Skip to main content

xxe

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

Zur Installation springen

Quellinformationen

Repository
BitterSecurity/Decepticon
Letzte Quellaktivität
2. Juni 2026 um 17:42
Erkannte Sprache von SKILL.md
Englisch
Sterne
5.611
Forks
1.061

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
xxe
description
Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.
metadata
{"subdomain":"web-exploitation","when_to_use":"xxe xml external entity parser file read ssrf cwe-611 dtd parameter entity blind oob"}
# XXE Playbook ## Find parser sinks - Java: `DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory` - Python: `lxml.etree`, `xml.dom.minidom`, `xml.sax` - .NET: `XmlDocument`, `XDocument`, `XmlReader` ## Dangerous defaults - DTD enabled - External entities enabled - Network/file entity resolution enabled ## Payloads - File read: entity to `file:///etc/passwd` - SSRF: entity to internal URL (metadata service, localhost admin) ## Validation - Positive: parser output contains file content or internal response markers. - Negative: same XML without entity expansion must not leak content.
Auf GitHub ansehen