<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Casaba Security &#187; Watcher</title>
	<atom:link href="http://www.casaba.com/blog/tag/watcher/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.casaba.com/blog</link>
	<description>Building and breaking software and robots</description>
	<lastBuildDate>Wed, 11 Jan 2012 18:08:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Porting Watcher checks to ModSecurity rules!</title>
		<link>http://www.casaba.com/blog/2012/01/porting-watcher-checks-to-modsecurity-rules/</link>
		<comments>http://www.casaba.com/blog/2012/01/porting-watcher-checks-to-modsecurity-rules/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 23:55:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ModSecurity]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false">http://www.casaba.com/blog/?p=381</guid>
		<description><![CDATA[Earlier this year, Ryan Barnett at TrustWave&#8217;s Spiderlabs started porting some of Watcher&#8217;s checks to ModSecurity.   After we chatted about this, I decided to get involved.  We always liked the idea of a server-side scanner watching the Web traffic, and since ModSecurity sits right in the sweet spot it all made sense to focus [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this year, Ryan Barnett at <a href="http://blog.spiderlabs.com/">TrustWave&#8217;s Spiderlabs</a> started <a href="http://blog.spiderlabs.com/2011/05/modsecurity-advanced-topic-of-the-week-passive-vulnerability-scanning-part-2-watcher-checks.html">porting some of Watcher&#8217;s checks to ModSecurity</a>.   After we chatted about this, I decided to get involved.  We always liked the idea of a server-side scanner watching the Web traffic, and since ModSecurity sits right in the sweet spot it all made sense to focus some effort there.</p>
<p>So over the past few months we&#8217;ve been working to port more of <a title="Watcher passive Web application scanner" href="http://websecuritytool.codeplex.com">Watcher&#8217;s </a>passive Web scanning checks to the<a title="ModSecurity" href="http://modsecurity.org/">ModSecurity </a>open source Web Application Firewall.  It seems to be working out, as some of the rules have made it into the latest release of <a title="Watcher and ModSecurity" href="http://blog.spiderlabs.com/2011/12/announcing-release-of-owasp-modsecurity-core-rule-set-v223.html">ModSecurity&#8217;s Core Rule Set v2.2.3</a> as well as some earlier rule sets.  There&#8217;s more to come.  Please send any feedback to me or Ryan, and look for more rules to be added very soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2012/01/porting-watcher-checks-to-modsecurity-rules/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher 1.4.0 released</title>
		<link>http://www.casaba.com/blog/2010/05/watcher-1-4-0-released/</link>
		<comments>http://www.casaba.com/blog/2010/05/watcher-1-4-0-released/#comments</comments>
		<pubDate>Tue, 25 May 2010 19:32:01 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=213</guid>
		<description><![CDATA[A new update to the Watcher passive Web-vulnerability scanner has been released. Based on user feedback we&#8217;ve built out the Wiki documentation on Codeplex with more details about the issues identified by each Watcher check. Inside the tool, a reference is now included as a link back to the Wiki. I hope to improve the [...]]]></description>
			<content:encoded><![CDATA[<p>A new update to the Watcher passive Web-vulnerability scanner has been released.  Based on user feedback we&#8217;ve built out the Wiki documentation on Codeplex with more details about the issues identified by each Watcher check.  Inside the tool, a reference is now included as a link back to the Wiki.  I hope to improve the documentation on the Wiki and welcome all your suggestions.</p>
<p>A new check has been added to detect when domain lowering occurs through javascript, typically done by setting document.domain equal to the parent domain.  We&#8217;ve also made some more efforts at noise-reduction, by enabling some of the noise-reduction configurations by default, namely in the cookie and VIEWSTATE checks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2010/05/watcher-1-4-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher 1.3.0 released</title>
		<link>http://www.casaba.com/blog/2010/02/watcher-1-3-0-released/</link>
		<comments>http://www.casaba.com/blog/2010/02/watcher-1-3-0-released/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 17:40:59 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[TFS]]></category>
		<category><![CDATA[VIEWSTATE]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false">http://www.casabasecurity.com/blog/?p=203</guid>
		<description><![CDATA[A new update to the Watcher passive vulnerability detection and security testing tool has been released. Watcher is an open source addon to the Fiddler Web proxy that aids developers, auditors, and penetration testers in finding Web-application security issues as well as hot-spots for deeper review. Among other things, we&#8217;ve added new checks to identify [...]]]></description>
			<content:encoded><![CDATA[<p>A new update to the Watcher passive vulnerability detection and security testing tool has been released.  Watcher is an open source addon to the Fiddler Web proxy that aids developers, auditors, and penetration testers in finding Web-application security issues as well as hot-spots for deeper review. Among other things, we&#8217;ve added new checks to identify the insecure ViewState issues as recently reported by Trustwave&#8217;s SpiderLabs [1].  </p>
<p><a href="http://websecuritytool.codeplex.com/releases/view/22212">Download Watcher </a>from CodePlex.  A short list of new features and improvements includes:</p>
<ul>
<li>A separate, optional component to export results to Team Foundation Server.</li>
<li>New check to identify insecure ASP.NET VIEWSTATE configurations subject to tampering and pervasive XSS attacks. </li>
<li>New check to identify insecure JavaServer MyFaces ViewState subject to tampering and XSS attacks. </li>
<li>New check for Silverlight EnableHtmlAccess.</li>
<li>Export results to HTML report.</li>
<li>Compliance mappings to Microsoft SDL.</li>
<li>If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.</li>
<li>Assorted bug fixes and improvements.</li>
</ul>
<p>Bryan Sullivan and Patrick Toomey&#8217;s ViewStateViewer plugin [2] provided inspiration for detecting ASP.NET VIEWSTATE MAC protection.  When testing .NET 4.0 we discovered a change in the MAC implementation which has also been accounted for in this check.  David Byrne from Trustwave [1] provided most of the methodology ideas for detecting insecure JavaServer MyFaces ViewState.</p>
<p>In addition to the main developers (Robert Mooney and Samuel Bucholtz), we wanted to thank everyone who helped or provided suggestions for this release:</p>
<p>Hidetake Jo<br />
Bryan Sullivan<br />
David Byrne<br />
Jason D. Montgomery<br />
Dave Wichers</p>
<p>[1] Trustwave advisory <a href="https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt.">https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</a><br />
[2] ViewStateViewer plugin for Fiddler <a href="http://labs.neohapsis.com/2009/08/03/viewstateviewer-a-gui-tool-for-deserializingreserializing-viewstate/">http://labs.neohapsis.com/2009/08/03/viewstateviewer-a-gui-tool-for-deserializingreserializing-viewstate/</a>  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2010/02/watcher-1-3-0-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New improved Watcher version 1.2.2 released</title>
		<link>http://www.casaba.com/blog/2009/08/new-improved-watcher-version-1-2-2-released/</link>
		<comments>http://www.casaba.com/blog/2009/08/new-improved-watcher-version-1-2-2-released/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 00:23:02 +0000</pubDate>
		<dc:creator>Samuel Bucholtz</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[A new point version of Watcher, Casaba&#039;s open source, passive, web security analyzer has been released on Codeplex. New in this version is multi-threaded check engine, support for OWASP&#039;s Application Security Verification Standard, and a number of new security checks. For more information checkout: http://websecuritytool.codeplex.com/]]></description>
			<content:encoded><![CDATA[<p>A new point version of Watcher, Casaba&#039;s open source, passive, web security analyzer has been released on Codeplex. New in this version is multi-threaded check engine, support for OWASP&#039;s Application Security Verification Standard, and a number of new security checks.</p>
<p>For more information checkout: <a href="http://websecuritytool.codeplex.com/" title="http://websecuritytool.codeplex.com/">http://websecuritytool.codeplex.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2009/08/new-improved-watcher-version-1-2-2-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft SDL blog post about Watcher</title>
		<link>http://www.casaba.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/</link>
		<comments>http://www.casaba.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 20:22:37 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[SDL]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Microsoft mentioned Watcher&#039;s usefulness in Web-security testing and SDL requirements verification. We&#039;re working to make this tool better so please share your success stories, bugs or false positives with us.]]></description>
			<content:encoded><![CDATA[<p>Microsoft mentioned Watcher&#039;s usefulness in <a href="http://blogs.msdn.com/sdl/archive/2009/04/16/watcher-a-new-web-security-testing-tool.aspx#comments">Web-security testing and SDL requirements verification<a />.   We&#039;re working to make this tool better so please share your success stories, bugs or false positives with us.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2009/04/microsoft-sdl-blog-post-about-watcher/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher v1.1.0 released</title>
