websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

WATOBO 0.9.13 released

AS
Andreas Schmidt
Fri, Aug 9, 2013 4:44 PM

Hi everybody,

I've just pushed the final release of WATOBO 0.9.13 to rubygems.org.

WATOBO - THE Web Application Toolbox

WATOBO is a security tool for testing web applications. It is intended to enable security professionals to perform efficient (semi-automated) web application security audits.

Most important features:

  • WATOBO has Session Management capabilities! You can define login scripts as well as logout signatures. So you don't have to login manually each time you get logged out.
  • WATOB can act as a transparent proxy (requires nfqueue)
  • WATOBO can perform vulnerability checks out of the box
  • WATOBO can perform checks on functions which are protected by Anti-CSRF-/One-Time-Tokens
  • WATOBO supports Inline De-/Encoding, so you don't have to copy strings to a transcoder and back again. Just do it inside the request/response window with a simple mouse click.
  • WATOBO has smart filter functions, so you can find and navigate to the most interesting parts of the application easily.
  • WATOBO is written in (FX)Ruby and enables you to easily define your own checks
  • WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby
  • WATOBO is free software ( licensed under the GNU General Public License Version 2)
  • It's by siberas ;)

More details are available here:
http://watobo.sourceforge.net

If you find a bug, have a feature request or simply want to tell some
success stories please send a mail to watobo@siberas.de.
You also can use the sourceforge bugrack system:
http://sourceforge.net/tracker/?group_id=307923&atid=1297009

Thanks for your contribution!

Regards,

Andy

Hi everybody, I've just pushed the final release of WATOBO 0.9.13 to rubygems.org. WATOBO - THE Web Application Toolbox === WATOBO is a security tool for testing web applications. It is intended to enable security professionals to perform efficient (semi-automated) web application security audits. Most important features: * WATOBO has Session Management capabilities! You can define login scripts as well as logout signatures. So you don't have to login manually each time you get logged out. * WATOB can act as a transparent proxy (requires nfqueue) * WATOBO can perform vulnerability checks out of the box * WATOBO can perform checks on functions which are protected by Anti-CSRF-/One-Time-Tokens * WATOBO supports Inline De-/Encoding, so you don't have to copy strings to a transcoder and back again. Just do it inside the request/response window with a simple mouse click. * WATOBO has smart filter functions, so you can find and navigate to the most interesting parts of the application easily. * WATOBO is written in (FX)Ruby and enables you to easily define your own checks * WATOBO runs on Windows, Linux, MacOS ... every OS supporting (FX)Ruby * WATOBO is free software ( licensed under the GNU General Public License Version 2) * It's by siberas ;) More details are available here: http://watobo.sourceforge.net If you find a bug, have a feature request or simply want to tell some success stories please send a mail to watobo@siberas.de. You also can use the sourceforge bugrack system: http://sourceforge.net/tracker/?group_id=307923&atid=1297009 Thanks for your contribution! Regards, Andy