# XML external entity injection checklist

Confirm that attacker-controlled XML reaches an entity-capable parser, then use in-band, error, or out-of-band behavior for file or network access.

## Recognition

- [ ] Endpoints accept XML, SOAP, SVG, office-like documents, imports, feeds, or content-type changes from JSON/form data.
- [ ] Malformed XML returns parser names, line numbers, entity errors, or expanded values.
- [ ] An import or conversion feature processes user-supplied structured documents.

## Manual workflow

- [ ] Preserve a valid baseline document and modify the smallest possible element.
- [ ] Confirm entity expansion with a harmless internal entity before referencing local files or URLs.
- [ ] Try in-band external entities when response data is reflected.
- [ ] Use error-based or external-DTD techniques when direct output is unavailable.
- [ ] Use a controlled callback to confirm blind retrieval and record DNS versus HTTP behavior.
- [ ] Select files compatible with the parser and output context; binary or markup-heavy files may fail.
- [ ] Chain file or network access to credentials, internal services, administrator access, or server execution.

## Escalation

- [ ] Read application configuration, source, environment, and service credentials.
- [ ] Reach localhost or internal HTTP services using external entity URLs.
- [ ] Use out-of-band retrieval when the parser can connect outward but the response is not reflected.

## Pitfalls

- [ ] Breaking the document before reaching the parser.
- [ ] Assuming all parsers allow DOCTYPE, external general entities, parameter entities, and network requests equally.
- [ ] Using a file whose characters make the XML response invalid.
- [ ] Recording a callback without proving which request caused it.

## Evidence

- [ ] Valid baseline XML
- [ ] Internal expansion proof
- [ ] External file or callback proof
- [ ] Parser-specific payload
- [ ] Chain to objective

## Tools

- [ ] Burp/ZAP content-type and body editing
- [ ] Python HTTP server
- [ ] Listener logs
- [ ] XML syntax reference

## Online references

- [PortSwigger XXE labs](<https://portswigger.net/web-security/xxe>)
- [OWASP XXE testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/07-Testing_for_XML_Injection>)

> Do you want to live curiously?