		<link>http://www.casaba.com/blog/2009/04/watcher-v1-1-0-released/</link>
		<comments>http://www.casaba.com/blog/2009/04/watcher-v1-1-0-released/#comments</comments>
		<pubDate>Sun, 12 Apr 2009 16:44:02 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We&#039;ve made some significant improvements to the Watcher web security and compliance auditing tool in version 1.1.0. Some new checks have been added, bug fixes, and performance improvements. I wanted to point out that Watcher helps not only in testing and auditing Web applications, but it has checks to assess the security strength of the [...]]]></description>
			<content:encoded><![CDATA[<p>We&#039;ve made some significant improvements to the <a href="http://websecuritytool.codeplex.com/">Watcher web security and compliance auditing tool</a> in version 1.1.0.  Some new checks have been added, bug fixes, and performance improvements.  </p>
<p>I wanted to point out that Watcher helps not only in testing and auditing Web applications, but it has  checks to assess the security strength of the operational configurations as well, such as the SSL version being used.  We&#039;ve also added a check for SharePoint related assessment, and are working to add more Sharepoing security tests in the next version.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2009/04/watcher-v1-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eric Lawrence introduces Watcher tool at MIX09 Conference</title>
		<link>http://www.casaba.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/</link>
		<comments>http://www.casaba.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 05:23:42 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#039;m happy to say IE8 Security Program Manager and Fiddler author Eric Lawrence announced our Watcher tool at MIX09 today. Check out his talk at http://videos.visitmix.com/MIX09/T54F it&#039;s an eye opener for Web developers &#8211; introducing us to the new features of IE8 while also covering state-of-the-art secure development practices for today&#039;s Web applications. Unfortunately CodePlex [...]]]></description>
			<content:encoded><![CDATA[<p>I&#039;m happy to say IE8 Security Program Manager and Fiddler author Eric Lawrence announced our Watcher tool at MIX09 today.  Check out his talk at <a href="http://videos.visitmix.com/MIX09/T54F">http://videos.visitmix.com/MIX09/T54F</a> it&#039;s an eye opener for Web developers &#8211; introducing us to the new features of IE8 while also covering state-of-the-art secure development practices for today&#039;s Web applications.   </p>
<p>Unfortunately CodePlex went down today, even with Microsoft&#039;s new release of !exploitable at CanSecWest.  Anyhow we&#039;re working hard to to add new checks to Watcher and reduce false positives in existing ones.  So please grab <a href="http://websecuritytool.codeplex.com/">Watcher from Codeplex</a> and send us any feedback you want.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2009/03/eric-lawrence-introduces-watcher-tool-at-mix09-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watcher security tool for web applications</title>
		<link>http://www.casaba.com/blog/2009/03/watcher-security-tool-for-web-applications/</link>
		<comments>http://www.casaba.com/blog/2009/03/watcher-security-tool-for-web-applications/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 04:06:15 +0000</pubDate>
		<dc:creator>Chris Weber</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Watcher]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Watcher is being released under an Open Source license. With over 30 checks in its first release, it helps you find issues in your web-apps fast and effortlessly. Watcher is a Fiddler plugin that passively audits a web application for a variety of security issues. It acts as an assistant to the developer, tester, or [...]]]></description>
			<content:encoded><![CDATA[<p>Watcher is being released under an Open Source license.  With over 30 checks in its first release, it helps you find issues in your web-apps fast and effortlessly.  Watcher is a Fiddler plugin that passively audits a web application for a variety of security issues. It acts as an assistant to the developer, tester, or pen-tester, by quickly identifying issues that commonly lead to security problems in web apps. Integrate it into your test passes to achieve more coverage of security testing goals.</p>
<p>Go get <a href="http://www.casabasecurity.com/content/tools">Watcher</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.casaba.com/blog/2009/03/watcher-security-tool-for-web-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

