Blind XXE with out-of-band interaction via XML parameter entities

Exploitation
the lab has a "check stock" feature that parses XML input

send to repeater

the portswigger labs doesn't allow third partie servers so we have to use collaborator urls instead

so the website is restricting the use of Entities.

let's use parameter entities and try if it will work



hope you found this walkthrough easy to understand and follow
Greeting From Sayonara
PreviousBlind XXE with out-of-band interactionNextExploiting blind XXE to exfiltrate data using a malicious external DTD
Last updated
Was this helpful?