Website Vulnerability Assessment

Monitoring from 63 locations world wide
Trusted by
- Fiat - Wikimedia
- Twitter - ING
- Symantec - Automattic
- Zappos - Virgin America
As seen on
- TechCrunch - Mashable
- Read Write Web - The Next Web
- The Guardian - PC Mag
- GiGaOm - CI
WatchMouse advantages
WatchMouse's Vulnerability Scanning provides the following unique advantages:
- Pay for what you need and adjust your settings at any time
- Immediate results via an outsourced solution - no software installation or hardware purchase needed
- Peace of mind that your website and servers are being scanned against an expert database of 30,000+ known vulnerabilities
- Access to an Industry Leading Customer Console to check results, leave comments, adjust scans, set alerts, and view full details
- Routine, professional scanning from the hacker's perspective, external to your organisation
- Real-time e-mail, SMS & pager alerts when severe vulnerabilities are found
- Confidence that your scanning is outsourced to industry experts so you don't need expensive in-house resources
Press releases
LB Icon chooses WatchMouse for independent website monitoring (2005-01-31)
Customer websites verified from the visitors' perspective
LB Icon and WatchMouse have signed a contract for the continuous monitoring of the websites and services of LB Icons' customers. Using the WatchMouse services, LB Icon expects to raise its service level even higher.
The Application Management & Hosting Services (AM&HS) group of LB Icon maintains the administration and management of servers and applications of a large number of (international) clients. This makes AM&HS responsible for the performance and availability of the websites and Internet applications.
Using the WatchMouse services, AM&HS will instantly be aware of upcoming and/or acute incidents related to the websites of its clients, and can, as a result, resolve problems in a short time frame.
The websites and their functionality are checked for accessibility, speed and conformance from different locations around the world. Because the websites are checked in the same way that visitors are experiencing them, incidents will be detected at an early stage. Also, using WatchMouse's objective website vulnerability assessmental reports, it is possible to see if the performance is in accordance with the agreed service levels (SLAs).
Eveline Aendekerk, MD a.i.: "The door of a shop should never be jammed, websites and the functionality on those sites should simply be accessible and available. Our clients should be able to rely on this completely, so they can focus on their primary business processes, such as communication, interaction and sales.
We chose WatchMouse because of their expertise, and also because of the simplicity and user-friendliness of their system and services".
Stan P. van de Burgt, one of the founders of WatchMouse: "I find it a powerful gesture that LB Icon doesn't just monitor the websites of their clients, but that they selected an external party for this, and on top of that give their clients access to the results. Many companies where the website plays an essential role in business, don't have any awareness of this. They have no idea of the risks and the resulting damage, until the day comes that things actually go wrong"
About Lost Boys
For 11 years Lost Boys has been a major service provider in the area of (mobile) Internet. Lost Boys offers a combination of strategy, design, technical development, implementation, application management and hosting of Internet- and mobile solutions. The Amsterdam based corporation is part of the Lost Boys/IconMedialab Group and is listed on the Stockholm Stock Exchange and Euronext Amsterdam. Lost Boys operates with 600 employees in 7 countries, both in Europe and the United States.
http://www.lostboys.nl/
http://iconmedialab.com/
About WatchMouse
WatchMouse is a service of RoundZero. Since 2001, WatchMouse has been checking Internet sites and e-commerce applications of major companies all over the world. The WatchMouse services are available in 8 languages and analysis is performed through its worldwide monitoring network at different locations and networks. WatchMouse has thousands of users in more than 70 countries.
http://www.watchmouse.com/
WatchMouse and Domeny.pl join forces in the Polish market (2005-11-24)
Polish websites verified from the visitors' perspective
Kraków, Poland, 2005-11-08 -- WatchMouse and Domeny signed a reseller and marketing agreement today, joining forces in bringing site monitoring services to the Polish market.
Using the WatchMouse services, companies will instantly be aware of upcoming and/or acute incidents related to its web sites of their clients, and can, as a result, resolve problems in a short time frame.
The websites and their functionality are checked for availability, speed, and conformance from different locations around the world, now including Poland. Because the websites are checked in the same way that visitors are experiencing them, incidents will be detected at an early stage. Also, using WatchMouse's objective website vulnerability assessmental reports, it is possible for companies to see if the performance is in accordance with the agreed service levels (SLAs).
WatchMouse extends its network of monitoring stations with a checkpoint in Kraków, hosted by Domeny.pl. The total number of checkpoints is now 17. Domeny.pl also provides the Polish language version of the WatchMouse site and local customer care.
