Extensible Markup Language (.xml)
W3C ΤυπικόExtensible Markup Language (XML) is a versatile markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable.
Συμπίεση XML Online
100% ιδιωτική συμπίεση στο πρόγραμμα περιήγησης – τα αρχεία δεν φεύγουν ποτέ από τη συσκευή σας
Επιθεώρηση & Μεταδεδομένα
Τα λειτουργικά συστήματα και τα εργαλεία ανάλυσης αρχείων αναγνωρίζουν τα αρχεία XML ελέγχοντας την αρχική δυαδική ακολουθία byte:
Υπογραφή κεφαλίδας σε επίπεδο byte (Magic Bytes)
Τα λειτουργικά συστήματα και τα εργαλεία ανάλυσης αρχείων αναγνωρίζουν τα αρχεία XML ελέγχοντας την αρχική δυαδική ακολουθία byte:
ΔΕΚΑΕΞΑΔΙΚΗ ΥΠΟΓΡΑΦΗ (OFFSET 0):
3C 3F 78 6DΑΝΑΠΑΡΑΣΤΑΣΗ ASCII: <?xm
Τυποποίηση: W3C Recommendation (XML 1.0 Fifth Edition)
Τεχνικές Προδιαγραφές
| Αρχιτεκτονική Περιέκτη | Hierarchical text markup language with custom semantic tags and attributes |
| Συμπίεση | Gzip / Deflate achieves 85%-92% compression on verbose closing tags |
| Endianness Byte | UTF-8 / UTF-16 character stream determined by XML declaration encoding attribute |
| Χρωματικοί Χώροι | Not applicable |
| Κανάλια & Δομή | Elements (<tag>), attributes (attr="val"), CDATA blocks, processing instructions |
| Μέγιστες Διαστάσεις | Unbounded hierarchical tree structure |
| Διαφάνεια | Not applicable |
| Streaming & Προοδευτική Φόρτωση | SAX (Simple API for XML) and StAX parsers enable memory-efficient stream reading |
Τεχνικός Πίνακας Σύγκρισης: XML έναντι Ανταγωνιστών
| Τεχνικό χαρακτηριστικό | XML (Τρέχον) | JSON | YAML | Protocol Buffers |
|---|---|---|---|---|
| Verbosity | High (closing tags and attribute syntax) | Low (compact key-value format) | Low (indentation-based) | Ultra-low (binary serialization) |
| Schema Validation | Mature XSD & DTD standards with compiler enforcement | JSON Schema (optional) | JSON Schema / Yaml schemas | Strict .proto schema definitions |
| Namespaces | Native XML namespaces (xmlns) support | No native namespace mechanism | No native namespace mechanism | Package declarations |
| Transformations | XSLT declarative transformation pipelines | Custom code / jq scripts | Custom code | Custom code |
Συνηθισμένοι Τρόποι Διαφθοράς & Οδηγός Ανάκτησης Hex
⚠️ XML Parsing Error: mismatched tag or entity not defined.
Βασική Αιτία: Unescaped reserved characters (like '&', '<', or '>') or case mismatch between opening and closing tags.
Ανάκτηση: Replace '&' with '&', '<' with '<', '>' with '>', or wrap arbitrary text inside '<![CDATA[ ... ]]>'' blocks.
Ανάλυση Ασφάλειας & Διανύσματα Επίθεσης Parser
XML parsers have historically been one of the most attacked components in enterprise computing due to powerful DTD and entity expansion capabilities.
Γνωστά διανύσματα επίθεσης
- XML External Entity (XXE): Malicious DOCTYPE referencing local server files ('file:///etc/passwd') or internal network endpoints.
- Billion Laughs Attack (XML Bomb): Nested entity declarations expanding exponentially in memory to cause denial of service.
- XPath Injection: Unsanitized user inputs allowing unauthorized querying of XML databases.
Βέλτιστες αμυντικές πρακτικές: Always disable external DTD resolution and external entity processing (setFeature 'disallow-doctype-decl' to true) in XML parsers.
Ιστορική Αναδρομή & Ορόσημα
Κύρια Πλεονεκτήματα
- Rigorous schema validation using XSD (XML Schema Definition) or DTD ensures strict data integrity.
- Namespaces (xmlns) prevent element name collisions in complex multi-source documents.
- Powerful querying and transformation toolchains (XPath, XSLT, XQuery).
Τεχνικοί Περιορισμοί & Μειονεκτήματα
- Extremely verbose: closing tags repeat element names, creating large file sizes and high bandwidth consumption.
- DOM parsing builds large memory-intensive object trees.
- Prone to XML External Entity (XXE) and entity expansion security vulnerabilities.
Ενδιαφέροντα Τεχνικά Στοιχεία
- XML is a simplified subset of SGML (Standard Generalized Markup Language), designed to work seamlessly over the World Wide Web.
- Modern office documents (.docx, .xlsx), vector images (.svg), and RSS feeds are all specialized XML dialects.
Συχνές Τεχνικές Ερωτήσεις
What is the difference between well-formed and valid XML?
'Well-formed' XML follows the basic syntax rules (matching tags, quotes around attributes, single root element). 'Valid' XML is well-formed AND adheres strictly to an external schema definition (XSD or DTD).
Why did JSON replace XML for most web APIs?
JSON maps directly to native JavaScript and programming language data structures (hash maps and arrays) with much less boilerplate, faster parsing, and smaller network payloads.