{"id":479728,"date":"2023-08-09T10:43:58","date_gmt":"2023-08-09T10:43:58","guid":{"rendered":""},"modified":"2023-09-05T11:19:26","modified_gmt":"2023-09-05T11:19:26","slug":"xml-external-entity","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/cn\/wiki\/xml-external-entity\/","title":{"rendered":"XML \u5916\u90e8\u5b9e\u4f53"},"content":{"rendered":"<h2>\u4ecb\u7ecd<\/h2>\n<p>XML \u5916\u90e8\u5b9e\u4f53 (XXE) \u662f\u4e00\u4e2a\u5f71\u54cd\u89e3\u6790 XML \u6570\u636e\u7684\u5e94\u7528\u7a0b\u5e8f\u7684\u5b89\u5168\u6f0f\u6d1e\u3002\u8be5\u6f0f\u6d1e\u53ef\u80fd\u5bfc\u81f4\u654f\u611f\u4fe1\u606f\u6cc4\u9732\u3001\u62d2\u7edd\u670d\u52a1\u751a\u81f3\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u3002\u5728\u672c\u6587\u4e2d\uff0c\u6211\u4eec\u5c06\u6df1\u5165\u63a2\u8ba8 XML \u5916\u90e8\u5b9e\u4f53\u7684\u5386\u53f2\u3001\u5de5\u4f5c\u539f\u7406\u3001\u7c7b\u578b\u3001\u7f13\u89e3\u7b56\u7565\u548c\u672a\u6765\u524d\u666f\u3002\u6b64\u5916\uff0c\u6211\u4eec\u8fd8\u5c06\u63a2\u8ba8\u4ee3\u7406\u670d\u52a1\u5668\u548c XXE \u6f0f\u6d1e\u4e4b\u95f4\u7684\u5173\u7cfb\u3002<\/p>\n<h2>XML \u5916\u90e8\u5b9e\u4f53\u7684\u5386\u53f2<\/h2>\n<p>XML \u5916\u90e8\u5b9e\u4f53\u7684\u6982\u5ff5\u6700\u65e9\u662f\u5728 1998 \u5e74\u7531\u4e07\u7ef4\u7f51\u8054\u76df (W3C) \u5728 XML 1.0 \u89c4\u8303\u4e2d\u5f15\u5165\u7684\u3002\u6b64\u529f\u80fd\u65e8\u5728\u5c06\u5916\u90e8\u8d44\u6e90\u7eb3\u5165 XML \u6587\u6863\uff0c\u8ba9\u5f00\u53d1\u4eba\u5458\u80fd\u591f\u91cd\u590d\u4f7f\u7528\u6570\u636e\u5e76\u66f4\u6709\u6548\u5730\u7ba1\u7406\u5185\u5bb9\u3002\u7136\u800c\uff0c\u968f\u7740\u65f6\u95f4\u7684\u63a8\u79fb\uff0c\u7531\u4e8e\u6b64\u529f\u80fd\u53ef\u80fd\u88ab\u6ee5\u7528\uff0c\u5b89\u5168\u95ee\u9898\u4e5f\u968f\u4e4b\u51fa\u73b0\u3002<\/p>\n<h2>\u6709\u5173 XML \u5916\u90e8\u5b9e\u4f53\u7684\u8be6\u7ec6\u4fe1\u606f<\/h2>\n<p>\u5f53\u653b\u51fb\u8005\u8bf1\u9a97 XML \u89e3\u6790\u5668\u5904\u7406\u5305\u542b\u6076\u610f\u8d1f\u8f7d\u7684\u5916\u90e8\u5b9e\u4f53\u65f6\uff0c\u5c31\u4f1a\u51fa\u73b0 XML \u5916\u90e8\u5b9e\u4f53\u6f0f\u6d1e\u3002\u8fd9\u4e9b\u6709\u6548\u8d1f\u8f7d\u53ef\u4ee5\u5229\u7528\u8be5\u6f0f\u6d1e\u8bbf\u95ee\u6587\u4ef6\u3001\u8d44\u6e90\uff0c\u751a\u81f3\u5728\u670d\u52a1\u5668\u4e0a\u6267\u884c\u4efb\u610f\u64cd\u4f5c\u3002<\/p>\n<h2>\u5185\u90e8\u7ed3\u6784\u53ca\u529f\u80fd<\/h2>\n<p>XML \u5916\u90e8\u5b9e\u4f53\u7684\u6838\u5fc3\u662f\u4f7f\u7528\u6587\u6863\u7c7b\u578b\u5b9a\u4e49 (DTD) \u6216\u5916\u90e8\u5b9e\u4f53\u58f0\u660e\u3002\u5f53 XML \u89e3\u6790\u5668\u9047\u5230\u5916\u90e8\u5b9e\u4f53\u5f15\u7528\u65f6\uff0c\u5b83\u4f1a\u83b7\u53d6\u6307\u5b9a\u7684\u8d44\u6e90\u5e76\u5c06\u5176\u5185\u5bb9\u5408\u5e76\u5230 XML \u6587\u6863\u4e2d\u3002\u6b64\u8fc7\u7a0b\u867d\u7136\u529f\u80fd\u5f3a\u5927\uff0c\u4f46\u4e5f\u4f1a\u4f7f\u5e94\u7528\u7a0b\u5e8f\u9762\u4e34\u6f5c\u5728\u653b\u51fb\u3002<\/p>\n<h2>XML \u5916\u90e8\u5b9e\u4f53\u7684\u4e3b\u8981\u7279\u6027<\/h2>\n<ul>\n<li>\u6570\u636e\u53ef\u91cd\u7528\u6027\uff1aXXE \u5141\u8bb8\u8de8\u591a\u4e2a\u6587\u6863\u91cd\u7528\u6570\u636e\u3002<\/li>\n<li>\u63d0\u9ad8\u6548\u7387\uff1a\u5916\u90e8\u5b9e\u4f53\u7b80\u5316\u5185\u5bb9\u7ba1\u7406\u3002<\/li>\n<li>\u5b89\u5168\u98ce\u9669\uff1aXXE \u53ef\u80fd\u88ab\u7528\u4e8e\u6076\u610f\u76ee\u7684\u3002<\/li>\n<\/ul>\n<h2>XML \u5916\u90e8\u5b9e\u4f53\u7684\u7c7b\u578b<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u7c7b\u578b<\/th>\n<th>\u63cf\u8ff0<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u5185\u90e8\u5b9e\u4f53<\/td>\n<td>\u6307\u5728 DTD \u4e2d\u5b9a\u4e49\u5e76\u76f4\u63a5\u5305\u542b\u5728 XML \u6587\u6863\u4e2d\u7684\u6570\u636e\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5916\u90e8\u89e3\u6790\u5b9e\u4f53<\/td>\n<td>\u6d89\u53ca\u5bf9 DTD \u4e2d\u5916\u90e8\u5b9e\u4f53\u7684\u5f15\u7528\uff0c\u5185\u5bb9\u7531 XML \u5904\u7406\u5668\u89e3\u6790\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5916\u90e8\u672a\u89e3\u6790\u5b9e\u4f53<\/td>\n<td>\u6307\u5411\u5916\u90e8\u4e8c\u8fdb\u5236\u6216\u672a\u89e3\u6790\u7684\u6570\u636e\uff0c\u8fd9\u4e9b\u6570\u636e\u4e0d\u80fd\u88ab XML \u89e3\u6790\u5668\u76f4\u63a5\u5904\u7406\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u5229\u7528\u7387\u3001\u6311\u6218\u548c\u89e3\u51b3\u65b9\u6848<\/h2>\n<h3>\u5229\u7528\u7387<\/h3>\n<ul>\n<li>XXE \u53ef\u7528\u4e8e\u4ece\u5185\u90e8\u6587\u4ef6\u4e2d\u63d0\u53d6\u6570\u636e\u3002<\/li>\n<li>\u901a\u8fc7\u8d44\u6e90\u8d85\u8f7d\u53ef\u4ee5\u53d1\u8d77\u62d2\u7edd\u670d\u52a1\uff08DoS\uff09\u653b\u51fb\u3002<\/li>\n<\/ul>\n<h3>\u6311\u6218\u4e0e\u89e3\u51b3\u65b9\u6848<\/h3>\n<ul>\n<li><strong>\u8f93\u5165\u9a8c\u8bc1<\/strong>\uff1a\u9a8c\u8bc1\u7528\u6237\u8f93\u5165\u4ee5\u9632\u6b62\u6076\u610f\u8d1f\u8f7d\u3002<\/li>\n<li><strong>\u7981\u7528 DTD<\/strong>\uff1a\u914d\u7f6e\u89e3\u6790\u5668\u4ee5\u5ffd\u7565 DTD\uff0c\u964d\u4f4e XXE \u98ce\u9669\u3002<\/li>\n<li><strong>\u9632\u706b\u5899\u548c\u4ee3\u7406<\/strong>\uff1a\u4f7f\u7528\u9632\u706b\u5899\u548c\u4ee3\u7406\u6765\u8fc7\u6ee4\u4f20\u5165\u7684 XML \u6d41\u91cf\u3002<\/li>\n<\/ul>\n<h2>\u6bd4\u8f83\u548c\u4e3b\u8981\u7279\u70b9<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u7279\u5f81<\/th>\n<th>XML \u5916\u90e8\u5b9e\u4f53 (XXE)<\/th>\n<th>\u8de8\u7ad9\u811a\u672c (XSS)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u6f0f\u6d1e\u7c7b\u578b<\/td>\n<td>\u89e3\u6790 XML \u6570\u636e<\/td>\n<td>\u5411\u7f51\u7ad9\u6ce8\u5165\u6076\u610f\u811a\u672c<\/td>\n<\/tr>\n<tr>\n<td>\u5265\u524a\u540e\u679c<\/td>\n<td>\u6570\u636e\u6cc4\u9732\u3001DoS\u3001\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c<\/td>\n<td>\u672a\u7ecf\u6388\u6743\u7684\u811a\u672c\u6267\u884c<\/td>\n<\/tr>\n<tr>\n<td>\u653b\u51fb\u5411\u91cf<\/td>\n<td>XML \u89e3\u6790\u5668\u3001\u8f93\u5165\u5b57\u6bb5<\/td>\n<td>Web \u8868\u5355\u3001URL<\/td>\n<\/tr>\n<tr>\n<td>\u9884\u9632<\/td>\n<td>\u8f93\u5165\u9a8c\u8bc1\uff0c\u7981\u7528 DTD<\/td>\n<td>\u8f93\u51fa\u7f16\u7801\u3001\u8f93\u5165\u9a8c\u8bc1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u672a\u6765\u524d\u666f\u548c\u6280\u672f<\/h2>\n<p>\u968f\u7740 XML \u6280\u672f\u7684\u53d1\u5c55\uff0c\u4eba\u4eec\u6b63\u5728\u52aa\u529b\u589e\u5f3a\u5b89\u5168\u63aa\u65bd\u5e76\u7f13\u89e3 XXE \u6f0f\u6d1e\u3002\u65b0\u7684 XML \u89e3\u6790\u5668\u6b63\u5728\u5f00\u53d1\u4e2d\uff0c\u5176\u5b89\u5168\u529f\u80fd\u5f97\u5230\u4e86\u6539\u8fdb\uff0cXML \u793e\u533a\u4e5f\u5728\u4e0d\u65ad\u5b8c\u5584\u5b89\u5168 