diff --git a/XXE Injection/README.md b/XXE Injection/README.md index 734588e6..eb642671 100644 --- a/XXE Injection/README.md +++ b/XXE Injection/README.md @@ -68,6 +68,13 @@ Basic entity test, when the XML parser parses the external entities the result s It might help to set the `Content-Type: application/xml` in the request when sending XML payload to the server. +These are different types of entities in XML: + +| Type | Prefix | Where usable | +| ---------------- | -------- | --------------------------- | +| General entity | `&name;` | Inside XML document content | +| Parameter entity | `%name;` | Only inside the DTD | + ## Exploiting XXE to Retrieve Files ### Classic XXE diff --git a/_LEARNING_AND_SOCIALS/YOUTUBE.md b/_LEARNING_AND_SOCIALS/YOUTUBE.md index c00951ce..7fea856c 100644 --- a/_LEARNING_AND_SOCIALS/YOUTUBE.md +++ b/_LEARNING_AND_SOCIALS/YOUTUBE.md @@ -64,4 +64,3 @@ - [EP003: Red Team | HACKING GOOGLE](https://youtu.be/TusQWn2TQxQ) - [EP004: Bug Hunters | HACKING GOOGLE](https://youtu.be/IoXiXlCNoXg) - [EP005: Project Zero | HACKING GOOGLE](https://youtu.be/My_13FXODdU) -