burp suite test webservice interface (rpm)

Use Wsdler test WebService interfaces:

In addition to the front of us that use SOAPUI NG Pro test WebService, in Burp also has a parsing WSDL interface definitions, manual testing WebService plugin by: Wsdler

Burp Suite test Web Services Interface Vulnerabilities

If you install this plug-in, then the Burp Proxy >> History, you can directly use the [Parse WSDL] function.

Burp Suite test Web Services Interface Vulnerabilities


After confirming the use of [] Parse WSDL parsing, this plug-in automatically parse out the services of Operation, Binding, Endpoint. After the election in an Operation, you can view the SOAP message text. At the same time, it can be transmitted to other components for further operation Burp.

Burp Suite test Web Services Interface Vulnerabilities

For example, we send a message to Intruder above figure, using a character block (Character blocks) the boundary parameters tested.

Burp Suite test Web Services Interface Vulnerabilities

Intruder screenshots sent as follows:

Burp Suite test Web Services Interface Vulnerabilities

payload using a string of 1, from 1 to 50, i.e. until 1,11,111,1111 ...... 50 1, the test parameters to boundary length

Burp Suite test Web Services Interface Vulnerabilities

Results and executes the generated payload as shown below:

Burp Suite test Web Services Interface Vulnerabilities

Guess you like

Origin www.cnblogs.com/liuhaixia/p/10985279.html