environment. 5:21 But now, please take this key and use hosting for free. 5:28 This key is basically for this guy who works maybe in some company. 5:38 And six months ago... 5:40 He was doing some crazy stuff and he put that key. 5:46 Is that key valid? 5:48 We can check it. 5:50 It's not a big deal. 5:51 We can check it, that key. 5:53 But imagine the situation where this key is from some big company and it was leaked. 6:04 you are able to connect to the cloud and just exfiltrate information. 6:10 So, 6:14 Let me also show you one stuff. 6:21 I want to show you keys. 6:26 This is... 6:33 Crypto audit. 6:38 So you can input here different keys and you can check if they are valid or not. 6:46 So that is super easy. 6:51 Let me show you how you can do it. 6:55 Just one sec. 6:57 So I'm clicking here. 7:03 I will also show you, meanwhile, how to intercept traffic on the web browser. 7:10 So you open Google Chrome, for example. 7:17 And you can go to history and you can see all the HTTP traffic. 7:21 So this is like some website. 7:26 You can go to example.com. 7:30 Or you can use, if you remember, we use this website. 7:35 Is it still live? 7:38 No, it's not live. 7:41 It's not live. 7:42 I will just put it up live again. 7:45 So I will show you. 7:46 I will show you now in details. 7:51 Clear all. 7:53 So now what is going on? 7:56 Nothing. 7:57 Each hacker globally who is hacking the websites is using HTTP proxy. 8:03 So he will exactly know what is going on. 8:05 Now, I am putting admin. 8:10 And some password. 8:14 So reset stuff. 8:19 So now login. 8:24 Let's do it. 8:25 Login failed, right? 8:27 What do I see in the background as attacker? 8:31 What do I see? 8:34 I just pressed. 8:38 So it opened me this stuff again. 8:40 So what do I see? 8:42 I see login. 8:44 This is record. 8:45 So you should understand this is HTTP request. 8:48 This is how it is formulated. 8:51 It is saying admin and password. 8:54 So now using that stuff, I can do brute force. 8:59 I'm taking this stuff and sending it to... 9:04 I can do the form brute force or I can send it to replacer. 9:09 So replacer will replace password. 9:14 So I know the login is admin. 9:16 So now I need to replace the password. 9:18 I add marker, right? 9:21 And I'm just going to... 9:25 Use the payloads which are maybe 9:34 Custom list. 9:37 I will put like, haha, bb, whatever, you know, I will just go and top 100 passwords GitHub. 9:51 I'll just show you. 9:53 So I just use top 1000 passwords. 9:58 From the GitHub, most common passwords, right? 10:02 So I'm just copying them. 10:04 Why it's like this? 10:06 Why it's like this crazy? 10:12 Something is going on. 10:14 Okay, I will open it here. 10:16 Yeah, now it's good. 10:18 So I'm going to input it here. 10:22 And I know that the password there should be admin or something. 10:29 I don't remember, but let's start attack. 10:32 This is how fast I put force. 10:37 So 1,000 will be within like one minute. 10:43 So if I will go make coffee, if I will go sleep, I will be able to definitely find, you know, the password. 10:51 Anomaly is one. 10:53 I found one anomaly. 10:56 And look. 10:57 I didn't know that, that, um, 11:01 Password was there. 11:02 I didn't check on purpose. 11:05 So I just took the stuff. 11:08 So length, time, status. 11:12 So where is anomaly? 11:15 Let's see. 11:17 Where is anomaly? 11:22 So payload password is anomaly. 11:27 So this is our anomaly. 11:29 So the password is password. 11:33 Let's go and check this stuff. 11:36 So it is admin, password, password. 11:41 That's it. 11:42 This is how, in reality, you're doing the brute force. 11:48 And it doesn't matter, you know, which website is this. 11:52 Now I will show you another stuff, even cooler, right? 11:56 So it was fun, but... 12:01 Let me show you. 12:04 HTTP. 12:08 Brute force, form brute force. 12:10 Now let's put this one, right? 12:12 Let's put it here. 12:14 Check target. 12:16 All good, reachable. 12:18 I don't need to detect CMS. 12:20 I don't need anything. 12:21 I don't need to scan ports. 12:24 I just want to detect fields. 12:29 So which are fields? 12:31 We have username and password. 12:34 Username is username. 12:35 Username is username. 12:37 Password is password. 12:38 Password is password. 12:40 So nobody is trying to fool us, right? 