product datasheet

White paper -
Taxonomy of XML attacks



What's new in SOAPbox?

SOAPbox 5.1 is the exciting new version of the acclaimed Vordel SOAPbox Web Service testing tool. It includes the following additional key elements:-

  • Advanced penetration testing of Web Services, including new attack path vectors
  • Ability to create test batteries
  • Advanced stress testing of Web Services
  • Extension of protocol support to Message Queues

What are the new penetration testing features?

SOAPbox 5.1 can be used to automatically inject malicious content into XML messages to aid penetration testing.  Malicious content includes SQL Injection, XPath Injection and Message value fuzzing.

What are the new test batteries?

The new SOAPbox includes an automatic testing framework to enable you to simulate real world service interactions. You can now run tests sequentially and retrieve values from one test for use with subsequent tests.

This allows you to create test sequences which map to real customer environments. These tests can be saved for future regression.  SOAPbox automatically stores completed test runs for comparison purposes. 

What is the new Stress Testing Tool in SOAPbox 5.1?

Vordel's stress testing tool SR (normally only available to XML Gateway customers) has been added to the new Vordel SOAPbox.  SR is a fast and efficient scriptable performance-testing tool. It is capable of producing sustained loads in excess of 50,000 messages per second. 

What are the “message pipelines” in Vordel SOAPbox 5.1?

Vordel has extended its acclaimed policy creation interface from its XML Gateway products into SOAPbox. This allows sophisticated rules such as “first insert a SAML Assertion, then sign the message, then encrypt the message” to be configured.

What are the new protocols supported in SOAPbox 5.1?

SOAPbox 5.1 recognizes that Web Services are only not tied to HTTP. SOAPbox 5.1 is capable of producing messages over JMS and messaging systems, as well as HTTP and SSL.

Vordel SOAPbox datasheet