XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, orcon.net.nz

Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

Report generated by XSS.CX at Sun May 15 14:45:11 CDT 2011.


Loading


1. Cross-site scripting (reflected)

2. Cookie without HttpOnly flag set

2.1. http://www.orcon.net.nz/athome.php

2.2. http://www.orcon.net.nz/atwork.php

2.3. http://www.orcon.net.nz/home/rural/

2.4. http://www.orcon.net.nz/mobile/broadband-plans

2.5. http://www.orcon.net.nz/mobile/broadband-plans/upgrade

2.6. http://www.orcon.net.nz/mobile/handsets

2.7. http://www.orcon.net.nz/mobile/plans

2.8. http://www.orcon.net.nz/mobile/plans/upgrade

2.9. http://www.orcon.net.nz/work/business_hosting

2.10. http://www.orcon.net.nz/work/business_internet

2.11. http://www.orcon.net.nz/

2.12. http://www.orcon.net.nz/about

2.13. http://www.orcon.net.nz/about/

2.14. http://www.orcon.net.nz/about/Terms_and_conditions

2.15. http://www.orcon.net.nz/about/browse/category/acquisitions/

2.16. http://www.orcon.net.nz/about/browse/category/awards/

2.17. http://www.orcon.net.nz/about/browse/category/media_releases/

2.18. http://www.orcon.net.nz/about/browse/category/news/

2.19. http://www.orcon.net.nz/about/careers

2.20. http://www.orcon.net.nz/about/careers/

2.21. http://www.orcon.net.nz/about/page/Privacy

2.22. http://www.orcon.net.nz/about/page/about_orcon

2.23. http://www.orcon.net.nz/about/page/contact_us

2.24. http://www.orcon.net.nz/about/sitemap

2.25. http://www.orcon.net.nz/about/sitemap/

2.26. http://www.orcon.net.nz/about/staff/

2.27. http://www.orcon.net.nz/address_locator/=&type=orconatwork

2.28. http://www.orcon.net.nz/business

2.29. http://www.orcon.net.nz/campaigns/landing/1monthfree

2.30. http://www.orcon.net.nz/home/

2.31. http://www.orcon.net.nz/home/dial-up/

2.32. http://www.orcon.net.nz/home/page/about_orcon_plus

2.33. http://www.orcon.net.nz/home/page/broadband_modems

2.34. http://www.orcon.net.nz/home/page/home_email

2.35. http://www.orcon.net.nz/home/page/o_zone

2.36. http://www.orcon.net.nz/home/page/orcon_homeline_and_tolls

2.37. http://www.orcon.net.nz/home/plans/

2.38. http://www.orcon.net.nz/img/bg_copy.gif

2.39. http://www.orcon.net.nz/index.php

2.40. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P10/

2.41. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P25/

2.42. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P5/

2.43. http://www.orcon.net.nz/lifestyle

2.44. http://www.orcon.net.nz/lifestyle/rss

2.45. http://www.orcon.net.nz/mobile

2.46. http://www.orcon.net.nz/mobile/

2.47. http://www.orcon.net.nz/no-brainer/joinUs

2.48. http://www.orcon.net.nz/site/login

2.49. http://www.orcon.net.nz/site/login/=&result=failure

2.50. http://www.orcon.net.nz/support

2.51. http://www.orcon.net.nz/support/

2.52. http://www.orcon.net.nz/support/browse/category/cloud_computing

2.53. http://www.orcon.net.nz/support/glossary/category/a

2.54. http://www.orcon.net.nz/support/network_status

2.55. http://www.orcon.net.nz/support/network_status_rss

2.56. http://www.orcon.net.nz/support/page/how_to_call_international_destinations_from_your_mobile

2.57. http://www.orcon.net.nz/support/page/roaming_charges_activation

2.58. http://www.orcon.net.nz/support/page/setting_up_your_mobile_voicemail

2.59. http://www.orcon.net.nz/support/page/what_are_your_dns_server_addresses

2.60. http://www.orcon.net.nz/support/page/what_does_standby_mean

2.61. http://www.orcon.net.nz/support/page/will_my_phone_number_change_with_orcon_homeline

