XML外部实体注入(XXE)漏洞学习资源及相关开源项目
近期推特用户@soaj1664ashar(https://twitter.com/soaj1664ashar)发布了有关XXE漏洞利用工具的学习资源和开源项目
现整理如下:
https://web-in-security.blogspot.com/2016/03/xxe-cheat-sheet.html
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XXE%20inject
https://vsecurity.com//download/papers/xm lDTDEntityAttacks.pdf
http://www.cloudscan.me/2016/02/xxe-xm l-injection-external-entity.html
https://www.contextis.com/en/blog/xslt-server-side-injection-attacks
https://blog.netspi.com/advisory-xxe-injection-oracle-databa se-cve-2014-6577
https://blog.netspi.com/forcing-xxe-reflection-server-error-messages/
本文由白帽汇整理并翻译,不代表白帽汇任何观点和立场
来源:https://twitter.com/i/web/status/1080877419723194370
昵称
邮箱
最新评论