17 June 2011

Web Services Vulnerabilities, Attacks and Defences

I'm now back in London after my talk and live demonstration at last night's well-attended OWASP Belgium chapter meeting.

Photograph of an metal & glass red public door to an office building, with a lock and push-button doorbell visible; the door has a handmade sign taped to the inside of the glass which reads 'For out of hours access, please push the bell - this will alert security immediately'

There's a good review of the evening added very promptly by Xavier Mertens (@xme) on his blog. Josh Corman (@joshcorman) provided an unexpected extra presentation towards the end of the evening where he discussed the ideas and manifesto of the rugged software initiative. I'll come back to that at a later date, but for now would like to mention the excellent talk given by Andreas Falkenberg on web services security.

He provided a carefully structured walk-through of web services technology and SOAP security features before introducing us to the idea of signature wrapping attacks, and how they might be used to exploit public web services. He also described recommended countermeasures. I won't go into the detail here, but Andreas has a paper available if you contact him. However, I did want to mention WS-Attacks.org which is a nascent project to provide information about vulnerabilities and attacks against web service standards and implementations. Many of these are unique to web services, and are in addition to the more widely-known web vulnerabilities that affect "normal" web applications.

This is a fantastic resource, and needs greater visibility amongst those responsible for designing and implementing web services.

Posted on: 17 June 2011 at 10:33 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Services Vulnerabilities, Attacks and Defences
http://www.clerkendweller.com/2011/6/17/Web-Services-Vulnerabilities-Attacks-and-Defences
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/6/17/Web-Services-Vulnerabilities-Attacks-and-Defences
Requested by 38.107.179.220 on Thursday, 17 May 2012 at 23:11 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2012 clerkendweller.com