use of ws-security actually increases likelyhood of successful attack

, posted: 16-Aug-2007 10:39

one of the many presentations to ponder from Black Hat: Brad Hill presented how ws-security is inherently less secure than just using client ssl certs. some of the reason: 1. increased attack surface 2. outta da box settings not ready for use 3. infinite loops in XSLT makes for easier dos Brad Hill's slides: iSEC_HILL_AttackingXMLSecurity_bh07.pdf previously mentioned on:

