4

Is there any tool to perform penetration/vulnerability testing on REST web services ?

Navin
  • 57
  • 1
  • 2

1 Answers1

3

To test REST web service I intercept the traffic from a legitimate client and then fuzz the intercepted requests using BURP's intruder module. OWAP's ZAP is free and will also do the trick.

When you fuzz any interface you need to have custom data set and you need to understand what can go wrong and how to identify vulnerabilities. This is not something for a novice to undertake.

rook
  • 47,238
  • 10
  • 96
  • 182