Using Burp Suite to exploit the vulnerability

Open Burp Suite in the main Dashboard tab, and click on the New scan option, as demonstrated in the following screenshot. Remember that these options are only available in Burp Suite Professional, and not in the Community Edition:

When you use the scanner, Burp Suite tests the application for vulnerabilities. Here, you can modify options about how the scanner did its job, and also configure credentials for automatic login. This is very important for the most part of application, because most of them have authentication control. For exploiting the XXE, we are going to launch a simple scan to the ...

Get Hands-On Application Penetration Testing with Burp Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.