2.62. http://www.orcon.net.nz/support/talk

2.63. http://www.orcon.net.nz/work/

2.64. http://www.orcon.net.nz/work/=&ref=iserve

2.65. http://www.orcon.net.nz/work/business_phone_sip_trunk

2.66. http://www.orcon.net.nz/work/hosting_plans/

2.67. http://www.orcon.net.nz/work/page/business_broadband_overview

2.68. http://www.orcon.net.nz/work/page/business_phone_line

2.69. http://www.orcon.net.nz/work/page/business_server_dedicated

2.70. http://www.orcon.net.nz/work/page/business_server_hosting_overview

2.71. http://www.orcon.net.nz/work/page/business_server_software

2.72. http://www.orcon.net.nz/work/page/business_server_virtual

2.73. http://www.orcon.net.nz/work/page/case_study_certus

2.74. http://www.orcon.net.nz/work/page/case_study_speedscan

2.75. http://www.orcon.net.nz/work/page/case_study_zeald

2.76. http://www.orcon.net.nz/work/page/cloud_computing_overview

2.77. http://www.orcon.net.nz/work/page/co-location

2.78. http://www.orcon.net.nz/work/page/domain_names_overview

2.79. http://www.orcon.net.nz/work/page/fibre_optic

2.80. http://www.orcon.net.nz/work/page/free_domain_hosting

2.81. http://www.orcon.net.nz/work/page/hosted_exchange

2.82. http://www.orcon.net.nz/work/page/hsns

2.83. http://www.orcon.net.nz/work/page/register_a_domain

2.84. http://www.orcon.net.nz/work/page/sip_trunk

2.85. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet

2.86. http://www.orcon.net.nz/work/page/wan

2.87. http://www.orcon.net.nz/work/page/zealous_support

2.88. http://www.orcon.net.nz/work/plans

2.89. http://www.orcon.net.nz/work/wholesale_services

3. Password field with autocomplete enabled

3.1. http://www.orcon.net.nz/site/login

3.2. http://www.orcon.net.nz/site/login/=&result=failure

4. Source code disclosure

4.1. http://www.orcon.net.nz/work/business_phone_sip_trunk

4.2. http://www.orcon.net.nz/work/wholesale_services

5. Flash cross-domain policy

6. Cross-domain POST

6.1. http://www.orcon.net.nz/

6.2. http://www.orcon.net.nz/about

6.3. http://www.orcon.net.nz/about/

6.4. http://www.orcon.net.nz/about/Terms_and_conditions

6.5. http://www.orcon.net.nz/about/browse/category/acquisitions/

6.6. http://www.orcon.net.nz/about/browse/category/awards/

6.7. http://www.orcon.net.nz/about/browse/category/media_releases/

6.8. http://www.orcon.net.nz/about/browse/category/news/

6.9. http://www.orcon.net.nz/about/careers

6.10. http://www.orcon.net.nz/about/careers/

6.11. http://www.orcon.net.nz/about/page/Privacy

6.12. http://www.orcon.net.nz/about/page/about_orcon

6.13. http://www.orcon.net.nz/about/page/contact_us

6.14. http://www.orcon.net.nz/about/sitemap

6.15. http://www.orcon.net.nz/about/sitemap/

6.16. http://www.orcon.net.nz/about/staff/

6.17. http://www.orcon.net.nz/address_locator/=&type=orconatwork

6.18. http://www.orcon.net.nz/business

6.19. http://www.orcon.net.nz/campaigns/landing/1monthfree

6.20. http://www.orcon.net.nz/home/

6.21. http://www.orcon.net.nz/home/dial-up/

6.22. http://www.orcon.net.nz/home/page/about_orcon_plus

6.23. http://www.orcon.net.nz/home/page/broadband_modems

6.24. http://www.orcon.net.nz/home/page/home_email

6.25. http://www.orcon.net.nz/home/page/o_zone

6.26. http://www.orcon.net.nz/home/page/orcon_homeline_and_tolls

6.27. http://www.orcon.net.nz/home/plans/

6.28. http://www.orcon.net.nz/home/rural/

6.29. http://www.orcon.net.nz/img/bg_copy.gif

6.30. http://www.orcon.net.nz/index.php

6.31. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P10/

6.32. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P25/

6.33. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P5/

6.34. http://www.orcon.net.nz/lifestyle

6.35. http://www.orcon.net.nz/mobile

6.36. http://www.orcon.net.nz/mobile/

6.37. http://www.orcon.net.nz/mobile/broadband-plans

6.38. http://www.orcon.net.nz/mobile/broadband-plans/upgrade

6.39. http://www.orcon.net.nz/mobile/handsets

6.40. http://www.orcon.net.nz/mobile/plans

6.41. http://www.orcon.net.nz/mobile/plans/upgrade

6.42. http://www.orcon.net.nz/site/login

6.43. http://www.orcon.net.nz/site/login

6.44. http://www.orcon.net.nz/site/login/=&result=failure

6.45. http://www.orcon.net.nz/site/login/=&result=failure

6.46. http://www.orcon.net.nz/support

6.47. http://www.orcon.net.nz/support/

6.48. http://www.orcon.net.nz/support/browse/category/cloud_computing

6.49. http://www.orcon.net.nz/support/glossary/category/a

6.50. http://www.orcon.net.nz/support/network_status

6.51. http://www.orcon.net.nz/support/page/how_to_call_international_destinations_from_your_mobile

6.52. http://www.orcon.net.nz/support/page/roaming_charges_activation

6.53. http://www.orcon.net.nz/support/page/setting_up_your_mobile_voicemail

6.54. http://www.orcon.net.nz/support/page/what_are_your_dns_server_addresses

6.55. http://www.orcon.net.nz/support/page/what_does_standby_mean

6.56. http://www.orcon.net.nz/support/page/will_my_phone_number_change_with_orcon_homeline

