<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="/rss.xsl"?><rss version="2.0"><channel><title>websecuritytool Releases Rss Feed</title><link>http://www.codeplex.com/websecuritytool/Release/ProjectReleases.aspx</link><description>websecuritytool Releases Rss Description</description><item><title>Updated Release: Watcher v1.5.7 (Mar 28, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;Program   Watcher Passive Web Security Tool for Fiddler &lt;br /&gt;Version   1.5.7&lt;br /&gt;Release   28-March-2013&lt;br /&gt;License   Custom Open Source&lt;br /&gt;Authors   Chris Weber&lt;br /&gt;Testers   Chris Weber&lt;br /&gt;Contact   chris@casaba.com&lt;br /&gt;Website   http://websecuritytool.codeplex.com/&lt;br /&gt;Company   http://www.casaba.com/&lt;br /&gt;Copyright (c) 2010 - 2013 Casaba Security, LLC.  All Rights Reserved.&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.7 2013-03-28&lt;br /&gt;  !!! Bug fix in check for custom-defined regex patterns&lt;br /&gt;&lt;br /&gt;v1.5.6 2013-01-08&lt;br /&gt;   + New check allows for custom-defined regex patterns&lt;br /&gt;   % Minor bugfixes &lt;br /&gt;&lt;br /&gt;v1.5.4 2011-10-01&lt;br /&gt;    + New check for internal IP address disclosure&lt;br /&gt;    % Watcher now defaults to automatically checking for updates at start&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Thu, 28 Mar 2013 18:55:42 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.7 (Mar 28, 2013) 20130328065542P</guid></item><item><title>Released: Watcher v1.5.7 (Mar 28, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
Program Watcher Passive Web Security Tool for Fiddler &lt;br&gt;
Version 1.5.7&lt;br&gt;
Release 28-March-2013&lt;br&gt;
License Custom Open Source&lt;br&gt;
Authors Chris Weber&lt;br&gt;
Testers Chris Weber&lt;br&gt;
Contact chris@casaba.com&lt;br&gt;
Website http://websecuritytool.codeplex.com/&lt;br&gt;
Company http://www.casaba.com/&lt;br&gt;
Copyright (c) 2010 - 2013 Casaba Security, LLC. All Rights Reserved.&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.7 2013-03-28&lt;br&gt;
!!! Bug fix in check for custom-defined regex patterns&lt;br&gt;
&lt;br&gt;
v1.5.6 2013-01-08&lt;br&gt;
&amp;#43; New check allows for custom-defined regex patterns&lt;br&gt;
% Minor bugfixes &lt;br&gt;
&lt;br&gt;
v1.5.4 2011-10-01&lt;br&gt;
&amp;#43; New check for internal IP address disclosure&lt;br&gt;
% Watcher now defaults to automatically checking for updates at start&lt;br&gt;
&lt;br&gt;
v1.5.3 2011-07-31&lt;br&gt;
! Bug fixes&lt;br&gt;
% X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br&gt;
&lt;br&gt;
v1.5.2 2011-05-21&lt;br&gt;
&amp;#43; New check for HTTP Strict-Transport-Security header on SSL sites&lt;br&gt;
&amp;#43; Added free-form text filter to Results display&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 28 Mar 2013 18:55:42 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.7 (Mar 28, 2013) 20130328065542P</guid></item><item><title>Updated Release: Watcher v1.5.7 (Mar 28, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;Program   Watcher Passive Web Security Tool for Fiddler &lt;br /&gt;Version   1.5.7&lt;br /&gt;Release   28-March-2013&lt;br /&gt;License   Custom Open Source&lt;br /&gt;Authors   Chris Weber&lt;br /&gt;Testers   Chris Weber&lt;br /&gt;Contact   chris@casaba.com&lt;br /&gt;Website   http://websecuritytool.codeplex.com/&lt;br /&gt;Company   http://www.casaba.com/&lt;br /&gt;Copyright (c) 2010 - 2013 Casaba Security, LLC.  All Rights Reserved.&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.7 2013-03-28&lt;br /&gt;  !!! Bug fix in check for custom-defined regex patterns&lt;br /&gt;&lt;br /&gt;v1.5.6 2013-01-08&lt;br /&gt;   + New check allows for custom-defined regex patterns&lt;br /&gt;   % Minor bugfixes &lt;br /&gt;&lt;br /&gt;v1.5.4 2011-10-01&lt;br /&gt;    + New check for internal IP address disclosure&lt;br /&gt;    % Watcher now defaults to automatically checking for updates at start&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Thu, 28 Mar 2013 18:52:20 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.7 (Mar 28, 2013) 20130328065220P</guid></item><item><title>Updated Release: Watcher v1.5.6 (Jan 08, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;Program   Watcher Passive Web Security Tool for Fiddler &lt;br /&gt;Version   1.5.6&lt;br /&gt;Release   08-January-2013&lt;br /&gt;License   Custom Open Source&lt;br /&gt;Authors   Chris Weber&lt;br /&gt;Testers   Chris Weber&lt;br /&gt;Contact   chris@casaba.com&lt;br /&gt;Website   http://websecuritytool.codeplex.com/&lt;br /&gt;Company   http://www.casaba.com/&lt;br /&gt;Copyright (c) 2010 - 2013 Casaba Security, LLC.  All Rights Reserved.&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.6 2013-01-08&lt;br /&gt;   + New check allows for custom-defined regex patterns&lt;br /&gt;   % Minor bugfixes &lt;br /&gt;&lt;br /&gt;v1.5.4 2011-10-01&lt;br /&gt;    + New check for internal IP address disclosure&lt;br /&gt;    % Watcher now defaults to automatically checking for updates at start&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Wed, 09 Jan 2013 00:48:47 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.6 (Jan 08, 2013) 20130109124847A</guid></item><item><title>Released: Watcher v1.5.6 (Jan 08, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
Program Watcher Passive Web Security Tool for Fiddler &lt;br&gt;
Version 1.5.6&lt;br&gt;
Release 08-January-2013&lt;br&gt;
License Custom Open Source&lt;br&gt;
Authors Chris Weber&lt;br&gt;
Testers Chris Weber&lt;br&gt;
Contact chris@casaba.com&lt;br&gt;
Website http://websecuritytool.codeplex.com/&lt;br&gt;
Company http://www.casaba.com/&lt;br&gt;
Copyright (c) 2010 - 2013 Casaba Security, LLC. All Rights Reserved.&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.6 2013-01-08&lt;br&gt;
&amp;#43; New check allows for custom-defined regex patterns&lt;br&gt;
% Minor bugfixes &lt;br&gt;
&lt;br&gt;
v1.5.4 2011-10-01&lt;br&gt;
&amp;#43; New check for internal IP address disclosure&lt;br&gt;
% Watcher now defaults to automatically checking for updates at start&lt;br&gt;
&lt;br&gt;
v1.5.3 2011-07-31&lt;br&gt;
! Bug fixes&lt;br&gt;
% X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br&gt;
&lt;br&gt;
v1.5.2 2011-05-21&lt;br&gt;
&amp;#43; New check for HTTP Strict-Transport-Security header on SSL sites&lt;br&gt;
&amp;#43; Added free-form text filter to Results display&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Wed, 09 Jan 2013 00:48:47 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.6 (Jan 08, 2013) 20130109124847A</guid></item><item><title>Updated Release: Watcher v1.5.5 (Jan 08, 2013)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;Program   Watcher Passive Web Security Tool for Fiddler &lt;br /&gt;Version   1.5.5&lt;br /&gt;Release   08-January-2013&lt;br /&gt;License   Custom Open Source&lt;br /&gt;Authors   Chris Weber&lt;br /&gt;Testers   Chris Weber&lt;br /&gt;Contact   chris@casaba.com&lt;br /&gt;Website   http://websecuritytool.codeplex.com/&lt;br /&gt;Company   http://www.casaba.com/&lt;br /&gt;Copyright (c) 2010 - 2013 Casaba Security, LLC.  All Rights Reserved.&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.5 2013-01-08&lt;br /&gt;   + New check allows for custom-defined regex patterns&lt;br /&gt;   % Minor bugfixes &lt;br /&gt;&lt;br /&gt;v1.5.4 2011-10-01&lt;br /&gt;    + New check for internal IP address disclosure&lt;br /&gt;    % Watcher now defaults to automatically checking for updates at start&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Wed, 09 Jan 2013 00:21:32 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.5 (Jan 08, 2013) 20130109122132A</guid></item><item><title>Updated Release: Watcher v1.5.4 (Oct 01, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.4 2011-10-01&lt;br /&gt;    + New check for internal IP address disclosure&lt;br /&gt;    % Watcher now defaults to automatically checking for updates at start&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Sat, 01 Oct 2011 20:33:55 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.4 (Oct 01, 2011) 20111001083355P</guid></item><item><title>Released: Watcher v1.5.4 (Oct 01, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.4 2011-10-01&lt;br&gt;
&amp;#43; New check for internal IP address disclosure&lt;br&gt;
% Watcher now defaults to automatically checking for updates at start&lt;br&gt;
&lt;br&gt;
v1.5.3 2011-07-31&lt;br&gt;
! Bug fixes&lt;br&gt;
% X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br&gt;
&lt;br&gt;
v1.5.2 2011-05-21&lt;br&gt;
&amp;#43; New check for HTTP Strict-Transport-Security header on SSL sites&lt;br&gt;
