Original title:
Nástroj pro bezpečnostní testování pro vzdálené volání procedur
Translated title:
Security Testing Tool for Remote Procedure Calls
Authors:
Binder, Šimon ; Fujdiak, Radek (referee) ; Martinásek, Zdeněk (advisor) Document type: Bachelor's theses
Year:
2026
Language:
slo Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[slo][eng]
Táto bakalárska práca sa zaoberá návrhom a implementáciou nástroja ptapitester pre automatizované bezpečnostné testovanie rozhraní XML-RPC a SOAP. V rámci práce sú zanalyzované vlastnosti a typické zraniteľnosti oboch protokolov, na základe ktorých sú navrhnuté testovacie postupy. Nástroj je implementovaný v jazyku Python ako modul rozširujúci sadu nástrojov PenterepTools. Modulárna architektúra nástroja umožňuje samostatné spúšťanie jednotlivých testov ako aj implementáciu nových testovacích mo- dulov bez zásahu do jadra nástroja. Súčasťou riešenia je vytvorenie izolovaného kontaj- nerového experimentálneho pracoviska so zámerne implementovanými zraniteľnosťami pre overenie funkčnosti nástroja. Výstupy testovania sú zaznamenávané do štandardi- zovaného formátu JSON a do formy čitateľnej pre človeka v tvare konzolového výpisu. Výsledky testovania potvrdzujú, že nástroj dokáže efektívne identifikovať bezpečnostné nedostatky v rozhraniach XML-RPC a SOAP.
This bachelor’s thesis deals with the design and implementation of the ptapitester tool for automated security testing of XML-RPC and SOAP interfaces. The thesis ana- lyzes the properties and typical vulnerabilities of both protocols, based on which testing procedures are designed. The tool is implemented in Python as a module extending the PenterepTools tool set. The modular architecture of the tool allows for separate execution of individual tests as well as implementation of new test modules without interfering with the core of the tool. Part of the solution is the creation of an isolated containerised experimental environment with deliberately implemented vulnerabilities to verify the functionality of the tool. The testing outputs are recorded in a standardized JSON format and in a human-readable form in the form of a console output. The test- ing results confirm that the tool can effectively identify security flaws in XML-RPC and SOAP interfaces.
Keywords:
Penterep; ptapitester; Python; security testing; SOAP; XML-RPC
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258297