WATOBO v0.9.8 Released
WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities.
- Ruby 1.9 Support – no more 1.8 don’t even try it
- WATOBO available as a Gem
- Reorganisation of WATOBO settings files.
- Reorganisation of WATOBO project.
- Introduced Framework capabilities
- Changed version numbering for Gem compatibility
- SSLChecker-Plugin: nicer gui, now you can scan a site which is not already in conversation list
- Conversation-Table: better search features, e.g. URL, Request or Response
- Chat-Viewer: added a ‘save’-button to save the response’s body to a file, e.g. save a flash file for further investigations
- Scanner: now follows 302-redirects – this option is only available via QuickScan
- GUI: purge (multiple) findings is possibel via FindingsTree
- lib/mixin/request_parser.rb: fixed file handling
- fixed pattern for detecting file upload fields
- optimized “tagless” view
- optimized lots of threading stuff, e.g. progress bars, log-windows, …
- lib/qGui: changed progress_window
WATOBO has no attack capabilities and is provided for legal vulnerability audit purposes only.
Additionally, WATOBO supports passive and active checks. Passive checks are more like filter functions. They are used to collect useful information, e.g. email or IP addresses. Passive checks will be performed during normal browsing activities. No additional requests are sent to the (web) application.
Active checks instead will produce a high number of requests (depending on the check module) because they do the automatic part of vulnerability identification, e.g. during a scan.
Download WATOBO v0.9.8