Web Hack List

Other nomination

Timothy Morgan -- What You Didn't Know About XML External Entity Attacks

Morgan's AppSec USA 2013 deck pushes XXE past 'unexploitable'. Parameter entities plus a remote DTD wrap unreadable files in CDATA or exfiltrate them out-of-band through a dynamically built URL. He catalogues the URL schemes each parser enables by default and shows Java's jar: handler uploading files by stalling a download and racing the temp file, ending in Tomcat RCE.

Record

Researcher
Timothy D. Morgan
Published by
2013.appsecusa.org
Format
Recording

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Timothy D. Morgan, first published at the original source. Preserved copies are kept so the citation survives its host.