Big thank you to Brilliant for sponsoring this video! To try Brilliant for free (for 30 days) and to get a 20% discount, visit: Brilliant.org/davidbombal // Tib3rius’ SOCIAL // KZbin: kzbin.info Website: tib3rius.com/ Twitch: www.twitch.tv/0xTib3rius GitHub: github.com/Tib3rius LinkedIn: www.linkedin.com/in/tib3rius/ X: x.com/0xtib3rius Bluesky: bsky.app/profile/tib3rius.bsky.social // Links REFERENCE // XXE Demo Repo: github.com/Tib3rius/XXE-Demos Dynamic Tool-DTD Repo: github.com/Tib3rius/Dynamic-DTD // Specific Webpage REFERENCE // en.wikipedia.org/wiki/Billion_laughs_attack tib3rius.com/robots.txt // David's SOCIAL // Discord: discord.com/invite/usKSyzb X: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin: www.youtube.com/@davidbombal // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up0:33 - Intro 03:07 - Brilliant Advert 04:22 - What is XXE 06:24 - XXE Demo Intro 08:54 - XML Spec Defined Entities 13:27 - XML Billion Laughs Attack 15:07 - XML Exploits 16:27 - XXE Demo Basic Example 1 22:33 - XXE Demo Basic Example 2 23:33 - Error-Based XXE Demo 30:11 - Dynamic DTD Demo 34:45 - The Community 35:33 - Out-Of-Band XXE Demo 40:12 - XML Tips & Tricks 41:25 - Outro xxe xss xml http https website xml external entities cross site scripting portswigger ajax jscript lol lol attack billion laughts billion lol javascript xss attack xxe attack xxe video tutorial xxs attack tutorial xxe explained xss explained xxe attack example xxe bug bounty xxe tutorial xxe vulnerability xxe vs csrf attack xe example kali linux penetration testing ethical hacking bug bounty cross site scripting cross-site scripting red teaming cyber security kali linux install kali linux 2025 ethical hacker course ethical hacker javascript ajax jquery node js node js hacking portswigger Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #xxe #xss #hacking
@rishiraj25484 күн бұрын
🎉
@Tib3rius4 күн бұрын
Thanks for having me on the show David! Glad I can share these fun / crazy exploit techniques with a wider community!
@sp99nz3Күн бұрын
I liked the video where can i start when it comes to ethical hacking should i consider programming and networking just needed an advise on where to start
@GajendraMahat19 сағат бұрын
Happy to you see here, sir 🥰🥰
@Whydidyouusemyname4 күн бұрын
The second X is a play on Ex just like XML is for extensible. This is why it is XXE instead of XEE.
@gamereditor59ner224 күн бұрын
Cool! Thank you, David, for the video, and thank you, Tib3ius, for the demo!
@davidbombal4 күн бұрын
Glad you liked it!
@rubenrodenascebrian38554 күн бұрын
In the CBBH, I found this much more advanced vulnerability with DTD and I tried to bypass the image file, the SVG.
@xu83r4 күн бұрын
I was unable to upload a svg?
@ByteBite1014 күн бұрын
While making animated explainers.. I use your video for refresher 🔥
@jessie176504 күн бұрын
I love your explainers
@ByteBite1014 күн бұрын
@@jessie17650 My man
@NextGenSellPOS4 күн бұрын
I just watched whole video. Great content
@davidbombal4 күн бұрын
Glad you enjoyed the video!
@TheCodeNinjas3 күн бұрын
Thanks David and Tib3rius, very interesting content.
@hellamean4 күн бұрын
Interesting, tryna learn XXE to help enhance my Bug Bounty Skills.
@davidbombal4 күн бұрын
Tib3rius does an amazing job teaching us XXE!
@hellamean4 күн бұрын
@ Yes, I can tell from the video… I was thinking if we could collaborate on a podcast? I added you on LinkedIn.
@hellamean4 күн бұрын
@@davidbombal Yes, I can tell from the video.
@Kwayjaye4 күн бұрын
Great job explaining xxe
@majiddehbi91864 күн бұрын
Good video as it's very helpfull that any network engineer need to know something about websites good initiative from uou David thx as always
@davidbombal4 күн бұрын
Than you! And you're welcome!
@Lykos-i2m2 күн бұрын
The error based XXE looks like a robbery...ha ha ha
@payloadhack4 күн бұрын
Not many people know these types of web attack, so they are actually a good way to hunt a bug
@adekojoadeyemi25964 күн бұрын
First time I see my like count. Very happy 😁
@MG-bm5oj3 күн бұрын
It’s a kind of hard to find a video with a guest. Would be great if you add in the description the video with Rana
@janekmachnicki25934 күн бұрын
Thanks Mr Bombal .Thanks for brilliant stuff you upload .It's been a few years since I've been follow your YT and Udemy content .Thanks a lots !!!!!
@davidbombal4 күн бұрын
Thank you!
@MecagothitsКүн бұрын
I thought hack only happen with Linux
@TheRealVegapunk4 күн бұрын
Tib3rius my man 🥳
@Crusaderon4 күн бұрын
THX David! What's about LinkedIn?
@davidbombal4 күн бұрын
Thank you for your support! Much appreciated! Not sure I understand what do you mean about LinkedIn?
@Crusaderon3 күн бұрын
@@davidbombal It's me Sascha!
@BellaSteery4 күн бұрын
Can you do a video on how a person can force their phone to only run on 5G standalone to enable their phones identifier information to have the highest level of protection please? 5G SA IS the only way to stop an IMSI ATTACK. Please look that up and teach us :)
@oneloveafrica8860Күн бұрын
error based XXE is very cool .. tanks sir
@BunnyShark-q8z4 күн бұрын
Make a video about local AIs e.g: Dolphin Mixtral 8x7b
@ادمزروق-ق6ج4 күн бұрын
Please kali linux series
@Fabian-d6n4 күн бұрын
We need master otw please 🙏🙏❤
@Kigenyi_Rahman4 күн бұрын
David can you create a Tutorial about configuring Linux for White hat hacking as in checking database vulnerabilities, please
@davidbombal4 күн бұрын
Great suggestion!
@funcool34514 күн бұрын
No comments?
@davidbombal4 күн бұрын
Lots of comments on the video already...
@funcool34514 күн бұрын
@davidbombal well I have a crappy internet connection and really love stuff you do and I particularly remember the video on Kali Linux about wifi where you were using Virtual box and was a requirement to own a adaptor type of thing but for same Problem we could easily use live boot usb which is easily available on any country ( especially for least developing countries where there is hard to find new techs) love your videos
@EthicalByteExplorers4 күн бұрын
Bro how to use esp 288 chip vedio plz❤
@Joe-gl8sr4 күн бұрын
Wow interesting stuff here!!!
@marshall16934 күн бұрын
I love xxe
@davidbombal4 күн бұрын
Happy to hear that!
@GamerX_Gaming55154 күн бұрын
❤
@BruceLeaakКүн бұрын
Great ! DONE.
@00Jimmy00Күн бұрын
i am java dev :D
@BellaSteery4 күн бұрын
Can you do an updated video on how a regular person with no computer program literacy can run MVT- Mobile Verification Toolkit and IMazing on iPhones to check for high level threats? I believe this is much needed