Code Monkey home page Code Monkey logo

hloverflow / xxe-study Goto Github PK

View Code? Open in Web Editor NEW
95.0 3.0 36.0 4.98 MB

This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a playground to teach or test with Vulnerability scanners / WAF rules / Secure Configuration settings.

License: MIT License

Dockerfile 6.15% Python 6.55% PHP 30.71% HTML 1.00% CSS 28.74% Shell 14.71% Java 12.14%
xxe-labs xxe-study external-entities xxe xxe-injection php-xxe-demo java-xxe-demo python-xxe-demo xml-entity xml-entity-expansion

xxe-study's People

Contributors

dependabot[bot] avatar hloverflow avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar

xxe-study's Issues

Not found: https://github.com/priorax/mock-ec2-metadata.git

 => ERROR [2/4] RUN git clone https://github.com/priorax/mock-ec2-metadata.git                           1.9s
------
 > [2/4] RUN git clone https://github.com/priorax/mock-ec2-metadata.git:
#5 0.472 Cloning into 'mock-ec2-metadata'...
#5 0.939 fatal: could not read Username for 'https://github.com': No such device or address
------
executor failed running [/bin/sh -c git clone https://github.com/priorax/mock-ec2-metadata.git]: exit code: 128
ERROR: Service 'aws-metadata-simulator' failed to build : Build failed

The project https://github.com/priorax/mock-ec2-metadata.git doesn't exist anymore so a substitute need be.

server not running

EXPLOITATION

Visit http://localhost:8082/xxe to access the vulnerable web application
Use http://attackerserver-php:8888/ to access the attacker hosting server from the vulnerable web app.

DEBUGGING

+---------------------------------+----------------------------------------------------------+
| docker containers | How to access |
+---------------------------------+----------------------------------------------------------+
| attacker server (file hosting ) | docker container exec -it attackerserver-php bash |
+---------------------------------+----------------------------------------------------------+
| vulnerable server | docker container exec -it vulnerableserver-php bash |
+---------------------------------+----------------------------------------------------------+
| aws metadata simulator | docker container exec -it aws-metadata-simulator-php bash|
+---------------------------------+---------------------------------
i tried as the video did as you mention here.

i am getting like this when i try to access http://localhost:8082/xxe i am not getting anythings?
could you please tell me what to do next

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.