15–25 min Updated

XML Bombs

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Unsafe treatment of XML entities can make your server vulnerable to attack from specially crafted XML files.

Prevalence
Rare
Exploitability
Easy
Impact
Devastating

What is an XML bomb?

An XML bomb is a denial of service attack in which an attacker uploads a small XML file that uses nested entity definitions to expand to an enormous size when parsed. The best known example is the billion laughs attack. Parsing the file exhausts the server's memory, taking the application offline for legitimate users.

What you'll learn

  • How inline DTDs let an XML document define its own entities
  • How nested entities expand a small file into gigabytes of data
  • Why you should disable inline DTD parsing in your XML parser

Where this lesson counts

OWASP Top 10

  • XML Bombs lab

    See how inline DTDs let an XML document define its own entities, then watch the billion laughs attack unfold step by step. A few lines of nested entity definitions expand into about three gigabytes of data, enough to crash the server parsing them.

  • How to prevent XML Bombs

    The prevention guide covers three approaches:

    • Disable Parsing of Inline DTDs
    • Consider Making XML Parsing Asynchronous
    • Throttle Uploads Per Client
  • XML Bombs quiz

    Two questions. Passing marks the lesson complete.

  • XML External Entities

    Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.

  • Denial of Service Attacks

    Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.

  • Regex Injection

    Regular expressions are frequently used in web-development, but can be abused by attackers.