Innovating The Next Big Thing May 25, 2013 ph.gif
ph.gif
Sections

Leadership & Vision
Innovation at HP
HP Buzz
Ecosystem: HP Partners & Customers
Competitive Landscape: HP Rivals
On the Go: Mobile & Wireless Solutions
Enterprise Solutions
Digital Arts & Entertainment
Fine Print: Imaging & Printing
Analyst Insights
Enterprise Insights
Network & Information Security
Enterprise Mobility
About

Next Innovator Group

TechnologyInnovator
• NextInnovator
EnterpriseInnovator
SecurityInnovator
DefenseInnovator
WirelessInnovator 
• HPinnovator
EnergyInnovator
TransportationInnovator
SMBinnovator (beta)

Contact

• NextInnovator(at)Live.com

Writers Wanted

Writers Wanted

HP.com Quick Links

Newsroom Home
Newsroom Archives
Fast Facts
Financial  Information
Global  Citizenship
HP Labs
Company History
HP in the News  
Videos
B-roll
Blogs
RSS Feeds

Channel HP

The HP Blog Hub

HP User Groups

Connect
Connect - Deutschland
3000 Newswire Blogs

Next Innovators

Ghost City
Frontline Sentinel
• Innovation Insights
WebInno
Over the River
Enderle Group
Security Insights Blog 
McAfee Audio Parasitics
Rethinking Security
Ovum
iSuppli
Canalys
• eMarketer 
• CRM Help Desk SW 
Rethink Research
The Gadgeteer
Master the Moment

Feedjit Live Web Stats


Barry's Books

 

Ads

ph.gif ph.gif
Network & Information Security HP Security Lab blog: Dynamic Web Services Assessment using HP WebInspect
Jun 19, 2012 – samareshm

“There is no greater agony than bearing an untold story inside you.” - Maya Angelou.

Over the last couple of releases, HP WebInspect has added stellar support for Web Services assessments. However, my interactions with various users have made me feel that we still have a story about our Web Services capabilities that hasn’t fully been told yet.  HP WebInspect 9.2 packs some powerful new features that can assist in very effective Web Services assessments. A totally reworked Web Service Test Designer can be a great asset when unit testing SOAP based Web Services.

Here is a summary of the broad new capabilities:

 

1)      Full-fledged assessment: Smart detection engines are now capable of detecting vulnerabilities such as blind SQL Injection, local file inclusion, and buffer overflows.
 

2)      Support for WCF:  Some basic templates to configure popular WCF options such as Custom, Federation and WSHttpBinding are included by default (ref: figure 1). Advanced configuration will allow non-text encodings such as MTOM and Binary.

wcf.jpg
  

                                                                                  Figure 1

 

3)       Handling message security:  A large variety of SOAP based assessments can now be supported   using WS-Security and WS_Addressing. A comprehensive setup screen can handle X 509, Cerberus and XAML tokens.

4)      RPC support: Users now can work with SOAP services with RPC encoding. The manual editor can be used to import payload data.

  

5)      Detecting Web services while scanning regular sites: WebInspect can detect web requests that resemble SOAP message structures. It then adds them in the Recommendations as shown below. Users can obtain the needed Web Services design to initiate a Web Services scan. 

wsdetect1.jpg 

Figure 2

In future posts I will suggest some good practices on Web Services scan workflow. Please add comments to this post to let us know what features interest you most.



» Send this article to a friend...
» Comments? Tell us what you think...
» More Network & Information Security articles...