&amp;#43; Added free-form text filter to Results display&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Sat, 01 Oct 2011 20:33:55 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.4 (Oct 01, 2011) 20111001083355P</guid></item><item><title>Updated Release: Watcher v1.5.3 (Jul 31, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.3&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;v1.5.3 2011-07-31&lt;br /&gt;    ! Bug fixes&lt;br /&gt;   % X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br /&gt;&lt;br /&gt;v1.5.2 2011-05-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Mon, 01 Aug 2011 02:49:03 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.3 (Jul 31, 2011) 20110801024903A</guid></item><item><title>Released: Watcher v1.5.3 (Jul 31, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Release, v1.5.3&lt;br&gt;
&lt;br&gt;
Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
v1.5.3 2011-07-31&lt;br&gt;
! Bug fixes&lt;br&gt;
% X-Frame-Options check now checks every page, unique to path, ignoring query.&lt;br&gt;
&lt;br&gt;
v1.5.2 2011-05-21&lt;br&gt;
&amp;#43; New check for HTTP Strict-Transport-Security header on SSL sites&lt;br&gt;
&amp;#43; Added free-form text filter to Results display&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Mon, 01 Aug 2011 02:49:03 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.3 (Jul 31, 2011) 20110801024903A</guid></item><item><title>Updated Release: Watcher v1.5.2 (May 04, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.2&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   + New check for HTTP Strict-Transport-Security header on SSL sites&lt;br /&gt;   + Added free-form text filter to Results display&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Thu, 05 May 2011 05:35:30 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.2 (May 04, 2011) 20110505053530A</guid></item><item><title>Released: Watcher v1.5.2 (May 04, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Release, v1.5.2&lt;br&gt;
&lt;br&gt;
Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
&amp;#43; New check for HTTP Strict-Transport-Security header on SSL sites&lt;br&gt;
&amp;#43; Added free-form text filter to Results display&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 05 May 2011 05:35:30 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.2 (May 04, 2011) 20110505053530A</guid></item><item><title>Updated Release: Watcher v1.5.1 (Feb 21, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.1&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Tue, 22 Feb 2011 07:06:10 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.1 (Feb 21, 2011) 20110222070610A</guid></item><item><title>Released: Watcher v1.5.1 (Feb 21, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Release, v1.5.1&lt;br&gt;
&lt;br&gt;
Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Tue, 22 Feb 2011 07:06:10 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.1 (Feb 21, 2011) 20110222070610A</guid></item><item><title>Updated Release: Watcher v1.5.1 (Feb 21, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.1&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Tue, 22 Feb 2011 07:04:22 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.1 (Feb 21, 2011) 20110222070422A</guid></item><item><title>Released: Watcher v1.5.1 (Feb 21, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Release, v1.5.1&lt;br&gt;
&lt;br&gt;
Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.1 - 2011-02-21&lt;br&gt;
% Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br&gt;
% Deprecating some Utility.cs functions.&lt;br&gt;
! Fixing various minor bugs.&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Tue, 22 Feb 2011 07:04:22 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.1 (Feb 21, 2011) 20110222070422A</guid></item><item><title>Updated Release: Watcher v1.5.1 (Feb 21, 2011)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.1&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.1 - 2011-02-21&lt;br /&gt;   % Moving checks to Majestic12 HtmlParser to overcome some bottlenecks.&lt;br /&gt;   % Deprecating some Utility.cs functions.&lt;br /&gt;   ! Fixing various minor bugs.&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Tue, 22 Feb 2011 06:48:14 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.1 (Feb 21, 2011) 20110222064814A</guid></item><item><title>Updated Release: Watcher v1.5.0 (Nov 17, 2010)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.5.0&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.5.0 - 2010-11-17&lt;br /&gt;+++ Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br /&gt;   % Fixed the ProgressDialog control to move incrementally.&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Wed, 17 Nov 2010 23:37:48 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.5.0 (Nov 17, 2010) 20101117113748P</guid></item><item><title>Released: Watcher v1.5.0 (Nov 17, 2010)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>
