👩🎓👨🎓 Learn how you can run a successful XXE injection via an image upload functionality. We are going to achieve this by uploading an SVG (scalable vector graphics) file.
Overview:
00:00 Intro
00:21 Lab overview
01:22 What are SVG files?
02:24 How does the HTTP request look like?
03:06 Learning about payloads
03:51 Exploiting the app
05:36 Conclusion
For more information, check out https://blog.intigriti.com/hackademy/....
🔗 Portswigger XXE Challenge: https://portswigger.net/web-security/...
🔗 XXE Payloads on Github: https://github.com/swisskyrepo/Payloa...
---
🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register
👾 Join our Discord - https://go.intigriti.com/discord
🎙️ This show is hosted by / pascalsec (@Hacksplained ) & / intigriti
👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com/