
Katy Anton -- OWASP Top 10 #4 XXE
Om avsnittet
A feature built into XML processing can become a path to file disclosure, internal requests, or denial of service. Katy Anton explains XML External Entities, the category added as A4 in the 2017 OWASP Top 10, and why developers need to understand their parser’s behavior. Chris and Robert ask how an XXE attack works, where the exposure appears in applications and web services, and how tools can help identify it. Katy walks through prevention options, including safer parser configuration and choosing simpler data formats when an application does not need XML’s capabilities. The discussion also considers legacy systems, developer education, and the difference between fixing an immediate configuration problem and reducing complexity over time. It is an accessible introduction to a frequently misunderstood vulnerability class.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Katy Anton:
→ Katy Anton on LinkedIn
Mentioned in this episode:
→ CWE-611 — XML External Entity Reference
→ OWASP XXE Prevention Cheat Sheet
→ OWASP Proactive Controls
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Understanding XXE with Katy Anton
01:42 OWASP Proactive Controls and community work
03:12 What XML External Entities means
06:07 When a parser feature becomes an attack
07:21 Parser defaults and affected applications
09:46 File disclosure and other XXE impacts
10:42 Denial of service and entity expansion
11:38 Finding XXE with testing and code review
13:14 Simpler data formats and JSON
15:52 Why applications still use XML
18:57 Preparing developers to address XXE
21:07 Hardening the XML parser
21:41 Immediate fixes and longer-term design choices
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.