9
Advanced XXE Exploitation Exercise 1 : Simple XXE (App port 8021) Philippe Arteau GoSecure Countertack 19/06/2019 Slides: http://bit.ly/xxeparis

Advanced XXE Exploitation Exercise 1 : Simple XXE (App

  • Upload
    others

  • View
    11

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

Advanced XXE ExploitationExercise 1 : Simple XXE (App port 8021)

Philippe ArteauGoSecure Countertack

19/06/2019Slides: http://bit.ly/xxeparis

Page 2: Advanced XXE Exploitation Exercise 1 : Simple XXE (App
Page 3: Advanced XXE Exploitation Exercise 1 : Simple XXE (App
Page 4: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

Running an HTTP server

$ python –m http.server 8888

(pick a port that is unused)

Page 5: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

Normal XML file

Page 6: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

Malicious XML file

Page 7: Advanced XXE Exploitation Exercise 1 : Simple XXE (App
Page 8: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

Directory listing

Page 9: Advanced XXE Exploitation Exercise 1 : Simple XXE (App

QuestionS ?

[email protected]/blog/@h3xStream @GoSecure_Inc