Later archive addition
From XML External Entity to NTLM Domain Hashes
A blind XXE in an internet-facing ASP.NET API is chained with Windows network authentication. By making the XML parser access an attacker-controlled UNC path through an external DTD, the server initiates SMB authentication and discloses an NTLM challenge-response hash for offline cracking or relay.
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.