3. XML External Entity XXE Injection
Introduction to XXE
XML Basics
XML Structure:
Exploitation Techniques
1. Local File Disclosure
2. Source Code Disclosure (PHP Filter)
3. Remote Code Execution (RCE) with Expect
4. CDATA Exfiltration via External DTD
5. Error-Based XXE with External DTD
6. Out-of-Band (OOB) Exfiltration with External DTD
7. Automated XXE Exploitation with XXEinjector
XXE Prevention
Key Takeaways
Last updated