6.57. http://www.orcon.net.nz/support/talk

6.58. http://www.orcon.net.nz/work/

6.59. http://www.orcon.net.nz/work/=&ref=iserve

6.60. http://www.orcon.net.nz/work/business_hosting

6.61. http://www.orcon.net.nz/work/business_internet

6.62. http://www.orcon.net.nz/work/business_phone_sip_trunk

6.63. http://www.orcon.net.nz/work/hosting_plans/

6.64. http://www.orcon.net.nz/work/hosting_plans/

6.65. http://www.orcon.net.nz/work/page/business_broadband_overview

6.66. http://www.orcon.net.nz/work/page/business_phone_line

6.67. http://www.orcon.net.nz/work/page/business_server_dedicated

6.68. http://www.orcon.net.nz/work/page/business_server_hosting_overview

6.69. http://www.orcon.net.nz/work/page/business_server_software

6.70. http://www.orcon.net.nz/work/page/business_server_virtual

6.71. http://www.orcon.net.nz/work/page/case_study_certus

6.72. http://www.orcon.net.nz/work/page/case_study_speedscan

6.73. http://www.orcon.net.nz/work/page/case_study_zeald

6.74. http://www.orcon.net.nz/work/page/cloud_computing_overview

6.75. http://www.orcon.net.nz/work/page/co-location

6.76. http://www.orcon.net.nz/work/page/domain_names_overview

6.77. http://www.orcon.net.nz/work/page/fibre_optic

6.78. http://www.orcon.net.nz/work/page/free_domain_hosting

6.79. http://www.orcon.net.nz/work/page/hosted_exchange

6.80. http://www.orcon.net.nz/work/page/hsns

6.81. http://www.orcon.net.nz/work/page/register_a_domain

6.82. http://www.orcon.net.nz/work/page/sip_trunk

6.83. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet

6.84. http://www.orcon.net.nz/work/page/wan

6.85. http://www.orcon.net.nz/work/page/zealous_support

6.86. http://www.orcon.net.nz/work/plans

6.87. http://www.orcon.net.nz/work/wholesale_services

7. Cross-domain script include

7.1. http://www.orcon.net.nz/

7.2. http://www.orcon.net.nz/business

7.3. http://www.orcon.net.nz/home/page/about_orcon_plus

7.4. http://www.orcon.net.nz/index.php

7.5. http://www.orcon.net.nz/work/

7.6. http://www.orcon.net.nz/work/=&ref=iserve

7.7. http://www.orcon.net.nz/work/business_internet

7.8. http://www.orcon.net.nz/work/page/business_broadband_overview

7.9. http://www.orcon.net.nz/work/page/fibre_optic

7.10. http://www.orcon.net.nz/work/page/hsns

7.11. http://www.orcon.net.nz/work/page/wan

7.12. http://www.orcon.net.nz/work/plans

8. TRACE method is enabled

9. Email addresses disclosed

9.1. http://www.orcon.net.nz/lifestyle

9.2. http://www.orcon.net.nz/lifestyle/rss

9.3. http://www.orcon.net.nz/scripts/jquery.pngFix.pack.js

9.4. http://www.orcon.net.nz/support/network_status_rss

9.5. http://www.orcon.net.nz/support/talk

9.6. http://www.orcon.net.nz/work/

9.7. http://www.orcon.net.nz/work/=&ref=iserve

9.8. http://www.orcon.net.nz/work/business_hosting

9.9. http://www.orcon.net.nz/work/business_internet

9.10. http://www.orcon.net.nz/work/business_phone_sip_trunk

9.11. http://www.orcon.net.nz/work/hosting_plans/

9.12. http://www.orcon.net.nz/work/page/business_broadband_overview

9.13. http://www.orcon.net.nz/work/page/business_phone_line

9.14. http://www.orcon.net.nz/work/page/business_server_dedicated

9.15. http://www.orcon.net.nz/work/page/business_server_hosting_overview

9.16. http://www.orcon.net.nz/work/page/business_server_software

9.17. http://www.orcon.net.nz/work/page/business_server_virtual

9.18. http://www.orcon.net.nz/work/page/case_study_certus

9.19. http://www.orcon.net.nz/work/page/case_study_speedscan

9.20. http://www.orcon.net.nz/work/page/case_study_zeald

9.21. http://www.orcon.net.nz/work/page/cloud_computing_overview

9.22. http://www.orcon.net.nz/work/page/co-location

9.23. http://www.orcon.net.nz/work/page/domain_names_overview

9.24. http://www.orcon.net.nz/work/page/fibre_optic

9.25. http://www.orcon.net.nz/work/page/free_domain_hosting

9.26. http://www.orcon.net.nz/work/page/hosted_exchange

9.27. http://www.orcon.net.nz/work/page/hsns

9.28. http://www.orcon.net.nz/work/page/register_a_domain

9.29. http://www.orcon.net.nz/work/page/sip_trunk

9.30. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet

9.31. http://www.orcon.net.nz/work/page/wan

9.32. http://www.orcon.net.nz/work/page/zealous_support

9.33. http://www.orcon.net.nz/work/plans

9.34. http://www.orcon.net.nz/work/wholesale_services

10. Robots.txt file



1. Cross-site scripting (reflected)  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /address_locator/=&type=orconatwork

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload cebce</script><script>alert(1)</script>30cb7ccddae was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.

Request

GET /address_locator/=&type=orconatwork?cebce</script><script>alert(1)</script>30cb7ccddae=1 HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:18 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439038; expires=Mon, 14-May-2012 17:57:18 GMT; path=/
Connection: close
Content-Length: 12693

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
;

$(document).ready(function() {
    $("#addressSearch").validate();
//fullURL = parent.document.URL;
//type = fullURL.substring(fullURL.indexOf('?')+6, fullURL.length);
var type = "orconatworkcebce</script><script>alert(1)</script>30cb7ccddae=1";

if(type == "orconatwork"){
connectionURL = 'atwork.php';
}else{
connectionURL = 'athome.php';
}


/*
$.ajax({
type: "GET",
url: "/modules/views/
...[SNIP]...

