0:00 Music 0:07 Let me show you some patterns so you will understand how vulnerabilities, you know, 0:15 Just get to exist. 0:17 Those are examples of vulnerable code. 0:23 I understand maybe it can sound like, you know, a little bit complex or not. 0:27 But look, guys, vulnerable code can be like two or three lines of code. 0:34 So in this example, you know, you can see that, 0:40 That guy is just using the library, which is legitimate for Python, which is called Pickle. 0:48 How that works? 0:50 So you take the data, you serialize it. 0:54 It means you just, you know, make it like... 0:58 archive, and after you release it. 1:01 So this is for data transferring inside the Python. 1:04 So this little, you know, three line of code, it's already vulnerable. 1:11 If you will just, you know, enter here malicious stuff, for example, 1:17 If you will enter here the command which will allow you to go to my server, download malicious script and run it, it will do it. 1:27 So if here you are putting as input my name, when I am going to register, I'm not going to put Bogdan. 1:35 I'm going to say malicious, blah, blah, blah, blah, blah, blah, blah, blah, blah. 1:40 So look, just an example. 1:45 If you are writing the source code, right, and you have that type of 1:51 Stuff. 1:52 So. 1:55 Let's go to chat and ask, what is this? 1:57 What is this? 1:59 I want to use pickle. 2:03 Look, it will rewrite me the code. 2:08 So now it made it more secure. 2:12 It is still using the pickle, but it is using it more secure way. 2:20 I want to use pickle with more secure method. 2:32 So. 2:35 You see, it is just trying to put some additional security controls. 2:39 But in reality, it can just make it, you know, make it three lines. 2:47 This guy is just going crazy, you know, in cybersecurity, just too much. 2:52 Very good developer. 2:55 Okay, like this. 2:57 So this is how it will be more secure. 3:03 So yeah, so it looks like you need to make it like more complex. 3:10 Like this, you cannot just use it. 3:12 But if you will go... 3:15 pickle, Python example, right? 3:19 You will see that this is guide, which will be used by developers, and they will just copy it. 3:30 Import pickle, and that's it. 3:32 So guys, just go to internet, they copy it, 3:35 And they use it. 3:37 So this happens all the time. 3:40 There is nothing around security here. 3:46 So open, pickle load. 3:52 Where is load? 3:53 Pickle load. 3:54 Great. 3:55 Just great. 3:56 Now think about this. 3:57 Guy will send a file, for example, his picture. 4:03 It will just take the picture. 4:06 make, you know, it's serialized, send it somewhere and open it. 4:12 Now think about this. 4:13 In picture, you can input Python code. 4:18 This is no difference if you're sending picture, if you're sending XZ, whatever. 4:22 And if server will say, this is not picture, you will say, it is not picture. 4:28 How do you know? 4:30 You will go and read how it knows that this is not picture, right? 4:34 And it will say, picture should have this. 4:36 It will say, if picture should have this, I will put it here. 4:41 Or down. 4:42 So when the script will work, right, that stuff, you will see it. 4:49 Or you just try to input it somewhere where server will read it, but it will not affect the execution of script. 4:56 So another example, PHP shell code PDF. 5:03 PNG. 5:05 PNG. 5:07 So, just for your knowledge, how guys are going this crazy level. 5:16 So, developer is saying, you can only upload PNG. 5:23 If you will not upload PNG, I will not allow this file. 5:29 Right? 5:29 So sounds, you know, serious. 5:32 Now let's imagine that the guy is just putting inside PNG, inside PNG, in the metadata, 5:44 PHP code. 5:46 Somebody expected this? 5:47 No. 5:49 So in the author name of the image is PHP code. 5:55 For example, so, you know, and during the parsing or during the analysis or during, you know, whatever, it will execute. 6:07 Why? 6:08 Okay, I will tell you why. 6:10 You see the extension here is .php. 6:14 So potentially when guy was uploading it, it didn't check the extension, but it checked this image. 6:22 This is first mistake, right? 6:24 So the guy was like, this is PNG? 6:28 Yes. 6:29 Do we allow it? 6:30 Yes. 6:32 First mistake. 6:32 Second mistake. 