Attacks through XML Payloads

When XML Payloads are permitted, system can be attacked through XML Data.

The Over sized Payload Attack: Sending huge files and causing DOS (Denial of Service).
The DOM Parser Attacks: Sending too complex lengthy data and causing out of memory in system.
SQL Injections: If data is used directly to insert into database through statements.

Development Side:
1. Define strict XSDs.
2. Avoid maxOccurs=”unbounded” and limit with max values
3. Don’t parse files/data if it exceeds configured size.

System Side:
Better to use XML Firewalls
Forum Sentry API Gateway:
Cisco ACE XML Gateways



