<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Xxe on Yusuf AlMahmeed</title><link>https://www.yusufalmahmeed.com/tags/xxe/</link><description>Recent content in Xxe on Yusuf AlMahmeed</description><generator>Hugo</generator><language>en-us</language><copyright>© 2026 Yusuf AlMahmeed · &lt;a href="https://www.yusufalmahmeed.com/privacy/"&gt;privacy&lt;/a&gt;</copyright><lastBuildDate>Fri, 09 Oct 2026 18:09:00 +0300</lastBuildDate><atom:link href="https://www.yusufalmahmeed.com/tags/xxe/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploiting XXE to Perform SSRF</title><link>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-xxe-to-ssrf/</link><pubDate>Fri, 09 Oct 2026 18:09:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-xxe-to-ssrf/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;XML external entity (XXE) injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Exploiting XXE to perform SSRF attacks&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Read the server&amp;rsquo;s IAM credentials from cloud metadata&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;In the &lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/"&gt;file-retrieval lab&lt;/a&gt;&#10; the&#10;external entity pointed at a local file with &lt;code&gt;file://&lt;/code&gt;. Point it at an &lt;code&gt;http://&lt;/code&gt;&#10;URL instead and the XML parser becomes an HTTP client that fetches whatever URL we&#10;give it. That is &lt;strong&gt;SSRF&lt;/strong&gt; (server-side request forgery): making the server send&#10;requests to targets we choose, from its own trusted position on the network.&lt;/p&gt;</description></item><item><title>Exploiting XXE to Retrieve Files</title><link>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/</link><pubDate>Fri, 09 Oct 2026 17:43:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;XML external entity (XXE) injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Exploiting XXE using external entities to retrieve files&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Read &lt;code&gt;/etc/passwd&lt;/code&gt; from the server&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="what-is-xxe"&gt;What is XXE?&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;XML external entity (XXE) injection&lt;/strong&gt; happens when an application parses XML we&#10;control, and the &lt;strong&gt;parser&lt;/strong&gt; (the library that reads the XML and turns it into data&#10;the app can use) is allowed to process &lt;strong&gt;external entities&lt;/strong&gt;. An &lt;em&gt;entity&lt;/em&gt;&#10;in XML is a named placeholder, declared in a &lt;strong&gt;DTD&lt;/strong&gt; (Document Type Definition)&#10;and referenced in the document; an &lt;em&gt;external&lt;/em&gt; entity takes its value from a URI&#10;the parser fetches. If we can declare our own entity that points at a local file,&#10;the parser reads that file and we can often get the contents reflected back.&lt;/p&gt;</description></item></channel></rss>