

Inspecting the `Send Message` button we can see that it's `onclick` is an `XMLFunction()`
Capturing the request with burp we have

Editing this we can test for `XXE`

`XXE` is in play. Hekkerman has a home folder, maybe the flag is in there

---
Back to [[_WebSite Publish/CTF/CTF Index|CTF Index]]]
Tags: #ctf #xxe #web
Related: