• Email
  • Favorite
  • Download
  • Embed
  • Private Content

Don't Drop the SOAP: Real World Web Service Testing for Web Hackers

by Tom Eston on Aug 31, 2011

  • 5,200 views

Over the years web services have become an integral part of web and mobile applications. From critical business applications like SAP to mobile applications used by millions, web services are becoming ...

Over the years web services have become an integral part of web and mobile applications. From critical business applications like SAP to mobile applications used by millions, web services are becoming more of an attack vector than ever before. Unfortunately, penetration testers haven't kept up with the popularity of web services, recent advancements in web service technology, testing methodologies and tools. In fact, most of the methodologies and tools currently available either don't work properly, are poorly designed or don't fully test for real world web service vulnerabilities. In addition, environments for testing web service tools and attack techniques have been limited to home grown solutions or worse yet, production environments.

In this presentation Tom, Josh and Kevin will discuss the new security issues with web services and release an updated web service testing methodology that will be integrated into the OWASP testing guide, new Metasploit modules and exploits for attacking web services and a open source vulnerable web service for the Samurai-WTF (Web Testing Framework) that can be used by penetration testers to test web service attack tools and techniques.

Accessibility

Categories

Tags

owasp web service oracle webservices defcon hacking webapp soap blackhat penetration test webapplication glassfish metasploit pentest security samurai-wtf

More...

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

11 Embeds 3,564

http://www.spylogic.net 3482
http://www.securitybloggersnetwork.com 31
http://feeds2.feedburner.com 15
http://w3.isvoc.com 11
http://feeds.feedburner.com 7
http://translate.googleusercontent.com 6
http://podcast.isvoc.com 6
http://blog.isvoc.com 3
http://www.netvibes.com 1
http://webcache.googleusercontent.com 1
http://twitter.com 1

More...

Statistics

Favorites
0
Downloads
80
Comments
0
Embed Views
3,564
Views on SlideShare
1,636
Total Views
5,200
Post Comment
Edit your comment Cancel

Don’t Drop the SOAP: Real World Web Service Testing for Web Hackers — Presentation Transcript