Not able to solve xml entity expansion issue in java

Viewed 885

i am using below request to send data to class

<!DOCTYPE foo [
<!ENTITY xeebri2n3 "o16ja">]>
<SubmitPaymentRequest xmlns="http://www.qwest.com/XMLSchema" xmlns:bim="http://www.qwest.com/XMLSchema/BIM">
    <EPWFHeaderInfo>
        <bim:RequestId>IR1BCSRDQBSIRW7745 &xeebri2n3;&xeebri2n3;&xeebri2n3;</bim:RequestId>
        <bim:SendTimeStamp>2019-12-23T14:23:01.183-05:00</bim:SendTimeStamp>
        <bim:MessageSrcSystem>IPS</bim:MessageSrcSystem>
    </EPWFHeaderInfo>
</SubmitPaymentRequest >

i am passing xml request to below code in string format now i want that all DOCTYPE and its ENTITY will not be used before converting to java object and i am using below code to achieve that one but not able to solve the problem entity value is still appended in data field , so attacker can still attack on code so is there any way i can remove doctype and entity without throwing an exception and processed my data without any DOCTYPE

class Parsing {

public static String formatXML(String s) {
        StringReader sr = null;
        StringWriter sw = null;
        Writer writer = null;
        try {
            t
            XMLReader reader = XMLReaderFactory.createXMLReader();
            //reader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);                        
            reader.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false);
            reader.setFeature("http://xml.org/sax/features/external-general-entities", false);
            reader.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
            Source xmlInput = new SAXSource(reader, new InputSource(new StringReader( s )));
            // sr = new StringReader(s);
             //Source xmlInput = new StreamSource(sr);
             sw = new StringWriter();
             StreamResult xmlOutput = new StreamResult(sw);
            
             // Configure transformer
             Transformer transformer =
             TransformerFactory.newInstance().newTransformer(); // An
            // identity
            // transformer
             transformer.setOutputProperty(OutputKeys.DOCTYPE_SYSTEM,
             "testing.dtd");
             transformer.setOutputProperty(OutputKeys.INDENT, "yes");
             transformer.setOutputProperty("{http://xml.apache.org/xslt}indent-amount",
             "4");
             transformer.transform(xmlInput, xmlOutput);
             writer = xmlOutput.getWriter();
             return writer.toString();
            
            
            
        } catch (Exception e) {
            logger.error("Caught exception", e);
        }
        finally{
        StringBuilder errMsg = new StringBuilder("Exception caught while closing");
        try{ if(sr != null) sr.close();}catch(Exception ie){logger.error(errMsg.append("StringReader").toString(),ie);}
        try{ if(sw != null)sw.close();}catch(IOException ie){logger.error(errMsg.append(" StringWriter").toString(),ie);}
        try{if(writer != null)writer.close();}catch(IOException ex){logger.error(errMsg.append("Writer"),ex);};
            
        }
        return s;
    }
}
0 Answers
Related