Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: xml over https

Re: xml over https

From: Mads Rasmussen <mads_at_opencs.com.br>
Date: Thu, 10 Feb 2005 10:25:11 -0300

Burke, Charles wrote:

>This web services was not using WS Security was it?
>I am assuming the xml encryption was custom or was it provided by WSE?
>
>
No WS security, not even webservices ;-)
Just simple encryption (a .dll doing 3des encryption) of specific XML
fields in an XML file, transported between the client and the server via
https
No encryption mode, that is ECB basically.

As I said, I did a small application calling their routine to decrypt
the fields without specifying the key.

Mads
Received on Feb 11 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos