WS-Attacker Logo

WS-Attacker

0
Free
Visit Website

WS-Attacker is a modular framework for web services penetration testing developed by the Chair of Network and Data Security, Ruhr University Bochum, and Hackmanit GmbH. It allows loading WSDL files, sending SOAP messages, and extending functionality with plugins and libraries for specific Web Services attacks. More information on its architecture and extensibility can be found in the Penetration Testing Tool for Web Services Security paper. Current version supports SOAPAction spoofing, WS-Addressing spoofing, XML Signature Wrapping, and XML-based DoS attacks.

FEATURES

ALTERNATIVES

Emulate operating systems behind SSH servers for testing automation.

Fast web spider written in Go

Automatic tool for DNS rebinding-based SSRF attacks

DET (extensible) Data Exfiltration Toolkit is a proof of concept tool for performing Data Exfiltration using multiple channels simultaneously.

A tool for interacting with Exchange servers remotely and exploiting client-side Outlook features.

APT Simulator is a tool for simulating a compromised system on Windows.

A modular, menu-driven tool for building repeatable, time-delayed, distributed security events.

A payload creation framework designed to bypass Endpoint Detection and Response (EDR) systems.

PINNED