Extensible Markup Language (.xml)

W3C มาตรฐาน

Extensible Markup Language (XML) is a versatile markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable.

บีบอัด XML ออนไลน์

บีบอัดแบบส่วนตัว 100% ในเบราว์เซอร์ – ไฟล์ไม่เคยออกจากอุปกรณ์ของคุณ

ตรวจสอบและดู Metadata

ระบบปฏิบัติการและเครื่องมือวิเคราะห์ไฟล์จะระบุไฟล์ XML โดยการตรวจสอบลำดับไบต์ไบนารีส่วนต้น:

เลือกหรือลากไฟล์

เลือกหรือวางไฟล์ที่นี่

การแปลงไฟล์แบบส่วนตัว 100% ในเบราว์เซอร์ - ไฟล์จะไม่ rời ออกจากอุปกรณ์ของคุณ

หรือวาง Ctrl+V
การรับประกันความเป็นส่วนตัวแบบไม่มีการส่งผ่านเครือข่าย: อัปโหลด 0 ไบต์ไปยังเซิร์ฟเวอร์ภายนอก การประมวลผลทั้งหมดเกิดขึ้นภายในแซนด์บ็อกซ์ของเบราว์เซอร์ของคุณ

ลายเซ็นส่วนหัวในระดับไบต์ (Magic Bytes)

ระบบปฏิบัติการและเครื่องมือวิเคราะห์ไฟล์จะระบุไฟล์ XML โดยการตรวจสอบลำดับไบต์ไบนารีส่วนต้น:

ลายเซ็น HEX (OFFSET 0):

3C 3F 78 6D

การแสดงผลรูปแบบ ASCII: <?xm

มาตรฐาน: W3C Recommendation (XML 1.0 Fifth Edition)

ข้อมูลจำเพาะทางเทคนิค

สถาปัตยกรรมคอนเทนเนอร์Hierarchical text markup language with custom semantic tags and attributes
การบีบอัดGzip / Deflate achieves 85%-92% compression on verbose closing tags
การจัดลำดับไบต์ (Byte Endianness)UTF-8 / UTF-16 character stream determined by XML declaration encoding attribute
พื้นที่สีNot applicable
ช่องสัญญาณและโครงสร้างElements (<tag>), attributes (attr="val"), CDATA blocks, processing instructions
ขนาดสูงสุดUnbounded hierarchical tree structure
ความโปร่งใสNot applicable
การสตรีมและแบบโปรเกรสซีฟSAX (Simple API for XML) and StAX parsers enable memory-efficient stream reading

ตารางเปรียบเทียบทางเทคนิค: XML กับคู่แข่ง

คุณลักษณะทางเทคนิคXML (ปัจจุบัน)JSONYAMLProtocol Buffers
VerbosityHigh (closing tags and attribute syntax)Low (compact key-value format)Low (indentation-based)Ultra-low (binary serialization)
Schema ValidationMature XSD & DTD standards with compiler enforcementJSON Schema (optional)JSON Schema / Yaml schemasStrict .proto schema definitions
NamespacesNative XML namespaces (xmlns) supportNo native namespace mechanismNo native namespace mechanismPackage declarations
TransformationsXSLT declarative transformation pipelinesCustom code / jq scriptsCustom codeCustom code

รูปแบบความเสียหายทั่วไปและคู่มือการกู้คืน Hex

⚠️ XML Parsing Error: mismatched tag or entity not defined.

สาเหตุหลัก: Unescaped reserved characters (like '&', '<', or '>') or case mismatch between opening and closing tags.

การกู้คืน: Replace '&' with '&amp;', '<' with '&lt;', '>' with '&gt;', or wrap arbitrary text inside '<![CDATA[ ... ]]>'' blocks.

การวิเคราะห์ความปลอดภัยและเวกเตอร์การโจมตีตัวแยกวิเคราะห์

XML parsers have historically been one of the most attacked components in enterprise computing due to powerful DTD and entity expansion capabilities.

เวกเตอร์การโจมตีที่ทราบ

  • XML External Entity (XXE): Malicious DOCTYPE referencing local server files ('file:///etc/passwd') or internal network endpoints.
  • Billion Laughs Attack (XML Bomb): Nested entity declarations expanding exponentially in memory to cause denial of service.
  • XPath Injection: Unsanitized user inputs allowing unauthorized querying of XML databases.

แนวทางปฏิบัติที่ดีที่สุดในการป้องกัน: Always disable external DTD resolution and external entity processing (setFeature 'disallow-doctype-decl' to true) in XML parsers.

ประวัติความเป็นมาและเหตุการณ์สำคัญ

2008W3C publishes XML 1.0 Fifth Edition, standardizing modern international character support.
1998W3C publishes XML 1.0 Recommendation as a simplified, web-friendly subset of SGML.

ข้อได้เปรียบและจุดเด่นสำคัญ

  • Rigorous schema validation using XSD (XML Schema Definition) or DTD ensures strict data integrity.
  • Namespaces (xmlns) prevent element name collisions in complex multi-source documents.
  • Powerful querying and transformation toolchains (XPath, XSLT, XQuery).

ข้อจำกัดทางเทคนิคและข้อควรพิจารณา

  • Extremely verbose: closing tags repeat element names, creating large file sizes and high bandwidth consumption.
  • DOM parsing builds large memory-intensive object trees.
  • Prone to XML External Entity (XXE) and entity expansion security vulnerabilities.

เกร็ดความรู้ทางเทคนิคที่น่าสนใจ

  • XML is a simplified subset of SGML (Standard Generalized Markup Language), designed to work seamlessly over the World Wide Web.
  • Modern office documents (.docx, .xlsx), vector images (.svg), and RSS feeds are all specialized XML dialects.

คำถามทางเทคนิคที่พบบ่อย

What is the difference between well-formed and valid XML?

'Well-formed' XML follows the basic syntax rules (matching tags, quotes around attributes, single root element). 'Valid' XML is well-formed AND adheres strictly to an external schema definition (XSD or DTD).

Why did JSON replace XML for most web APIs?

JSON maps directly to native JavaScript and programming language data structures (hash maps and arrays) with much less boilerplate, faster parsing, and smaller network payloads.