Xxe Phantom

An XXE detection and exploitation methodology engine. Triggered when testing for XML injection, interacting with XML content-types/endpoints, or processing XML-based file uploads (SVG, DOCX, SAML, SOAP). Facilitates classic file reads, blind OOB exfiltration, WAF bypasses, and SSRF chaining. Includes report structuring.

Rifteo Updated

File contents

Rifteo/skills/tree/main/xxe-phantom commit 723726bd0c

Frequently asked questions

npx skillmds@latest add rifteo/xxe-phantom