XXE Injection, now in six languages on SecDim Play

News1 min read

In December 2024, a vulnerability was identified in http4k, a toolkit for Kotlin HTTP applications. It could allow access to sensitive files, command execution or Server Side Request Forgery. http4k parsed XML request content with DocumentBuilder without security settings such as disabling external entities.

XXE takes advantage of behaviour supported by the XML specification. If an attacker sends a document that declares an external entity and the parser resolves it, the application may read local files or make requests from inside the network on the attacker’s behalf.

We used this vulnerability as the basis for a SecDim Play challenge, now available in six languages. The vulnerability class stays the same, but parser behaviour, defaults and remediation vary by stack. Recognising XXE is one skill. Applying the correct fix in the language and framework in front of you is another.

Pick your language:

C#: Play - SecDim

Java: Play - SecDim

Python: Play - SecDim

JavaScript: Play - SecDim

TypeScript: Play - SecDim

Ruby: Play - SecDim

Each challenge gives you a running application with the vulnerability. Find it, patch it and have your fix scored on whether the vulnerability is gone.

Start with the language you ship in, then try one you do not.

Questions or comments? Discuss this post on SecDim Community →

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.