Skip to content
An Out-of-Band XXE server for retrieving file contents over FTP.
Python
Branch: master
Clone or download
Latest commit 502bcd9 Apr 13, 2019
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
.gitattributes 💥🐫 Added .gitattributes & .gitignore files Dec 20, 2017
.gitignore Boy scout: ignore extracted.log file Dec 26, 2017
230.py Update 230.py Nov 13, 2018
README.md Update README.md Apr 13, 2019
example_payload.xml 230OOB Dec 20, 2017
logo.png Add files via upload Sep 27, 2018
oob.dtd 230OOB Dec 20, 2017

README.md


Out-of-Band XXE tool
A python script to achieve file read via FTP!

230OOB is a tool that emulates an FTP server, assisting you in achieving file read via Out-of-Band XXE.

Installation

git clone https://github.com/lc/230-OOB

Usage:

Generate an XXE payload & DTD at http://xxe.sh

Start the server:

python3 230.py 2121

everything will be logged to -> extracted.log

You can’t perform that action at this time.