XXE Injection, now in six languages on SecDim Play
In December 2024, a vulnerability was identified in http4k, a toolkit for Kotlin HTTP applications. It could allow access to sensitive files, command execution or Server Side Request Forgery. http4k parsed XML request content with DocumentBuilder without security settings such as disabling external entities.
XXE takes advantage of behaviour supported by the XML specification. If an attacker sends a document that declares an external entity and the parser resolves it, the application may read local files or make requests from inside the network on the attacker’s behalf.
We used this vulnerability as the basis for a SecDim Play challenge, now available in six languages. The vulnerability class stays the same, but parser behaviour, defaults and remediation vary by stack. Recognising XXE is one skill. Applying the correct fix in the language and framework in front of you is another.
Pick your language:
C#: Play - SecDim
Java: Play - SecDim
Python: Play - SecDim
JavaScript: Play - SecDim
TypeScript: Play - SecDim
Ruby: Play - SecDim
Each challenge gives you a running application with the vulnerability. Find it, patch it and have your fix scored on whether the vulnerability is gone.
Start with the language you ship in, then try one you do not.
