You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on May 14, 2020. It is now read-only.
during the last chat meeting, we talked about creating one or more rules to handle XXE attacks. I'm quite near to a PR, I just want to share with you some topics. I'm trying to cover:
during the last chat meeting, we talked about creating one or more rules to handle XXE attacks. I'm quite near to a PR, I just want to share with you some topics. I'm trying to cover:
Questions
before opening a new PR:
REQUEST-...-APPLICATION-ATTACK-XXE.conf
?SYSTEM "<wrapper-list>://..."
in PL1, what do you think about completely deny!ENTITY
tag in PL3 for example?Example rule
PoC
thanks
The text was updated successfully, but these errors were encountered: