Other nomination
Timothy Morgan -- What You Didn't Know About XML External Entity Attacks
Morgan's AppSec USA 2013 deck pushes XXE past 'unexploitable'. Parameter entities plus a remote DTD wrap unreadable files in CDATA or exfiltrate them out-of-band through a dynamically built URL. He catalogues the URL schemes each parser enables by default and shows Java's jar: handler uploading files by stalling a download and racing the temp file, ending in Tomcat RCE.
Record
- Researcher
- Timothy D. Morgan
- Published by
- 2013.appsecusa.org
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Timothy D. Morgan, first published at the original source. Preserved copies are kept so the citation survives its host.