Skip to main content

xxe

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
June 2, 2026 at 17:42
Detected SKILL.md language
English
Stars
5,611
Forks
1,061

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
xxe
description
Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.
metadata
{"subdomain":"web-exploitation","when_to_use":"xxe xml external entity parser file read ssrf cwe-611 dtd parameter entity blind oob"}
# XXE Playbook ## Find parser sinks - Java: `DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory` - Python: `lxml.etree`, `xml.dom.minidom`, `xml.sax` - .NET: `XmlDocument`, `XDocument`, `XmlReader` ## Dangerous defaults - DTD enabled - External entities enabled - Network/file entity resolution enabled ## Payloads - File read: entity to `file:///etc/passwd` - SSRF: entity to internal URL (metadata service, localhost admin) ## Validation - Positive: parser output contains file content or internal response markers. - Negative: same XML without entity expansion must not leak content.
View on GitHub