Penetration Testing mailing list archives
RE: Tools to test web services
From: "Rosado, Rafael (Rafael)" <rarosado () lucent com>
Date: Mon, 26 Apr 2004 10:15:10 -0600
PAK, I forgot to mention some other tools that do some application level pen testing: AppScan from Sanctum (http://www.sanctuminc.com/) ScanDo from KavaDo (http://www.kavado.com/) There is also an automated penetration testing tool called Core Impact (http://www.coresecurity.com/products/coreimpact/) you might want to look into. Rafael Rosado, CISSP, CISA Lucent IT Infrastructure Security Voice: 954-885-2176 Fax: 954-885-3861 Email: rarosado () lucent com This e-mail message and any attachment(s) to it are intended only for the use of the addressee(s). The information in this e-mail message is confidential and proprietary and may be subject to legal privilege. The reading or dissemination of this email by anyone other than the intended recipient is strictly prohibited. If you believe you have received this e-mail in error, please notify the sender immediately and permanently delete this e-mail, any attachments and all copies thereof from any drives or storage media and destroy any printouts. -----Original Message----- From: Leewarner, Joshua (US - Seattle) [mailto:jleewarner () deloitte com] Sent: Saturday, April 24, 2004 4:53 PM To: pak; pen-test () securityfocus com Subject: RE: Tools to test web services Pak, You might want to look at WebInspect from SPIDynamics. Specs on their tool here: http://www.spidynamics.com/productline/WE_specs.html. I don't recall off-hand what all components it can check, but I know that it does assess web-services to an extent. You might have to inquire from the company to see if they can cover your laundry list below. Joshua Leewarner, CISSP Deloitte / Security Services Group -----Original Message----- From: pak [mailto:pak_ml () btopenworld com] Sent: Saturday, April 24, 2004 2:15 AM To: pen-test () securityfocus com Subject: Tools to test web services Hi, I was asked to do penetration testing of web services built on .NET Framework; therefore I'm looking for the tool that could test web services and adequately supports standards such as WS-Security, SAML, XML-Encryption, XML-Signature. So far the only thing I could do is to write such tool on my own, but maybe there are tools out there (commercial and/or non-commercial), I'm not aware of, that can help me. Any help/suggestions/tools/papers what and how to test are more than welcome. Cheers, Pak76 ------------------------------------------------------------------------ ------ Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ------------------------------------------------------------------------ ------- This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. If you are not the intended recipient, you should delete this message. Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited. ---------------------------------------------------------------------------- -- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ---------------------------------------------------------------------------- --- ------------------------------------------------------------------------------ Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html -------------------------------------------------------------------------------
Current thread:
- Tools to test web services pak (Apr 24)
- <Possible follow-ups>
- RE: Tools to test web services Leewarner, Joshua (US - Seattle) (Apr 26)
- RE: Tools to test web services Rosado, Rafael (Rafael) (Apr 26)
- Re: Tools to test web services pak (Apr 26)
- RE: Tools to test web services Rosado, Rafael (Rafael) (Apr 26)