&lt;div class="wikidoc"&gt;Release, v1.5.0&lt;br&gt;
&lt;br&gt;
Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br&gt;
&lt;br&gt;
WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS. Installation and further instructions are included in the ZIP file.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
{&amp;quot; &lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; major new feature &lt;br&gt;
&amp;#43; minor new feature&lt;br&gt;
* changed feature&lt;br&gt;
% improved performance or quality &lt;br&gt;
! fixed minor bug&lt;br&gt;
!!! fixed major bug&lt;br&gt;
&lt;br&gt;
v1.5.0 - 2010-11-17&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Added a button to process sessions offline. Now a user can load a .SAZ (session archive) file and process the data offline in Fiddler/Watcher.&lt;br&gt;
% Fixed the ProgressDialog control to move incrementally.&lt;br&gt;
&lt;br&gt;
v1.4.1 - 2010-11-09&lt;br&gt;
* Exporting results now includes all results rather than just those selected.&lt;br&gt;
* XML report now includes metadata about Watcher version and configuration.&lt;br&gt;
% Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br&gt;
&lt;br&gt;
v1.4.0 - 2010-04-24 &lt;br&gt;
Attempts have been made at noise-reduction, see below.&lt;br&gt;
Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Check descriptions all improved and updated with recommendations and external references.&lt;br&gt;
&amp;#43; New check for javascript document.domain lowering.&lt;br&gt;
* IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br&gt;
* New installations now come with a few noisy checks disabled by default.&lt;br&gt;
* New installations now come with some check configs enabled by default to reduce noise.&lt;br&gt;
! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br&gt;
! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br&gt;
! Assorted bug fixes.&lt;br&gt;
&lt;br&gt;
v1.3.0 - 2010-02-25&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; .NET Framework 3.5 is now required.&lt;br&gt;
&amp;#43;&amp;#43;&amp;#43; Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br&gt;
&amp;#43; New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br&gt;
&amp;#43; New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br&gt;
&amp;#43; New check for Silverlight EnableHtmlAccess.&lt;br&gt;
&amp;#43; Export results to HTML report.&lt;br&gt;
&amp;#43; If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br&gt;
&amp;#43; Added compliance mappings for Microsoft SDL.&lt;br&gt;
! Assorted bug fixes throughout check library.&lt;br&gt;
&lt;br&gt;
v1.2.2 - 2009-07-24&lt;br&gt;
&amp;#43; User-Agent now sends version information during update check for tracking purposes.&lt;br&gt;
&amp;#43; Added Windows 7 support to installer.&lt;br&gt;
! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br&gt;
! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br&gt;
* Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br&gt;
* Moved the check configuration to a tab of its own.&lt;br&gt;
% Updates to the UI look and feel.&lt;br&gt;
% Moved check configurations to their own page in UI.&lt;br&gt;
&lt;br&gt;
v1.2.1 - 2009-07-12&lt;br&gt;
!!! Fixed issue where response payloads greater than 200K caused the entire&lt;br&gt;
session to be ignored.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Wed, 17 Nov 2010 23:37:48 GMT</pubDate><guid isPermaLink="false">Released: Watcher v1.5.0 (Nov 17, 2010) 20101117113748P</guid></item><item><title>Updated Release: Watcher v1.4.1 (Nov 09, 2010)</title><link>http://websecuritytool.codeplex.com/releases/view/22212</link><description>&lt;div class="wikidoc"&gt;Release, v1.4.1&lt;br /&gt;&lt;br /&gt;Watcher.zip contains the two DLL&amp;#39;s for manual installation of the plugin - drop them in your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherSetup.exe is an installer built with NSIS that will copy the two DLL&amp;#39;s into either your Fiddler2\Scripts user or program files folder.&lt;br /&gt;&lt;br /&gt;WatcherTFS.zip contains the Team Foundation Server (TFS) component which Watcher uses to export results to TFS.  Installation and further instructions are included in the ZIP file.