Use Wsdler test WebService interfaces:
In addition to the front of us that use SOAPUI NG Pro test WebService, in Burp also has a parsing WSDL interface definitions, manual testing WebService plugin by: Wsdler
If you install this plug-in, then the Burp Proxy >> History, you can directly use the [Parse WSDL] function.
After confirming the use of [] Parse WSDL parsing, this plug-in automatically parse out the services of Operation, Binding, Endpoint. After the election in an Operation, you can view the SOAP message text. At the same time, it can be transmitted to other components for further operation Burp.
For example, we send a message to Intruder above figure, using a character block (Character blocks) the boundary parameters tested.
Intruder screenshots sent as follows:
payload using a string of 1, from 1 to 50, i.e. until 1,11,111,1111 ...... 50 1, the test parameters to boundary length
Results and executes the generated payload as shown below: