PS: Thanks to J. Monteiro, P. Lourenço
sexta-feira, 19 de dezembro de 2014
LIST: Web Services (Part 2)
A friend of mine pointed me to a series of
posts from the Infosec Institute focusing on the Web Services Penetration
Testing subject:
Etiquetas:
Infosec Institute,
SOA; Penetration Testing,
Web Services
quinta-feira, 18 de dezembro de 2014
LIST: Web Services Security Resources
The top 5 google search links returned me very interesting
results that are must reads for anyone working with SOA/Web Services - either developing and deploying or testing. Some are from
people I know very well (not the NSA ones).
- https://www.nsa.gov/ia/_files/factsheets/soa_security_vulnerabilities_web.pdf (NSA classification for vulnerabilities)
- http://www2.informatik.uni-freiburg.de/~accorsi/papers/igi-chapter.pdf (model based security)
- https://eden.dei.uc.pt/~mvieira/dsn_ws.pdf
- http://www.infosectoday.com/Articles/webservices.pdf
- https://www.blackhat.com/presentations/bh-europe-07/Bhalla-Kazerooni/Whitepaper/bh-eu-07-bhalla-WP.pdf
PS: Not in any particular order.
Etiquetas:
2014-12,
Security,
SOA,
Web Services,
WS
Subscrever:
Mensagens (Atom)