Burp Suite User Forum

Create new post

Expert XXE challenge solvable in incorrect manner

Owen | Last updated: May 09, 2023 06:29PM UTC

Hello, While messing about with the "Expert" XXE Academy challenge ("Exploiting XXE to retrieve data by repurposing a local DTD"), I found that executing the same payload as the prior "Practitioner" challenge ("Exploiting blind XXE to retrieve data via error messages") also solves the expert challenge. The documentation (/web-security/xxe/blind) alludes to the fact that outbound connections should be blocked in this scenario, however I was able to load the malicious DTD file from the exploit server of the previous challenge. This may be a non-issue but thought I would put a ticket in, in case this is something that you are interested in knowing. Kind Regards, Owen

Michelle, PortSwigger Agent | Last updated: May 10, 2023 03:58PM UTC

Thanks for getting in touch. We'll pass this on to the team.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.