ArticleExploiting XXE via image file upload
Exploiting XXE via image file upload: This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.…
Practical security research, write-ups, guides, and lessons learned.
ArticleExploiting XXE via image file upload: This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.…
ArticleExploiting XXE to retrieve data by repurposing a local DTD: This lab’s Check stock feature parses XML input but does not display the result. • PortSw…
ArticleExploiting XInclude to retrieve files: This lab has a Check stock feature that embeds user input inside a server side XML document, which is then par…
ArticleExploiting blind XXE to retrieve data via error messages: Lab: XXE with External DTD and Error Based Exfiltration • PortSwigger • XXE • conditional,…
ArticleSQL injection vulnerability in WHERE clause allowing retrieval of hidden data: This lab exposes a SQL injection vulnerability in the product category…
ArticleExploiting blind XXE to exfiltrate data using a malicious external DTD: This lab’s Check stock feature parses XML but doesn't reflect output. My goal…
ArticleBlind XXE with out of band interaction via XML parameter entities: The Check stock endpoint parses XML but: Doesn’t display unexpected values (blind…
ArticleBlind XXE with out of band interaction: The Check stock endpoint parses XML but does not display results. I need to detect blind XXE by triggering ou…
ArticleExploiting XXE to perform SSRF attacks: The Check stock endpoint parses XML and reflects unexpected values in the response. The lab simulates an EC2…
ArticleWhat is XML and XXE and how does it work?: XXE:r XML External Entity Injection What is XML External Entity Injection? XML External Entity Injection (…
ArticleBlind SQL injection with conditional responses Part 1: Blind SQL Injection Lab – Tracking Cookie Exploit This lab contains a blind SQL injection vuln…
ArticleBlind SQL injection with conditional responses part 2: The TrackingId cookie is vulnerable to boolean‑based blind SQL injection. The app leaks a sign…