15–25 min Updated

XML External Entities

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.

Prevalence
Rare
Exploitability
Difficult
Impact
Devastating

What is an XML external entity (XXE) attack?

An XML external entity (XXE) attack is an injection attack against applications that parse XML. The attacker submits a document declaring an external entity that points to a local file or internal URL, and a misconfigured parser fetches it and includes the contents. Attackers use it to read sensitive files and probe internal networks.

What you'll learn

  • How external entities make an XML parser fetch files and URLs
  • How an attacker reads server files through a parser error message
  • How disabling inline DTDs and limiting server permissions contain the risk

Where this lesson counts

OWASP Top 10

  • XML External Entities lab

    Mal finds a social network whose OpenID login fetches and parses XML. Follow him as he hosts a file with an external entity pointing at /etc/shadow, feeds its URL to the login and gets the server's password file back inside an error message.

  • How to prevent XML External Entities

    The prevention guide covers two approaches:

    • Disable Parsing of Inline DTDs
    • Limit the Permissions of Your Web Server Process
  • XML External Entities quiz

    Two questions. Passing marks the lesson complete.

Sources

  • XML Bombs

    Unsafe treatment of XML entities can make your server vulnerable to attack from specially crafted XML files.

  • Server-Side Request Forgery

    An attacker can use SSRF vulnerabilities to probe your internal network.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • File Upload Vulnerabilities

    File uploads are an easy way for an attacker to inject malicious code into your application.