XML \u5904\u7406\u7684\u6700\u4f73\u5b9e\u8df5\u3002<\/p>\n<h2>XML \u5916\u90e8\u5b9e\u4f53\u548c\u4ee3\u7406\u670d\u52a1\u5668<\/h2>\n<p>\u4ee3\u7406\u670d\u52a1\u5668\uff08\u4f8b\u5982 OneProxy (oneproxy.pro) \u63d0\u4f9b\u7684\u4ee3\u7406\u670d\u52a1\u5668\uff09\u5728\u7f13\u89e3 XXE \u6f0f\u6d1e\u65b9\u9762\u53d1\u6325\u7740\u81f3\u5173\u91cd\u8981\u7684\u4f5c\u7528\u3002\u901a\u8fc7\u5145\u5f53\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u4e2d\u4ecb\uff0c\u4ee3\u7406\u670d\u52a1\u5668\u53ef\u4ee5\u5728\u5c06 XML \u8bf7\u6c42\u4f20\u9012\u5230\u76ee\u6807\u670d\u52a1\u5668\u4e4b\u524d\u5b9e\u65bd\u5b89\u5168\u63aa\u65bd\uff0c\u4f8b\u5982\u8f93\u5165\u9a8c\u8bc1\u3001\u6570\u636e\u6e05\u7406\u548c DTD \u7981\u7528\u3002\u8fd9\u589e\u52a0\u4e86\u4e00\u5c42\u989d\u5916\u7684\u4fdd\u62a4\u6765\u62b5\u5fa1 XXE \u653b\u51fb\u3002<\/p>\n<h2>\u76f8\u5173\u94fe\u63a5<\/h2>\n<p>\u6709\u5173 XML \u5916\u90e8\u5b9e\u4f53\u53ca\u5176\u5b89\u5168\u5f71\u54cd\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605\u4ee5\u4e0b\u8d44\u6e90\uff1a<\/p>\n<ul>\n<li><a href=\"https:\/\/www.w3.org\/TR\/REC-xml\/\" target=\"_new\" rel=\"noopener nofollow\">W3C XML 1.0 \u89c4\u8303<\/a><\/li>\n<li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/XML_External_Entity_Prevention_Cheat_Sheet.html\" target=\"_new\" rel=\"noopener nofollow\">OWASP XXE \u9884\u9632\u5907\u5fd8\u5355<\/a><\/li>\n<li><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-95\/final\" target=\"_new\" rel=\"noopener nofollow\">NIST XML \u5b89\u5168\u6307\u5357<\/a><\/li>\n<li><a href=\"https:\/\/oneproxy.pro\/cn\/\" target=\"_new\" rel=\"noopener\">OneProxy \u2013 \u4fdd\u62a4\u60a8\u7684 XML \u6d41\u91cf<\/a><\/li>\n<\/ul>\n<p>\u603b\u4e4b\uff0c\u4e86\u89e3 XML \u5916\u90e8\u5b9e\u4f53\u6f0f\u6d1e\u5bf9\u4e8e\u786e\u4fdd\u57fa\u4e8e XML \u7684\u5e94\u7528\u7a0b\u5e8f\u7684\u5b89\u5168\u81f3\u5173\u91cd\u8981\u3002\u968f\u7740\u6280\u672f\u7684\u53d1\u5c55\uff0c\u5bf9\u589e\u5f3a XML \u5904\u7406\u5b89\u5168\u6027\u7684\u5173\u6ce8\u5ea6\u4e0d\u65ad\u63d0\u9ad8\uff0c\u5b89\u5168\u4e13\u5bb6\u3001\u5f00\u53d1\u4eba\u5458\u548c OneProxy \u7b49\u4ee3\u7406\u670d\u52a1\u63d0\u4f9b\u5546\u4e4b\u95f4\u7684\u5408\u4f5c\u53ef\u4ee5\u4e3a\u66f4\u5b89\u5168\u7684\u6570\u5b57\u73af\u5883\u505a\u51fa\u91cd\u5927\u8d21\u732e\u3002<\/p>","protected":false},"featured_media":479729,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-479728","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>XML External Entity (XXE) Vulnerability: Exploring Risks and Mitigation<\/mark>","faq_items":[{"question":"What is an XML External Entity (XXE) vulnerability?","answer":"<p>An XML External Entity (XXE) vulnerability is a security flaw that affects applications processing XML data. It occurs when an attacker manipulates an XML parser to include external entities containing malicious content. This can lead to unauthorized access, data exposure, denial of service, and even remote code execution.<\/p>"},{"question":"How did the concept of XML External Entity originate?","answer":"<p>The concept of XML External Entity was introduced in the XML 1.0 specification by the W3C in 1998. It aimed to enable the reuse of data across XML documents, but over time, security concerns emerged due to potential misuse.