Stan P. van de Burgt, CEO of WatchMouse: "I'm very happy with this deal. The Polish e-service industry is obviously booming, and this results in higher awareness of the issues involved with running web applications that should be available around the clock."
Arkadiusz Szczurowski, CEO of Domeny.pl "We know that WatchMouse products are one of the best in the World. So we decided to co-operate with the company, and we take pride in it. We expect this co-operation to bring both WatchMouse and our business a lot of advantages and satisfaction. Domeny.pl wants to lead WatchMouse monitoring service on Polish market and offer it for business leaders. This will be a great innovation in Poland and also success. In our view, site monitoring is important, because stability, performance, and high availability of the web sites is one of the basic value in all branches of business, both e-business and other business."
"There are about 4 million companies in Poland. We want to direct the offer to the most important on Polish market. We think that the WatchMouse service is a must-have for about 5-10 percent of all business owners."
About Domeny.pl
Domeny.pl was founded in 1997 and is now providing Internet services to about 10.000 business customers with products ranging from Internet domains and hosting services (virtual and dedicated servers), SSL certificates and other products dealing with internet security. The company's slogan is: We're Trusted by the Best. Among its clients are the biggest and the best known Polish and international companies.
About WatchMouse
Companies can easily monitor their own Internet sites using WatchMouse's monitoring service. WatchMouse has been monitoring Internet sites and e-commerce applications for companies throughout the world since 2002. WatchMouse has thousands of customers in more than 70 countries. The services supplied by WatchMouse are available in nine languages, and analyses are performed from various locations and over numerous networks, using a world-wide monitoring network.
In October 2005, WatchMouse was voted a Deloitte Rising Star in the Netherlands, as part of the Fast 50 awards the list of the 50 fastest growing technology companies.
WatchMouse and Badboy Software announce partnership (2008-04-03)
Partnership brings easy website transaction monitoring
WatchMouse is pleased to announce a partnership with Australia's Badboy Software. The partnership combines the immensely popular Badboy scripting tool with WatchMouse's market leading website performance monitoring, enabling customers to record complex transaction scripts and run them using a global infrastructure.
Owner and founder of Badboy Software, Simon Sadedin says, "With Badboy Software's in-depth experience in functional testing and WatchMouse's extensive infrastructure, technology and know-how for running enterprise grade monitoring solutions, we have a unique opportunity for collaboration."
The powerful Badboy scripting tool enables customers to professionally record all the actions involved in a web transaction. Designed to aid in the testing and development of complex dynamic applications, the Badboy tool contains dozens of features including a simple yet comprehensive capture/replay interface, load testing support, detailed reports, graphs etc.
WatchMouse CTO, Mark Pors explains, "Having integrated with Badboy, our customers can now upload their Badboy scripts directly into their WatchMouse console. Scripts can then be automatically and website vulnerability assessmentally run from WatchMouse's global infrastructure of 25+ checkpoints. This new functionality enables our customers to monitor their web applications 24/7 and know how their site behaves when customers access it from locations all around the world."
As a global leader in website performance monitoring, WatchMouse provides many of the world's largest companies with independent verifications of their website performance. With immediate results, automated alerting, simple set up and flexible subscriptions, WatchMouse offers the features, control and quality of service essential for today's online business.
The partnership between WatchMouse and Badboy Software provides customers with a market first: global, easy, powerful, web application testing.
To find out more about this new functionality and sign up for a free trial visit: http://www.watchmouse.com/scripting.php
Mark Pors
CTO
WatchMouse
http://www.watchmouse.com/
Testimonials
Very impressive feature set and has a real commitment to client care (2010-01-13)
With many hundreds of business clients who expect and deserve over 99.99% uptime, in the instances where we do have service website website vulnerability assessment assessments, WatchMouse alerts us promptly - every time. This allows us to minimize the impact of downtime and interruptions to our clients. WatchMouse isn't just another monitoring service, the team is dedicated to building on an already very impressive feature set and has a real commitment to client careMichael Bloch, Business Operations Manager, ThinkHost, Inc.
