webProeasy

Lab 144 — InsightForge — Blind XXE via XML Data Import

hackadvisor

Task: Flask data analytics platform with XML import endpoint that parses external entities. Solution: Upload XML with DOCTYPE declaring file:///root/flag.txt entity — contents reflected in data_preview JSON response field.

$ ls tags/ techniques/
xxe_file_readexternal_entity_injectiondecoy_flag_detectionin_band_xxe

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups