XML External Entities
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.
- Prevalence
- Rare
- Exploitability
- Difficult
- Impact
- Devastating
What is an XML external entity (XXE) attack?
An XML external entity (XXE) attack is an injection attack against applications that parse XML. The attacker submits a document declaring an external entity that points to a local file or internal URL, and a misconfigured parser fetches it and includes the contents. Attackers use it to read sensitive files and probe internal networks.
What you'll learn
- How external entities make an XML parser fetch files and URLs
- How an attacker reads server files through a parser error message
- How disabling inline DTDs and limiting server permissions contain the risk
Where this lesson counts
OWASP Top 10
Default accounts, verbose errors, unhardened parsers and permissive headers leave the door open.
Learn more about A02This lesson includes
-
XML External Entities lab
Mal finds a social network whose OpenID login fetches and parses XML. Follow him as he hosts a file with an external entity pointing at /etc/shadow, feeds its URL to the login and gets the server's password file back inside an error message.
-
How to prevent XML External Entities
The prevention guide covers two approaches:
- Disable Parsing of Inline DTDs
- Limit the Permissions of Your Web Server Process
-
XML External Entities quiz
Two questions. Passing marks the lesson complete.
Sources
- XML external entity (XXE) injection PortSwigger
- What is XML External Entity (XXE)? Acunetix
- XML External Entity (XXE) Processing OWASP
Related lessons
Browse all 45 lessons
XML Bombs
Unsafe treatment of XML entities can make your server vulnerable to attack from specially crafted XML files.
Server-Side Request Forgery
An attacker can use SSRF vulnerabilities to probe your internal network.
Information Leakage
Revealing system information helps an attacker learn about your tech stack.
File Upload Vulnerabilities
File uploads are an easy way for an attacker to inject malicious code into your application.