Skip to content
An Out-of-Band XXE server for retrieving file contents over FTP.
Branch: master
Clone or download
Latest commit 502bcd9 Apr 13, 2019
Type Name Latest commit message Commit time
Failed to load latest commit information.
.gitattributes 💥🐫 Added .gitattributes & .gitignore files Dec 20, 2017
.gitignore Boy scout: ignore extracted.log file Dec 26, 2017 Update Nov 13, 2018 Update Apr 13, 2019
example_payload.xml 230OOB Dec 20, 2017
logo.png Add files via upload Sep 27, 2018
oob.dtd 230OOB Dec 20, 2017

Out-of-Band XXE tool
A python script to achieve file read via FTP!

230OOB is a tool that emulates an FTP server, assisting you in achieving file read via Out-of-Band XXE.


git clone


Generate an XXE payload & DTD at

Start the server:

python3 2121

everything will be logged to -> extracted.log

You can’t perform that action at this time.