2. Cookie without HttpOnly flag set  previous  next
There are 89 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



2.1. http://www.orcon.net.nz/athome.php  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /athome.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /athome.php HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 302 Found
Date: Sun, 15 May 2011 17:50:43 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: home/
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=0b90abaf68abad988935d21792bc1d84; path=/
Connection: close


2.2. http://www.orcon.net.nz/atwork.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /atwork.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /atwork.php HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 302 Found
Date: Sun, 15 May 2011 17:50:45 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: /work/
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=fef3d8253f091d724a82ce08418f19be; path=/
Connection: close


2.3. http://www.orcon.net.nz/home/rural/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /home/rural/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/rural/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:54:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:54:38 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438878; expires=Mon, 14-May-2012 17:54:38 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fhome%2Frural%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=e6bc587b8bce09263088863d8fd1ecea; path=/
Connection: close
Content-Length: 22978

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.4. http://www.orcon.net.nz/mobile/broadband-plans  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /mobile/broadband-plans

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/broadband-plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:15 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439035; expires=Mon, 14-May-2012 17:57:15 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fmobile%2Fbroadband-plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=09e4ece0388eddfc86bc7ea539fe2544; path=/
Connection: close
Content-Length: 27866

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.5. http://www.orcon.net.nz/mobile/broadband-plans/upgrade  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /mobile/broadband-plans/upgrade

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/broadband-plans/upgrade HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:15 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439035; expires=Mon, 14-May-2012 17:57:15 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fmobile%2Fbroadband-plans%2Fupgrade%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=04ea22d024062d336988fbe32aea003a; path=/
Connection: close
Content-Length: 27874

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.6. http://www.orcon.net.nz/mobile/handsets  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /mobile/handsets

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/handsets HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:56:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:56:20 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438979; expires=Mon, 14-May-2012 17:56:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A17%3A%22%2Fmobile%2Fhandsets%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=b3a1d71f26b693a0a754f42e1fc446e1; path=/
Connection: close
Content-Length: 22213

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.7. http://www.orcon.net.nz/mobile/plans  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /mobile/plans

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439034; expires=Mon, 14-May-2012 17:57:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fmobile%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=d560c6b9cc26aa1f2ce251c02c4eb80d; path=/
Connection: close
Content-Length: 35545

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.8. http://www.orcon.net.nz/mobile/plans/upgrade  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /mobile/plans/upgrade

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/plans/upgrade HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:14 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439034; expires=Mon, 14-May-2012 17:57:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A22%3A%22%2Fmobile%2Fplans%2Fupgrade%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=5c456fb2a3b1024dc72d8e3c58c2c34e; path=/
Connection: close
Content-Length: 34141

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.9. http://www.orcon.net.nz/work/business_hosting  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /work/business_hosting

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/business_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:49 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:49 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437989; expires=Mon, 14-May-2012 17:39:49 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fbusiness_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=3124d3340bbb6b50e6a4c5f0d48241b9; path=/
Connection: close
Content-Length: 24860

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.10. http://www.orcon.net.nz/work/business_internet  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.orcon.net.nz
Path:   /work/business_internet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/business_internet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fwork%2Fbusiness_internet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=1a88672d816fc2815ca829c6bbc91339; path=/
Connection: close
Content-Length: 24366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.11. http://www.orcon.net.nz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:48:39 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:48:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438519; expires=Mon, 14-May-2012 17:48:39 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.12. http://www.orcon.net.nz/about  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305437066; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.6.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A2%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:46 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437086; expires=Mon, 14-May-2012 17:24:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A3%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A2%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 16243


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.13. http://www.orcon.net.nz/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438608; expires=Mon, 14-May-2012 17:50:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16235


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.14. http://www.orcon.net.nz/about/Terms_and_conditions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/Terms_and_conditions

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/Terms_and_conditions HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:51 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:51 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438591; expires=Mon, 14-May-2012 17:49:51 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fabout%2FTerms_and_conditions%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18173

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.15. http://www.orcon.net.nz/about/browse/category/acquisitions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/acquisitions/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/browse/category/acquisitions/ HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/about
Cookie: exp_last_visit=990076976; exp_last_activity=1305437085; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.7.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A3%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A2%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:57 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:57 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437097; expires=Mon, 14-May-2012 17:24:57 GMT; path=/
Set-Cookie: exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 17999

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.16. http://www.orcon.net.nz/about/browse/category/awards/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/awards/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/browse/category/awards/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:28 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:28 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438628; expires=Mon, 14-May-2012 17:50:28 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A30%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fawards%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17913

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.17. http://www.orcon.net.nz/about/browse/category/media_releases/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/media_releases/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/browse/category/media_releases/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438634; expires=Mon, 14-May-2012 17:50:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A38%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fmedia_releases%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19143

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.18. http://www.orcon.net.nz/about/browse/category/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/news/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/browse/category/news/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438618; expires=Mon, 14-May-2012 17:50:18 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fnews%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18707

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.19. http://www.orcon.net.nz/about/careers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/careers

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/careers HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438574; expires=Mon, 14-May-2012 17:49:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fcareers%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22973

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.20. http://www.orcon.net.nz/about/careers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/careers/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/careers/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:17 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438617; expires=Mon, 14-May-2012 17:50:17 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fcareers%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22964

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.21. http://www.orcon.net.nz/about/page/Privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/Privacy

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/page/Privacy HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:55 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438594; expires=Mon, 14-May-2012 17:49:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fabout%2Fpage%2FPrivacy%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16956


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.22. http://www.orcon.net.nz/about/page/about_orcon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/about_orcon

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/page/about_orcon HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:59 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fabout%2Fpage%2Fabout_orcon%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17610


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.23. http://www.orcon.net.nz/about/page/contact_us  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/contact_us

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/page/contact_us HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fabout%2Fpage%2Fcontact_us%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19693


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.24. http://www.orcon.net.nz/about/sitemap  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/sitemap

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/sitemap HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:59 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:59 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fsitemap%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14349

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.25. http://www.orcon.net.nz/about/sitemap/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/sitemap/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/sitemap/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:44 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:44 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438644; expires=Mon, 14-May-2012 17:50:44 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fsitemap%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14349

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.26. http://www.orcon.net.nz/about/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/staff/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /about/staff/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:14 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438614; expires=Mon, 14-May-2012 17:50:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A13%3A%22%2Fabout%2Fstaff%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14158

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.27. http://www.orcon.net.nz/address_locator/=&type=orconatwork  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /address_locator/=&type=orconatwork

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /address_locator/=&type=orconatwork HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:06 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:06 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438666; expires=Mon, 14-May-2012 17:51:06 GMT; path=/
Connection: close
Content-Length: 12641

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.28. http://www.orcon.net.nz/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /business

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /business HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A10%3A%22%2Fbusiness%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16314


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Free review of your
...[SNIP]...

2.29. http://www.orcon.net.nz/campaigns/landing/1monthfree  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /campaigns/landing/1monthfree

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /campaigns/landing/1monthfree HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 404 Not Found
Date: Sun, 15 May 2011 17:57:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439040; expires=Mon, 14-May-2012 17:57:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A30%3A%22%2Fcampaigns%2Flanding%2F1monthfree%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 12961


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.30. http://www.orcon.net.nz/home/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:55:52 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:55:52 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438952; expires=Mon, 14-May-2012 17:55:52 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fhome%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18318

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.31. http://www.orcon.net.nz/home/dial-up/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/dial-up/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/dial-up/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:54:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:54:46 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438886; expires=Mon, 14-May-2012 17:54:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fhome%2Fdial-up%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18755

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.32. http://www.orcon.net.nz/home/page/about_orcon_plus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/about_orcon_plus

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/page/about_orcon_plus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:15 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438674; expires=Mon, 14-May-2012 17:51:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fhome%2Fpage%2Fabout_orcon_plus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33732


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.33. http://www.orcon.net.nz/home/page/broadband_modems  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/broadband_modems

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/page/broadband_modems HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:52:21 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:52:22 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438741; expires=Mon, 14-May-2012 17:52:21 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fhome%2Fpage%2Fbroadband_modems%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18218


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.34. http://www.orcon.net.nz/home/page/home_email  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/home_email

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/page/home_email HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:52:23 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:52:24 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438743; expires=Mon, 14-May-2012 17:52:23 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A22%3A%22%2Fhome%2Fpage%2Fhome_email%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17644


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.35. http://www.orcon.net.nz/home/page/o_zone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/o_zone

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/page/o_zone HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438679; expires=Mon, 14-May-2012 17:51:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A18%3A%22%2Fhome%2Fpage%2Fo_zone%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19577


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.36. http://www.orcon.net.nz/home/page/orcon_homeline_and_tolls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/orcon_homeline_and_tolls

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/page/orcon_homeline_and_tolls HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438679; expires=Mon, 14-May-2012 17:51:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fhome%2Fpage%2Forcon_homeline_and_tolls%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 21493


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.37. http://www.orcon.net.nz/home/plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/plans/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home/plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:55:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:55:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438920; expires=Mon, 14-May-2012 17:55:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fhome%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 38815

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.38. http://www.orcon.net.nz/img/bg_copy.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /img/bg_copy.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /img/bg_copy.gif HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/css/orcon_ice.css?20110318
Cookie: exp_last_visit=990076976; exp_last_activity=1305436976; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.1.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 404 Not Found
Date: Sun, 15 May 2011 17:23:12 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305436992; expires=Mon, 14-May-2012 17:23:12 GMT; path=/
Content-Length: 12778


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...

2.39. http://www.orcon.net.nz/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.php HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.40. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P10/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.php/about/browse/category/acquisitions/P10/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439036; expires=Mon, 14-May-2012 17:57:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A40%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP10%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18764

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.41. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P25/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P25/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.php/about/browse/category/acquisitions/P25/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439040; expires=Mon, 14-May-2012 17:57:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A40%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP25%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.42. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P5/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P5/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index.php/about/browse/category/acquisitions/P5/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439036; expires=Mon, 14-May-2012 17:57:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP5%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18727

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.43. http://www.orcon.net.nz/lifestyle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /lifestyle

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /lifestyle HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:56 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:56 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438656; expires=Mon, 14-May-2012 17:50:56 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A11%3A%22%2Flifestyle%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16002

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.44. http://www.orcon.net.nz/lifestyle/rss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /lifestyle/rss

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /lifestyle/rss HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:47 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Tue, 01 Mar 2011 00:31:40 GMT
Last-Modified: Mon, 28 Feb 2011 23:31:40 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/xml; charset=utf-8
Set-Cookie: exp_last_activity=1305438287; expires=Mon, 14-May-2012 17:44:47 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Flifestyle%2Frss%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34490

<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:admin="http://webns.net/
...[SNIP]...

