Monday, July 11, 2005

Free Open source tool released for web services security scanning

Foundstone, Inc.� Strategic Security

Have not checked it out yet. Sounds promising. Although it would be nice to have a scanning tool that can do application security checks regardless of the protocol being HTML over HTTP, XML over HTTP, SOAP, etc. Many of the attacks and scanning signatures will be the same. Only the formatting and perhaps the detection of success/fail of a test. I'd be interested in knowing more about what they encountered as to whether the differences are significant enough to warrant a separate tool.

