
Full Disclosure mailing list archives
Using XXE vulnerabilities for attacks on other sites
From: "MustLive" <mustlive () websecurity com ua>
Date: Sat, 10 Aug 2013 23:45:20 +0300
Hello participants of Mailing List. I'll tell you about using XXE vulnerabilities for attacks on other sites (about it I already wrote last year). Those who haven't read my 2012's article "Using XML External Entities (XXE) for attacks on other sites" (http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2012-August/008481.html) can do it now to remind this topic for themselves. In that article I've told about using XML External Entities (XXE) vulnerabilities (WASC-43) for conducting CSRF and DoS attacks on other sites. And in new article I continued this topic. In June I wrote new article "Using XXE vulnerabilities for attacks on other sites", which I translated recently (http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-August/008887.html). I described many new software and web applications, which are vulnerable to XXE, such as libraptor, Advanced XML Reader, PHP 5.3 and 5.4, WordPress 3.5 and 3.5.1 and Sybase EAServer. And mentioned about my tool for automation of such attacks - DAVOSET. Which can be used for conducting attacks on othersites via Abuse of Functionality vulnerabilities and I was planning to add support of attacks via XXE.
Last month I released DAVOSET v.1.1.2 - DDoS attacks via other sites execution tool. In this version I added support of XML requests for XXE vulnerabilities. So now you can use XML External Entities (XXE) holes at web sites for conducting automated DoS and DDoS attacks on other sites. Best wishes & regards, MustLive Administrator of Websecurity web sitehttp://websecurity.com.ua
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Using XXE vulnerabilities for attacks on other sites MustLive (Aug 10)