RE: Tools to test web services

From: Rosado, Rafael (Rafael) (rarosado_at_lucent.com)
Date: 04/26/04

  • Next message: Robert E. Lee: "RE: Questions: nmap, nessus unreliability, setting up a packet capture box, using Impacket"
    To: "Leewarner, Joshua (US - Seattle)" <jleewarner@deloitte.com>, pak <pak_ml@btopenworld.com>, pen-test@securityfocus.com
    Date: Mon, 26 Apr 2004 10:15:10 -0600
    
    

    PAK,

    I forgot to mention some other tools that do some application level pen
    testing:

    AppScan from Sanctum (http://www.sanctuminc.com/)
    ScanDo from KavaDo (http://www.kavado.com/)

    There is also an automated penetration testing tool called Core Impact
    (http://www.coresecurity.com/products/coreimpact/) you might want to look
    into.

    Rafael Rosado, CISSP, CISA
    Lucent IT Infrastructure Security
    Voice: 954-885-2176
    Fax: 954-885-3861
    Email: rarosado@lucent.com

    This e-mail message and any attachment(s) to it are intended only for the
    use of the addressee(s). The information in this e-mail message is
    confidential and proprietary and may be subject to legal privilege. The
    reading or dissemination of this email by anyone other than the intended
    recipient is strictly prohibited. If you believe you have received this
    e-mail in error, please notify the sender immediately and permanently delete
    this e-mail, any attachments and all copies thereof from any drives or
    storage media and destroy any printouts.
    -----Original Message-----
    From: Leewarner, Joshua (US - Seattle) [mailto:jleewarner@deloitte.com]
    Sent: Saturday, April 24, 2004 4:53 PM
    To: pak; pen-test@securityfocus.com
    Subject: RE: Tools to test web services

    Pak,

    You might want to look at WebInspect from SPIDynamics.

    Specs on their tool here:
    http://www.spidynamics.com/productline/WE_specs.html.

    I don't recall off-hand what all components it can check, but I know that it
    does assess web-services to an extent. You might have to inquire from the
    company to see if they can cover your laundry list below.

    Joshua Leewarner, CISSP
    Deloitte / Security Services Group

    -----Original Message-----
    From: pak [mailto:pak_ml@btopenworld.com]
    Sent: Saturday, April 24, 2004 2:15 AM
    To: pen-test@securityfocus.com
    Subject: Tools to test web services

    Hi,

    I was asked to do penetration testing of web services built on .NET
    Framework; therefore I'm looking for the tool that could test web services
    and adequately supports standards such as WS-Security, SAML, XML-Encryption,
    XML-Signature. So far the only thing I could do is to write such tool on my
    own, but maybe there are tools out there (commercial and/or non-commercial),
    I'm not aware of, that can help me.
    Any help/suggestions/tools/papers what and how to test are more than
    welcome.

    Cheers,

    Pak76

    ------------------------------------------------------------------------
    ------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab.
    Master the skills of an Ethical Hacker to better assess the security of your
    organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ------------------------------------------------------------------------
    -------

    This message (including any attachments) contains confidential information
    intended for a specific individual and purpose, and is protected by law. If
    you are not the intended recipient, you should delete this message. Any
    disclosure, copying, or distribution of this message, or the taking of any
    action based on it, is strictly prohibited.

    ----------------------------------------------------------------------------

    --
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the
    skills of an Ethical Hacker to better assess the security of your
    organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------
    

  • Next message: Robert E. Lee: "RE: Questions: nmap, nessus unreliability, setting up a packet capture box, using Impacket"

    Relevant Pages

    • Re: The Ultimate Toolkit...
      ... |>> to facilitate one-on-one interaction with one of our expert instructors. ... |>> pen testing experience in our state of the art hacking lab. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Pen-Test)
    • RE: Removing Local Admin Rights...
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: Cisco CSA
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • RE: Minimum password requirements
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Betr.: RE: fax software in the domain
      ... Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... pen testing experience in our state of the art hacking lab. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)

  • Quantcast