With shift to web services, where we are relying on client to secure stuff, we have to remember not to trust the client.
Gave a methodology for testing web services:
Tools shown:
Disclaimer The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way.