230-OOB
230-OOB copied to clipboard
An Out-of-Band XXE server for retrieving file contents over FTP.
Out-of-Band XXE tool
A python script to achieve file read via FTP!
230OOB is a tool that emulates an FTP server, assisting you in achieving file read via Out-of-Band XXE.
Installation
git clone https://github.com/lc/230-OOB
Usage:
Generate an XXE payload & DTD at http://xxe.sh
Start the server:
python3 230.py 2121
everything will be logged to -> extracted.log