Java XXE Data Exfiltration Paths
Lab DocumentBuilder/TransformerFactory features to disable, tiny file:// entity to a lab file, parser throws or ignores — no FTP exfil.
Lab DocumentBuilder/TransformerFactory features to disable, tiny file:// entity to a lab file, parser throws or ignores — no FTP exfil.
Lab Swift class LabVault: $s… mangled names, xcrun swift demangle, nm before/after strip, the one @objc method that survives in __objc_methname. class-dump, lldb, ASAN. cryptid=1 stops the lab.
One lab APK, one arm64-v8a .so. file/readelf/llvm-objdump through JNI_OnLoad, Java_* exports, GetStringUTFChars, a 32-byte stack copy, tombstone and ASAN. Frida logs length and prefix only.
Lab PyYAML: yaml.safe_load vs yaml.load, implicit typing, billion-laughs-sized crash — no os.system gadget via YAML tags.
Lab crash on a self-signed LabSession: dwarfdump -u, atos against the dSYM, why UIKit frames are not in nm of the app, crash report with [REDACTED] paths. No DSC extraction. cryptid=1 stops the lab.
Futex, perf_event, and get_user-era Android kernel LPE classes as broken invariants. No kernel exploit code. A toy C file-TOCTOU analog, a planted strcpy, ASAN output.
Lab UA / UA-CH request headers, navigator.userAgentData mock dump, nginx log_format for defenders — no exploit targeting.
Self-built AIDL service com.lab.binder. dumpsys and logcat Binder, Parcel bytes for writeInterfaceToken + int + string, ARM64 BnEcho::onTransact. No privilege escalation.