12:45 And based on this stuff, we just need to click start, but it is blocked. 12:54 So I'm going to start. 12:59 So I click start and it is trying to. 13:05 Brute force. 13:06 La la la. 13:10 Now it is doing it automatically. 13:15 But what I can see, what I don't like, that it is brute forcing the usernames which I didn't want to brute force because I didn't check. 13:25 But it is trying to brute force like demo, password, whatever. 13:28 Different. 13:29 It is using, it is brute forcing username and password and passwords for each username. 13:35 So manager, password, manager operator. 13:40 So, valid credential found. 13:48 So, very credential found. 13:53 Yeah. 13:55 Let's check. 13:58 Admin password. 14:03 View proof. 14:06 Let's make it a little bit more easier because it was too much. 14:12 It was too much. 14:13 Detect fields. 14:15 Again. 14:18 Yeah, results. 14:26 I'm not sure why it's saying that. 14:30 Admin password password this one is basically should be 14:40 should be right i'm not sure why it said no success i think because of token so the token here you see this is the hidden token and it should be respected 14:54 I think he didn't respect the token. 14:57 So this system, maybe without refresh, CSRF token, maybe without refresh, stop first match. 15:12 JS mode. 15:16 form base. 15:19 Yeah, found one credentials. 15:23 Yeah. 15:24 That's my password. 15:25 Done. 15:27 That's it. 15:28 We just need to remove the refresh system token because it was trying to refresh this one. 15:37 So we reused the token, which we got one time, for a million of requests. 15:43 It took us zero seconds. 15:46 So if we will, again, let's put again this list. 15:53 So I'm just showing you the impact of brute force. 15:56 So we put like 1,000 passwords and we basically start the attack again. 16:04 It will take us like zero seconds, but... 16:10 If we will just go here and try to put it like somewhere in the end, 16:20 Just here, maybe. 16:23 Let's see how much time it will take. 16:26 Again, it's taking zero because it is so fast. 16:30 It is so fast. 16:34 So, yeah, you should understand that that brute force is going crazy. 16:41 And anyone can, you know, if you don't have protection, you will be brute forced. 16:50 Now let's remove. 16:51 Let's remove. 16:56 I don't know why it's still getting it. 16:57 Maybe because it is here. 16:58 1, 2, 3, 1, 2, 3, 1, 2, 3, 4, 5. 17:01 Let's see if we don't have this in there. 17:05 I don't know why it's still getting that result. 17:13 I was cooking in response. 17:15 So it's one, two, three. 17:20 Very strange. 17:21 Very strange. 17:21 So sometimes it's more reliable to use manual stuff, but automatic is also, you know, usually working fine.
0:00 Music 0:08 There are different attack chains related to attack on humans. 0:15 So there are technical and human attacks, obviously. 0:21 So technical is when you're hacking Wi-Fi, you're hacking LAN, you are getting the software information, system information, and much more. 0:30 But for human, you can collect information from LinkedIn, Twitter, social media. 0:35 You can do OSINT and a lot of other stuff. 0:38 So what is OSINT, right? 0:42 Ossent. 0:43 Let me show you what is Ossent. 0:49 What exactly is interesting for us? 0:54 Let's analyze, for example, just full company. 1:02 So like this. 1:05 So now I am running 112 audits against website. 1:14 112 audits. 1:16 You can do it manually or you can do it automatically. 1:20 So here, this is example. 1:23 We went to the website, which is called urskan.io. 1:31 And that website is providing us with information about all the IPs which we used. 1:40 It is basically showing us the technologies which we used. 1:46 Here you can also see the information, but all the stuff you can collect. 1:52 From sub tabs here if they will pop up here. 1:58 But in reality, you can just see. 2:02 This is a subdomain which was collected. 2:05 So how this data is collected? 2:07 This data is collected from the third party websites. 2:11 So it goes to Google and collects the information. 2:14 It goes to the Wayback Machine, which is on this website. 2:20 Let me just show you so you understand. 2:23 Way back machine. 2:24 Way back machine. 2:30 Way back. 2:30 Machine. 2:31 Way back machine. 