Re: XXE (Xml eXternal Entity) attack

From: Miles Sabin (milesat_private)
Date: Wed Oct 30 2002 - 01:15:54 PST

  • Next message: Martin Schulze: "[SECURITY] [DSA 184-1] New krb4 packages fix buffer overflow"

    Gregory Steuck wrote,
    > Gregory Steuck security advisory #1, 2002
    
    Excellent stuff ... I've posted a link to the bugtraq archive to 
    xml-dev.
    
    > Acknowledgments:
    > Even though the issue was discovered and researched independently I
    > cannot claim to be the first one to realize the risks associated
    > with XML external entities. E.g. RFC 2518 discusses the issue in
    > section 17.7 Implications of XML External Entities.
    
    FWIW, this has been an occasional topic of discussion on xml-dev for the 
    last couple of years. See here,
    
      http://www.megginson.com/ugly/slides/
      http://lists.xml.org/archives/xml-dev/200101/msg00057.html
      http://lists.xml.org/archives/xml-dev/200206/msg00240.html
      http://lists.xml.org/archives/xml-dev/200206/msg00247.html
      http://lists.xml.org/archives/xml-dev/200210/msg01461.html
    
    The xml-dev reaction has by and large been "of course, don't do that", 
    but xml-dev is a relatively rarified place, so it's nice to seeing this 
    issue getting wider security related circulation. It's also nice to see 
    someone not just discussing theoretical attacks, but actually testing 
    deployed software.
    
    Cheers,
    
    
    Miles
    



    This archive was generated by hypermail 2b30 : Wed Oct 30 2002 - 09:21:20 PST