SIFT - Information Security Services
This tool takes an interesting approach to helping with web services security reviews. It looks for methods which may serve up sensitive information but which are not published into the WSDL...
SIFT - Information Security Services
This tool takes an interesting approach to helping with web services security reviews. It looks for methods which may serve up sensitive information but which are not published into the WSDL...
Web Services Are Biggest Security Challenge
An interesting article reporting on Netsec 2004, it focuses on some of the challenges facing web services security. I definately agree with the point that's made in the article about the problem of how contracts between web services will be negotiated. Initially when I saw information about UDDI I thought it looked cool for internal applications, but for external B2B, there needs to be something more, as suppliers will inevitably want to charge for their webservices and customers will inevitably want some guarantees about the service they'll be getting....
Over at www.xmethods.net there's a really cool list of functional web services.
With each there's a link so you can try them out. It's a pretty diverse bunch including practical things like curency conversion and less practical things like... random George W Bush quotes