3 ms·
On a related note, the XML standard defines a way to include external files in the document. If you come across a service which replies with a part of your requ
by didymospl 7y ago
On a related note, the XML standard defines a way to include external files in the document. If you come across a service which replies with a part of your request(e.g. validation errors) and uses XML parser with this feature turned on, which is true by default in many cases, this can be used to read arbitrary files. I wonder how many poorly maintained enterprise systems systems are vulnerable to that.
https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Pr...
- amlozano 7y agoAbout a year and a half ago it was a very common vulnerability to find when doing web application assessments. Especially if uploading Excel spreadsheets was somehow involved. Its less common now that most major parsers are turning this feature off by default though.
- Sohcahtoa82 7y agoXXE is a feature that never should have happened. Whoever decided that not only should it be a thing, but that it should be enabled by default, needs to have their keyboard taken away.