Collected research
Timothy Morgan -- What You Didn't Know About XML External Entity Attacks
What You Didn't Know About XML External Entities Attacks
Morgan's AppSec USA 2013 deck pushes XXE past 'unexploitable'. Parameter entities plus a remote DTD wrap unreadable files in CDATA or exfiltrate them out-of-band through a dynamically built URL. He catalogues the URL schemes each parser enables by default and shows Java's jar: handler uploading files by stalling a download and racing the temp file, ending in Tomcat RCE.
Record
- Document
- What You Didn't Know About XML External Entities Attacks
- Researcher
- Timothy D. Morgan
- Published by
- 2013.appsecusa.org
- Format
- Recording
- Topic
- Other
In the archive
Related sources
- What You Didn't Know About XML External Entity Attacks Whitepaper
- What You Didn't Know About XML External Entities Attacks - Timothy Morgan
Tags
This page is the archive's own catalogue record. The research is the work of Timothy D. Morgan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .