wstg icon indicating copy to clipboard operation
wstg copied to clipboard

Added Test for XXE

Open DotDotSlashRepo opened this issue 4 years ago • 14 comments

This PR covers issue #8

  • [x] This PR handles the issue and requires no additional PRs. Refer TODOs
  • [x] You have validated the need for this change.

What did this PR accomplish?

  • Added test case for XXE

TODO

  1. Edit top level page to link to test case.
  2. This test case has overlap with WSTG-INPV-07 , XML injection. WSTG-INPV-07 is to be modified to eliminate duplication.
  3. Need to re-order test case, XXE makes more sense to be after XML injection

Thank you for your contribution!

DotDotSlashRepo avatar Jan 12 '21 17:01 DotDotSlashRepo

The following issues were identified: document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md:15:78 MD009/no-trailing-spaces Trailing spaces [Expected: 0 or 2; Actual: 1] document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md:74:1 MD010/no-hard-tabs Hard tabs [Column: 1] document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md:96:188 MD009/no-trailing-spaces Trailing spaces [Expected: 0 or 2; Actual: 1]

github-actions[bot] avatar Jan 12 '21 17:01 github-actions[bot]

The following mistakes were identified:

/home/runner/work/wstg/wstg/document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md 117:98 ✖ Incorrect usage of the term: “an URL”, use “a URL” instead terminology

github-actions[bot] avatar Jan 12 '21 17:01 github-actions[bot]

The following mistakes were identified:

/home/runner/work/wstg/wstg/document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md 117:98 ✖ Incorrect usage of the term: “an URL”, use “a URL” instead terminology

github-actions[bot] avatar Jan 12 '21 18:01 github-actions[bot]

Following links are broken: FILE:document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/20-Testing_for_XXE_Injection.md [✖] https://www.securityfocus.com/archive/1/297714 → Status: 0

github-actions[bot] avatar Feb 05 '21 18:02 github-actions[bot]

TODO

Edit top level page to link to test case. This test case has overlap with WSTG-INPV-07 , XML injection. WSTG-INPV-07 is to be modified to eliminate duplication. Need to re-order test case, XXE makes more sense to be after XML injection

@kingthorin : Can I go ahead with these ?

DotDotSlashRepo avatar Feb 05 '21 18:02 DotDotSlashRepo

I'm good with you addressing duplicate content. However re-ordering things should wait until we are headed to 5.x. Currently we are still planning further 4.x releases, so maybe just create an issue and we can assign it to the 5.0 milestone.

kingthorin avatar Feb 05 '21 18:02 kingthorin

Please comment if you are still working on this PR, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it for new contributors to take over.

github-actions[bot] avatar Mar 15 '21 00:03 github-actions[bot]

Please comment if you are still working on this PR, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it for new contributors to take over.

github-actions[bot] avatar Jun 15 '21 00:06 github-actions[bot]

@DotDotSlashRepo do you intend to finish this?

kingthorin avatar Dec 04 '21 03:12 kingthorin

@DotDotSlashRepo do you intend to finish this?

kingthorin avatar Mar 11 '22 22:03 kingthorin

@RiieCco might you have some time to give this a look?

@kingthorin what is still needed for this? I'll be giving this a look as well.

ThunderSon avatar Apr 19 '22 22:04 ThunderSon

Comments from Feb 5th and Rejah’s more recent comments.

kingthorin avatar Apr 19 '22 22:04 kingthorin

Alright. Let's re-review that comment, as that seems to be creating an issue, and is not a blocker right now. Let's try to recall the exact concern and then move this. This is a good addition, I'll try to review this ASAP.

ThunderSon avatar Apr 19 '22 22:04 ThunderSon

It was this discussion:

TODO Edit top level page to link to test case. This test case has overlap with WSTG-INPV-07 , XML injection. WSTG-INPV-07 is to be modified to eliminate duplication. Need to re-order test case, XXE makes more sense to be after XML injection


I'm good with you addressing duplicate content. However re-ordering things should wait until we are headed to 5.x. Currently we are still planning further 4.x releases, so maybe just create an issue and we can assign it to the 5.0 milestone.

kingthorin avatar Apr 19 '22 23:04 kingthorin