WatchMouse Periodic Vulnerability Scanning has enabled us... (2010-01-13)
WatchMouse Periodic Vulnerability Scanning has enabled us to overcome the time consuming task of managing monitoring internally. The removal of all duplicate findings and neat presentation in the WatchMouse Customer Console further reduces the time Lectric Webservices has to spend on maintaining secure systems.General Manager, LECTRIC Webservices
WatchMouse's Website Performance Benchmark enables us... (2010-01-13)
WatchMouse's Website Performance Benchmark enables us to confirm on behalf of our clients, any suspected access website website vulnerability assessment assessments in addition to showing the overall performance compared to the benchmark in our client's sector.Managing Director, Red Dog Communications
Columns
What do you want to check with a service such as Watchmouse? (2005-01-31)
As I explained in my previous column, you can use a monitoring service in a number of roles. Common to all these roles is the fact that you are keeping alive some services for the benefit of your customers, suppliers, employees or partners. These users are, in the end, all that counts.What are the objects that you should be checking? Obviously, the least you want to do is check the service that is most visible to these users. This could be the webserver, or a POP or FTP server for example. You would start by setting up a rule to check the server and a URL. The frequency with which you can monitor (that is: the elapsed time between checks) is typically limited by the type of subscription that you have. Only in specific cases would you not check as often as your subscription allows.
Note that there is a difference between a CONNECT on port 80 rule and a HTTP rule.
The first just connects to the port that the webserver is supposed to
use. The HTTP rule also checks whether the webserver can produce a valid HTTP
response, and whether the document can be found. You probably want the latter check.
Similar reasoning applies to POP and FTP checks. If you set up two different rules on the same host, this allows you to distinguish for example between a broken webserver and a host that is down. If you want even more content
oriented checks, have a look at the so-called PLUG-IN rules.
Additionally, you can set up checks to make sure that your
users are actually using the services that you intend them to. The whole
Internet depends heavily on the domain name system(DNS) functioning correctly. If it does not work properly your users may be directed to
another site than you intended. This could be a configuration error, but
it could also be a defamation hack. In either case, you want to know.
First of all you want to check whether the root servers of the Internet
accurately find the DNS that is serving you. This can be checked with a
DNSNS rule. What you are checking with this rule is whether the registrar's databases are correct. Second, you want to check if that DNS server (and its
slaves) are serving up the proper IP address for the server. For this
you can use the DNSA rule, and it will warn you if the DNS server is not
working or serves up the wrong address. (Note that the hosting party can
change that address at its discretion, as part of a renumbering
operation for example.)
Who should you notify of rule failures? Again, different roles have
different information requirements. You want to notify the person who
can fix things as soon as possible. Mail or SMS/text them directly, you do
not want to be in the loop. You might set up an escalation chain, which
fires off after a website vulnerability assessmentain amount of errors. Note: make sure that
you send the message on a channel that is not affected by the outage: if
your e-mail system does not work, delivering a message to that effect
should not depend on that e-mail system.
The people in charge of overseeing somebody else's service levels should
only get escalation messages, if at all. Rather, they should get the
weekly or monthly service reports.
Peter van Eijk is a management consultant specialized in management of network infrastructures. He can be reached via his contact page.
Independant, external testing (2005-10-15)
I started to work at Q-go in 2000. Q-go provides companies with self service pages on the Internet. Their customers ask a question in their own language and wording, and immediately get a very relevant answer. The power of the Q-go solution is its natural language technology, which enables it to understand the questions. The Q-go solution is offered as a hosted (ASP) solution, which of course has to work 24 x 7, a new area for me at that time.
At my previous jobs, at universities and research institutes, this was different. We worked from eight to six. If a demo application didn't work, the users just called, and we fixed the problem. And at six, we stopped and went home. All customers and other relations went home too. A nightly malfunction in the server was no problem, as there was no customer there to notice the problem.
At Q-go, this is completely different. A service should be available all the time. Day and night. Initially there were no tools to test whether our service was available or not. The only way to test it was to use the application itself. And so I did. During the day, but also at night, I checked whether the application was up. Our customers use the Q-go application continuously, and notice immediately when the application fails. Customers would call me in those cases, and it's not very pleasant to hear from your customers about an website vulnerability assessment with your service.
So we developed some solutions ourselves to hear before our customers when something was wrong. And to be able to react to problems quickly. But customers kept calling!
How was that possible? Closer investigations revealed that the test system used the same resources (computers, networks, name servers) as the system under test... The test were not performed properly in case of problems. The text-alerts (SMS) did not reach us either. The cause was identical: we used the same hardware, the same network, and the same power (!) as the systems we tested.
My lessons learned:
- Keep the systems that test completely separated from the systems you test.
