|
Category: Security/Security-Related
Watcher 1.1.0
Download: http://download.softpedia.com/dl/b06e18462607a3eca8c3380a2e64edaf/49e8bad5/100125979/software/security/WatcherSetup.exe
Operation System: Windows 2K / XP / 2003 / Vista License: Size: 371 KB Date: 2009-04-17 19:13:03
Watcher was designed to be a runtime passive-analysis tool for HTTP-based Web applications. It detects Web-application security issues as well as operational configuration issues.
Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing. It looks for issues related to mashups, user-controlled payloads (potential XSS), cookies, comments, HTTP headers, SSL, Flash, Silverlight, referrer leaks, information disclosure, Unicode, and more. Watcher is built as a plugin for the Fiddler HTTP debugging proxy.
Watcher is built in C# as a small framework with 30+ checks already included. It's built so that new checks can be easily created to perform custom audits specific to your organizational policies, or to perform more general-purpose security assessments.
Examples of the types of issues Watcher will currently identify: - Cross-domain stylesheet and javascript references - User-controllable cross-domain references - User-controllable attribute values such as href, form action, etc. - User-controllable javascript events (e.g. onclick) - Cross-domain form POSTs - Insecure cookies which don't set the HTTPOnly or secure flags - Open redirects which can be abused by spammers and phishers - Insecure Flash object parameters useful for cross-site scripting - Insecure Flash crossdomain.xml - Insecure Silverlight clientaccesspolicy.xml - Charset declarations which could introduce vulnerability (non-UTF-8) - User-controllable charset declarations - Dangerous context-switching between HTTP and HTTPS - Insufficient use of cache-control headers when private data is concerned (e.g. no-store) - Potential HTTP referer leaks of sensitive user-information - Potential information leaks in URL parameters - Source code comments worth a closer look - Insecure authentication protocols like Digest and Basic - SSL certificate validation errors - SSL insecure protocol issues (allowing SSL v2) - Unicode issues with invalid byte streams - Sharepoint insecurity checks
www.cracksdata.com/get.php?id=277865
newcracks.net/down.php?n=370897
|
|

| |