6:34 If a guy is saying, I want to check if this is PNG and I want to be sure that it has that PNG in the beginning, what is the catch here? 6:47 Do you have the answer on this? 6:49 So again, this is a logical task for you. 6:53 Most likely you will not be able to answer because it has some technical behind it. 6:59 So, guy is checking if this is PNG extension and if it is PNG by the beginning of the file. 7:08 So, how can you possibly upload the malicious... 7:14 PHP file there. 7:16 Script. 7:16 We'll check. 7:17 Extension is PNG. 7:20 How it will check it? 7:20 It will say file name has .png. 7:24 Maybe you will put png.php. 7:27 Maybe you will put. 7:29 PNG.php. 7:34 Or developer will say, I'm smart enough. 7:37 I know this trick. 7:39 You will not fool me. 7:40 So PHP is not allowed. 7:42 You cannot put, for example, PHP, right? 7:47 So the guy will do and say, okay. 7:51 He will just go. 7:53 Here and say list me list me all executable 8:01 names for php like php3 so what server will be executing php5 php5 to 3 8:12 So this one, no, this is not. 8:16 I talk about extensions similar to PHP, which will execute. 8:26 On Apache server. 8:29 So I'm just telling you how guys are finding the way. 8:33 So all those extensions, all those extensions will execute on the server. 8:38 So guy need to put all those extensions. 8:43 Or he can be just smart and, you know, just put that. 8:46 From this folder, only PNG can be stopped. 8:49 And also, smart developer will take that image, will process it, will redo it, will resize it, and after put it. 9:02 And during the resize, it will just be destroyed. 9:05 So all that stuff... 9:07 Which you will upload, most likely will cause server to run it. 9:12 You get the point. 9:13 This is not about shell.php, .jpg, image, phtml. 9:21 Also, there is a very funny story that Apache server 9:28 If you will upload shell.php.gpg or png, it will execute the first extension, which it sees. 9:38 But if you put it in the end, it will also execute it because it is like PHP in the end of the day. 9:45 So it cannot execute PNG, right? 9:48 So it will say, okay, PHP is there. 9:50 In the end, this is legitimate. 9:51 Okay, PHP is here. 9:53 Let's run it. 9:54 So I don't know how they go to that level. 9:57 But in reality, if you will upload something like this, you know, it will execute PHP.
0:00 Music 0:07 Let me show you some patterns so you will understand how vulnerabilities, you know, 0:15 Just get to exist. 0:17 Those are examples of vulnerable code. 0:23 I understand maybe it can sound like, you know, a little bit complex or not. 0:27 But look, guys, vulnerable code can be like two or three lines of code. 0:34 So in this example, you know, you can see that, 0:40 That guy is just using the library, which is legitimate for Python, which is called Pickle. 0:48 How that works? 0:50 So you take the data, you serialize it. 0:54 It means you just, you know, make it like... 0:58 archive, and after you release it. 1:01 So this is for data transferring inside the Python. 1:04 So this little, you know, three line of code, it's already vulnerable. 1:11 If you will just, you know, enter here malicious stuff, for example, 1:17 If you will enter here the command which will allow you to go to my server, download malicious script and run it, it will do it. 1:27 So if here you are putting as input my name, when I am going to register, I'm not going to put Bogdan. 1:35 I'm going to say malicious, blah, blah, blah, blah, blah, blah, blah, blah, blah. 1:40 So look, just an example. 1:45 If you are writing the source code, right, and you have that type of 1:51 Stuff. 1:52 So. 1:55 Let's go to chat and ask, what is this? 1:57 What is this? 1:59 I want to use pickle. 2:03 Look, it will rewrite me the code. 2:08 So now it made it more secure. 2:12 It is still using the pickle, but it is using it more secure way. 2:20 I want to use pickle with more secure method. 2:32 So. 2:35 You see, it is just trying to put some additional security controls. 2:39 But in reality, it can just make it, you know, make it three lines. 2:47 This guy is just going crazy, you know, in cybersecurity, just too much. 2:52 Very good developer. 2:55 Okay, like this. 2:57 So this is how it will be more secure. 3:03 So yeah, so it looks like you need to make it like more complex. 3:10 Like this, you cannot just use it. 3:12 But if you will go... 3:15 pickle, Python example, right? 