04Modules
Error-based XXE Technique
Medium45MIN
What if there is no printout?
So far, we have familiarized ourselves with the so-called reflected (reflected) XXE vulnerabilities, where something is returned from XML back to the browser. In such cases, exploiting the vulnerability is usually quite easy, as the attacker only needs to add the SYSTEM entity to the XML in the appropriate place within the XML. But what if there is no output after all?
In such cases, we can often resort to leaking data through some side channel. In this module, we focus on error-based techniques, where the goal is to force the application to throw an error message containing the content of the desired file.
1 / 9
Hakatemia Pro
Learn to hack — start here
Hundreds of interactive courses, virtual labs and CTF challenges in your browser. Start a free trial — no card required.