WSFuzzer icon

WSFuzzer For Linux

3.4/5 10
GPL    

WSFuzzer is a fuzzing penetration testing tool used against HTTP SOAP based web services.. #Penetration testing  #Fuzzing attacks  #XML parser  #Fuzzing  #Penetration  #Testing  

Description

Free Download

WSFuzzer is a fuzzing penetration testing tool used against HTTP SOAP based web services. It is a GPL licensed program, written in Python, that currently targets web services. In the current version HTTP based SOAP services are the main target. This tool was created based on, and to automate, some real-world manual SOAP pen testing work.

This tool is NOT meant to be a replacement for solid manual human analysis. Please view WSFuzzer as a tool to augment analysis performed by competent and knowledgable professionals. Web Services are not trivial in nature so expertise in this area is a must for proper pen testing.

� To automate some of the more intense SOAP fuzzing processes that would be quite time consuming if performed manually � To do attack vector generation in a dynamic and intelligent fashion based on the specific target � Providing its functionality/resulting data to other tools in a seamless fashion � To facilitate the repeatable use of known successful attack vectors, especially against specific targets � To be part of a solid web application pen testing toolkit � To be as easy to use within the spectrum of understanding, and working with, SOAP services

It is not the goal of WSFuzzer to replace human analysis. AAMOF WSFuzzer does not currently do any analysis of the results gathered. The job of analysis is left to the analyst/engineer running a given pen test.

This tool is ultimately meant to augment a pen testers job in respect to SOAP services.

Here are some key features of "WSFuzzer":

� Pen tests an HTTP SOAP web service based on either valid WSDL, known good XML payload, or a valid endpoint & namespace. � It can try to intelligently detect WSDL for a given target. � Includes a simple TCP port scanner. � WSFuzzer has the ability to Fuzz methods with multiple parameters. There are 2 modes of attack/fuzzing: "individual" and "simultaneous". Each parameter is either handled as a unique entity (individual mode), and can either be attacked or left alone, or multiple parameters are attacked simultaneously (hence the name - simultaneous mode) with a given data set. � The fuzz generation (attack strings) consists of a combination of a dictionary file, some optional dynamic large injection patterns, and some optional method specific attacks including automated XXE and WSSE attack generation. � The tool also provides the option of using some IDS Evasion techniques which makes for a powerful security infrastructure (IDS/IPS) testing experience. � A time measurement of each round trip between request and response is now provided to potentially aid in results analysis. � For any given program run the generated attack vectors are saved out to an xml file. The XML file is named XXX and is located in the same directory where the results HTML file is saved. A previously generated XML file of attack vectors can be utilized instead of the dictionary/automated combo. This is for the sake of repeatability when the same vectors need to be used over and over again.

What's New in This Release:

� Toned down some of the random attack vector generation processes so as to improve prog run time performance. � Added support for Document/Literal SOAP payloads to be submitted via the --xml option. � Added code to check for host availability at the earliest possible stage. Prog dies if host not available. � Added code to automatically save (to local file) all generated attack vectors for a given run. The file is in a simple XML format. � Added a feature to utilize saved attack vectors from the XML file as opposed to the dynamic generation of attack vectors. This option is invoked with the "--attacks=" switch. � Added more options into the config file model so that when one is used less interactive aspects are exercised.

WSFuzzer 1.9.3

add to watchlist add to download basket send us an update REPORT
  runs on:
Linux
  filename:
wsfuzzer-1.9.3.tar.gz
  main category:
Security
  developer:
  visit homepage

Zoom Client 6.0.3.37634

The official desktop client for Zoom, the popular video conferencing and collaboration tool used by millions of people worldwide
Zoom Client

Context Menu Manager 3.3.3.1

Customize Windows’ original right-click context menu using this free, portable and open-source utility meant to enhance your workflow
Context Menu Manager

IrfanView 4.67

With support for a long list of plugins, this minimalistic utility helps you view images, as well as edit and convert them using a built-in batch mode
IrfanView

ShareX 16.0.1

Capture your screen, create GIFs, and record videos through this versatile solution that includes various other amenities: an OCR scanner, image uploader, URL shortener, and much more
ShareX

Microsoft Teams 24060.3102.2733.5911 Home / 1.7.00.7956 Work

Effortlessly chat, collaborate on projects, and transfer files within a business-like environment by employing this Microsoft-vetted application
Microsoft Teams

calibre 7.9.0

Effortlessly keep your e-book library thoroughly organized with the help of the numerous features offered by this efficient and capable manager
calibre

4k Video Downloader 1.5.3.0080 Plus / 4.30.0.5655

Export your favorite YouTube videos and playlists with this intuitive, lightweight program, built to facilitate downloading clips from the popular website
4k Video Downloader

Windows Sandbox Launcher 1.0.0

Set up the Windows Sandbox parameters to your specific requirements, with this dedicated launcher that features advanced parametrization
Windows Sandbox Launcher

7-Zip 23.01 / 24.04 Beta

An intuitive application with a very good compression ratio that can help you not only create and extract archives, but also test them for errors
7-Zip

Bitdefender Antivirus Free 27.0.35.146

Feather-light and free antivirus solution from renowned developer that keeps the PC protected at all times from malware without requiring user configuration
Bitdefender Antivirus Free

% discount
Windows Sandbox Launcher
  • Windows Sandbox Launcher
  • 7-Zip
  • Bitdefender Antivirus Free
  • Zoom Client
  • Context Menu Manager
  • IrfanView
  • ShareX
  • Microsoft Teams
  • calibre
  • 4k Video Downloader
essentials


Click to load comments
This enables Disqus, Inc. to process some of your data. Disqus privacy policy