Home > Software Quality News > Web services pen testing tool released
Software Quality News:
EMAIL THIS

Web services pen testing tool released

By SearchAppSecurity.com Staff
26 Apr 2006 | SearchAppSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

NeuroFuzz has released WSFuzzer Version 1.5, a pen testing tool that audits HTTP-based SOAP targets.

The program currently targets Web Services and includes the following features:

  • It attacks a Web service based on either valid WSDL, a valid endpoint and namespace, or it can try to intelligently detect WSDL for a given target.
  • It gives you the ability to handle methods with multiple parameters. Each parameter is handled as a unique entity and can either be attacked or left alone.
  • The fuzz generation (attack strings) consists of a combination of a dictionary file and some dynamic large injection patterns.
  • It provides the option of using some IDS evasion techniques, which makes for a powerful security infrastructure (IDS/IPS) testing experience.

The creators warn that WSFuzzer is a dangerous tool. You can easily bring down your target if it is susceptible to any of the attack vectors generated and sent in, they say. They also stress that WSFuzzer should be used only on targets that have given you permission to pen test their Web services and applications.

Requirements to run WSFuzzer:

  • A working version of Python
  • A working version of SOAPpy

The program has successfully been used in Linux, Mac OS X and Windows (using Active-State Python) environments.

For more information, visit http://www.neurofuzz.com/modules/software/wsfuzzer.php



Tags: Software security testing and techniquesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Software security testing and techniques
Web server weaknesses you don't want to overlook
Using firewalls for software testing: Pros and cons
Beating software's cross-site scripting, authentication problems
Free Web proxy security tools software testers should get to know
How to get management on board with Web 2.0 security issues
Web application security best practices: Tips on implementation
Testing strategies for complex environments
How to make your software tamperproof
Ways to approach application performance testing on a tight budget
How can I tell if my software security has been breached?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Software Development Methods - Extreme Programming, Agile Programming, Scrum
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts