> For the complete documentation index, see [llms.txt](https://thmflags.gitbook.io/thm-walkthroughs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thmflags.gitbook.io/thm-walkthroughs/difficulty-easy/owasp-top-10/task-16-xml-external-entity-exploiting.md).

# Task 16 - XML External Entity - Exploiting

## Task 16 <mark style="color:blue;background-color:blue;">\[Severity 4]</mark> XML External Entity - Exploiting

### Try to display your own name using any payload.

{% hint style="success" %}
**HINT:** No answer needed
{% endhint %}

### See if you can read the /etc/passwd

{% hint style="success" %}
**HINT:** No answer needed
{% endhint %}

### What is the name of the user in /etc/passwd

<details>

<summary>Reveal Flag <span data-gb-custom-inline data-tag="emoji" data-code="1f6a9">🚩</span></summary>

:triangular\_flag\_on\_post:`falcon`

</details>

### Where is falcon's SSH key located?

<details>

<summary>Reveal Flag <span data-gb-custom-inline data-tag="emoji" data-code="1f6a9">🚩</span></summary>

:triangular\_flag\_on\_post:`/home/falcon/.ssh/id_rsa`

</details>

### What are the first 18 characters for falcon's private key

<details>

<summary>Reveal Flag <span data-gb-custom-inline data-tag="emoji" data-code="1f6a9">🚩</span></summary>

:triangular\_flag\_on\_post:`MIIEogIBAAKCAQEA7`

</details>
