Web Hack List

Later archive addition

Automating local DTD discovery for XXE exploitation

The article automates discovery of reusable local DTD files for XXE exploitation when outbound retrieval of an attacker-hosted DTD is unavailable. DTD Finder inventories packaged DTDs, enumerates overridable entities, tests five injection patterns, and emits working error-based file-read payloads.

Record

Researcher
@h3xStream

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @h3xStream, first published at the original source. Preserved copies are kept so the citation survives its host.