3:19 You will see that this is guide, which will be used by developers, and they will just copy it. 3:30 Import pickle, and that's it. 3:32 So guys, just go to internet, they copy it, 3:35 And they use it. 3:37 So this happens all the time. 3:40 There is nothing around security here. 3:46 So open, pickle load. 3:52 Where is load? 3:53 Pickle load. 3:54 Great. 3:55 Just great. 3:56 Now think about this. 3:57 Guy will send a file, for example, his picture. 4:03 It will just take the picture. 4:06 make, you know, it's serialized, send it somewhere and open it. 4:12 Now think about this. 4:13 In picture, you can input Python code. 4:18 This is no difference if you're sending picture, if you're sending XZ, whatever. 4:22 And if server will say, this is not picture, you will say, it is not picture. 4:28 How do you know? 4:30 You will go and read how it knows that this is not picture, right? 4:34 And it will say, picture should have this. 4:36 It will say, if picture should have this, I will put it here. 4:41 Or down. 4:42 So when the script will work, right, that stuff, you will see it. 4:49 Or you just try to input it somewhere where server will read it, but it will not affect the execution of script. 4:56 So another example, PHP shell code PDF. 5:03 PNG. 5:05 PNG. 5:07 So, just for your knowledge, how guys are going this crazy level. 5:16 So, developer is saying, you can only upload PNG. 5:23 If you will not upload PNG, I will not allow this file. 5:29 Right? 5:29 So sounds, you know, serious. 5:32 Now let's imagine that the guy is just putting inside PNG, inside PNG, in the metadata, 5:44 PHP code. 5:46 Somebody expected this? 5:47 No. 5:49 So in the author name of the image is PHP code. 5:55 For example, so, you know, and during the parsing or during the analysis or during, you know, whatever, it will execute. 6:07 Why? 6:08 Okay, I will tell you why. 6:10 You see the extension here is .php. 6:14 So potentially when guy was uploading it, it didn't check the extension, but it checked this image. 6:22 This is first mistake, right? 6:24 So the guy was like, this is PNG? 6:28 Yes. 6:29 Do we allow it? 6:30 Yes. 6:32 First mistake. 6:32 Second mistake. 6:34 If a guy is saying, I want to check if this is PNG and I want to be sure that it has that PNG in the beginning, what is the catch here? 6:47 Do you have the answer on this? 6:49 So again, this is a logical task for you. 6:53 Most likely you will not be able to answer because it has some technical behind it. 6:59 So, guy is checking if this is PNG extension and if it is PNG by the beginning of the file. 7:08 So, how can you possibly upload the malicious... 7:14 PHP file there. 7:16 Script. 7:16 We'll check. 7:17 Extension is PNG. 7:20 How it will check it? 7:20 It will say file name has .png. 7:24 Maybe you will put png.php. 7:27 Maybe you will put. 7:29 PNG.php. 7:34 Or developer will say, I'm smart enough. 7:37 I know this trick. 7:39 You will not fool me. 7:40 So PHP is not allowed. 7:42 You cannot put, for example, PHP, right? 7:47 So the guy will do and say, okay. 7:51 He will just go. 7:53 Here and say list me list me all executable 8:01 names for php like php3 so what server will be executing php5 php5 to 3 8:12 So this one, no, this is not. 8:16 I talk about extensions similar to PHP, which will execute. 8:26 On Apache server. 8:29 So I'm just telling you how guys are finding the way. 8:33 So all those extensions, all those extensions will execute on the server. 8:38 So guy need to put all those extensions. 8:43 Or he can be just smart and, you know, just put that. 8:46 From this folder, only PNG can be stopped. 8:49 And also, smart developer will take that image, will process it, will redo it, will resize it, and after put it. 9:02 And during the resize, it will just be destroyed. 9:05 So all that stuff... 9:07 Which you will upload, most likely will cause server to run it. 9:12 You get the point. 9:13 This is not about shell.php, .jpg, image, phtml. 9:21 Also, there is a very funny story that Apache server 9:28 If you will upload shell.php.gpg or png, it will execute the first extension, which it sees. 9:38 But if you put it in the end, it will also execute it because it is like PHP in the end of the day. 9:45 So it cannot execute PNG, right? 9:48 So it will say, okay, PHP is there. 9:50 In the end, this is legitimate. 9:51 Okay, PHP is here. 9:53 Let's run it. 9:54 So I don't know how they go to that level. 9:57 But in reality, if you will upload something like this, you know, it will execute PHP.