Tools no image

Published on February 27th, 2011 | by NJ Ouchn


WATOBO – THE Web Application Toolbox v0.9.6rev266 released

WATOBO is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. We are convinced that the semi-automated approach is the best way to perform an accurate audit and to identify most of the vulnerabilities.

WATOBO has no attack capabilities and is provided for legal vulnerability audit purposes only.

Additionally, WATOBO supports passive and active checks. Passive checks are more like filter functions. They are used to collect useful information, e.g. email or IP addresses. Passive checks will be performed during normal browsing activities. No additional requests are sent to the (web) application.

Active checks instead will produce a high number of requests (depending on the check module) because they do the automatic part of vulnerability identification, e.g. during a scan.


  • General: Supports One-Time-Tokens (e.g. Anti-CSRF-Tokens)
  • General: NTLM Authentication (Server and Proxy)
  • New Plugin: FileFinder
  • GUI: switch the icon and text size for lower screen resolution
  • Manual Request Editor: Table-View for easier parameter manipulation




Tags: ,

About the Author

"Passion is needed for any great work, and for the revolution, passion and audacity are required in big doses"

Back to Top ↑