Skip to main content

xxe

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

Ir para a instalação

Informações da origem

Repositório
BitterSecurity/Decepticon
Última atividade na origem
2 de junho de 2026 às 17:42
Idioma detectado do SKILL.md
inglês
Estrelas
5.611
Forks
1.061

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
xxe
description
Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.
metadata
{"subdomain":"web-exploitation","when_to_use":"xxe xml external entity parser file read ssrf cwe-611 dtd parameter entity blind oob"}
# XXE Playbook ## Find parser sinks - Java: `DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory` - Python: `lxml.etree`, `xml.dom.minidom`, `xml.sax` - .NET: `XmlDocument`, `XDocument`, `XmlReader` ## Dangerous defaults - DTD enabled - External entities enabled - Network/file entity resolution enabled ## Payloads - File read: entity to `file:///etc/passwd` - SSRF: entity to internal URL (metadata service, localhost admin) ## Validation - Positive: parser output contains file content or internal response markers. - Negative: same XML without entity expansion must not leak content.
Ver no GitHub