WS-Attacker Logo

WS-Attacker

0
Free
Visit Website

WS-Attacker is a modular framework for web services penetration testing developed by the Chair of Network and Data Security, Ruhr University Bochum, and Hackmanit GmbH. It allows loading WSDL files, sending SOAP messages, and extending functionality with plugins and libraries for specific Web Services attacks. More information on its architecture and extensibility can be found in the Penetration Testing Tool for Web Services Security paper. Current version supports SOAPAction spoofing, WS-Addressing spoofing, XML Signature Wrapping, and XML-based DoS attacks.

FEATURES

ALTERNATIVES

A cross-platform tool for creating malicious MS Office documents with hidden VBA macros and anti-analysis features.

Automatic SSRF fuzzer and exploitation tool

Generates randomized C2 profiles for Cobalt Strike to evade detection.

A tutorial on how to use Apache mod_rewrite to randomly serve payloads in phishing attacks

Back-end component for red team operations with crucial design considerations.

A Go client to communicate with Chaos DB API

Data exfiltration & infiltration tool using text-based steganography to evade security controls.

GNU/Linux Wireless distribution for security testing with XFCE desktop environment.