Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: xml over https
From: Mads Rasmussen <mads () opencs com br>
Date: Thu, 10 Feb 2005 10:25:11 -0300

Burke, Charles wrote:

This web services was not using WS Security was it?
I am assuming the xml encryption was custom or was it provided by WSE?
No WS security, not even webservices ;-)
Just simple encryption (a .dll doing 3des encryption) of specific XML fields in an XML file, transported between the client and the server via https
No encryption mode, that is ECB basically.

As I said, I did a small application calling their routine to decrypt the fields without specifying the key.

Mads


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]