filmov
tv
What You Didn't Know About XML External Entities Attacks - Timothy Morgan
Показать описание
What You Didn't Know About XML External Entities Attacks - Timothy Morgan
The eXtensible Markup Language (XML) is an extremely pervasive technology used in countless software projects. Certain features built into the design of XML, namely inline schemas and document type definitions (DTDs) are a well-known source of potential security problems. Despite being a publicly discussed for more than a decade, a significant percentage of software using XML remains vulnerable to malicious schemas and DTDs. This talk will describe a collection of techniques for exploiting XML external entities (XXE) vulnerabilities, some of which we believe are novel. These techniques can allow for more convenient file content theft, sending of arbitrary data to arbitrary internal TCP services, uploads of arbitrary files to known locations on a vulnerable system, as well as several possible denial of service attacks. We hope this talk will raise awareness about the overall risk associated with XXE attacks and will provide recommendations that developers and XML library implementors can use to help prevent these attacks.
-
The eXtensible Markup Language (XML) is an extremely pervasive technology used in countless software projects. Certain features built into the design of XML, namely inline schemas and document type definitions (DTDs) are a well-known source of potential security problems. Despite being a publicly discussed for more than a decade, a significant percentage of software using XML remains vulnerable to malicious schemas and DTDs. This talk will describe a collection of techniques for exploiting XML external entities (XXE) vulnerabilities, some of which we believe are novel. These techniques can allow for more convenient file content theft, sending of arbitrary data to arbitrary internal TCP services, uploads of arbitrary files to known locations on a vulnerable system, as well as several possible denial of service attacks. We hope this talk will raise awareness about the overall risk associated with XXE attacks and will provide recommendations that developers and XML library implementors can use to help prevent these attacks.
-
What you didn't know about YouTube.
What You Didn't Know About Diddy
What you didn't know about TikTok. 🤫
What you didn't know about Apple.
10 Things You Didn't Know About Blazing Saddles
50 Insane Declassified FBI Secrets You Didn’t Know
What you didn't know about Xiaomi.
Random Facts You Didn't Know 13
Incredible Inventions You Didn't Know About
What you didn't know about narcissists and empathy...
Stephen Miller: Everything You Didn't Know About His Sh*tty Past
Top 20 Songs You Didn't Know Were Written by Bruno Mars
Pastor Gino Jennings [ January 21, 2025 ]…TERRIFYING: What You Didn't Know About Jesus!
10 Things You Didn't Know About Fast Times at Ridgemont High
30 Facts You Didn't Know About Titanic
10 Things You Didn't Know Could Kill You Reaction
'I Didn’t Know I Was Pregnant - Until I Gave Birth on Christmas Day!' | This Morning
14 Facts You Didn't Know About The Willoughbys | Netflix After School
20 Things You Didn't Know About Call Me by Your Name
10 Facts About Our Planet You Didn't Learn In School
What You Didn’t Know About Walt Disney…
Wendy and Lyndon Show How to Save Water and Don’t Waste Natural Resources | Kids Learn Life Lessons...
Lego Pieces that you didn't know got updated 9
Things You Didn't Know About Table Tennis
Комментарии