2:35 So you just go here, you input your website, and you can see how it looked before. 2:46 And why do we need this information? 2:48 We need this information because potentially you can collect information which is not there anymore. 2:58 This is historical data. 3:00 So you can just click, for example, how it looks maybe. 3:08 One month ago. 3:10 You see something is wrong with the Wayback Machine, but usually this website works. 3:18 Yeah, now I can click and it will show me how this website works. 3:25 So, yeah. 3:28 It will show that stuff. 3:30 What else interesting? 3:31 You can also collect the DNS information, information about where this website was hosted. 3:41 Also, this is very interesting stuff. 3:44 It went to GitHub and collected me all the names. 3:51 Related to a company name. 3:54 So it assumed that if I'm using CQR with company, it should go to GitHub. 4:01 and find that specific name. 4:04 So let me show you some real example. 4:10 It will be secret. 4:15 Password. 4:17 I'll just show you. 4:18 So potentially, you can go to code and you can search the name of your company and put the secret. 4:27 So if they have the GitHub repo, you will be able to find it. 4:38 So you just put AWS. 4:41 Secret key. 4:44 Why it's in here? 4:46 Okay. 4:49 So let's just spend a few minutes here. 4:55 Potentially, we will be able to find some keys. 5:00 Like this. 5:01 So this is environment which can have those keys. 5:07 And if we are doing the research about company, we can find their GitHub, you see, for example, this is test, test, test. 5:18 So this is like test environment. 5:21 But now, please take this key and use hosting for free. 5:28 This key is basically for this guy who works maybe in some company. 5:38 And six months ago... 5:40 He was doing some crazy stuff and he put that key. 5:46 Is that key valid? 5:48 We can check it. 5:50 It's not a big deal. 5:51 We can check it, that key. 5:53 But imagine the situation where this key is from some big company and it was leaked. 6:04 you are able to connect to the cloud and just exfiltrate information. 6:10 So, 6:14 Let me also show you one stuff. 6:21 I want to show you keys. 6:26 This is... 6:33 Crypto audit. 6:38 So you can input here different keys and you can check if they are valid or not. 6:46 So that is super easy. 6:51 Let me show you how you can do it. 6:55 Just one sec. 6:57 So I'm clicking here. 7:03 I will also show you, meanwhile, how to intercept traffic on the web browser. 7:10 So you open Google Chrome, for example. 7:17 And you can go to history and you can see all the HTTP traffic. 7:21 So this is like some website. 7:26 You can go to example.com. 7:30 Or you can use, if you remember, we use this website. 7:35 Is it still live? 7:38 No, it's not live. 7:41 It's not live. 7:42 I will just put it up live again. 7:45 So I will show you. 7:46 I will show you now in details. 7:51 Clear all. 7:53 So now what is going on? 7:56 Nothing. 7:57 Each hacker globally who is hacking the websites is using HTTP proxy. 8:03 So he will exactly know what is going on. 8:05 Now, I am putting admin. 8:10 And some password. 8:14 So reset stuff. 8:19 So now login. 8:24 Let's do it. 8:25 Login failed, right? 8:27 What do I see in the background as attacker? 8:31 What do I see? 8:34 I just pressed. 8:38 So it opened me this stuff again. 8:40 So what do I see? 8:42 I see login. 8:44 This is record. 8:45 So you should understand this is HTTP request. 8:48 This is how it is formulated. 8:51 It is saying admin and password. 8:54 So now using that stuff, I can do brute force. 8:59 I'm taking this stuff and sending it to... 9:04 I can do the form brute force or I can send it to replacer. 9:09 So replacer will replace password. 9:14 So I know the login is admin. 9:16 So now I need to replace the password. 9:18 I add marker, right? 9:21 And I'm just going to... 9:25 Use the payloads which are maybe 9:34 Custom list. 9:37 I will put like, haha, bb, whatever, you know, I will just go and top 100 passwords GitHub. 9:51 I'll just show you. 9:53 So I just use top 1000 passwords. 9:58 From the GitHub, most common passwords, right? 10:02 So I'm just copying them. 10:04 Why it's like this? 10:06 Why it's like this crazy? 10:12 Something is going on. 10:14 Okay, I will open it here. 10:16 Yeah, now it's good. 10:18 So I'm going to input it here. 10:22 And I know that the password there should be admin or something. 