Skip to main content
This page aggregates cross-platform resources to practice XML External Entity: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 19 challenges across 3 platforms — 6 HackTheBox · 9 PortSwigger · 4 TryHackMe. 6 with a Spanish writeup, 6 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerExploiting XXE to perform SSRF attacks (Apprentice) · 🇬🇧
  2. PortSwiggerExploiting XXE to retrieve data by repurposing a local DTD (Apprentice) · 🇬🇧
  3. PortSwiggerExploiting XXE using external entities to retrieve files (Apprentice) · 🇬🇧
  4. TryHackMeAdvent of Cyber 2024 (Easy · ~1440 min) · 🇬🇧
  5. HackTheBoxBountyHunter (Fácil) · 🇪🇸 🇬🇧 📹
  6. HackTheBoxNodeBlog (Fácil) · 🇪🇸 🇬🇧 📹

Curated resources

HTB machines practicing XML External Entity (6)

PortSwigger labs practicing XML External Entity (9)

TryHackMe rooms practicing XML External Entity (4)


Back to the full glossary Last updated: 2026-08-13