Web Hack List

Collected research

FileCry - The New Age of XXE

FileCry

Internet Explorer up to version 11 can be pushed back onto the vulnerable MSXML3 parser via a compatibility-mode meta tag, and its XML external entity resolution does not re-check the same-origin policy after a redirect. A malicious page can therefore read cross-origin JSON endpoints authenticated by cookies, and arbitrary local files, with no user prompt.

Record

Document
FileCry
Researcher
Hormazd Billimoria, Xiaoran Wang, Sergey Gorbaty and Jonathan Brossard
Published by
blackhat.com
Format
Recording
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Hormazd Billimoria, Xiaoran Wang, Sergey Gorbaty and Jonathan Brossard, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .