Watcher: The Passive Web-App Vulnerability Scanner
The majority of users do not want or cannot manually inspect a Web-app for many of its security issues, such as cookie settings, SSL configuration, leaks , etc., but everyone without exception wants to find the vulnerabilities it has and fix them.
That's why Watcher, a passive web app vulnerability scanner, was created. Watcher provides this level of security analysis, as it provides hot-spot detection to help pen-testers focus on dangerous spots.
Wαtcher is a Fiddler add-on that aims to help penetration testers passively find Web-app vulnerabilities. The tool was implemented as a plugin for Fiddler which already provides the HTTP proxy framework for debugging.
Some reasons to use Watcher:
1. It is safe for Cloud and hosting environments. Being passive, Wαtcher has many advantages – when applications run in the Cloud there is often a risk that, while performing security checks, there will be damage to the shared infrastructure. However, using a passive tool like Wαtcher ensures that there is no chance of damage to the Cloud-like infrastructure.
2. It is safe for production environments. Wαtcher does not attack web-applications with annoying requests, does not modify the inputs to your application. Unlike crawlers and other web-application scanners, Watcher does not generate dangerous traffic. It quietly analyzes normal user interaction and compiles reports on the security of the application.
3. It has a low overhead, and requires no training. Wαtcher provides valuable safety information without special training requirements, requirements for the use of machinery, or other resources.
The controls make up the most useful part of the tool – they provide analysis of HTTP traffic and reporting of security. The user running the tool can enable, disable, and configure the controls independently. If you are a developer, you can create custom and new controls for private use or to contribute to the public project.


