XWSS

XML Web Services Security Forum - Est. 2002

Welcome to XWSS

XWSS is an independent forum dedicated to the security of XML-based web services and API security. Our community of enterprise architects, security researchers, and standards contributors discusses practical approaches to securing SOAP endpoints, implementing WS-Security, deploying XML firewalls, and the security specifications that continue to underpin modern enterprise integration.

Whether you are deploying BEA WebLogic, IBM WebSphere, or Apache Axis, or evaluating XML signature and encryption standards for your organization, XWSS provides a vendor-neutral space for technical discussion and peer review.

Recent Discussions

Topic Author Replies Last Post
How to Break XML Encryption: The CBC Flaw at the Heart of WS-Security Confidentiality [Article] mhendricks 0 2026-08-25
XML Signature Wrapping: The WS-Security Flaw That Will Not Die [Article] mhendricks 0 2026-08-12
XML Parser Vulnerabilities in Web Services Endpoints - Security Advisory mhendricks 4 2003-11-14
WS-Security interop between WebLogic 8.1 and .NET 1.1 p_richardson 17 2004-02-08
XML Firewall evaluation - DataPower vs Reactivity d_kumar 23 2004-01-22
SAML 1.1 token validation fails on expired NotOnOrAfter s_yamamoto 9 2003-12-03
Canonical XML and whitespace handling in signed SOAP bodies xmlsecguy 12 2003-09-18
Apache Axis 1.1 handler chain - where to insert WS-Security? jturner_dev 7 2003-08-27
WS-I Basic Profile compliance and security header ordering r_foster 14 2003-10-11
XPath injection in SOAP request dispatchers mhendricks 6 2003-07-05
IBM WebSphere 5.0.2 WS-Security UsernameToken problems c_lin 11 2003-06-19
Securing SOAP with WS-Security: A Practical Guide [Article] p_richardson 31 2003-05-14