Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

XML External Entity Injection (XXE) - Exploiting Web Application Vulnerabilities - Episode 3

CryptoCat via YouTube

Overview

Learn how to exploit XML External Entity (XXE) vulnerabilities in this 13-minute tutorial focused on hacking the Gin and Juice Shop, a deliberately vulnerable web application by Portswigger. Master essential XXE concepts including basic XML structure, scanning result analysis, file retrieval techniques, Server-Side Request Forgery (SSRF), and blind XXE data exfiltration methods. Explore practical demonstrations using Burp Suite and other security tools while discovering hidden attack surfaces. Perfect for aspiring bug bounty hunters, security researchers, penetration testers, and CTF players looking to enhance their web application security testing skills.

Syllabus

Intro
XML/XXE basics
Review scan results
Recreate the vulnerability XXE
XXE to retrieve files
XXE to SSRF
Blind XXE data exfiltration
Find hidden attack surface
Conclusion

Taught by

CryptoCat

Reviews

Start your review of XML External Entity Injection (XXE) - Exploiting Web Application Vulnerabilities - Episode 3

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.