Lesson 3 · 20 min

Blind XXE via an external DTD

No reflection, no errors — exfiltrate over HTTP with parameter entities.

This lesson is locked

Enrol in XML External Entity (XXE) Injection to unlock this lesson and the rest of the curriculum.

0.0110 BTC
Sign In to Enrol