PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.
Exploiting XXE to Perform SSRF


PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.

PortSwigger Web Security Academy: XXE in a stock-check XML endpoint, defining an external entity to read /etc/passwd off the server.

PortSwigger Web Security Academy: escaping a sandboxed FreeMarker engine by walking Java reflection from a user-supplied object all the way to an arbitrary file read.

PortSwigger Web Security Academy: leaking Django’s SECRET_KEY through SSTI by using the {% debug %} tag and a reachable settings object, no code execution required.

PortSwigger Web Security Academy: fingerprinting Twig from errors, reading the app’s own source through an exposed object, and chaining its methods into a custom exploit that reads and deletes files.