2.45. http://www.orcon.net.nz/mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305437017; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.4.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437059; expires=Mon, 14-May-2012 17:24:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A2%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 17355

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.46. http://www.orcon.net.nz/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mobile/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:56:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:56:17 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438977; expires=Mon, 14-May-2012 17:56:17 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17317

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.47. http://www.orcon.net.nz/no-brainer/joinUs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /no-brainer/joinUs

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /no-brainer/joinUs HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 302 Found
Date: Sun, 15 May 2011 17:48:42 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Location: /home/
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438522; expires=Mon, 14-May-2012 17:48:42 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A19%3A%22%2Fno-brainer%2FjoinUs%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close


2.48. http://www.orcon.net.nz/site/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/login HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436991; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.2.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437000; expires=Mon, 14-May-2012 17:23:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 9633

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.49. http://www.orcon.net.nz/site/login/=&result=failure  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login/=&result=failure

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /site/login/=&result=failure HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436998; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.3.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437018; expires=Mon, 14-May-2012 17:23:38 GMT; path=/
Content-Length: 9706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.50. http://www.orcon.net.nz/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438658; expires=Mon, 14-May-2012 17:50:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A9%3A%22%2Fsupport%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 53631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.51. http://www.orcon.net.nz/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:57 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:57 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438417; expires=Mon, 14-May-2012 17:46:57 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A9%3A%22%2Fsupport%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 53631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.52. http://www.orcon.net.nz/support/browse/category/cloud_computing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/browse/category/cloud_computing

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/browse/category/cloud_computing HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:51 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:44:51 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438291; expires=Mon, 14-May-2012 17:44:51 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A41%3A%22%2Fsupport%2Fbrowse%2Fcategory%2Fcloud_computing%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 38799


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Co
...[SNIP]...

2.53. http://www.orcon.net.nz/support/glossary/category/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/glossary/category/a

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/glossary/category/a HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:42 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:42 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438402; expires=Mon, 14-May-2012 17:46:42 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fsupport%2Fglossary%2Fcategory%2Fa%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16161

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.54. http://www.orcon.net.nz/support/network_status  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/network_status

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/network_status HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:47:53 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:47:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438473; expires=Mon, 14-May-2012 17:47:53 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fsupport%2Fnetwork_status%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19852

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.55. http://www.orcon.net.nz/support/network_status_rss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/network_status_rss

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/network_status_rss HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Tue, 10 May 2011 04:18:47 GMT
Last-Modified: Tue, 10 May 2011 03:18:47 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/xml; charset=utf-8
Set-Cookie: exp_last_activity=1305438286; expires=Mon, 14-May-2012 17:44:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fsupport%2Fnetwork_status_rss%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 8160

<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:admin="http://webns.net/
...[SNIP]...

2.56. http://www.orcon.net.nz/support/page/how_to_call_international_destinations_from_your_mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/how_to_call_international_destinations_from_your_mobile

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/how_to_call_international_destinations_from_your_mobile HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:21 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:21 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438381; expires=Mon, 14-May-2012 17:46:21 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A70%3A%22%2Fsupport%2Fpage%2Fhow_to_call_international_destinations_from_your_mobile%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 39342

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.57. http://www.orcon.net.nz/support/page/roaming_charges_activation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/roaming_charges_activation

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/roaming_charges_activation HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:37 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:37 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438397; expires=Mon, 14-May-2012 17:46:37 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A41%3A%22%2Fsupport%2Fpage%2Froaming_charges_activation%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 81775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.58. http://www.orcon.net.nz/support/page/setting_up_your_mobile_voicemail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/setting_up_your_mobile_voicemail

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/setting_up_your_mobile_voicemail HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:45:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:45:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438354; expires=Mon, 14-May-2012 17:45:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A47%3A%22%2Fsupport%2Fpage%2Fsetting_up_your_mobile_voicemail%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33110

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.59. http://www.orcon.net.nz/support/page/what_are_your_dns_server_addresses  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/what_are_your_dns_server_addresses

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/what_are_your_dns_server_addresses HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:33 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:33 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438393; expires=Mon, 14-May-2012 17:46:33 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A49%3A%22%2Fsupport%2Fpage%2Fwhat_are_your_dns_server_addresses%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33200

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.60. http://www.orcon.net.nz/support/page/what_does_standby_mean  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/what_does_standby_mean

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/what_does_standby_mean HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:45:23 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:45:24 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438323; expires=Mon, 14-May-2012 17:45:23 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A37%3A%22%2Fsupport%2Fpage%2Fwhat_does_standby_mean%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 37053

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.61. http://www.orcon.net.nz/support/page/will_my_phone_number_change_with_orcon_homeline  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/will_my_phone_number_change_with_orcon_homeline

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/page/will_my_phone_number_change_with_orcon_homeline HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:36 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:36 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438396; expires=Mon, 14-May-2012 17:46:36 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A62%3A%22%2Fsupport%2Fpage%2Fwill_my_phone_number_change_with_orcon_homeline%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 36203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...

