TMCnet News
Security Researchers Unveil New Open Source Web Service Testing Methodology and Tools at Black Hat USA 2011 and DEF CON 19BOSTON --(Business Wire)-- Rapid7, the leading provider of security risk intelligence solutions, today announced that its senior security consultant and researcher, Joshua "Jabra (News - Alert)" Abraham, has teamed up with industry experts Tom Eston of SecureState and Kevin Johnson of Secure Ideas to present groundbreaking research on testing Web services. During their sessions at Black Hat USA 2011 and DEF CON 19, the trio will disclose a new Web services testing methodology and portfolio of open source testing tools. This development answers a longstanding industry need for clarification on Web services testing and stronger testing solutions, and will provide immediate relief for penetration testers. "Web services connect many back-end systems over the Internet and have therefore become an essential part of enterprise Web infrastructures. However, as Web service usage continues to rapidly increase, it has quickly become clear that the testing process is insufficient and confusing for penetration testers," said Abraham. "In the past few years there have been several attacks against common Web services management interfaces, highlighting a need for enhancements for even the most versatile tools. This research aims to improve the Web service testing process; provide the ability to better scope Web service tests; and ensure penetration testers are testing all of the crucial elements of Web services." The industry standard for Web services testing, OWASP, has struggled to keep up with recent advancements in technology and the increasing amount of customized Web services penetration testers face today. In addition, testing methodologies lack technical details on how to properly test Web services, focus on old technology and vulnerabilities, and ignore a complete threat model for Web services, therefore, lacking in both functionality and usefulness for penetration testers. "For too long, the security industry has been lacking in its understanding of Web services testing, and we are excited to finally provide an answer to this problem," said Eston, senior security consultant for SecureState. "By developing a new methodology for Web services testing, we are finally able to ensure that scoping of Web services actually works and helps penetration testers to focus more on the process they are following. We are confident that this advancement will change the way that security professionals think about Web services testing." In addition to developing the new methodology, the researchers determined that there was a strong industry need to provide tangible, immediate answers to Web services testing, and ave therefore created a portfolio of open source solutions, including modules that work with the well-known Metasploit® Framework that will be released immediately during the Black Hat presentation. One other significant challenge that penetration testers previously faced was a lack of testing environments to learn, train or practice Web services testing. "Currently, penetration testers are forced to either use production systems or build their own system for Web services - a complex, timely process that has resulted in a constant industry demand for a publicly available practice application," said Johnson, security consultant with Secure Ideas. "Today, we are also extremely proud to release a series of vulnerable Web services specifically to allow the penetration tester to have an environment for practice. This includes not only a stand-alone service designed for supporting PHP, but the creation of the Damn Vulnerable Web Services (DVWS), which will be packaged into the well-known Damn Vulnerable Web Application (DVWA)." The security trio's presentation will take place at Black Hat on Thursday, August 4, 2011 at 10:00 a.m. PT in the Roman Room at Caesar's Palace and at DEF CON on Saturday, August 6, 2011 at 10:00 a.m. PT at Track Two in the Rio. The tools will be released at Black Hat with links available immediately. The solutions are also open for further development from the community. A copy of the whitepaper, "Don't drop the SOAP: Real World Web Service Testing," will be published on Rapid7's Community Blog following Black Hat. About Rapid7 Rapid7® is the leading provider of security risk intelligence solutions. Rapid7's integrated vulnerability management and penetration testing products, NeXpose® and Metasploit®, empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7's solutions are being used by more than 1,600 enterprises and government agencies, while the Company's free products are downloaded more than one million times per year and enhanced further by over 125,000 security community users and contributors. Rapid7 has been recognized as one of the fastest growing security companies worldwide by Inc. Magazine and is backed by Bain Capital Ventures. For more information about Rapid7, please visit http://www.rapid7.com. About SecureState SecureState is a management consulting firm specializing in information security. SecureState draws upon the skill sets of its team members, and their extensive experience in government, private-sector, and Big X consulting companies. The SecureState team is comprised of five specialties - Advisory Services, Audit and Compliance, Profiling, Risk Management, and Business Preservation Services. Whether you need to be compliant with industry regulations, need your network tested for security, desire to build a solid security program, or have experienced a data breach, SecureState has the expert team that you need. For more information about SecureState, please visit www.securestate.com. About Secure Ideas Secure Ideas is a security-consulting firm focused on improving security within organizations. Secure Ideas' group of security consultants has spent years researching various exploits and vulnerabilities, building toolsets, and helping organizations secure their networks. Our experts have worked in a vast array of industries including health, legal, financial, energy, insurance, retail, telecommunications, utilities, manufacturing, IT, engineering, non-profit, military, and all levels of government from local to federal. Given the number of industries in which Secure Ideas experts have worked, we are able to bring specific areas of concern and interest into light during our security assessments in order to benefit your organization. We offer a number of security services that include web application penetration testing, mobile application testing, network penetration testing, social engineering, social networking assessment, security architecture reviews, presentations and briefings. Secure Ideas has also recently released MySecurityScanner, which is a subscription-based service for assessing web applications and network security. In addition to our security consulting services, Secure Ideas, LLC is involved in a number of open-source projects, such as SamuraiWTF and Weaponized Flash. Additionally, our personnel are regular instructors at well-known conferences and training venues such as The SANS Institute (News - Alert), Black Hat, DEF CON, RSA, OWASP, Infragard, SCADA, ShmooCon, ISACA and ISSA.
|

