When XML Payloads are permitted, system can be attacked through XML Data.
The Over sized Payload Attack: Sending huge files and causing DOS (Denial of Service).
The DOM Parser Attacks: Sending too complex lengthy data and causing out of memory in system.
SQL Injections: If data is used directly to insert into database through statements.
1. Define strict XSDs.
2. Avoid maxOccurs=”unbounded” and limit with max values
3. Don’t parse files/data if it exceeds configured size.
Better to use XML Firewalls
Forum Sentry API Gateway: http://www.forumsys.com/products/forum-sentry-api-gateway/
Cisco ACE XML Gateways