stackyFACTS
Technology

How a tiny XML file can unleash a billion laughs

HERE’S THE INTERESTING PART

Also known as an XML entity expansion attack, this vulnerability is beautifully malicious. A hacker writes a tiny text file where 'lol' is defined as ten 'lol's, and those ten are defined as ten more, compounding recursively. When the parser tries to read it, it geometrically multiplies the word until the server's brain absolutely implodes under the weight of a billion laughs.

How a tiny XML file can unleash a billion laughs
STACKY / Technology
One discovery leads to another.

Keep exploring facts in this topic.

Technology →
STACKY FOR IPHONE

A bigger world.
One discovery
at a time.

Keep discovering with Stacky. Interesting facts in an app that is always within reach.

Download on the App Store
ONE MORE DISCOVERY?

Keep exploring

All in this topic →
Security questions can be defeated with public records
Technology

Security questions can be defeated with public records

The security industry somehow believes your mother's maiden name is a highly guarded secret. Systems lock down your account with encrypted passwords, only to…

Discover more
How did facial recognition software rapidly adapt to identify people wearing masks during the global pandemic?
Technology

How did facial recognition software rapidly adapt to identify people wearing masks during the global pandemic?

How did facial recognition software rapidly adapt to identify people wearing masks during the global pandemic?

Discover more
With AI deepfakes mimicking faces and voices on video calls, which simple security habit now matters most when approving large financial transfers or sensitive requests?
Technology

With AI deepfakes mimicking faces and voices on video calls, which simple security habit now matters most when approving large financial transfers or sensitive requests?

With AI deepfakes mimicking faces and voices on video calls, which simple security habit now matters most when approving large financial transfers or…

Discover more
What is widely considered the most dangerously insecure form of two-factor authentication today?
Technology

What is widely considered the most dangerously insecure form of two-factor authentication today?

What is widely considered the most dangerously insecure form of two-factor authentication today?

Discover more
The tiny lock parts designed to defeat lockpicks
Technology

The tiny lock parts designed to defeat lockpicks

Basic locks are laughably easy to pick, so engineers added tiny, defensively shaped pins. When a thief tries to blindly shove them upward, the mushroom-shaped…

Discover more
How shared cloud storage can expose private files
Technology

How shared cloud storage can expose private files

Cloud breaches often feel like stories from a faraway digital world—until suddenly it’s your family photos or private notes drifting in places they were never…

Discover more
StackyMore discoveries in the app
Download on the App Store