AddThis Social Bookmark Button

Comments
blog comments powered by Disqus

Search HPInnovator

ph.gif ph.gif
Support This Site



Newest Articles

• 5/24 Frontline Sentinel: What Java's installer should really say (Funny)
• 5/24 Frontline Sentinel: How to build C-level support for the benefits of penetration testing
• 5/23 Frontline Sentinel: "Interview with a Blackhat" by Whitehat Security
• 5/23 Gartner Says IT Spending in Indian Banking and Securities Market To Reach 422 Billion Rupees In 2013
• 5/23 Gartner Announces Rankings of Its 2013 Supply Chain Top 25
• 5/23 iSuppli: Global Touch-Screen Panel Shipments to Double by 2016, IHS Analyst Announces at SID
• 5/23 iSuppli: Falling Commodity Prices Give Buyers Using Cost Analysis the Upper Hand in Supplier Negotiations
• 5/23 Connect: Countdown to HP Discover May 23, 2013
• 5/23 Wireless Watch: New Intel chief puts post-smartphone devices at the heart of his agenda
• 5/23 Wireless Watch: Satellite spectrum under siege from cellular predators
• 5/23 Faultline: TiVo blows away numbers – still ignored by investors
• 5/23 Faultline: Yahoo gambles on social networking to make up for lost time
• 5/23 Canalys: Top iOS and Android apps largely absent on Windows Phone and BlackBerry 10 - App quality not quantity now needs to be the priority for Microsoft and BlackBerry
• 5/22 2013 Security Market Outlook - Gartner Security & Risk Management Summit Preview
• 5/22 iSuppli: China’s Labor Day LCD TV Sales Surge by Double-Digit Percentage
• 5/22 Connect: Countdown to HP Discover May 22, 2013
• 5/21 Gartner Says IT Operations and Management Software Market Grew 4.8 Percent in 2012
• 5/21 iSuppli: One Quarter of All Notebooks to Ship with Touchscreens by 2016; Intel Endorses Touch Technology at SID
• 5/21 iSuppli: Can UHD Televisions Avoid the Fate of 3D Sets?
• 5/21 iSuppli: After a Year of Decline, Global Flat-Panel TV Market Ekes Out Marginal Growth in the First Quarter
• 5/21 Connect: Countdown to HP Discover May 20, 2013
• 5/21 Connect: Countdown to HP Discover May 21, 2013
• 5/21 Frontline Sentinel: Network perimeter security: How to audit remote access services
• 5/20 Gartner Says Business Intelligence/Analytics Is Top Area for CFO Technology Investment Through 2014
• 5/20 Gartner Says Worldwide Supply Chain Management Software Market Grew 7.1 Percent to Reach $8.3 Billion in 2012
• 5/20 Yahoo Acquisition of Tumblr Can Lead to Content Platforms
• 5/20 iSuppli: Top IHS Experts to Attend SID Display Week 2013
• 5/20 iSuppli: How Intel Can Enable a Successful $200 PC in the Age of the Media Tablet
• 5/17 Connect: Countdown to HP Discover May 17, 2013
• 5/16 iSuppli: Shipments of Sports and Fitness Monitors to Total One-Quarter Billion from 2013 Through 2017
• 5/16 Connect: Countdown to Discover - May 16
• 5/16 Canalys: World-class speaker line-up announced for Canalys Channels Forums 2013 - Confirmed sponsors include Lenovo, HP, Cisco and EMC at keynote level
• 5/15 Gartner Says PC Market in Western Europe Declined 20.5 Percent in First Quarter of 2013
• 5/15 Gartner Highlights 2013 Cool Vendors That Are Transforming How Businesses Operate
• 5/15 iSuppli: Google Unlikely to Deploy its Fiber Broadband Service Nationwide
• 5/15 Connect: Countdown to HP Discover
• 5/15 Connect: Call for Papers Now Open - 2013 NonStop Advanced TBC
• 5/14 Asia Pacific CEOs View Themselves as Tech-Savvy Pioneers, According to Gartner CEO and Senior Business Executive Survey
• 5/14 Gartner Says Asia/Pacific Led Worldwide Mobile Phone Sales to Growth in First Quarter of 2013
• 5/14 Gartner Identifies Five Actions for Enterprise Architects to Harness the Disruption of Consumerization
• 5/14 iSuppli: Small Cells with Wi-Fi Set to Reshape Wireless Communications Market
• 5/13 Frontline Sentinel: How Facebook Updates Would Look in Real Life [Funny]
• 5/13 Gartner Says Project and Portfolio Management Software Market Grew 11 Percent in 2012
• 5/13 Gartner Says India IT Infrastructure Spending Will Reach $2.3 Billion By 2014
• 5/13 What to Expect at Google I/O
• 5/13 iSuppli: EU Antidumping Duties to Price Chinese Modules out of the European Market
• 5/13 iSuppli: Combo MEMS Inertial Sensors Motor Their Way to Brisk Growth in the Automotive Market
• 5/12 Frontline Sentinel: Two-Factor Authentication for Social Media Sites
• 5/12 Print Service Providers Worldwide Accelerate Growth with the HP Indigo 10000 Digital Press
• 5/10 McAfee Blogs: RealTime for ePO – Optimized Endpoint Security

AddThis Feed Button

Barry's Books


Ads

ph.gif
ph.gif Top ph.gif

© 2008 HPInnovator. All rights reserved.