XML external entities or ACSI, which is a four of the OWASP Top 10. Such molner abilities exist when poorly configured XML processors evaluate external entity references with XML documents. Exploitation of this vulnerability can result in disclosure of internal files using the urri handler. Internal file shares internal port scanning, remote code execution and denial of service attacks. Let's get started in a web goat lesson to demonstrate csy. You don't have Web go running at startup. Java jar. Let go filename. Open- server dot port. Make it 9090. Use the username and password you selected when you set this up or you don't have one register new user. Go to injection flaws.** Y. Here's the first part of the lesson. We need to list the contents of the root directory. Route is usually represented as a/ in Unix filesystems. Let's start up work sweet and turn intercepting on. Type in anything right here. Let's take a look at this XML code at the bottom. This is what's going to be processed by the XML processor of the web application. This is where we need to insert our EXE to instruct the system to list the root directory. Right here. Root directory is what is going to be listed. Let's forward that traffic. See the results. Here's the content of the root directory. Moving on to the next one. OK, we have some instructions here. Same exercise. Try to perform the same XML injection as we did in the first assignment. It mentions Jason.