Web Apps
Intermediate
XML External Entity (XXE) Injection
Abuse XML parsers that resolve external entities to read local files, reach internal services (SSRF), and exfiltrate data blind through an external DTD.
Beaulah Marks
4 lessons
About this class
What you'll learn
XXE occurs when an application parses XML input and the parser is configured to resolve external entities. This class covers a DTD primer, in-band file read and SSRF, blind exfiltration via an attacker-hosted DTD, finding hidden XML attack surface, and prevention.
Practice
Pair with XXE for local file disclosure and blind XXE via a malicious external DTD.
Curriculum
On this page
Price
0.0110 BTC≈ $715.00
At a glance
- Category
- Web Apps
- Difficulty
- Intermediate
- Lessons
- 4 ยท 2 free
- Total time
- 1h
- Students
- 0 enrolled
- Tutor
- Beaulah Marks
- Published
- Sep 2026