The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Expert XXE challenge solvable in incorrect manner

Owen | Last updated: May 09, 2023 06:29PM UTC

Hello, While messing about with the "Expert" XXE Academy challenge ("Exploiting XXE to retrieve data by repurposing a local DTD"), I found that executing the same payload as the prior "Practitioner" challenge ("Exploiting blind XXE to retrieve data via error messages") also solves the expert challenge. The documentation (/web-security/xxe/blind) alludes to the fact that outbound connections should be blocked in this scenario, however I was able to load the malicious DTD file from the exploit server of the previous challenge. This may be a non-issue but thought I would put a ticket in, in case this is something that you are interested in knowing. Kind Regards, Owen

Michelle, PortSwigger Agent | Last updated: May 10, 2023 03:58PM UTC