Web Hack List

Collected research

Timothy Morgan -- What You Didn't Know About XML External Entity Attacks

What You Didn't Know About XML External Entities Attacks

Morgan's AppSec USA 2013 deck pushes XXE past 'unexploitable'. Parameter entities plus a remote DTD wrap unreadable files in CDATA or exfiltrate them out-of-band through a dynamically built URL. He catalogues the URL schemes each parser enables by default and shows Java's jar: handler uploading files by stalling a download and racing the temp file, ending in Tomcat RCE.

Record

Document
What You Didn't Know About XML External Entities Attacks
Researcher
Timothy D. Morgan
Published by
2013.appsecusa.org
Format
Recording
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Timothy D. Morgan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .