Vulnerability assessment tool for web services and XML ?

Vulnerability assessment tool for web services and XML ?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Vulnerability assessment tool for web services and XML ? SAD 09-27-2005
Posted by SAD on September 27, 2005, 11:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
This list of XML and web services vulnerabilities includes libraries,
operating systems, databases, and protocols:

http://www.webservicessummit.com/Vulnerabilities.htm

Is there a vulnerability assessment tool that can analyze XML,
libraries, SOAP, and web service message flows?



Posted by Lassi Hippeläinen on September 28, 2005, 10:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
SAD kirjoitti:
> This list of XML and web services vulnerabilities includes libraries,
> operating systems, databases, and protocols:
>
> http://www.webservicessummit.com/Vulnerabilities.htm
>
> Is there a vulnerability assessment tool that can analyze XML,
> libraries, SOAP, and web service message flows?

Codenomicon does many kinds of testing. Check if they have what you need:
http://www.codenomicon.com/products/

-- Lassi


Posted by Volker Birk on October 4, 2005, 3:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> This list of XML and web services vulnerabilities includes libraries,
> operating systems, databases, and protocols:
> http://www.webservicessummit.com/Vulnerabilities.htm
> Is there a vulnerability assessment tool that can analyze XML,
> libraries, SOAP, and web service message flows?

"Security of webservices" is an oxymoron.

Webservices are the idea to ignore all those incommodious "firewalls"
and all that stuff by establishing a protocol for tunneling RPC and
message exchange through HTTP and SMTP. This protocol is named SOAP.

It has exactly NONE advantages at all above other well-known middleware
architectures like CORBA, with the exception that it is doing this
and having the drawback of needing factor 100 to 1000 times the CPU
and bandwidth SUN RPC or even IIOP is needing to do just the same.

So not without irony I would say, SOAP can be driven safely in a well
controlled encrypted VPN :-P

Oh, I forgot, it has the great advantage to be XML. Being XML is an
advantage, isn't it? All of the tie wearing chainiks recommend it,
so there _must_ be an advantage after all!!1!!!!111

;-)

Yours,
VB.
--
MAC-Filtering bringt so viel Schutz vor "Hackern" wie Zeitungspapier vor
einer Atombome. (MAC filtering is protecting against "hackers" like newsprint
is protecting against a nuclear bomb)
- Christian Forler in de.comp.security.misc


Similar ThreadsPosted
** Risk Assessment / C&A consulting August 22, 2006, 6:04 pm
Stealth Network Assessment Techniques January 11, 2006, 9:28 am
Services on Netscreen firewall November 24, 2006, 12:54 am
https web mail services January 11, 2007, 6:12 am
Limousine Services Orange County February 23, 2008, 6:42 am
Windows Utility to Monitor Starting of Services? April 27, 2008, 2:42 pm
SSRT3622 rev.1 Potential Security Vulnerabilities in HP WBEM Services for HP-UX June 7, 2005, 5:01 pm
SSRT3622 rev.2 Potential Security Vulnerabilities in HP WBEM Services for HP-UX June 10, 2005, 6:39 pm
SSRT4717 rev.2 WBEM Services Remote Denial of Service (DoS) June 23, 2005, 3:53 pm
IBM Launches Services to Combat Worm and Virus Threats March 28, 2006, 2:02 pm

The site map in XML format XML site map

Contact Us | Privacy Policy