EPISODE · Feb 23, 2018 · 24 MIN
Katy Anton -- OWASP Top 10 #4 XXE
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A feature built into XML processing can become a path to file disclosure, internal requests, or denial of service. Katy Anton explains XML External Entities, the category added as A4 in the 2017 OWASP Top 10, and why developers need to understand their parser’s behavior. Chris and Robert ask how an XXE attack works, where the exposure appears in applications and web services, and how tools can help identify it. Katy walks through prevention options, including safer parser configuration and choosing simpler data formats when an application does not need XML’s capabilities. The discussion also considers legacy systems, developer education, and the difference between fixing an immediate configuration problem and reducing complexity over time. It is an accessible introduction to a frequently misunderstood vulnerability class.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Katy Anton:→ Katy Anton on LinkedInMentioned in this episode:→ CWE-611 — XML External Entity Reference→ OWASP XXE Prevention Cheat Sheet→ OWASP Proactive ControlsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Understanding XXE with Katy Anton01:42 OWASP Proactive Controls and community work03:12 What XML External Entities means06:07 When a parser feature becomes an attack07:21 Parser defaults and affected applications09:46 File disclosure and other XXE impacts10:42 Denial of service and entity expansion11:38 Finding XXE with testing and code review13:14 Simpler data formats and JSON15:52 Why applications still use XML18:57 Preparing developers to address XXE21:07 Hardening the XML parser21:41 Immediate fixes and longer-term design choices
Embed this episode
What this episode covers
A feature built into XML processing can become a path to file disclosure, internal requests, or denial of service. Katy Anton explains XML External Entities, the category added as A4 in the 2017 OWASP Top 10, and why developers need to understand their parser’s behavior. Chris and Robert ask how an XXE attack works, where the exposure appears in applications and web services, and how tools can help identify it. Katy walks through prevention options, including safer parser configuration and ch...
Ready to play
Katy Anton -- OWASP Top 10 #4 XXE
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.