EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard
A security researcher discovers a vulnerability in a web application where an attacker can submit a crafted XML payload to an endpoint that processes XML data. The payload includes an external entity declaration that attempts to read a local file from the server, such as `/etc/passwd`, and include its content in the XML parser's output. Which type of attack is this?
- AXPath Injection
- BSOAP Injection
- CJSON Web Token (JWT) Forgery
- DXML External Entity (XXE) Injection
Show answer & explanationAnswer & explanation
Correct answer: D. XML External Entity (XXE) Injection
The scenario describes injecting an external entity declaration within an XML payload to read local files, which is the hallmark of an XML External Entity (XXE) Injection attack. This vulnerability exploits features of XML parsers that allow defining entities from external sources.
Why the other options are wrong
- A. XPath Injection targets XPath queries to manipulate their logic, similar to SQL injection but for XML data.
- B. SOAP Injection is a broader term for injecting malicious data into SOAP-based web services, often via XML payloads, but XXE is a more specific type of XML injection.
- C. JWT Forgery involves manipulating or creating forged JSON Web Tokens, which is unrelated to XML parsing vulnerabilities.
XML External Entity (XXE) Injection
A web application vulnerability that allows an attacker to interfere with an application's processing of XML data, often leveraging features of XML parsers to access local files or internal resources.
- Exploits external entity declarations (DOCTYPE) within XML.
- Can lead to information disclosure, server-side request forgery (SSRF), or denial of service.
- Mitigation includes disabling DTDs or external entities in XML parsers.
Memory trick: XXE means 'eXploiting External Entities' in XML.