Watcher is a runtime passive-analysis tool for HTTP-based Web
applications. It detects Web-application security issues as well as
operational configuration issues. Watcher provides pen-testers hot-
spot detection for vulnerabilities, developers quick sanity checks,
and auditors PCI compliance auditing. It looks for issues related to
mashups, user-controlled payloads (potential XSS), cookies, comments,
HTTP headers, SSL, Flash, Silverlight, referrer leaks, information
disclosure, Unicode, and more.
http://websecuritytool.codeplex.com/