0:00 Music 0:06 What are the mandatory patterns? 0:10 If you are doing the analysis of your source code, you should definitely understand which type of applications we are discussing. 0:20 If we talk about website, right, which is the most common web application. 0:26 globally, which is usually analyzed by static analyzers. 0:32 We can see that mostly static analyzers will be finding the web vulnerabilities or known CVEs. 0:44 API keys based on the patterns and entropy. 0:48 So let me dig a little bit more into that topic. 0:55 In this slide, we have seven possible mandatory patterns categories. 1:02 So those are the most important seven categories, which are 1:08 There, if you are creating the application for dating, for example, that application for dating, people can register there and they input their data and they can communicate 1:24 between each other. 1:26 It has like two, three, five features. 1:29 And at 1:31 So, first of all, it is important to understand that that application is hosted in the web and it can have a 1:43 big amount of vulnerabilities connected to web. 1:46 And I will show you examples of vulnerable web application and vulnerable code. 1:53 Additionally, that application can have already known vulnerabilities. 1:59 So there are some vulnerabilities which are known and they marked as CVE. 2:07 So what is basically CV? 2:12 CVE is the database where you can find a big amount, like hundreds of thousands of known vulnerabilities and their patterns. 2:25 So you need to scan your code, not only for web vulnerabilities, but also for known CVE patterns. 2:34 Additionally, accidentally, you can commit, not even accidentally, but you can commit the API keys on your application. 2:44 I can give you a great example of API key committed to the web application. 2:50 So it was... 2:52 One big cryptocurrency exchange, which had helped us. 3:00 integrated in the website. 3:02 So when you wanted to start using that exchange, you had to pass KYC. 3:10 KYC is now your customer and you had to upload your passport and help desk will approve it. 3:20 Or accept it, or we'll ask you questions. 3:22 So we intercepted the communication with the help desk, and we understood that that help desk is using third-party application, 3:35 and that third-party application is using the API key. 3:39 To communicate between you, chat box, and the agent. 3:45 So we took that API key in hope that that API key was used only for chat. 3:56 So we chat, so for some reason it is using the API key. 4:00 But that API key 4:02 was not only for communication. 4:04 That API key allowed just to go and to read the documentation of that origin of that API key. 4:14 And that API key provided ability to run 4:19 almost anything on that service. 4:22 So what this means, we just read the documentation and we were able to see all communications of the agents and 4:30 all the files which were uploaded by all people who communicated with agents, potentially all the passports of all people from that exchange, we were able to obtain. 4:41 So it was very critical for cryptocurrency exchange, and that was governmental cryptocurrency exchange. 4:50 So let's imagine that a governmental cryptocurrency exchange has that vulnerability. 4:58 If it will not be mitigated on time, basically attackers will download all the passport data of all people who tried to pass KYC. 5:11 And it was not only passport data. 5:14 It was like big amount of data because people had to prove their identity. 5:18 In the chat box, they were uploading and agent was saying like, if he likes it or he wants to do the picture when you're holding the passport and all that stuff. 5:28 So potentially. 5:30 You can just get all that stuff and pass any KYC in any other cryptocurrency and just register it for that specific guy. 5:41 Without his knowledge, obviously. 5:42 So the damage will be big. 5:44 And it was only a pay key which was used there on purpose. 5:52 So they use it on purpose. 5:53 They know they used it, right? 5:55 But they didn't understand that if somebody will take that API key, they can... 6:00 get not only ability to communicate with the chat box, but also to see all the communications and all the files. 6:08 Number four, dependency confusion. 6:10 So what is dependency confusion? 6:13 It sounds a little bit strange. 6:18 What is dependency confusion? 6:21 I will give you a real example of what is this. 6:26 So pip install or anything else. 6:32 Let me show you the download pip. 6:38 So on this website, 6:42 It's a big amount of different libraries. 6:47 And 99% of developers who develop on Python use third-party libraries. 6:56 So we can see that almost 1 million projects 7:00 are deployed here with a big amount of files. 7:03 And you should understand that each of those files, this is another topic, but each of those files can be malicious, each. 7:11 By statistics, for you just to be clear, if you download one library, that library, 7:20 is using around eight other libraries. 7:24 Why? 7:25 Because one library is using second library. 7:29 Second library is using like two other libraries and it goes almost like crazy. 7:35 So when you download two libraries, you download 160 libraries. 7:41 When you download like five libraries, it's around at least 200 libraries. 7:46 You download it. 7:47 But usually each project at least has 10 libraries. 7:52 So you are depending on at least, I don't know, 80 or 100 other libraries. 8:02 libraries. 8:03 So let's imagine that somebody compromised that library or something like this. 8:10 You should also understand that when you do not analyze the third-party libraries, you're putting your company at a big risk. 8:20 And this is only if you talk about Python. 8:23 There are also Java packages. 8:26 There are also PHP packages, Ruby packages, and each programming language, they have the packet manager. 8:36 So talking about pay, well, Apple, I guess, dependency confusion paid. 8:48 So what happened? 8:50 Five years ago. 8:55 This is like 2022. 8:58 So what is dependency confusion, right? 9:03 Let me show you it real quick. 9:08 Like random Python package, GitHub. 9:13 So we just go here. 9:15 And we just go into some random C Python. 9:20 C Python is not random, but it is just an example. 9:26 So not a good example. 9:29 It doesn't have that stuff. 9:30 I just need the random Python scripts, okay? 9:35 So random Python scripts. 9:37 There is one script to work with AWS. 9:40 It's a random script. 9:41 So any script can be like this. 9:43 What can we see here? 9:44 Import config parser. 9:47 So if guy is putting here import library, which is called config parser, right? 9:56 You can go here and... 10:00 Python, BIP, so. 10:06 here, right? 10:07 So this is the package. 10:09 This is the legitimate package, which we basically can download and we can read some documentation about this package. 10:18 So what can be a problem here? 10:22 The problem is hidden from developers because they don't know what interesting stuff. 10:27 If they will download this package and they will just rename it to like this, 10:33 just for local usage. 10:35 So they download the package and they just renamed it. 10:38 And that package is not registered here, right? 10:44 So what can I do? 10:47 If I know that this package is popular, right? 10:51 For example, like package Google, right? 10:53 Let's see. 10:55 Google. 10:56 If I put like Google one, 10:59 You see somebody registered Google 3. 11:03 Or I will put like Google, you see? 11:07 So that can be official one. 11:09 But let me... 11:10 make something like Google. 11:17 So somebody can make that mistake. 11:19 This is first stuff. 11:21 So I would just go register and I will create a package. 11:26 So if somebody 11:28 from Google, right, or from any other company, want to use their, you know, Google search, and they will accidentally write the wrong package, they will download my package. 11:40 And my package will not be that much pleasant. 11:43 It will be the same as Google, right? 11:47 package, I will just download it, I will unpack it, and I will pack our little malware there. 11:56 So every time the guy will be using my package, he will be infected. 12:02 So what is dependency confusion? 12:05 You will ask. 12:06 So dependency confusion is 12:09 When you are downloading the local, 12:17 when you create the local library, that local library, first of all, goes for update to the internet. 12:26 So what this means, again, if this guy, let's take this. 12:32 Code. 12:35 Let's take this code and say, 12:42 test. 12:44 So, can you spot potential dependency confusion here? 12:52 So, 12:56 Yes, clear dependency confusion. 12:59 You see? 13:02 But here, someone is importing. 13:06 So what this means, if I would download the legitimate package on my computer, after I will modify it, and I will rename it to like test or whatever, and 13:21 For example, this is like big company, right? 13:23 And I'm doing some open source project and I created such stuff and I committed it, right? 13:30 So somebody can go and check if the package is existing. 13:36 If it's not, he will go register it and you will automatically, even if you don't want, it will download it from there. 