10:29 I don't remember, but let's start attack. 10:32 This is how fast I put force. 10:37 So 1,000 will be within like one minute. 10:43 So if I will go make coffee, if I will go sleep, I will be able to definitely find, you know, the password. 10:51 Anomaly is one. 10:53 I found one anomaly. 10:56 And look. 10:57 I didn't know that, that, um, 11:01 Password was there. 11:02 I didn't check on purpose. 11:05 So I just took the stuff. 11:08 So length, time, status. 11:12 So where is anomaly? 11:15 Let's see. 11:17 Where is anomaly? 11:22 So payload password is anomaly. 11:27 So this is our anomaly. 11:29 So the password is password. 11:33 Let's go and check this stuff. 11:36 So it is admin, password, password. 11:41 That's it. 11:42 This is how, in reality, you're doing the brute force. 11:48 And it doesn't matter, you know, which website is this. 11:52 Now I will show you another stuff, even cooler, right? 11:56 So it was fun, but... 12:01 Let me show you. 12:04 HTTP. 12:08 Brute force, form brute force. 12:10 Now let's put this one, right? 12:12 Let's put it here. 12:14 Check target. 12:16 All good, reachable. 12:18 I don't need to detect CMS. 12:20 I don't need anything. 12:21 I don't need to scan ports. 12:24 I just want to detect fields. 12:29 So which are fields? 12:31 We have username and password. 12:34 Username is username. 12:35 Username is username. 12:37 Password is password. 12:38 Password is password. 12:40 So nobody is trying to fool us, right? 12:45 And based on this stuff, we just need to click start, but it is blocked. 12:54 So I'm going to start. 12:59 So I click start and it is trying to. 13:05 Brute force. 13:06 La la la. 13:10 Now it is doing it automatically. 13:15 But what I can see, what I don't like, that it is brute forcing the usernames which I didn't want to brute force because I didn't check. 13:25 But it is trying to brute force like demo, password, whatever. 13:28 Different. 13:29 It is using, it is brute forcing username and password and passwords for each username. 13:35 So manager, password, manager operator. 13:40 So, valid credential found. 13:48 So, very credential found. 13:53 Yeah. 13:55 Let's check. 13:58 Admin password. 14:03 View proof. 14:06 Let's make it a little bit more easier because it was too much. 14:12 It was too much. 14:13 Detect fields. 14:15 Again. 14:18 Yeah, results. 14:26 I'm not sure why it's saying that. 14:30 Admin password password this one is basically should be 14:40 should be right i'm not sure why it said no success i think because of token so the token here you see this is the hidden token and it should be respected 14:54 I think he didn't respect the token. 14:57 So this system, maybe without refresh, CSRF token, maybe without refresh, stop first match. 15:12 JS mode. 15:16 form base. 15:19 Yeah, found one credentials. 15:23 Yeah. 15:24 That's my password. 15:25 Done. 15:27 That's it. 15:28 We just need to remove the refresh system token because it was trying to refresh this one. 15:37 So we reused the token, which we got one time, for a million of requests. 15:43 It took us zero seconds. 15:46 So if we will, again, let's put again this list. 15:53 So I'm just showing you the impact of brute force. 15:56 So we put like 1,000 passwords and we basically start the attack again. 16:04 It will take us like zero seconds, but... 16:10 If we will just go here and try to put it like somewhere in the end, 16:20 Just here, maybe. 16:23 Let's see how much time it will take. 16:26 Again, it's taking zero because it is so fast. 16:30 It is so fast. 16:34 So, yeah, you should understand that that brute force is going crazy. 16:41 And anyone can, you know, if you don't have protection, you will be brute forced. 16:50 Now let's remove. 16:51 Let's remove. 16:56 I don't know why it's still getting it. 16:57 Maybe because it is here. 16:58 1, 2, 3, 1, 2, 3, 1, 2, 3, 4, 5. 17:01 Let's see if we don't have this in there. 17:05 I don't know why it's still getting that result. 17:13 I was cooking in response. 17:15 So it's one, two, three. 17:20 Very strange. 17:21 Very strange. 17:21 So sometimes it's more reliable to use manual stuff, but automatic is also, you know, usually working fine.