{"id":1630,"date":"2009-04-13T09:29:47","date_gmt":"2009-04-13T09:29:47","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=1630"},"modified":"2015-09-09T19:38:08","modified_gmt":"2015-09-09T11:38:08","slug":"watcher-passive-analysis-tool-for-http-web-applications","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2009\/04\/watcher-passive-analysis-tool-for-http-web-applications\/","title":{"rendered":"Watcher – Passive Analysis Tool For HTTP Web Applications"},"content":{"rendered":"

[ad]<\/p>\n

Watcher is a run time passive-analysis tool for HTTP-based Web applications. Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing. It looks for issues related to mashups, user-controlled payloads, cookies, comments, HTTP headers, SSL, Flash, Silverlight, referrer leaks, information disclosure, Unicode, and more.<\/p>\n

Major Features:<\/strong><\/p>\n

    \n
  1. Passive detection of security, privacy, and PCI compliance issues in HTTP, HTML, Javascript, and CSS<\/li>\n
  2. Works seamlessly with complex Web 2.0 applications while you drive the Web browser<\/li>\n
  3. Non-intrusive, will not raise alarms or damage production sites<\/li>\n
  4. Real-time analysis and reporting – findings are reported as they\u2019re found, exportable to XML<\/li>\n
  5. Configurable domains with wildcard support<\/li>\n
  6. \nExtensible framework for adding new checks<\/li>\n<\/ol>\n

    Watcher is built as a plugin for the Fiddler HTTP debugging proxy available at www.fiddlertool.com<\/a>. Watcher works seamlessly with today\u2019s complex Web 2.0 applications by running silently in the background while you drive your browser and interact with the Web-application.<\/p>\n

    Watcher is built in C# as a small framework with 30+ checks already included. It’s built so that new checks can be easily created to perform custom audits specific to your organizational policies, or to perform more general-purpose security assessments. <\/p>\n

    You can download Watcher here:<\/p>\n

    Watcher.zip<\/a><\/p>\n

    <\/p>\n

    Or read more here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"

    [ad] Watcher is a run time passive-analysis tool for HTTP-based Web applications. Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing. It looks for issues related to mashups, user-controlled payloads, cookies, comments, HTTP headers, SSL, Flash, Silverlight, referrer leaks, information disclosure, Unicode, and more. Major Features: Passive detection […]<\/p>\n","protected":false},"author":25,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[9,15],"tags":[2864,2227,396],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Darknet","author_link":"https:\/\/www.darknet.org.uk\/author\/darknet\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/1630"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=1630"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/1630\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=1630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=1630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=1630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}