<\/p>"},{"question":"What are the key characteristics of XXE vulnerabilities?","answer":"<p>XXE vulnerabilities offer data reusability, increased content management efficiency, but also present a security risk. They can be exploited to extract internal data, launch DoS attacks, and execute remote code.<\/p>"},{"question":"What are the types of XML External Entity?","answer":"<p>There are three types of XML External Entities:<\/p><ol><li><strong>Internal Entity:<\/strong> Data defined within the DTD and included directly in the XML document.<\/li><li><strong>External Parsed Entity:<\/strong> References an external entity in the DTD, with its content parsed by the XML processor.<\/li><li><strong>External Unparsed Entity:<\/strong> Points to external binary or non-parsed data, not processed directly by the XML parser.<\/li><\/ol>"},{"question":"How can XXE vulnerabilities be mitigated?","answer":"<p>To mitigate XXE vulnerabilities, consider these solutions:<\/p><ul><li><strong>Input Validation:<\/strong> Thoroughly validate user input to prevent malicious payloads.<\/li><li><strong>Disable DTDs:<\/strong> Configure parsers to ignore DTDs, reducing XXE risk.<\/li><li><strong>Firewalls and Proxies:<\/strong> Use firewalls and proxy servers to filter incoming XML traffic.<\/li><\/ul>"},{"question":"How do proxy servers like OneProxy help with XXE vulnerabilities?","answer":"<p>Proxy servers like OneProxy act as intermediaries between clients and servers, adding an extra layer of protection. They can implement security measures such as input validation, data sanitization, and disabling DTDs before passing XML requests to the target server. This enhances the security of XML traffic.<\/p>"},{"question":"What are the future perspectives of XXE vulnerabilities?","answer":"<p>As XML technologies advance, efforts to enhance security measures against XXE vulnerabilities continue. New XML parsers are being developed with improved security features, and best practices for secure XML processing are refined to create a safer digital environment.<\/p>"},{"question":"Where can I find more information on XXE vulnerabilities?","answer":"<p>For more information on XML External Entity vulnerabilities and their security implications, refer to these resources:<\/p><ul><li><a href=\"https:\/\/www.w3.org\/TR\/REC-xml\/\" target=\"_new\">W3C XML 1.0 Specification<\/a><\/li><li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/XML_External_Entity_Prevention_Cheat_Sheet.html\" target=\"_new\">OWASP XXE Prevention Cheat Sheet<\/a><\/li><li><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-95\/final\" target=\"_new\">NIST Guidelines on XML Security<\/a><\/li><li><a href=\"https:\/\/oneproxy.pro\/\" target=\"_new\">OneProxy - Secure Your XML Traffic<\/a><\/li><\/ul>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/479728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/479728\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media\/479729"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media?parent=479728"}],"curies":[{"name":"\u53ef\u6e7f\u6027\u7c89\u5242","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}