Ga naar content
HackIndex logo

HackIndex

Tools

SOAP WSDL naar Acties Generator

Plak ruwe WSDL-XML — ontvang SOAP-enveloppen en curl-commando's voor elke operatie.

Tip: je kunt een WSDL ophalen door ?wsdl of ?WSDL toe te voegen aan een SOAP-service-URL.

Hoe het werkt

Deze tool parseert een WSDL-document (Web Services Description Language) en genereert een complete, verzendklare SOAP-envelop en curl-commando voor elke operatie die in de service is gedefinieerd — zodat je tijdens een CTF of pentest geen XML-standaardcode met de hand hoeft te schrijven.

  1. 1. Haal de WSDL op: toevoegen ?wsdl of ?WSDL aan de service-URL, of vind het in de broncode. Sla de volledige XML op.
  2. 2. Plak de WSDL: plak de ruwe XML in het tekstveld en klik op Acties genereren.
  3. 3. Ontvang je enveloppen: elke SOAP-operatie krijgt zijn eigen envelop met plaatshouderparameterwaarden, plus een curl-commando met het juiste eindpunt en SOAPAction-header.
  4. 4. Verstuur het verzoek: kopieer het curl-commando, vervang de plaatshouderwaarden door echte invoer en stuur het naar het doel.

Wat is WSDL?

WSDL is een XML-gebaseerde interfacebeschrijvingstaal voor SOAP-webservices. Het definieert de beschikbare operaties, hun invoer-/uitvoerberichttypen en parameternamen, de gegevenstypes (via XML Schema), de binding (hoe SOAP op HTTP wordt gemapped) en de eindpunt-URL. SOAP-services stellen WSDL publiekelijk beschikbaar zodat clients stubs kunnen genereren — en zodat pentesters het volledige aanvalsoppervlak kunnen ontdekken.

wsdl:operation

Defines an available action. The name maps directly to the SOAP body element and often to the SOAPAction header value.

wsdl:message

Describes the input or output of an operation as a set of typed parts (parameters).

wsdl:types

Contains the XML Schema (XSD) definitions for all message types, including parameter names, types and cardinality.

soap:address location

The HTTP endpoint URL where SOAP requests must be sent, extracted and used directly in the curl command.

FAQ

Does this send requests to the target service?

No. Everything happens server-side in PHP. The tool only parses the XML you paste and generates strings. No outbound requests are made.

Where do I find the WSDL?

Append ?wsdl or ?WSDL to the service base URL (e.g. https://example.com/service.asmx?wsdl). Some services list the path in their homepage or error page.

What SOAP versions are supported?

SOAP 1.1 (the most common, uses http://schemas.xmlsoap.org/soap/envelope/) and SOAP 1.2 (uses http://www.w3.org/2003/05/soap-envelope). The tool detects the version from the binding and generates the correct envelope namespace.

Can I use this for CTF challenges?

Yes. SOAP services appear regularly in CTF web challenges. This tool cuts the time spent decoding WSDL XML and writing envelope boilerplate so you can focus on the actual vulnerability.

Why are my parameter values placeholders?

The tool inserts VALUE placeholders where the XSD type cannot be inferred as a primitive. Replace them with real values before sending the request.