13:46 So next time when you will redeploy it, it will just go and get it from the official website. 13:53 So because there is priority. 13:57 Priority is first e-download from the internet. 14:01 After, it is checking locally. 14:03 I don't know why the priority is there. 14:06 Maybe to keep the packages updated, but this is the priority. 14:11 So we can check. 14:14 That's tough. 14:15 So why dependency confusion exists? 14:25 Let me hide that stuff. 14:29 Is it because of priority of dependency download? 14:39 You see? 14:47 So the example here is that if this item is not published in the internet, it will use local. 14:59 If it's published, it can download it from the internet to keep updated. 15:04 So what happened? 15:06 Big amount of guys, they found a repos for big companies like PayPal, YouTube, Apple, and they hacked them. 15:17 And they got a good amount of money because of that stuff. 15:24 depend, then see confusion. 15:28 Let me show you. 15:33 So you know those guys. 15:35 For example, Uber has a back bounty program. 15:39 And what was done? 15:42 So Uber has their repo. 15:46 This is Uber repo. 15:49 No, it is different. 15:51 GitHub, Uber. 15:57 So this is GitHub of the Uber. 16:01 And they have different libraries, which most likely they use for their own good, you know. 16:08 And based on this small research, 16:13 There are different programming languages which are used, and they are using Java a lot. 16:19 And what was done, basically? 16:26 Each repo was analyzed with software, which is called Dependency Confuser. 16:37 As I remember, GitHub Dependency Confusion. 16:43 Confused. 16:44 It's called Confused, yes. 16:45 So, yeah. 16:47 So, what this... 16:49 Software does. 16:51 It is checking the dependency file. 16:55 And based on that dependency file, it will say, look, 17:01 you have the local package, which is not registered in the internet. 17:06 So next time when you will be installing it or when you will ask somebody to install it, right, it will go to the internet and download that stuff. 17:15 And it can be malicious stuff. 17:18 So that type of vulnerability, not a lot of people know, but that is something that should be also checked in the part of mandatory patterns.
0:00 Music 0:06 What are the mandatory patterns? 0:10 If you are doing the analysis of your source code, you should definitely understand which type of applications we are discussing. 0:20 If we talk about website, right, which is the most common web application. 0:26 globally, which is usually analyzed by static analyzers. 0:32 We can see that mostly static analyzers will be finding the web vulnerabilities or known CVEs. 0:44 API keys based on the patterns and entropy. 0:48 So let me dig a little bit more into that topic. 0:55 In this slide, we have seven possible mandatory patterns categories. 1:02 So those are the most important seven categories, which are 1:08 There, if you are creating the application for dating, for example, that application for dating, people can register there and they input their data and they can communicate 1:24 between each other. 1:26 It has like two, three, five features. 1:29 And at 1:31 So, first of all, it is important to understand that that application is hosted in the web and it can have a 1:43 big amount of vulnerabilities connected to web. 1:46 And I will show you examples of vulnerable web application and vulnerable code. 1:53 Additionally, that application can have already known vulnerabilities. 1:59 So there are some vulnerabilities which are known and they marked as CVE. 2:07 So what is basically CV? 2:12 CVE is the database where you can find a big amount, like hundreds of thousands of known vulnerabilities and their patterns. 2:25 So you need to scan your code, not only for web vulnerabilities, but also for known CVE patterns. 2:34 Additionally, accidentally, you can commit, not even accidentally, but you can commit the API keys on your application. 2:44 I can give you a great example of API key committed to the web application. 2:50 So it was... 2:52 One big cryptocurrency exchange, which had helped us. 3:00 integrated in the website. 3:02 So when you wanted to start using that exchange, you had to pass KYC. 3:10 KYC is now your customer and you had to upload your passport and help desk will approve it. 3:20 Or accept it, or we'll ask you questions. 3:22 So we intercepted the communication with the help desk, and we understood that that help desk is using third-party application, 3:35 and that third-party application is using the API key. 3:39 To communicate between you, chat box, and the agent. 3:45 So we took that API key in hope that that API key was used only for chat. 3:56 So we chat, so for some reason it is using the API key. 4:00 But that API key 4:02 was not only for communication. 4:04 That API key allowed just to go and to read the documentation of that origin of that API key. 4:14 And that API key provided ability to run 4:19 almost anything on that service. 4:22 So what this means, we just read the documentation and we were able to see all communications of the agents and 4:30 all the files which were uploaded by all people who communicated with agents, potentially all the passports of all people from that exchange, we were able to obtain. 4:41 So it was very critical for cryptocurrency exchange, and that was governmental cryptocurrency exchange. 4:50 So let's imagine that a governmental cryptocurrency exchange has that vulnerability. 4:58 If it will not be mitigated on time, basically attackers will download all the passport data of all people who tried to pass KYC. 5:11 And it was not only passport data. 5:14 It was like big amount of data because people had to prove their identity. 5:18 In the chat box, they were uploading and agent was saying like, if he likes it or he wants to do the picture when you're holding the passport and all that stuff. 5:28 So potentially. 5:30 You can just get all that stuff and pass any KYC in any other cryptocurrency and just register it for that specific guy. 5:41 Without his knowledge, obviously. 5:42 So the damage will be big. 5:44 And it was only a pay key which was used there on purpose. 5:52 So they use it on purpose. 5:53 They know they used it, right? 5:55 But they didn't understand that if somebody will take that API key, they can... 6:00 get not only ability to communicate with the chat box, but also to see all the communications and all the files. 6:08 Number four, dependency confusion. 6:10 So what is dependency confusion? 6:13 It sounds a little bit strange. 6:18 What is dependency confusion? 6:21 I will give you a real example of what is this. 6:26 So pip install or anything else. 6:32 Let me show you the download pip. 6:38 So on this website, 6:42 It's a big amount of different libraries. 6:47 And 99% of developers who develop on Python use third-party libraries. 6:56 So we can see that almost 1 million projects 7:00 are deployed here with a big amount of files. 7:03 And you should understand that each of those files, this is another topic, but each of those files can be malicious, each. 7:11 By statistics, for you just to be clear, if you download one library, that library, 7:20 is using around eight other libraries. 7:24 Why? 7:25 Because one library is using second library. 7:29 Second library is using like two other libraries and it goes almost like crazy. 7:35 So when you download two libraries, you download 160 libraries. 7:41 When you download like five libraries, it's around at least 200 libraries. 7:46 You download it. 7:47 But usually each project at least has 10 libraries. 7:52 So you are depending on at least, I don't know, 80 or 100 other libraries. 8:02 libraries. 8:03 So let's imagine that somebody compromised that library or something like this. 8:10 You should also understand that when you do not analyze the third-party libraries, you're putting your company at a big risk. 8:20 And this is only if you talk about Python. 8:23 There are also Java packages. 8:26 There are also PHP packages, Ruby packages, and each programming language, they have the packet manager. 8:36 So talking about pay, well, Apple, I guess, dependency confusion paid. 8:48 So what happened? 8:50 Five years ago. 8:55 This is like 2022. 8:58 So what is dependency confusion, right? 9:03 Let me show you it real quick. 9:08 Like random Python package, GitHub. 9:13 So we just go here. 9:15 And we just go into some random C Python. 9:20 C Python is not random, but it is just an example. 9:26 So not a good example. 9:29 It doesn't have that stuff. 9:30 I just need the random Python scripts, okay? 9:35 So random Python scripts. 9:37 There is one script to work with AWS. 9:40 It's a random script. 9:41 So any script can be like this. 9:43 What can we see here? 9:44 Import config parser. 9:47 So if guy is putting here import library, which is called config parser, right? 9:56 You can go here and... 10:00 Python, BIP, so. 10:06 here, right? 10:07 So this is the package. 10:09 This is the legitimate package, which we basically can download and we can read some documentation about this package. 