{"author_name":"hamayanhamayan","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fblog.hamayanhamayan.com%2Fentry%2F2019%2F07%2F20%2F181443\" title=\"XXE on JSON Endpoints - \u306f\u307e\u3084\u3093\u306f\u307e\u3084\u3093\u306f\u307e\u3084\u3093\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","categories":["Security"],"version":"1.0","blog_url":"https://blog.hamayanhamayan.com/","title":"XXE on JSON Endpoints","height":"190","published":"2019-07-20 18:14:43","image_url":null,"width":"100%","author_url":"https://blog.hatena.ne.jp/hamayanhamayan/","url":"https://blog.hamayanhamayan.com/entry/2019/07/20/181443","type":"rich","provider_url":"https://hatena.blog","provider_name":"Hatena Blog","description":"\u6982\u8981 JSON\u3092\u6e21\u3059API\u306b\u5bfe\u3057\u3066\u3001XML\u3092\u6e21\u3059\u3053\u3068\u304c\u3067\u304d\u308b\u5834\u5408\u304c\u3042\u308b \u305d\u306e\u5834\u5408\u306bXXE\u304c\u884c\u3048\u3066\u3057\u307e\u3046 JSON\u3092\u6e21\u3059API\u306b\u5bfe\u3057\u3066XML\u304c\u6e21\u305b\u308b\u73fe\u8c61 Playing with Content-Type \u2013 XXE on JSON Endpoints\u306e\u307b\u307c\u65e5\u672c\u8a9e\u8a33\u3002 \u4f8b\u3048\u3070\u3001 POST /netspi HTTP/1.1 Host: someserver.netspi.com Accept: application/json Content-Type: application/json Content-Length: 38 {\"search\":\"name\",\"value\":\"netspitest\u2026","blog_title":"\u306f\u307e\u3084\u3093\u306f\u307e\u3084\u3093\u306f\u307e\u3084\u3093"}