2.62. http://www.orcon.net.nz/support/talk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/talk

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /support/talk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:47:32 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:47:32 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438452; expires=Mon, 14-May-2012 17:47:32 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fsupport%2Ftalk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 12839


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conte
...[SNIP]...

2.63. http://www.orcon.net.nz/work/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fwork%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.64. http://www.orcon.net.nz/work/=&ref=iserve  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/=&ref=iserve

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/=&ref=iserve HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:22:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:22:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_visit=990076978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Set-Cookie: exp_last_activity=1305436978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Content-Length: 25007

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.65. http://www.orcon.net.nz/work/business_phone_sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_phone_sip_trunk

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/business_phone_sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438007; expires=Mon, 14-May-2012 17:40:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fbusiness_phone_sip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23240

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.66. http://www.orcon.net.nz/work/hosting_plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/hosting_plans/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/hosting_plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437994; expires=Mon, 14-May-2012 17:39:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fwork%2Fhosting_plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 43575

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.67. http://www.orcon.net.nz/work/page/business_broadband_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_broadband_overview

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_broadband_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fwork%2Fpage%2Fbusiness_broadband_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23332


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.68. http://www.orcon.net.nz/work/page/business_phone_line  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_phone_line

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_phone_line HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Fbusiness_phone_line%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22344


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.69. http://www.orcon.net.nz/work/page/business_server_dedicated  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_dedicated

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_server_dedicated HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A37%3A%22%2Fwork%2Fpage%2Fbusiness_server_dedicated%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24691


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.70. http://www.orcon.net.nz/work/page/business_server_hosting_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_hosting_overview

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_server_hosting_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:06 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:06 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437946; expires=Mon, 14-May-2012 17:39:06 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A44%3A%22%2Fwork%2Fpage%2Fbusiness_server_hosting_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22925


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.71. http://www.orcon.net.nz/work/page/business_server_software  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_software

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_server_software HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fbusiness_server_software%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25514


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.72. http://www.orcon.net.nz/work/page/business_server_virtual  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_virtual

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/business_server_virtual HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A35%3A%22%2Fwork%2Fpage%2Fbusiness_server_virtual%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24396


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.73. http://www.orcon.net.nz/work/page/case_study_certus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_certus

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/case_study_certus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:33 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437973; expires=Mon, 14-May-2012 17:39:33 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fcase_study_certus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25348


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.74. http://www.orcon.net.nz/work/page/case_study_speedscan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_speedscan

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/case_study_speedscan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fcase_study_speedscan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25529


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.75. http://www.orcon.net.nz/work/page/case_study_zeald  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_zeald

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/case_study_zeald HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fwork%2Fpage%2Fcase_study_zeald%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25380


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.76. http://www.orcon.net.nz/work/page/cloud_computing_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/cloud_computing_overview

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/cloud_computing_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:10 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:10 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437950; expires=Mon, 14-May-2012 17:39:10 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fcloud_computing_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22975


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.77. http://www.orcon.net.nz/work/page/co-location  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/co-location

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/co-location HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:29 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:29 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437969; expires=Mon, 14-May-2012 17:39:29 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Fco-location%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24773


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.78. http://www.orcon.net.nz/work/page/domain_names_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/domain_names_overview

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/domain_names_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437956; expires=Mon, 14-May-2012 17:39:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A33%3A%22%2Fwork%2Fpage%2Fdomain_names_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24137


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.79. http://www.orcon.net.nz/work/page/fibre_optic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/fibre_optic

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/fibre_optic HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:01 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Ffibre_optic%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24785


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.80. http://www.orcon.net.nz/work/page/free_domain_hosting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/free_domain_hosting

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/free_domain_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437960; expires=Mon, 14-May-2012 17:39:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Ffree_domain_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22441


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.81. http://www.orcon.net.nz/work/page/hosted_exchange  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hosted_exchange

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/hosted_exchange HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:27 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:27 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437967; expires=Mon, 14-May-2012 17:39:27 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fhosted_exchange%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26840


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.82. http://www.orcon.net.nz/work/page/hsns  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hsns

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/hsns HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:02 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:02 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437942; expires=Mon, 14-May-2012 17:39:02 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A16%3A%22%2Fwork%2Fpage%2Fhsns%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24630


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.83. http://www.orcon.net.nz/work/page/register_a_domain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/register_a_domain

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/register_a_domain HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:26 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:26 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437966; expires=Mon, 14-May-2012 17:39:26 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fregister_a_domain%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22206


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.84. http://www.orcon.net.nz/work/page/sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A21%3A%22%2Fwork%2Fpage%2Fsip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25404


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.85. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk_data_sheet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/sip_trunk_data_sheet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fsip_trunk_data_sheet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26751


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.86. http://www.orcon.net.nz/work/page/wan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/wan

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/wan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:04 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:05 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437944; expires=Mon, 14-May-2012 17:39:04 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fwork%2Fpage%2Fwan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24986


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.87. http://www.orcon.net.nz/work/page/zealous_support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/zealous_support

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/page/zealous_support HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fzealous_support%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 28147


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...

2.88. http://www.orcon.net.nz/work/plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/plans

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:35 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437975; expires=Mon, 14-May-2012 17:39:35 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fwork%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34246

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

2.89. http://www.orcon.net.nz/work/wholesale_services  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/wholesale_services

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /work/wholesale_services HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A25%3A%22%2Fwork%2Fwholesale_services%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...

