Skip to Content
Software Architect's Handbook
book

Software Architect's Handbook

by Joseph Ingeno
August 2018
Beginner
594 pages
22h 33m
English
Packt Publishing
Content preview from Software Architect's Handbook

XML external entity (XXE) attack

An XML external entity (XXE) attack is one that can take place against an application that parses XML input. When XML input contains a reference to an external entity and is then processed by an XML parser that has not been configured appropriately, the application is vulnerable to this attack.

Denial of service (DoS), the disclosure of sensitive data, and Server-Side Request Forgery (SSRF) are all possible with an XXE attack. One type of DoS attack that is made possible with XXE is called a billion laughs attack. Sometimes this type of attack is referred to as an XML bomb or an exponential entity expansion attack.

Regardless of the name, it works by defining ten entities, the first of which is simply defined ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Solutions Architect's Handbook

Solutions Architect's Handbook

Saurabh Shrivastava, Neelanjali Srivastav
Solutions Architect's Handbook - Second Edition

Solutions Architect's Handbook - Second Edition

Saurabh Shrivastava, Neelanjali Srivastav
Software Architecture in Practice, 4th Edition

Software Architecture in Practice, 4th Edition

Len Bass, Paul Clements, Rick Kazman
Solutions Architect's Handbook - Third Edition

Solutions Architect's Handbook - Third Edition

Saurabh Shrivastava, Neelanjali Srivastav

Publisher Resources

ISBN: 9781788624060Other