- XML jar remote host and hang for a remote code exec.
- The flag is hosted inside of a DMZ machine and the only machine it can talk to is the public facing server which run the java application which is vulnerable to xml the script
- wNormal XML for a remote DTD exfiltrate the flag.
- Local DTD file exfiltration.