Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 34 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow How to create a local client to consume web service?
EH-Net
May 19, 2013, 12:25:34 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How to create a local client to consume web service?  (Read 3441 times)
0 Members and 1 Guest are viewing this topic.
cgseymour
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: May 14, 2010, 07:14:34 AM »

Hello,
I am a somewhat newbie pen-tester.  I have been tasked by my company to pen test one of our web sites (Silverlight, ASP.Net).
The WSDL is not published.

How could I go about creating a local client to try to consume some of the web services?

Any articles, books, tutorials or pointers would be greatly appreciated.

Thanks.

Chris
Logged
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #1 on: May 14, 2010, 07:56:00 AM »

Hello and welcome to the forum!

I am sorry if I do not understand what you are exactly asking; what do you mean when by "creating a local client to try to consume some of the web services?"

Are you saying that the site(s) are in the developmental stages and you want to run local pen tests?

Please clarify. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
cgseymour
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: May 14, 2010, 11:08:39 AM »

Sorry I wasn't more clear
What I would like to be able to do, is to see if I could create a local client (say in c#) that would call the remote web service to see if I can return information from the service without proper authorization.

So within the company application this service would require authorization and authentication -- I want to see if it is possible to access the web service without the proper credentials and determine if any of th company data could be at risk

I hope that makes more sense.

Thanks.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #3 on: May 14, 2010, 12:04:54 PM »

I may be missing something, but I don't think that you have to write anything for that.  Fire up any intercepting proxy based tool, like Burp or WebScarab, access your web application through the proxy.   It will begin to record all requests.   You can then manipulate those requests and replay them, all in the tool.   
Logged

~~~~~~~~~~~~~~
Ketchup
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #4 on: May 14, 2010, 02:03:32 PM »

Hey,

I have wrote several web services myself for a "Big Bank" and the best tool to use is soapUI http://www.soapui.org/. Very easy to use.

Quote
The WSDL is not published
What do you mean by the WSDL is not published? It should always be... That's one of the fundamental piece of SOAP. Do you mean there is no "publicity" about them or they aren't available at all? If they aren't available, then soapUI isn't the best tool...

Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.