Main > Security & Privacy > Security >

WSFuzzer 1.9.3

WSFuzzer 1.9.3

Sponsored Links

WSFuzzer 1.9.3 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 7.7 MB
Platform: Mac OS X
License: GPL
Price: FREE
Downloads: 27
Date added: 2009-05-28
Publisher: Andres Andreu

WSFuzzer 1.9.3 description

Fuzzing penetration testing tool used against HTTP SOAP based web services

WSFuzzer is a fuzzing penetration testing tool used against HTTP SOAP based web services.
WSFuzzer is capable of testing numerous aspects (XML Parser, input validation, etc) of the SOAP target.
In the current version HTTP based SOAP services are the main target. This tool was created based on, and to automate, some real-world manual SOAP pen testing work.
WSFuzzer is NOT meant to be a replacement for solid manual human analysis. Please view WSFuzzer as a tool to augment analysis performed by competent and knowledgable professionals. Web Services are not trivial in nature so expertise in this area is a must for proper pen testing.
WARNING: WSFuzzer is only to be used against targets that have granted permission to be tested.

Main features:
- Pen tests an HTTP SOAP web service based on either valid WSDL, known good XML payload, or a valid endpoint & namespace.
- It can try to intelligently detect WSDL for a given target.
- Includes a simple TCP port scanner.
- WSFuzzer has the ability to Fuzz methods with multiple parameters. There are 2 modes of attack/fuzzing: "individual" and "simultaneous". Each parameter is either handled as a unique entity (individual mode), and can either be attacked or left alone, or multiple parameters are attacked simultaneously (hence the name - simultaneous mode) with a given data set.
- The fuzz generation (attack strings) consists of a combination of a dictionary file, some optional dynamic large injection patterns, and some optional method specific attacks including automated XXE and WSSE attack generation.
- The tool also provides the option of using some IDS Evasion techniques which makes for a powerful security infrastructure (IDS/IPS) testing experience.
- A time measurement of each round trip between request and response is now provided to potentially aid in results analysis.
- For any given program run the generated attack vectors are saved out to an xml file. The XML file is named XXX and is located in the same directory where the results HTML file is saved. A previously generated XML file of attack vectors can be utilized instead of the dictionary/automated combo. This is for the sake of repeatability when the same vectors need to be used over and over again.

WSFuzzer 1.9.3 Screenshot

Advertisements

WSFuzzer 1.9.3 Keywords

Bookmark WSFuzzer 1.9.3

Hyperlink code:
Link for forum:

WSFuzzer 1.9.3 Copyright

WareSeeker periodically updates pricing and software information of WSFuzzer 1.9.3 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of WSFuzzer 1.9.3 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Kuler - widget for the web-based color theme search and share application from Adobe Free Download
ATutor is a rather praiseworthy Open Source Web-based Learning Content Management System (LCMS) which has accessibility and adaptability in mind. Free Download
Free and open source Java web processing toolkit for your Mac JWebPro is a Java-based Web Processing toolkit that can interact with Google search via Google Web APIs and then process the returned Web Free Download
A graphical web based front end for the nfdump netflow tools NfSen is a graphical web based front end for the nfdump netflow tools. Different tasks need different interfaces to your netflow data Free Download
Webmin is created to be a smart web-based interface which helps with system administration for Unix. Free Download
Java instant messaging solution. Free Download
SOAP Client is a Cocoa-based developer application for Mac OS X Tiger that allows you to access and debug SOAP-based Web Service Free Download
A full-stack Enterprise Web Framework for agile development of secure database-driven web-based applications. Free Download