10:18 So what can be a problem here? 10:22 The problem is hidden from developers because they don't know what interesting stuff. 10:27 If they will download this package and they will just rename it to like this, 10:33 just for local usage. 10:35 So they download the package and they just renamed it. 10:38 And that package is not registered here, right? 10:44 So what can I do? 10:47 If I know that this package is popular, right? 10:51 For example, like package Google, right? 10:53 Let's see. 10:55 Google. 10:56 If I put like Google one, 10:59 You see somebody registered Google 3. 11:03 Or I will put like Google, you see? 11:07 So that can be official one. 11:09 But let me... 11:10 make something like Google. 11:17 So somebody can make that mistake. 11:19 This is first stuff. 11:21 So I would just go register and I will create a package. 11:26 So if somebody 11:28 from Google, right, or from any other company, want to use their, you know, Google search, and they will accidentally write the wrong package, they will download my package. 11:40 And my package will not be that much pleasant. 11:43 It will be the same as Google, right? 11:47 package, I will just download it, I will unpack it, and I will pack our little malware there. 11:56 So every time the guy will be using my package, he will be infected. 12:02 So what is dependency confusion? 12:05 You will ask. 12:06 So dependency confusion is 12:09 When you are downloading the local, 12:17 when you create the local library, that local library, first of all, goes for update to the internet. 12:26 So what this means, again, if this guy, let's take this. 12:32 Code. 12:35 Let's take this code and say, 12:42 test. 12:44 So, can you spot potential dependency confusion here? 12:52 So, 12:56 Yes, clear dependency confusion. 12:59 You see? 13:02 But here, someone is importing. 13:06 So what this means, if I would download the legitimate package on my computer, after I will modify it, and I will rename it to like test or whatever, and 13:21 For example, this is like big company, right? 13:23 And I'm doing some open source project and I created such stuff and I committed it, right? 13:30 So somebody can go and check if the package is existing. 13:36 If it's not, he will go register it and you will automatically, even if you don't want, it will download it from there. 13:46 So next time when you will redeploy it, it will just go and get it from the official website. 13:53 So because there is priority. 13:57 Priority is first e-download from the internet. 14:01 After, it is checking locally. 14:03 I don't know why the priority is there. 14:06 Maybe to keep the packages updated, but this is the priority. 14:11 So we can check. 14:14 That's tough. 14:15 So why dependency confusion exists? 14:25 Let me hide that stuff. 14:29 Is it because of priority of dependency download? 14:39 You see? 14:47 So the example here is that if this item is not published in the internet, it will use local. 14:59 If it's published, it can download it from the internet to keep updated. 15:04 So what happened? 15:06 Big amount of guys, they found a repos for big companies like PayPal, YouTube, Apple, and they hacked them. 15:17 And they got a good amount of money because of that stuff. 15:24 depend, then see confusion. 15:28 Let me show you. 15:33 So you know those guys. 15:35 For example, Uber has a back bounty program. 15:39 And what was done? 15:42 So Uber has their repo. 15:46 This is Uber repo. 15:49 No, it is different. 15:51 GitHub, Uber. 15:57 So this is GitHub of the Uber. 16:01 And they have different libraries, which most likely they use for their own good, you know. 16:08 And based on this small research, 16:13 There are different programming languages which are used, and they are using Java a lot. 16:19 And what was done, basically? 16:26 Each repo was analyzed with software, which is called Dependency Confuser. 16:37 As I remember, GitHub Dependency Confusion. 16:43 Confused. 16:44 It's called Confused, yes. 16:45 So, yeah. 16:47 So, what this... 16:49 Software does. 16:51 It is checking the dependency file. 16:55 And based on that dependency file, it will say, look, 17:01 you have the local package, which is not registered in the internet. 17:06 So next time when you will be installing it or when you will ask somebody to install it, right, it will go to the internet and download that stuff. 17:15 And it can be malicious stuff. 17:18 So that type of vulnerability, not a lot of people know, but that is something that should be also checked in the part of mandatory patterns.