20
Information Security Inc. Watobo

Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Inc.

Watobo

Page 2: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Contents

2

• About Watobo

• Features

• Testing Environment

• Installing Watobo

• Using Watobo

• References

Page 3: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

About Watobo

3

• WATABO is a security tool for testing web applications. It is

intended to enable security professionals to perform efficient (semi-

automated) web application security audit

Page 4: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Features

4

• Powerful session management capabilities! You can define login

scripts as well as logout signatures. So you don't have to login

manually each time you get logged out

• Can act as a transparent proxy (requires nfqueue)

• Vulnerability checks (SQLinjectin, XSS, LFI) out of the box

• Handles Anti-CSRF-/One-Time-Tokens

Page 5: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Features

5

• Supports inline de-/encoding, so you don't have to copy strings to a

transcoder and back again. Just do it inside the request/response

window with a simple mouse click.

• Smart filter functions, so you can find and navigate to the most

interesting parts of the application easily.

• Is written in (FX) Ruby and enables you to easily define your own

checks

• Runs on Windows, Linux, MacOS every OS supporting (FX) Ruby

Page 6: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Testing Environment

6

• Kali Linux 2017

Page 7: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Installing Watobo

7

• apt-get install watobo

Page 8: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

8

• Starting Watobo for the first time

Page 9: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

9

• Starting Watobo

Page 10: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

10

• Watobo Transcoder

Page 11: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

11

• Watobo: create a new project => File > New/Open

Page 12: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

12

• Project Name

Page 13: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

13

• Session Name

Page 14: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

14

• Watobo listens on port 8081

Page 15: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

15

• Configure browser proxy

Page 16: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

16

• Watobo Interceptor

Page 17: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

17

• Watobo > send to SQLmap

Page 18: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

18

• Watobo > send to SQLmap

Page 19: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

Using Watobo

19

• Watobo > send to SQLmap

Page 20: Watobo - 情報セキュリティ株式会社 · 2017. 10. 19. · About Watobo 3 •WATABO is a security tool for testing web applications. It is intended to enable security professionals

Information Security Confidential - Partner Use Only

References

20

• Kitploit

http://www.kitploit.com/2013/08/watobo-0913-web-application-toolbox.html

• Kali Linux

https://www.kali.org/downloads/

• fxruby

https://github.com/larskanis/fxruby