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=CHANGELOG"&gt;CHANGELOG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;{&amp;quot;  &lt;br /&gt; +++ major new feature &lt;br /&gt;      + minor new feature&lt;br /&gt;       * changed feature&lt;br /&gt;      % improved performance or quality &lt;br /&gt;       ! fixed minor bug&lt;br /&gt;     !!! fixed major bug&lt;br /&gt;&lt;br /&gt;v1.4.1 - 2010-11-09&lt;br /&gt;   * Exporting results now includes all results rather than just those selected.&lt;br /&gt;   * XML report now includes metadata about Watcher version and configuration.&lt;br /&gt;   % Check for &amp;#39;Charset not UTF-8&amp;#39; improvements.&lt;br /&gt;&lt;br /&gt;v1.4.0 - 2010-04-24   &lt;br /&gt;   Attempts have been made at noise-reduction, see below.&lt;br /&gt;   Wiki has been updated with more check descriptions, all linked to from inside Watcher.&lt;br /&gt; +++ Check descriptions all improved and updated with recommendations and external references.&lt;br /&gt;   + New check for javascript document.domain lowering.&lt;br /&gt;   * IMPORTANT: All cookie checks now perform noise filtering by default, with no option to change.&lt;br /&gt;   * New installations now come with a few noisy checks disabled by default.&lt;br /&gt;   * New installations now come with some check configs enabled by default to reduce noise.&lt;br /&gt;   ! Fixed bug in loosely scoped domain where it wasn&amp;#39;t defaulting to origin when one&amp;#39;s not specified.&lt;br /&gt;   ! Fixed bug where check configurations weren&amp;#39;t saving.&lt;br /&gt;   ! Assorted bug fixes.&lt;br /&gt;&lt;br /&gt;v1.3.0 - 2010-02-25&lt;br /&gt;  +++ .NET Framework 3.5 is now required.&lt;br /&gt;  +++ Optional plugin (separate download) to export results to Team Foundation Server (TFS).&lt;br /&gt;    + New (BETA) check for ASP.NET VIEWSTATE tampering vulnerability. (thanks to Bryan Sullivan for suggestions)&lt;br /&gt;    + New (BETA) check for JavaServer Faces ViewState tampering vulnerability. (thanks to David Byrne for ideas)&lt;br /&gt;    + New check for Silverlight EnableHtmlAccess.&lt;br /&gt;    + Export results to HTML report.&lt;br /&gt;    + If no origin domain is specified, each response domain will be treated as the origin, enabling better cross-domain analysis.&lt;br /&gt;    + Added compliance mappings for Microsoft SDL.&lt;br /&gt;    ! Assorted bug fixes throughout check library.&lt;br /&gt;&lt;br /&gt;v1.2.2 - 2009-07-24&lt;br /&gt;    + User-Agent now sends version information during update check for tracking purposes.&lt;br /&gt;    + Added Windows 7 support to installer.&lt;br /&gt;    ! Fixed the configuration page so checking and unchecking immediately affect what checks are run on a request.&lt;br /&gt;    ! Checks that maintain URL caches weren&amp;#39;t clearing when the results list was cleared.&lt;br /&gt;    * Changed the &amp;#39;Charset not UTF-8&amp;#39; check to ignore a missing meta tag charset when Content-Type header is defined (thanks Dave Wichers for reporting)&lt;br /&gt;    * Moved the check configuration to a tab of its own.&lt;br /&gt;    % Updates to the UI look and feel.&lt;br /&gt;    % Moved check configurations to their own page in UI.&lt;br /&gt;&lt;br /&gt;v1.2.1 - 2009-07-12&lt;br /&gt;  !!! Fixed issue where response payloads greater than 200K caused the entire&lt;br /&gt;      session to be ignored.&lt;br /&gt;&lt;br /&gt;v1.2.0 - 2009-06-22&lt;br /&gt;  +++ Major refactoring.&lt;br /&gt;  +++ Including Majestic12 Html Parser (http://www.majestic12.co.uk/).&lt;br /&gt;  +++ Added MultiThreading to checks.&lt;br /&gt;    + Added mappings to OWASP ASVS compliance levels.&lt;br /&gt;    + Added checks for X-FRAME-OPTIONS HTTP header.&lt;br /&gt;    + Added checks for IE&amp;#39;s X-XSS-Protection HTTP header.&lt;br /&gt;    + Added checks for X-CONTENT-TYPE-OPTIONS:nosniff HTTP header.&lt;br /&gt;    + Added search filter for finding checks.&lt;br /&gt;    * Improved check for user controlled attributes to look at all HTML attributes.&lt;br /&gt;    * Changed severity for Javascript eval() from Informational to Medium.&lt;br /&gt;    ! Fixed improper filtering of previously seen cookies.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>chrisweber</author><pubDate>Tue, 09 Nov 2010 19:44:50 GMT</pubDate><guid isPermaLink="false">Updated Release: Watcher v1.4.1 (Nov 09, 2010) 20101109074450P</guid></item></channel></rss>