> For the complete documentation index, see [llms.txt](https://yasmeen-rezk.gitbook.io/my-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yasmeen-rezk.gitbook.io/my-notes/bug-bounty-playbook-v2/more-owasp/xxe.md).

# XXE

XML External Entity

### <mark style="color:yellow;">Extensible Markup Language (XML)</mark>

A language designed to store and transport data similar to JSON.

#### basic structure of XML

<figure><img src="https://509923538-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJ2ZeCCTH4XZTY31hlbGx%2Fuploads%2FAcEhQs0NneQqqwxw2AQh%2Fimage.png?alt=media&amp;token=a25e76ff-f09e-4ceb-b0eb-9f6d47e5a12f" alt=""><figcaption></figcaption></figure>

**Document Type Definition (DTD):** defines the structure and the legal elements and attributes of an XML document.

**Entity:** acts as a variable.

**External Entity:** loads its data from an external source such as url or a file on disk.

* 💡Note: to read the data the entity must be returned in the response.
* EX: \<!DOCTYPE foo\[ \<!ENTITY ext SYSTEM "file:///path/to/file" > ]>

### <mark style="color:yellow;">XML External Entity(XXE) Attack</mark>

#### Description

Appears when an application parses XML.

#### Impact

Read arbitrary files which can lead to fully compromising a machine.

#### Indicator

Whenever you see XML you should test for XXE.

* \<?xml version="1.0" encoding="UTF-8"?>

#### Exploitation

💡If the server does not block external entities the response will be reflected

To test for XXE -> put in a malicious external entity and replace each node value with it.

<mark style="color:green;">**Scenario:**</mark> Retrieving the contents of the /etc/passwd file

<figure><img src="https://509923538-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJ2ZeCCTH4XZTY31hlbGx%2Fuploads%2FvPjGBNHnbhztiyILBx8v%2Fimage.png?alt=media&amp;token=d8a0f33b-b233-4f60-b195-23cea031e883" alt=""><figcaption><p>XML Normal code</p></figcaption></figure>

TO DO:

1. Create an external entity to grab the data in the /etc/passwd file
2. Store it in the entity xxe
3. Place the variable in the node

<figure><img src="https://509923538-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJ2ZeCCTH4XZTY31hlbGx%2Fuploads%2FPMtaAm6ehClKL3SqLJyJ%2Fimage.png?alt=media&amp;token=24c1fa27-3f78-4d56-9183-e2e64abe4818" alt=""><figcaption></figcaption></figure>
