XML External Entity – Beyond /etc/passwd (For Fun & Profit)
ATT&CK techniques detected
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Summary
<p><img alt="" class="attachment-full size-full wp-post-image" height="857" src="https://www.blackhillsinfosec.com/wp-content/uploads/2017/04/ahhh_pivot.png" width="742" /></p> <p>Robert Schwass*//   Last week I was asked twice in one day if I knew what XML External Entity (XXE) Vulnerabilities were. Maybe they are making a comeback in mainstream security […]</p> <p>The post <a href="https://www.blackhillsinfosec.com/xml-external-entity-beyond-etcpasswd-fun-profit/">XML External Entity – Beyond /etc/passwd (For Fun & Profit)</a> appeared first on <a href="https://www.blackhillsinfosec.com">Black Hills Information Security, Inc.</a>.</p>