Katy Anton -- OWASP Top 10 #4 XXE episode artwork

EPISODE · Feb 23, 2018 · 24 MIN

Katy Anton -- OWASP Top 10 #4 XXE

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A feature built into XML processing can become a path to file disclosure, internal requests, or denial of service. Katy Anton explains XML External Entities, the category added as A4 in the 2017 OWASP Top 10, and why developers need to understand their parser’s behavior. Chris and Robert ask how an XXE attack works, where the exposure appears in applications and web services, and how tools can help identify it. Katy walks through prevention options, including safer parser configuration and choosing simpler data formats when an application does not need XML’s capabilities. The discussion also considers legacy systems, developer education, and the difference between fixing an immediate configuration problem and reducing complexity over time. It is an accessible introduction to a frequently misunderstood vulnerability class.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Katy Anton:→ Katy Anton on LinkedInMentioned in this episode:→ CWE-611 — XML External Entity Reference→ OWASP XXE Prevention Cheat Sheet→ OWASP Proactive ControlsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Understanding XXE with Katy Anton01:42 OWASP Proactive Controls and community work03:12 What XML External Entities means06:07 When a parser feature becomes an attack07:21 Parser defaults and affected applications09:46 File disclosure and other XXE impacts10:42 Denial of service and entity expansion11:38 Finding XXE with testing and code review13:14 Simpler data formats and JSON15:52 Why applications still use XML18:57 Preparing developers to address XXE21:07 Hardening the XML parser21:41 Immediate fixes and longer-term design choices

Episode metadata supplied by the publisher feed · Published Feb 23, 2018

Embed this episode

A feature built into XML processing can become a path to file disclosure, internal requests, or denial of service. Katy Anton explains XML External Entities, the category added as A4 in the 2017 OWASP Top 10, and why developers need to understand their parser’s behavior. Chris and Robert ask how an XXE attack works, where the exposure appears in applications and web services, and how tools can help identify it. Katy walks through prevention options, including safer parser configuration and ch...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Katy Anton -- OWASP Top 10 #4 XXE

0:00 24:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 24 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 23, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!