The Type of Bug That We Can’t See

4 months ago 35
BOOK THIS SPACE FOR AD
ARTICLE AD

Advanced XXE Injection- The Blind and CDATA Kind

Quintius Walker

Photo by Osarugue Igbinoba on Unsplash

Continuing with our research into XXE Injections.

Vulnerabilities
are not always
straightforward to exploit,

And all the ones that are
they can be found
with Metasploit.

So some formats
won’t be readable
through basic X-X-E,

And if you think
your payload
is repeatable
Let’s see.

Since the web app
may not show us
any values through reflection,

we cannot
see the output
like we did
in other sections.

No denying…. that we must hide
our variables
with filters,

En-code our files
like Jesus did
in parables
through scriptures.

Read Entire Article