<- HTB


8 minutes to read

Hack The Box. Linux. Easy machine. This machine has a website that is vulnerable to XML External Entity (XXE) injection and that has sudo permissions configured. Some knowledge about XXE, PHP and Python is needed to compromise this machine. This writeup uses a custom Bash script to read files from the server exploiting XXE