The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Academy XXE Labs

Chris | Last updated: Dec 15, 2021 12:02PM UTC

In an update to my last post, there are six labs in total affected. I've had other users at home check also, so isn't just a local issue. These are the affected labs containing error reports on loading Lab: Exploiting blind XXE to exfiltrate data using a malicious external DTD Lab: Blind XXE with out-of-band interaction via XML parameter entities Lab: Exploiting blind XXE to retrieve data via error messages Lab: Exploiting XXE to retrieve data by repurposing a local DTD Lab: Exploiting XInclude to retrieve files Lab: Exploiting XXE via image file upload

Ben, PortSwigger Agent | Last updated: Dec 15, 2021 02:16PM UTC