All language subtitles for 1. Introduction to the Web Security Academy Series

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Hi everyone, welcome to the first video of my channel.

I'm very excited to finally be sharing the series with you, so I'm going to jump right

ahead and talk about the type of videos that you'll be seeing in the next upcoming months.

So the series is going to be called the Web Security Academy series, and that's because

we'll be using the Web Security Academy platform that is developed by Port Swigger.

For those of you that have never heard of the Web Security Academy, it's essentially

a free online training platform for web application security.

Again, it was developed by the Port Swigger research team, and one of the authors is actually

the author of the Web Application Hacker's handbook, which is considered to be the Bible

of Web Application Security.

This is the book that I personally read and studied from when I first got started in this

field, and I'm a huge fan of it.

The book hasn't been updated since about 2011.

The fundamentals are still the same, and I always recommend it to anyone that asks me

how to get started in this field.

That being said, I do recognize that we are in a constantly evolving field with new vulnerabilities

and attack vectors coming out every day, and so I've always recommended this book with

additional outside resources that tackled modern web technologies.

However, when I heard that the author of the book had started a Web Security Academy,

I obviously immediately signed up and just like I'm a huge fan of the book, I'm also

a huge fan of the Academy, and so now whenever anyone asks me, I recommend the Web Application

Hacker's handbook for the fundamentals and the Web Security Academy for hands-on experience.

Now, before we continue, it's worth mentioning that I'm not in any way affiliated to Port

Swiggar.

This is just me sharing a platform that I think is very useful to the community.

All right, let's go to their website and look at the type of training that they provide.

So to access the Academy, visit portswiggar.net slash Web Security.

You'll be presented with this page over here where you could sign up in order to access

the labs.

We're not going to do that.

Instead, we're going to go down and click on View All Learning Materials.

This presents you with the page that lists all the topics that the Academy covers.

We're going to go down one more time and click on Web Security Academy.

Okay, so most people don't know that the Academy has a learning path, so this is essentially

the suggested learning path by Port Swiggar or anyone that is either new to Web Security

or doesn't know which topic to begin with.

And it's a path that we'll be following in our videos.

It's divided into three sections, so server-side topics, client-side topics, and advanced topics.

For the server-side topics, it covers the vulnerabilities that affect the backend of

the application.

Examples include SQL injection, command injection, SSRF, server-side request forgery, and so

on.

For the second section, client-side topics, that covers the vulnerabilities that affect

the front end of the application.

So a common example is cross-site scripting, clickjacking, vulnerabilities that affect

WebSockets.

So this is not common, but definitely an interesting class of vulnerabilities to look into.

And then you've got the advanced topics, so topics that require vulnerabilities that require

a deeper understanding of the material.

And examples include insecurity serialization, server-side template injection.

So this is definitely relevant to modern technologies, and same goes with this one, OAuth

authentication, and so on.

And you'll see each topic has a bunch of labs associated to it.

So the nice thing that I like about the Academy is the fact that it can be easily updated.

So unlike the book, which hasn't been updated since 2011, you'll see that the Academy is

constantly updated by the Portzweger team.

So you'll see them add new labs to existing topics or new topics as a whole.

And the vulnerabilities that they cover in the Academy are realistic vulnerabilities that

are found in the wild.

All right, let's go back to the slides and talk about how the videos complement the Web

Security Academy.

So my vision for the videos is that if you follow the, if you watch the videos, you do

the exercises in the Academy, and you have the book as a reference.

So you read the book, then you would be up to an intermediate level of knowledge in terms

of your web application pentesting skills.

So to get to an advanced level, you obviously need years of real-world experience.

However, if you have these three resources, if you follow these three resources, then

you should be above a beginner level, about an intermediate level in terms of your knowledge.

So the videos will essentially just complement the Academy and the book.

We'll be following the same learning path that Portzweger recommended.

And so we'll start off with the SQL injection module.

For each module, we'll have two types of videos, theory videos and lab videos.

