LAB 241 - Defending C# Applications Against eXternal XML Entity (XXE) Vulnerabilities

Course Overview

This lab simulates a Weak File Upload Validation vulnerability found in the LetSee Cyber Range. The challenge includes a Web App developed in C# that fails to implement the security principle of “Validate all Untrusted Input Before Using”.

Using Visual Studio Code, participants will analyze code to identify and mitigate instances of “Failure to validate input in file upload”. The objective of this lab is to find the vulnerable code and fix the weakness.

Upon completion of this lab participants will:

  • Apply strategic principles to keep C# applications safe
  • Demonstrate the skills needed to discover XXE attacks
  • Fix XXE vulnerabilities in C#

Looking To Learn More?

Request more information on our courses and labs.

Course Details

Course Number: LAB 241

Course Duration: 10 minutes

Course CPE Credits: 0.25





Foreign Languages Available:

  • English