Explore the security implications of XML technologies in this 47-minute conference talk from Hack in Paris. Delve into a year-long research on XML format and processing practices, covering targets from browsers to enterprise-level security solutions and web-service back-ends. Examine key technologies including XML grammar (DTD), homo-iconicity, self-contained dynamic SVG images, design and implementation vulnerabilities in XSLT and XPath engines, in-memory exploitation of Java-based XSLT engines, and XML databases. Learn about systematically released proof-of-concept code for patched vulnerabilities, gaining valuable insights into potential security risks and mitigation strategies in XML processing.
Overview
Syllabus
Nicolas Gregoire Attacking XML Processing
Taught by
Hack in Paris