XML External Entity (XXE)
Source: https://www.synack.com/blog/a-deep-dive-into-xxe-injection/
What are XML and DTD and Entities?
<!DOCTYPE STRUCTURE [
<!ELEMENT SPECIFICATIONS (#PCDATA)>
<!ENTITY VERSION “1.1”>
<!ENTITY file SYSTEM “file:///c:/server_files/application.conf” >
]><?xml version=”1.0″ encoding=”UTF-8″?>
<!DOCTYPE foo SYSTEM “http://validserver.com/formatting.dtd”>
<specifications>&file;</specifications>Video Explaination
Regular Injection
Out of band

Pass the SOAP



Recon with XXE (Post Exploitation)



XXE to RCE
Last updated