One of our agents managed to install a service on MOTHER’s network. We can use it to extract secrets, but she didn’t tell me how! Can you figure it out?
nc extract.tghack.no 6000
Analysis
Target service requires us to provide XML document.
Simple XXE vulnerabilty that can be exploited here by sending following payload: