PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.
Exploiting XXE to Perform SSRF

whoami
Cybersecurity professional focused on information security, governance, compliance, and data protection, with a Master’s degree in cybersecurity and certifications including CISSP, OSCP, and CDPSE. The work I enjoy most is the whole loop: finding the weaknesses, then working with the team to fix them. It’s a purple-team mindset, attacking and defending the same system, and it depends on staying as close to the teams outside security as to the ones inside it.
cat skills.md
ls ~/ # where to next
Start here: new to the blog? Try the Shakabrah machine walkthrough , the SSTI lab series , or my recon tool Cataract .

PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.

PortSwigger Web Security Academy: XXE in a stock-check XML endpoint, defining an external entity to read /etc/passwd off the server.

An OffSec Linux box: an OS command injection in a web-based ping tool lands a reverse shell as www-data, and a SUID vim.basic binary hands over root.

PortSwigger Web Security Academy: escaping a sandboxed FreeMarker engine by walking Java reflection from a user-supplied object all the way to an arbitrary file read.

PortSwigger Web Security Academy: leaking Django’s SECRET_KEY through SSTI by using the {% debug %} tag and a reachable settings object, no code execution required.