home.social

#xxe — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xxe, aggregated by home.social.

  1. Une souscription lancée pour restaurer le piano d’un compositeur français du XXe siècle

    Les biographes de Samson François, pianiste et compositeur français spécialiste du répertoire romantique, ont lancé une souscription pour…
    #Rennes #FR #France #Actu #News #Europe #EU #actu #Actualités #bretagne #compositeur #europe #français #lancée #piano #Républiquefrançaise #restaurer #siècle #souscription #xxe
    europesays.com/fr/455332/

  2. Very well written breakdown of the discovery and patching of xxe and ../ in Xerox FreeFlow.

    horizon3.ai/attack-research/at

    #cve #xxe

  3. Уязвимости XXE в разрезе Java

    В этой статье мы рассмотрим дефект безопасности XXE в контексте Java. Поговорим о причинах возникновения и возможных последствиях, посмотрим на примеры и, конечно, обсудим способы защиты.

    habr.com/ru/companies/axiomjdk

    #XXE #Java #XML #security #информационная_безопасность #axiomjdk #axiom_jdk #openjdk #libercat

  4. License Plate Detector by Darkart (every camera you drive by surveillance) This program is intended solely for ethical and educational purposes. #anon #anonymous #graphicdesign #programing #coding #engineers #tech #technology #hacker #hacking #python #linux #c #rust #HCI #XXE #sql #security #news

  5. 🚨 New Perspective on #Magento #XXE Vulnerability! 🚨

    Most write-ups cover the basic arbitrary file read vector. We’ve taken it further to demonstrate how CVE-2024-34102 can be chained to impersonate an admin user! 🔐

    github.com/redwaysecurity/CVEs

    #CyberSecurity #InfoSec

  6. Getting XXE in Web Browsers using ChatGPT - by Igor Sak-Sakovskiy -
    swarm.ptsecurity.com/xxe-chrom < Using XLS’s document() function for loading remote XML documents to trigger XXE 🤔 #infosec #XXE

  7. CVE-2024-23525 has been fixed in latest release of Spreadsheet::ParseXLSX

    metacpan.org/dist/Spreadsheet-

  8. "XXE-scape through the front door: circumventing the firewall with HTTP request smuggling"

    In this write-up, I explain all about how I bypassed a firewall stopping me from exploiting an XXE vulnerability. So if you think your firewall alone will keep the bad guys out, think again!

    honoki.net/2020/03/18/xxe-scap

    #repost #crosspost #xxe #bugbounty #writeup

  9. "XXE-scape through the front door: circumventing the firewall with HTTP request smuggling"

    Read my write-up about a pretty cool way in which I bypassed a firewall stopping me from exploiting an XXE vulnerability.

    honoki.net/2020/03/18/xxe-scap #bugbounty #writeup #xxe #crosspost

  10. If you haven't heard about local DTDs in XXE yet, check it out here: github.com/GoSecure/dtd-finder

    Another cool trick with error-based XXE is to access a file starting with colon (:) to trigger a "no protocol" error.

    #xxe #websec