UGC Approved Journal no 63975(19)

ISSN: 2349-5162 | ESTD Year : 2014
Call for Paper
Volume 11 | Issue 4 | April 2024

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 8 Issue 5
May-2021
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2105163


Registration ID:
308794

Page Number

b255-b259

Share This Article


Jetir RMS

Title

XML External Entity Attacks and Mitigation in XML Parsers

Abstract

The increasing dependency of almost every organization in web applications has introduced a whole new set of vulnerabilities and attack vectors. Due to the ever-evolving nature of the information security space, new vulnerabilities, attack methods, and mitigation strategies are being introduced each day. XML External Entity Attack is such an attack. Being recently featured in the updated Open Web-Application Security Project (OWASP) Top 10 2017 list, this attack is prevalent in modern-day web applications and XML parsers. Recent statistics have shown a steep increase in XXE injections. But in spite of the fact, limited literature is available regarding this vulnerability. As XXE usually has a high-security impact on web applications, it is important to implement protective measures against XXE attacks. In this paper, we focus on XXE attack mitigation in various XML parsers. Firstly, we give a brief introduction to various XXE injection attacks and XML parsers. Then we test popular XML parsers for XXE injections. In addition to this, we suggest preventive measures for XML parsers in popular programming languages.

Key Words

XML, XML External Entity Attack (XXE), XML Parsers, Billion Laugh Attack (BIL), Server Side Request Forgery (SSRF), Security Testing

Cite This Article

"XML External Entity Attacks and Mitigation in XML Parsers", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.8, Issue 5, page no.b255-b259, May-2021, Available :http://www.jetir.org/papers/JETIR2105163.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"XML External Entity Attacks and Mitigation in XML Parsers", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.8, Issue 5, page no. ppb255-b259, May-2021, Available at : http://www.jetir.org/papers/JETIR2105163.pdf

Publication Details

Published Paper ID: JETIR2105163
Registration ID: 308794
Published In: Volume 8 | Issue 5 | Year May-2021
DOI (Digital Object Identifier):
Page No: b255-b259
Country: Kanpur Dehat, Uttar Pradesh, India .
Area: Engineering
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

000556

Print This Page

Current Call For Paper

Jetir RMS