Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Exploiting XXE to perform SSRF attacks (Apprentice) · 🇬🇧
- PortSwigger — Exploiting XXE to retrieve data by repurposing a local DTD (Apprentice) · 🇬🇧
- PortSwigger — Exploiting XXE using external entities to retrieve files (Apprentice) · 🇬🇧
- TryHackMe — Advent of Cyber 2024 (Easy · ~1440 min) · 🇬🇧
- HackTheBox — BountyHunter (Fácil) · 🇪🇸 🇬🇧 📹
- HackTheBox — NodeBlog (Fácil) · 🇪🇸 🇬🇧 📹
Curated resources
HTB machines practicing XML External Entity (6)
PortSwigger labs practicing XML External Entity (9)
TryHackMe rooms practicing XML External Entity (4)
Related skills
← Back to the full glossary Last updated: 2026-08-13