logo

XML External Entity – Beyond /etc/passwd (For Fun & Profit)

ID: a0febc52-9a5e-50c3-8792-476bc7856921

STIX ID: report--a0febc52-9a5e-50c3-8792-476bc7856921

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-04-27

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post provides a hands-on tutorial for exploiting XML External Entity (XXE) vulnerabilities: it shows a vulnerable PHP XML parser, example payloads to exfiltrate files and issue HTTP requests from the server, techniques to base64-encode responses, an internal web scanning script, and a complete pivoting chain culminating in a reverse shell against an internal host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.