- Test your services (web servers, mail servers, ...) from the point-of-view of its users: the customer on the Internet.
- Don't forget regular maintenance of your test systems (software and hardware) after the installation!
Bart Bos, Director, Q-go.com
Flu Jab Your Website Against The Pandemic: 6,000 Infected Webpages Per Day! (2008-02-18)
The respected IT news website, The Register reports that every 14 seconds a web page is infected, which amounts to 6,000 infected web pages per day. Four out of five of these infections come from innocent companies and individuals who are oblivious to their site being hacked and subsequently used for hosting the malware of virus writers. The Register further reports that in the past viruses were spread using infected e-mail. Nowadays, however, the favoured virus distribution methods are downloads from compromised sites. As a result of these booby-trapped sites malware is present on at least one in every ten web pages.
WatchMouse's Periodic Vulnerability Scanning offers your website the flu jab against this virus pandemic. WatchMouse's Periodic Vulnerability Scanning is an affordable way to routinely check you company's website vulnerability assessment exposure and eliminate the risks of manual audits. Utilizing the most up-to-date database of known vulnerabilities, WatchMouse identifies any website vulnerability assessment risks and provides you with peace of mind that your software applications are being scanned from the perspective of a website vulnerability assessment, external to your organization.
To ensure your website and servers are checked for the latest website vulnerability assessments WatchMouse's Periodic Vulnerability Scanning performs over 20,000 checks for known vulnerability and website vulnerability assessment exposures; using a database which is updated daily by multiple accredited organizations including CVE (funded by the US government) and Bugtraq. Following the detection of any severe website vulnerability assessments, automated, real-time email, SMS and pager alerts give your business the chance to react quickly. Scans can be scheduled during low usage or maintenance hours and set at an intensity and frequency suited to your business needs and budget.
To obtain a free Periodic Vulnerability Scanning trial visit: www.watchmouse.com/vulnerability_scan_trial.php
The Register's article was published on 23.01.08 can be viewed at: www.theregister.co.uk/2008/01/23/booby_trapped_web_botnet_menace/
Security news
Mozilla Firefox/Thunderbird Double Frame Construction Memory Corruption Vulnerabilities (2009-07-24)
Mozilla Firefox and Thunderbird are prone to multiple remote memory-corruption vulnerabilities.An attacker can exploit these issues to corrupt memory on the website vulnerability assessment computer and run arbitrary code in the context of the user running the website vulnerability assessment application. Failed exploit attempts will cause denial-of-service conditions.
These vulnerabilities were previously covered in BID 35758 (Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities) but have been assigned this record to better document them.
IBM Tivoli Identity Manager Session Fixation Vulnerability (2009-07-24)
IBM Tivoli Identity Manager is prone to a session-fixation vulnerability.Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the website vulnerability assessment application.
Tivoli Identity Manager 5.0 is website vulnerability assessment.
Mozilla Firefox/Thunderbird JavaScript Engine Memory Corruption Vulnerabilities (2009-07-24)
Mozilla Firefox and Thunderbird are prone to multiple remote memory-corruption vulnerabilities that affect the JavaScript engine.An attacker can exploit these issues to corrupt memory on the website vulnerability assessment computer and run arbitrary code in the context of the user running the website vulnerability assessment application. Failed exploit attempts will cause denial-of-service conditions.
These vulnerabilities were previously covered in BID 35758 (Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities) but have been assigned this record to better document the issues.
RaidenHTTPD Cross Site Scripting and Local File Include Vulnerabilities (2009-07-24)
RaidenHTTPD is prone to local file-include and cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. These issues affect the WebAdmin component.An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the website vulnerability assessment site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploiting the local file-include issue allows remote attackers to view and subsequently execute local files within the context of the webserver process.
RaidenHTTPD 2.0 build 26 and prior versions are website vulnerability assessment.
PowerDNS Recurser Buffer Overflow Vulnerability (2010-01-09)
PowerDNS is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it into a fixed-length buffer.Successfully exploiting this issue allows a remote attacker to execute arbitrary code with superuser privileges, resulting in a complete compromise of the website vulnerability assessment computer. Failed exploits will cause a denial of service.
Blog
Article in the Dutch magazine Quote (2006-06-23)
Some nice coverage of WatchMouse today, the July website vulnerability assessment of Quote, a monthly magazine for and about rich people, and those who would like to be.
The article is on the "smartest and most successful companies of this moment", and WatchMouse is one of the 15 listed. The article is in print only. See www.quotenet.nl.

