Security Engineer Interview Questions - What is XML External Entities (XXE)?

  Рет қаралды 1,925

AppSecEngineer

AppSecEngineer

Күн бұрын

Never be caught tongue-tied in an Application Security Engineer Interview. In this video Abhay Bhargav explores the popular Security Engineer Interview question from Glassdoor and Indeed "What is XXE?"
#XXE is a key vulnerability in OWASP (Open Web Application Security Project) Top 10 and is a serious vulnerability that can have devastating impacts against your Web Application or Web Service. XXE can result in Local-File Include, Remote File Include, Remote Code Execution, Server-Side Request Forgery or #SSRF and Denial of Service.
Abhay explores XXE in the form of an offensive and defensive demo directly from AppSecEngineer's Learning Path "Application Security"
AppSecEngineer is a powerful training platform that delivers amazing hands-on training on AppSec, AWS Security, Cloud Security, Kubernetes, Container Security and Advanced Application Security.
#AppSecEngineer is ideal for jobseekers, knowledge seekers and companies that want to get their workforce equipped to handle real-world security issues with their newly minted and highly educated AppSec Engineers
Content of this video
0:00- Intro
0:18- What is XML external entities
02:18- XML DTD
03:17- XXE- Remote code execution
04:17 -XXE SSRF
05:27- XXE interactive lab demo
15:30- Like and subscribe
Learn more about XXE at appsecengineer.com/applicatio...
Twitter: / appsecengineer
Linkedin: / appsecengineer

Пікірлер: 5
XML External Entities (XXE) Explained
20:11
PwnFunction
Рет қаралды 152 М.
2017 OWASP Top 10: XML External Entities
10:18
F5 DevCentral
Рет қаралды 97 М.
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 49 МЛН
THEY WANTED TO TAKE ALL HIS GOODIES 🍫🥤🍟😂
00:17
OKUNJATA
Рет қаралды 21 МЛН
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 25 МЛН
Cybersecurity "Experts" suck at coding.  It's a problem.
15:12
LaurieWired
Рет қаралды 106 М.
Coding a Web Server in 25 Lines - Computerphile
17:49
Computerphile
Рет қаралды 327 М.
Implementing Secure by Design Principles in AWS | AWS Security
14:58
Interview with Computer Security Trainer
10:49
Programmers are also human
Рет қаралды 247 М.
Webinar: Rapid Threat Modeling with GenAI and LLMs
1:11:21
AppSecEngineer
Рет қаралды 676
secret backdoor found in open source software (xz situation breakdown)
8:28
Low Level Learning
Рет қаралды 430 М.
Robotaxis | Big Ideas 2024
9:41
ARK Invest
Рет қаралды 60 М.
Google Data Center 360° Tour
8:29
Google Cloud Tech
Рет қаралды 5 МЛН
Cross-Site Request Forgery (CSRF) Explained
14:11
PwnFunction
Рет қаралды 435 М.