<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-12015723</id><updated>2009-08-04T02:19:01.817-07:00</updated><title type='text'>wsChess Toolkit</title><subtitle type='html'>Objective of this blog is to keep track of wschess activities &amp; place holder for knowledge base. It is web services assessment and defense toolkit.&lt;br&gt;
&lt;br&gt;
Shreeraj Shah&lt;br&gt;
Founder &amp; Director&lt;br&gt;&lt;img src="http://net-square.com/advisory/_netsquare.gif"&gt;
&lt;a href="www.net-square.com"&gt;n e t - s q u a r e&lt;/a&gt;&lt;br&gt;
shreeraj@net-square.com&lt;br&gt;
&lt;a href="http://shreeraj.blogspot.com"&gt;[My blog]&lt;/a&gt;
&lt;br&gt;&lt;br&gt;
&lt;a href="http://www.net-square.com/wschess/"&gt;Download wschess&lt;/a&gt;&lt;br&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://wschess.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>shreeraj</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>19</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-12015723.post-115592267598814707</id><published>2006-08-18T10:37:00.000-07:00</published><updated>2006-08-18T10:37:56.000-07:00</updated><title type='text'>Book - Hacking Web Services</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.amazon.com/gp/product/1584504803/"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/6364/975/320/HWS_book.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Web Services are an integral part of next generation Web applications. The development and use of these services is growing at an incredible rate, and so too are the security issues surrounding them. Hacking Web Services is a practical guide for understanding Web services security and assessment methodologies. Written for intermediate-to-advanced security professionals and developers, the book provides an in-depth look at new concepts and tools used for Web services security. Beginning with a brief introduction to Web services technologies, the book discusses Web services assessment methodology, WSDL -- an XML format describing Web services as a set of endpoints operating on SOAP messages containing information -- and the need for secure coding. Various development issues and open source technologies used to secure and harden applications offering Web services are also covered. Throughout the book, detailed case studies, real-life demonstrations, and a variety of tips and techniques are used to teach developers how to write tools for Web services. If you are responsible for securing your company's Web services, this is a must read resource!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/gp/product/1584504803/"&gt;More information&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-115592267598814707?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/115592267598814707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/115592267598814707'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2006/08/book-hacking-web-services.html' title='Book - Hacking Web Services'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-113843933320158518</id><published>2006-01-28T01:05:00.000-08:00</published><updated>2006-01-28T01:08:53.213-08:00</updated><title type='text'>Releasing 1.5</title><content type='html'>Following changes are included.&lt;br /&gt;&lt;br /&gt;+ Few bugs are solved&lt;br /&gt;+ wspawn is now querying Xmethods. UBRs are closed for Microsoft, IBM etc.&lt;br /&gt;+ wsknight has analysis engine in place. You can supply regex patterns and wsaudit will detect them.  It will change color of text. Sample rule file is included.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-113843933320158518?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/113843933320158518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/113843933320158518'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2006/01/releasing-15.html' title='Releasing 1.5'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-113698673697602626</id><published>2006-01-11T05:38:00.000-08:00</published><updated>2006-01-11T05:38:56.986-08:00</updated><title type='text'>Domain footprinting is branched out into MSNPawn</title><content type='html'>It is in the form of new tool called MSNPawn.&lt;br /&gt;&lt;br /&gt;MSNPawn has been designed and developed on the .Net framework and must be installed on the system. The following utilities have been bundled with MSNPawn.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MSNHostFP&lt;/b&gt; - Supply an IP Address or IP Address range to fetch all possible virtual hosts or application running on each IP addresses.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MSNDomainFP -&lt;/b&gt; Supply a domain name to fetch the top 50 child domains, considering the supplied domain name as parent.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MSNCrossDomainFP -&lt;/b&gt; Supply an application domain to fetch the top 50 domains pointing to this particular domain on the Internet.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MSNCrawler -&lt;/b&gt; Supply a domain or application name to fetch all possible links crawled by the search engine.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MSNFetch -&lt;/b&gt; Supply a domain and rules file. The tool will run each rule in the file against the domain specified and fetch the first five results of the resultant query. This can help in assessing an application.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Search.MSN -&lt;/b&gt; Provides place to run your search against MSN and gather all URLs.&lt;br /&gt;&lt;br /&gt;Whitepaper is included for better understanding for all these tools.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://net-square.com/msnpawn/msnpawn_1.0.zip"&gt;[Download]&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://net-square.com/msnpawn/MSNPawn_research_usage.pdf"&gt;[Download paper]&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-113698673697602626?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/113698673697602626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/113698673697602626'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2006/01/domain-footprinting-is-branched-out.html' title='Domain footprinting is branched out into MSNPawn'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-112348189093287356</id><published>2005-08-07T23:14:00.000-07:00</published><updated>2005-08-17T22:34:32.066-07:00</updated><title type='text'>Releasing beta 1.4</title><content type='html'>Some bugs are rectified in this build. These bugs were in following areas&lt;br /&gt;1. wsKnight - SOAP action tag in header and host&lt;br /&gt;2. WSsearch - Parsing error&lt;br /&gt;3. Domain footprinting is removed from wspawn and planning to build a seperate tool.&lt;br /&gt;&lt;br /&gt;Thanks for reporting bugs. Few more stuff to be added in next build.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-112348189093287356?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/112348189093287356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/112348189093287356'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/08/releasing-beta-14.html' title='Releasing beta 1.4'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111805042827671248</id><published>2005-06-06T02:29:00.000-07:00</published><updated>2005-06-06T03:11:05.226-07:00</updated><title type='text'>Releasing beta 1.3</title><content type='html'>wsKnight is updated with 4 new audit/attack vectors. This will help in auditing or testing web services. &lt;br /&gt;&lt;br /&gt;1. Bruteforcing - One can specify user/pass fields and map it to files. This will launch bruteforcing combinations on the wire.&lt;br /&gt;2. Buffer overflow - Specify parameter and buffer size.&lt;br /&gt;3. LDAP and XPath injection - This is very simple just a different category.&lt;br /&gt;&lt;br /&gt;Stay tune more to go.&lt;br /&gt;&lt;br /&gt;Cheers!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111805042827671248?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111805042827671248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111805042827671248'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/06/releasing-beta-13.html' title='Releasing beta 1.3'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111700144841915810</id><published>2005-05-24T23:09:00.000-07:00</published><updated>2005-05-24T23:10:48.423-07:00</updated><title type='text'>ASP.NET web services advisory</title><content type='html'>wschess helped in finding this bug in ASP.NET. Recent finding on ASP.NET is posted on security tracker.&lt;br /&gt;&lt;a href="http://securitytracker.com/alerts/2005/May/1013996.html"&gt;Read Here&lt;/a&gt;&lt;br /&gt;&lt;img src="http://securitytracker.com/images/small-st.jpg" background="white"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111700144841915810?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111700144841915810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111700144841915810'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/05/aspnet-web-services-advisory_24.html' title='ASP.NET web services advisory'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111633401250931267</id><published>2005-05-17T05:37:00.000-07:00</published><updated>2005-05-17T05:51:33.583-07:00</updated><title type='text'>Releasing beta 1.2</title><content type='html'>Changes are as follows&lt;br /&gt;&lt;br /&gt;1. Doamin footprinting is added to wspawn. Methodlogy is discussed in paper &lt;a href="http://net-square.com/wschess/domain_footprints.pdf"&gt;[Read]&lt;/a&gt;&lt;br /&gt;2. wspawn threading is much more controlled now with option to stop.&lt;br /&gt;3. wspawn's command line is also posted which can run under linux with &lt;a href="http://www.mono-project.com/Main_Page"&gt;mono&lt;/a&gt;.&lt;br /&gt;&lt;img src="http://www.mono-project.com/files/2/21/Mono_icon_linux.gif"&gt;&lt;br&gt;&lt;br /&gt;Planning to add few more audit/attack modules for xpath,xss,ldap etc in wsknight in next release.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111633401250931267?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111633401250931267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111633401250931267'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/05/releasing-beta-12.html' title='Releasing beta 1.2'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111451073067119618</id><published>2005-04-26T03:17:00.000-07:00</published><updated>2005-04-26T03:18:50.673-07:00</updated><title type='text'>[External] Beta 1.1</title><content type='html'>Following changes are made&lt;br /&gt;1. Threaded engine in place&lt;br /&gt;2. GUI thread is different from core&lt;br /&gt;3. SSL support is added&lt;br /&gt;4. Messaging improved&lt;br /&gt;&lt;br /&gt;That is it! stay tuned for next.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111451073067119618?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111451073067119618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111451073067119618'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/04/external-beta-11.html' title='[External] Beta 1.1'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384324081698863</id><published>2005-04-18T09:52:00.000-07:00</published><updated>2005-04-18T22:15:58.230-07:00</updated><title type='text'>[Internal] Beta 1.1 released</title><content type='html'>Threaded engine in place with separate UI thread. Possible to do several activities at the same time. Key SSL support is added for all tools and possible to assess any SSL enabled application.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384324081698863?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384324081698863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384324081698863'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/04/internal-beta-11-released.html' title='[Internal] Beta 1.1 released'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384310623574320</id><published>2005-04-09T03:42:00.000-07:00</published><updated>2005-04-18T09:51:46.236-07:00</updated><title type='text'>wsChess 1.0 (beta/prototype) - Web Services Assessment and Defense toolkit</title><content type='html'>A set of tools written C# for the .Net platform. This is a prototype, released as beta with limited support at this point. It has the following tools:&lt;br /&gt;&lt;br /&gt;wsPawn - Web services footprinting, discovery and search tools. If you are looking for registered web services and their access points, this tool will help you in retrieving information from public UDDI.&lt;br /&gt;&lt;br /&gt;wsKnight - Web services profiling, proxy and audit tool. This tool helps in profiling web services from its WSDL. It also allows you to invoke methods and intercept them before they go on the wire to the target, so that you can manipulate the SOAP envelope if needed. The autoaudit feature allows you to inject characters and attack strings for assessment work.&lt;br /&gt;&lt;br /&gt;wsRook - This is a very simple technology demonstration for developers. This is a regular expression-based defense for web services input content. This is a hook in HTTP pipe using the HttpModule interface.&lt;br /&gt;&lt;br /&gt;Whitepapers are included for better understanding for all these tools. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://net-square.com/wschess/"&gt;Read &amp; Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384310623574320?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384310623574320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384310623574320'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/04/wschess-10-betaprototype-web-services.html' title='wsChess 1.0 (beta/prototype) - Web Services Assessment and Defense toolkit'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384302333762476</id><published>2005-04-02T09:49:00.000-08:00</published><updated>2005-04-18T09:50:23.336-07:00</updated><title type='text'>[Internal] wsRook &amp; wsAudit</title><content type='html'>With GUI wsAudit is released for internal use. wsRook - a small prototype created.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384302333762476?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384302333762476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384302333762476'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/04/internal-wsrook-wsaudit.html' title='[Internal] wsRook &amp; wsAudit'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384290395918602</id><published>2005-03-30T09:47:00.000-08:00</published><updated>2005-04-18T09:48:23.960-07:00</updated><title type='text'>Paper for wsRook methodology - IHttpModule</title><content type='html'>Web applications are vulnerable to many attacks, mainly due to poor input validation at the source code level. Firewalls can block access to ports but once a web application goes live and TCP ports 80 and 443 are accessible, the web application can be an easy prey for attackers. HTTP traffic is legitimate traffic for web applications; all the more reason to include application-level content-filtering over unencrypted and encrypted communication channels. Application-level content filtering is possible to some extent but may not work over HTTPS (port 443). The only way to provide a strong defense is by applying powerful content-filtering at the application-level for both TCP port 80 and TCP port 443.&lt;br /&gt;&lt;br /&gt;The .Net framework with ASP.NET provides the IHttpModule interface access to HTTP pipes - the lowest of programming layers - before an incoming HTTP request hits the web application. This can provide defense at the gates. In this paper, we look at how one can build this sort of defense in all three aspects - coding, deployment and configuration.&lt;br /&gt;&lt;a href="http://www.infosecwriters.com/texts.php?op=display&amp;id=276"&gt;Read Here&lt;/a&gt;&lt;br /&gt;&lt;img src="http://www.infosecwriters.com/images/grad.gif"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384290395918602?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384290395918602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384290395918602'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/03/paper-for-wsrook-methodology.html' title='Paper for wsRook methodology - IHttpModule'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384280609863073</id><published>2005-03-20T05:41:00.000-08:00</published><updated>2005-04-18T09:46:46.096-07:00</updated><title type='text'>[Internal] wsProxy tool released</title><content type='html'>wsProxy is TCP intercepter for SOAP envelope - prototype released.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384280609863073?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384280609863073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384280609863073'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/03/internal-wsproxy-tool-released.html' title='[Internal] wsProxy tool released'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384270243938512</id><published>2005-03-18T09:44:00.000-08:00</published><updated>2005-04-18T09:45:02.440-07:00</updated><title type='text'>wsEnum methodology</title><content type='html'>Web services assessment can begin with a corporate name or some other such bit of information. This simple hint offers a wealth of information that needs to be unearthed. Focus first on locating single or multiple access points for a particular corporate. The methodology, which includes web services footprinting, discovery and search, is described in another paper (http://packetstormsecurity.org/papers/web/Defense_using_mod_security.pdf). Once an access point for a web service is uncovered, the next obvious step is to extract information from it.&lt;br /&gt;&lt;br /&gt;Web services are deployed to invoke remote calls over HTTP/HTTPS. To make calls such as these, requires that information about the calls be shared with the end client. In the past, during the days of CORBA, developers used to share IDL (Interface Definition Language) files providing the required information over the network. Now, in the days of web services this has changed to WSDL (Web Services Definition Language). WSDL is a major source for information and can help in the enumeration process. We shall go over the enumeration process in subsequent sections.&lt;br /&gt;&lt;a href="http://packetstormsecurity.org/papers/web/WebServices_Profiling.pdf"&gt;Read Here&lt;/a&gt;&lt;br /&gt;&lt;img src="http://www2.packetstormsecurity.org/images/ps.gif"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384270243938512?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384270243938512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384270243938512'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/03/wsenum-methodology.html' title='wsEnum methodology'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111384265507391035</id><published>2005-01-04T09:43:00.000-08:00</published><updated>2005-04-18T09:44:15.073-07:00</updated><title type='text'>wsEnum tool</title><content type='html'>wsEnum comand line version released. This tool parses WSDL file and profile web services.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111384265507391035?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384265507391035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111384265507391035'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2005/01/wsenum-tool.html' title='wsEnum tool'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111382184964907834</id><published>2004-12-20T19:55:00.000-08:00</published><updated>2005-04-18T03:57:29.650-07:00</updated><title type='text'>[Internal] wsPawn release</title><content type='html'>wsPawn ported on .Net framework with command line utility. Ristricted release with footprinting and discovery features only. Google search is not part of it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111382184964907834?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382184964907834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382184964907834'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2004/12/internal-wspawn-release.html' title='[Internal] wsPawn release'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111382170146508839</id><published>2004-11-25T07:54:00.000-08:00</published><updated>2005-04-18T03:55:01.466-07:00</updated><title type='text'>Paper on methodology for wsPawn</title><content type='html'>Web Services is growing at a rapid rate and bringing into focus, new security issues in the web security landscape. How do we start assessing web services deployed at any corporate location? That is the fundamental question and once again it all starts with information gathering. UDDI, WSDL and SOAP are three cornerstones of this technology and they can be powerful tools for information gathering. Universal Business Registry (UBR) can help in footprinting using UDDI. UBR and technology fingerprinting can be used to perform discovery of web services. The scope in this paper is limited to only the first phase, namely the Web Services Information Gathering Phase. The entire methodology for web services information gathering is covered in this paper. The next two phases of the Assessment methodology are enumeration and defining attack vectors, both extensive topics too. These will be taken up in later papers.&lt;br /&gt;&lt;a href="http://www.infosecwriters.com/texts.php?op=display&amp;id=235"&gt;Infosecwriters (Read Here)&lt;/a&gt;&lt;br&gt;&lt;br /&gt;&lt;img src="http://www.infosecwriters.com/images/grad.gif"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111382170146508839?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382170146508839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382170146508839'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2004/11/paper-on-methodology-for-wspawn.html' title='Paper on methodology for wsPawn'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111382161046359548</id><published>2004-11-18T03:52:00.000-08:00</published><updated>2005-04-18T03:53:30.463-07:00</updated><title type='text'>wsFootprinting in Java...</title><content type='html'>Prototype of wsPawn was released and demo at HITB 2004. This is a technology and method demonstration.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111382161046359548?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382161046359548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382161046359548'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2004/11/wsfootprinting-in-java.html' title='wsFootprinting in Java...'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry><entry><id>tag:blogger.com,1999:blog-12015723.post-111382109412641432</id><published>2004-10-15T03:43:00.000-07:00</published><updated>2005-04-18T03:47:52.193-07:00</updated><title type='text'>wsChess Methodology defined</title><content type='html'>HITB (Hack In The Box) 2004 Presentation by shreeraj Shah: "Web Services - Attacks and Defense Strategies, Methods and Tools". The web service is the new security Lego Land. The main building blocks are UDDI, SOAP and WSDL. This presentation will briefly touch upon each of these aspects.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://packetstormsecurity.org/hitb04/hitb04-shreeraj-shah.pdf"&gt;Read Here&lt;/a&gt;&lt;br /&gt;&lt;img src="http://www2.packetstormsecurity.org/images/ps.gif"&gt;&lt;br /&gt;&lt;img length="350" width="100" src="http://conference.hackinthebox.org/hitbsecconf2004/logo.jpg"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12015723-111382109412641432?l=wschess.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382109412641432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12015723/posts/default/111382109412641432'/><link rel='alternate' type='text/html' href='http://wschess.blogspot.com/2004/10/wschess-methodology-defined.html' title='wsChess Methodology defined'/><author><name>shreeraj</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10386038077187513844'/></author></entry></feed>