IE11-XXE
XML External Entity for Internet Explorer11
POC to exfil Windows "system.ini" file. Note: Edit attacker server IP in the script to suit your needs.
-
Use below script to create the "datatears.xml" XML and XXE embedded "msie-xxe-0day.mht" MHT file.
-
python -m SimpleHTTPServer
-
Place the generated "datatears.xml" in Python server web-root.
-
Open the generated "msie-xxe-0day.mht" file, watch your files be exfiltrated.