Skip to content

Test 9) Weak WS SecurityPolicy: Insecure Transport

Yalçın YOLALAN edited this page Mar 28, 2018 · 2 revisions

Weak WS-SecurityPolicy: Insecure Transport Test

Vulnerability Type Static

Test Web Service URI http://[yourhostName]/InsecureTransport.wsdl

Vulnerable Code Block Http token is used instead of Https token in the following line:

<sp:HttpToken RequireClientCertificate="false" xmlns:sp="http://schemas.xmlsoap.org/ws/2005/07/securitypolicy" />

Indications of Vulnerability Static analysis reveals http token is used.