Nytro Posted November 6, 2014 Report Posted November 6, 2014 CONTENTIntroductionIt's all about entitiesParameter entitiesValidity and well-formednessXXE Data RetrievalPeculiar features of attacks on various parsersReferencesAbout Positive TechnologiesDownload: https://media.blackhat.com/eu-13/briefings/Osipov/bh-eu-13-XML-data-osipov-wp.pdf Quote