XML Bombs
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Unsafe treatment of XML entities can make your server vulnerable to attack from specially crafted XML files.
- Prevalence
- Rare
- Exploitability
- Easy
- Impact
- Devastating
What is an XML bomb?
An XML bomb is a denial of service attack in which an attacker uploads a small XML file that uses nested entity definitions to expand to an enormous size when parsed. The best known example is the billion laughs attack. Parsing the file exhausts the server's memory, taking the application offline for legitimate users.
What you'll learn
- How inline DTDs let an XML document define its own entities
- How nested entities expand a small file into gigabytes of data
- Why you should disable inline DTD parsing in your XML parser
Where this lesson counts
OWASP Top 10
Default accounts, verbose errors, unhardened parsers and permissive headers leave the door open.
Learn more about A02This lesson includes
-
XML Bombs lab
See how inline DTDs let an XML document define its own entities, then watch the billion laughs attack unfold step by step. A few lines of nested entity definitions expand into about three gigabytes of data, enough to crash the server parsing them.
-
How to prevent XML Bombs
The prevention guide covers three approaches:
- Disable Parsing of Inline DTDs
- Consider Making XML Parsing Asynchronous
- Throttle Uploads Per Client
-
XML Bombs quiz
Two questions. Passing marks the lesson complete.
Related lessons
Browse all 45 lessons
XML External Entities
Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.
Denial of Service Attacks
Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.
Regex Injection
Regular expressions are frequently used in web-development, but can be abused by attackers.