Web Hack List

Top 10 winner

Exploiting XXE with local DTD files

Blind XXE usually needs an attacker-hosted DTD because the internal subset forbids a parameter entity inside markup. Loading a DTD file that already exists on the target host and redefining one of its parameter entities smuggles that nesting into the internal subset, so file contents are returned in a parser error message with no outbound network access.

Record

Researcher
Arseniy Sharoglazov and @_mohemiv
Published by
mohemiv.com
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Arseniy Sharoglazov and @_mohemiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .