WebSecurityTool Watcher v1.1.0 available on CodePlex
Watcher (The Open source Web Security Testing Tool and PCI compliancy auditing utility) is a runtime passive-analysis tool for HTTP-based Web applications. It detects Web-application security issues as well as operational configuration issues.
Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing. It looks for issues related to mashups, user-controlled payloads (potential XSS), cookies, comments, HTTP headers, SSL, Flash, Silverlight, referrer leaks, information disclosure, Unicode, and more.
Major Features:
- Passive detection of security, privacy, and PCI compliance issues in HTTP, HTML, Javascript, and CSS
- Works seamlessly with complex Web 2.0 applications while you drive the Web browser
- Non-intrusive, will not raise alarms or damage production sites
- Real-time analysis and reporting - findings are reported as they’re found, exportable to XML
- Configurable domains with wildcard support
- Extensible framework for adding new checks
Dependencies
- Fiddler (The Web Debugging Proxy)
Post scriptum
Compliance Mandates
|
Related Articles
Application Scanner |
|
Configurations checks |
|
Vulnerability Scanner |
|
Watcher |
|