For the theory videos, we'll cover the background knowledge that is required in order to do

the hands-on exercises.

So we'll cover the technical details of the vulnerability, how to detect it, so how to

find it, how to exploit it, and then how to prevent it.

The pictures that you see on the slides over here are from the SQL injection theory video

that is coming out next week.

And that's something that I forgot to mention earlier.

Videos are scheduled to come out on a weekly basis.

Now for the theory, videos will go more in depth than the Academy in terms of technical

details and it will be more in line with the web application hacker's handbook.

Okay, now once you have the background knowledge, we'll jump into the lab exercises.

Each lab has a dedicated video where we exploit the vulnerability manually first and then we

script it.

That's something that I'm really focusing on in the labs.

I believe that to be an effective pen tester, you do need to know at least one scripting

language.

And you'll see a lot of debate about this online, but the reality is during your pen testing

career, you will come across situations where it's very unrealistic that you can exploit

a vulnerability using only manual means.

And a classic example of that that we'll see in the videos and in the labs is Boolean-based

blind SQL injection where you're stuck asking the application to unfalse questions.

And if you want to properly exploit that vulnerability and extract, for example, password hashes or

reset tokens, you need to send hundreds if not thousands of requests to the application.

So if you don't know how to script it, all you would have to show to the client is the

fact that there is a blind SQL injection vulnerability because that's easy.

That can be done with one request.

However, you can't really show the detrimental effect of exploiting that vulnerability.

So that's why in each lab, we will script the exploit regardless of how trivial it is.

And our programming language of choice is going to be Python 3.

All right.

That's how the videos will be structured.

Now let's discuss the type of individuals that will find the videos useful.

The first obvious answer is our individuals that are trying to get into the web application

pen testing field.

Again, I've mentioned this earlier and I'll mention it over here.

If anyone asks me how to get into this field, I always recommend the web application hackers

handbook for the fundamentals and the web security academy for hands-on experience.

And these videos will just complement those two resources.

Up next, we've got the web developers.

So the idea is that we develop secure applications from the get go.

And so learning how web app pen testers test applications that could be very useful to web

app developers when they're developing their applications.

And then we have the bug bounty hunter.

So I personally don't do bug bounty, but I do follow a bunch of people that have experience

in that field.

And I read the write-ups when their bugs get published.

And I can say for sure that the academy covers realistic vulnerabilities that are found in

the wild.

Up next, we've got the individuals who want to enroll in the OSWE.

So the offensive security web expert certification.

This might be the majority of you.

So this is a white box web application pen testing certification offered by offensive

security.

I'm currently working through the certification and I always get questions and get asked the

type of knowledge that people need before they enroll in the certification.

So how to prepare for the cert.

And I always mention it, and I'll mention it again over here, is that this certification

is definitely not an entry level certification.

And it's not advertised as an entry level certification.

So having gone through the material myself, you definitely need a year's worth of experience

in web app pen testing, whether that's through your profession or through bug bounty hunting

or through resources like this.

But you definitely need at least a year's worth of experience before you enroll in the

cert.

I'll have a separate video discussing my experience with the OSWE certification, but for now,

if you're looking to enroll in the cert sometime in the future, then a great resource would

be to first enroll in the web security academy and start learning about all the different

types of vulnerabilities that could potentially exist in applications.

Now another thing that we do in the video that would be very useful for the certification

is the fact that we script all of our exploits.

So in the certification, you're going to have to chain a bunch of vulnerabilities to first

bypass authentication and then to eventually gain remote code execution.

And that chain of vulnerabilities needs to be scripted in one script so that when you

run the script, it automatically does all that for you.

And that's what we do in the videos.

So if you gain a little bit of experience in that before you enroll in the cert, it's

definitely going to come in handy when you are working in the OSWE labs.

Okay, last but not least, I'm being a little bit ambitious with this last one, but everyone

else.

Anyone that is interested in this field, I'm sure you'll find something in these videos

useful.

And that wraps up the security academy series intro.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.