Xxe Injection Methodology

XML外部实体注入(XXE)的检测与利用方法论。当目标有 XML 解析、SOAP API、文件上传(DOCX/XLSX/SVG)、或任何接受 XML 输入的端点时使用。包含基础文件读取、盲 XXE 外带(参数实体+外部DTD)、SVG/DOCX XXE、SOAP Envelope XXE、JSON→XML 转换攻击。即使 API 文档说只接受 JSON,也应尝试 XML Content-Type 测试隐式 XXE。

netvar1337 c008d06 5 files · 13.6 KB Updated

File contents

netvar1337/agent-skill-canon/tree/main/skills/aboutsecurity/exploit/web-method/xxe-injection-methodology commit c008d060fa

Frequently asked questions

npx skillmds@latest add netvar1337/xxe-injection-methodology