After HP & Microsoft’s security tool, Google’s gotten onto distribuing a Security Audit tool. Here’s Ratproxy which is a passive web security audit tool based on the observation of existing, user-initiated traffic in complex web 2.0 environments.
Detects and prioritizes broad classes of security problems, such as dynamic cross-site trust model considerations, script inclusion issues, content serving problems, insufficient XSRF and XSS defenses, and much more.
Some of the key features ( from Ratproxy’s documentation) :
Ratproxy is currently believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments.
Links:
Ratproxy @ Google Code
RatProxy Documentation
Related articles by Zemanta
- ratproxy: Rat out those security issues in your Web app
- Google RatProxy looks for cross-site flaws
- Ratproxy: Open Source Site Security by Google
- Google gives away free Web app security scanner

