Advanced XXE Injection

4 months ago 38
BOOK THIS SPACE FOR AD
ARTICLE AD

A Bug Hunter’s Poetic Reflection of a Blind Type Injection vulnerability

Quintius Walker

ILLUMINATION

Photo by Amber Weir on Unsplash

Vulnerabilities
are not always
straightforward to exploit,

And all the ones that are

they can be found
with Metasploit.

So some formats
won’t be readable
through basic X-X-E,

And if you think
your payload
is repeatable
Let’s see.

screenshot of author’s computer

Since the web app
may not show us
any values through reflection,

we cannot
see the output
like we did
in other sections.

No denying….
that we must hide
our variables
with filters,

En-code our files
like Jesus did
in parables
through scriptures.

Read Entire Article