skip to content

XML Security and XXE

0 questions

XML parsers are dangerously helpful by default: external entities read local files and make outbound requests, and nested entities blow up memory. Security interviews want you to name XXE and billion laughs and to state the fix, which is disabling DOCTYPE and external entity resolution.

questions

no questions here yet

this part of the tree is still being written

>
0 questions in this topic or below it