XML External Entity Injection (XXE) - Episode 3 of hacking the Gin and Juice shop; an intentionally vulnerable web application developed by Portswigger. The website was created primarily to demonstrate the features of Burp pro vulnerability scanner. However, throughout the series, we will leverage burp suite (and other tools) to exploit the high, medium, low and informational issues identified by the scanner. Hopefully these videos will be useful for aspiring bug bounty hunters, security researchers, pentesters, CTF players etc 🙂 #BugBounty #EthicalHacking #PenTesting #AppSec #WebSec #InfoSec #OffSec
↢Portswigger: Gin and Juice Shop↣
https://ginandjuice.shop
https://portswigger.net/blog/gin-and-...
https://portswigger.net/burp/vulnerab...
https://portswigger.net/web-security
👷♂️Resources🛠
https://cryptocat.me/resources
↢Chapters↣
0:00 Intro
1:17 XML/XXE basics
3:42 Review scan results
4:25 Recreate the vulnerability (XXE)
5:39 XXE to retrieve files
6:28 XXE to SSRF
8:21 Blind XXE (data exfiltration)
11:39 Find hidden attack surface
12:33 Conclusion