> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# XML External Entity

> Recursos cross-platform para XML External Entity: máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# XML External Entity

Esta página agrega los **recursos para practicar XML External Entity** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente     | Enlace                                                                                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| HackTricks | [https://book.hacktricks.wiki/en/pentesting-web/xxe-xee-xml-external-entity.html](https://book.hacktricks.wiki/en/pentesting-web/xxe-xee-xml-external-entity.html) |

## Máquinas HTB que practican XML External Entity (6)

| Máquina                                                | SO      | Dificultad                                           |
| ------------------------------------------------------ | ------- | ---------------------------------------------------- |
| [Aragog](/htb/machines/linux/medio/aragog)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [BountyHunter](/htb/machines/linux/facil/bountyhunter) | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [DevOops](/htb/machines/linux/medio/devoops)           | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Fulcrum](/htb/machines/linux/insano/fulcrum)          | Linux   | <span className="dbadge dbadge-insane">INSANE</span> |
| [NodeBlog](/htb/machines/linux/facil/nodeblog)         | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [RE](/htb/machines/windows/dificil/re)                 | Windows | <span className="dbadge dbadge-hard">HARD</span>     |

## Labs PortSwigger que practican XML External Entity (9)

| Lab                                                                                                                                                        | Dificultad                                                 | Topic                     | Oficial                                                                                                               |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| [Exploiting XXE to perform SSRF attacks](/portswigger/labs/xxe/exploiting-xxe-to-perform-ssrf)                                                             | <span className="dbadge dbadge-easy">APPRENTICE</span>     | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/lab-exploiting-xxe-to-perform-ssrf)                                  |
| [Exploiting XXE to retrieve data by repurposing a local DTD](/portswigger/labs/xxe/blind-xxe-trigger-error-message-by-repurposing-local-dtd)               | <span className="dbadge dbadge-easy">APPRENTICE</span>     | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/blind/lab-xxe-trigger-error-message-by-repurposing-local-dtd)        |
| [Exploiting XXE using external entities to retrieve files](/portswigger/labs/xxe/exploiting-xxe-to-retrieve-files)                                         | <span className="dbadge dbadge-easy">APPRENTICE</span>     | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/lab-exploiting-xxe-to-retrieve-files)                                |
| [Blind XXE with out-of-band interaction](/portswigger/labs/xxe/blind-xxe-with-out-of-band-interaction)                                                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/blind/lab-xxe-with-out-of-band-interaction)                          |
| [Blind XXE with out-of-band interaction via XML parameter entities](/portswigger/labs/xxe/blind-xxe-with-out-of-band-interaction-using-parameter-entities) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/blind/lab-xxe-with-out-of-band-interaction-using-parameter-entities) |
| [Exploiting blind XXE to exfiltrate data using a malicious external DTD](/portswigger/labs/xxe/blind-xxe-with-out-of-band-exfiltration)                    | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/blind/lab-xxe-with-out-of-band-exfiltration)                         |
| [Exploiting blind XXE to retrieve data via error messages](/portswigger/labs/xxe/blind-xxe-with-data-retrieval-via-error-messages)                         | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/blind/lab-xxe-with-data-retrieval-via-error-messages)                |
| [Exploiting XInclude to retrieve files](/portswigger/labs/xxe/xinclude-attack)                                                                             | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/lab-xinclude-attack)                                                 |
| [Exploiting XXE via image file upload](/portswigger/labs/xxe/xxe-via-file-upload)                                                                          | <span className="dbadge dbadge-medium">PRACTITIONER</span> | XXE (XML External Entity) | [Abrir](https://portswigger.net/web-security/xxe/lab-xxe-via-file-upload)                                             |

## Rooms TryHackMe que practican XML External Entity (4)

| Room                                                                | Dificultad                                         | Tipo        | Acceso  | Oficial                                                   |
| ------------------------------------------------------------------- | -------------------------------------------------- | ----------- | ------- | --------------------------------------------------------- |
| [Advent of Cyber 2024](/tryhackme/rooms/adventofcyber2024)          | <span className="dbadge dbadge-easy">EASY</span>   | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/adventofcyber2024)     |
| [GeoServer: CVE-2025-58360](/tryhackme/rooms/geoservercve202558360) | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/geoservercve202558360) |
| [NahamStore](/tryhackme/rooms/nahamstore)                           | <span className="dbadge dbadge-easy">MEDIUM</span> | Challenge   | 🟢 Free | [Abrir](https://tryhackme.com/room/nahamstore)            |
| [XXE Injection](/tryhackme/rooms/xxeinjection)                      | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP  | [Abrir](https://tryhackme.com/room/xxeinjection)          |

## Skills relacionadas

* [/skills/lfi](/skills/lfi)
* [/skills/ssrf](/skills/ssrf)

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"XML External Entity","termCode":"xxe","inLanguage":"es","url":"https://rootea.es/skills/xxe","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"Máquinas HTB que practican XML External Entity","numberOfItems":6,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/htb/machines/linux/medio/aragog","name":"Aragog"},{"@type":"ListItem","position":2,"url":"https://rootea.es/htb/machines/linux/facil/bountyhunter","name":"BountyHunter"},{"@type":"ListItem","position":3,"url":"https://rootea.es/htb/machines/linux/medio/devoops","name":"DevOops"},{"@type":"ListItem","position":4,"url":"https://rootea.es/htb/machines/linux/insano/fulcrum","name":"Fulcrum"},{"@type":"ListItem","position":5,"url":"https://rootea.es/htb/machines/linux/facil/nodeblog","name":"NodeBlog"},{"@type":"ListItem","position":6,"url":"https://rootea.es/htb/machines/windows/dificil/re","name":"RE"}]}`}
</script>

*Última actualización: 2026-05-09*
