Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 61 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow How to create a local client to consume web service?
EH-Net
May 25, 2012, 11:40:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How to create a local client to consume web service?  (Read 2866 times)
0 Members and 1 Guest are viewing this topic.
cgseymour
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: May 14, 2010, 07:14:34 AM »

Hello,
I am a somewhat newbie pen-tester.  I have been tasked by my company to pen test one of our web sites (Silverlight, ASP.Net).
The WSDL is not published.

How could I go about creating a local client to try to consume some of the web services?

Any articles, books, tutorials or pointers would be greatly appreciated.

Thanks.

Chris
Logged
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #1 on: May 14, 2010, 07:56:00 AM »

Hello and welcome to the forum!

I am sorry if I do not understand what you are exactly asking; what do you mean when by "creating a local client to try to consume some of the web services?"

Are you saying that the site(s) are in the developmental stages and you want to run local pen tests?

Please clarify. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
cgseymour
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: May 14, 2010, 11:08:39 AM »

Sorry I wasn't more clear
What I would like to be able to do, is to see if I could create a local client (say in c#) that would call the remote web service to see if I can return information from the service without proper authorization.

So within the company application this service would require authorization and authentication -- I want to see if it is possible to access the web service without the proper credentials and determine if any of th company data could be at risk

I hope that makes more sense.

Thanks.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #3 on: May 14, 2010, 12:04:54 PM »

I may be missing something, but I don't think that you have to write anything for that.  Fire up any intercepting proxy based tool, like Burp or WebScarab, access your web application through the proxy.   It will begin to record all requests.   You can then manipulate those requests and replay them, all in the tool.   
Logged

~~~~~~~~~~~~~~
Ketchup
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 660



View Profile
« Reply #4 on: May 14, 2010, 02:03:32 PM »

Hey,

I have wrote several web services myself for a "Big Bank" and the best tool to use is soapUI http://www.soapui.org/. Very easy to use.

Quote
The WSDL is not published
What do you mean by the WSDL is not published? It should always be... That's one of the fundamental piece of SOAP. Do you mean there is no "publicity" about them or they aren't available at all? If they aren't available, then soapUI isn't the best tool...

Logged

GPEN, GSEC, CEH, CISSP, PMP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.259 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.