11.8 Lab: Exploiting XXE via image file upload | 2024

8 months ago 66
BOOK THIS SPACE FOR AD
ARTICLE AD

This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files. To solve the lab, upload an image that displays the contents of the /etc/hostname file after processing. Then use the “Submit solution” button to submit the value of the server hostname | Karthikeyan Nagaraj

Karthikeyan Nagaraj

This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.

To solve the lab, upload an image that displays the contents of the /etc/hostname file after processing. Then use the "Submit solution" button to submit the value of the server hostname.

Open a Terminal and save the below code into a file with .svg Extension

2. Now, Click a Blog Post and Fill in some details on it.

3. Upload the SVG file that you created.

4. Then, right click on the image, click Open Image in New tab.

5. Note down the value and paste it into the solution to solve the Lab.

Read Entire Article