3. Password field with autocomplete enabled  previous  next
There are 2 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).


3.1. http://www.orcon.net.nz/site/login  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /site/login HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436991; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.2.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437000; expires=Mon, 14-May-2012 17:23:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 9633

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<div class="styleBox-2">
<form id="account" method="post" action="https://orcres.cosmos.net.nz/orconmembersarea.php" name="accountlogin">
<fieldset>
...[SNIP]...
</label>
<input id="account_login_password" class="required" type="password" value="" name="password"/>
</div>
...[SNIP]...

3.2. http://www.orcon.net.nz/site/login/=&result=failure  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login/=&result=failure

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /site/login/=&result=failure HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436998; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.3.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437018; expires=Mon, 14-May-2012 17:23:38 GMT; path=/
Content-Length: 9706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<div class="styleBox-2">
<form id="account" method="post" action="https://orcres.cosmos.net.nz/orconmembersarea.php" name="accountlogin">
<fieldset>
...[SNIP]...
</label>
<input id="account_login_password" class="required" type="password" value="" name="password"/>
<p class="error">
...[SNIP]...

4. Source code disclosure  previous  next
There are 2 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


4.1. http://www.orcon.net.nz/work/business_phone_sip_trunk  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.orcon.net.nz
Path:   /work/business_phone_sip_trunk

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /work/business_phone_sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438007; expires=Mon, 14-May-2012 17:40:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fbusiness_phone_sip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23240

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<!-- SECTION end : menu -->


<?php
session_start();
   if(isset( $_SESSION['networkId'])){
   if( $_SESSION['networkId']!='1040' && $_SESSION['networkId']!='1046' && $_SESSION['networkId']!='1053' && $_SESSION['networkId']!='1054' ){
$_SESSION['networkId'] = '1094';
    }
    }else{
    $_SESSION['networkId'] = '1094';
    }

?>


           <!-- SECTION begin : banner -->
...[SNIP]...

4.2. http://www.orcon.net.nz/work/wholesale_services  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.orcon.net.nz
Path:   /work/wholesale_services

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /work/wholesale_services HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A25%3A%22%2Fwork%2Fwholesale_services%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<!-- SECTION end : menu -->


<?php
session_start();
   if(isset( $_SESSION['networkId'])){
   if( $_SESSION['networkId']!='1040' && $_SESSION['networkId']!='1046' && $_SESSION['networkId']!='1053' && $_SESSION['networkId']!='1054' ){
$_SESSION['networkId'] = '1094';
    }
    }else{
    $_SESSION['networkId'] = '1094';
    }

?>


           <!-- SECTION begin : banner -->
...[SNIP]...

5. Flash cross-domain policy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.orcon.net.nz

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
Last-Modified: Wed, 05 Aug 2009 03:37:16 GMT
ETag: "174003-104-4705cb82b7300"
Accept-Ranges: bytes
Content-Length: 260
Vary: Accept-Encoding
Content-Type: application/xml
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="test.orcon.net.nz" />
<allow-access-from domain="internal.orcon.net.nz" />
<allow-access-from domain="orcon.dev" /> <!-- Ga
...[SNIP]...

6. Cross-domain POST  previous  next
There are 87 instances of this issue:

Issue background

The POSTing of data between domains does not necessarily constitute a security vulnerability. You should review the contents of the information that is being transmitted between domains, and determine whether the originating application should be trusting the receiving domain with this information.


6.1. http://www.orcon.net.nz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:48:39 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:48:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438519; expires=Mon, 14-May-2012 17:48:39 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.2. http://www.orcon.net.nz/about  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305437066; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.6.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A2%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:46 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437086; expires=Mon, 14-May-2012 17:24:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A3%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A2%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 16243


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.3. http://www.orcon.net.nz/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438608; expires=Mon, 14-May-2012 17:50:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16235


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.4. http://www.orcon.net.nz/about/Terms_and_conditions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/Terms_and_conditions

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/Terms_and_conditions HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:51 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:51 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438591; expires=Mon, 14-May-2012 17:49:51 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fabout%2FTerms_and_conditions%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18173

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.5. http://www.orcon.net.nz/about/browse/category/acquisitions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/acquisitions/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/browse/category/acquisitions/ HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/about
Cookie: exp_last_visit=990076976; exp_last_activity=1305437085; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.7.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A3%3A%7Bi%3A0%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A1%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A2%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:57 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:57 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437097; expires=Mon, 14-May-2012 17:24:57 GMT; path=/
Set-Cookie: exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 17999

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.6. http://www.orcon.net.nz/about/browse/category/awards/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/awards/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/browse/category/awards/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:28 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:28 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438628; expires=Mon, 14-May-2012 17:50:28 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A30%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fawards%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17913

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.7. http://www.orcon.net.nz/about/browse/category/media_releases/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/media_releases/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/browse/category/media_releases/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438634; expires=Mon, 14-May-2012 17:50:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A38%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fmedia_releases%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19143

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.8. http://www.orcon.net.nz/about/browse/category/news/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/browse/category/news/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/browse/category/news/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438618; expires=Mon, 14-May-2012 17:50:18 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fabout%2Fbrowse%2Fcategory%2Fnews%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18707

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.9. http://www.orcon.net.nz/about/careers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/careers

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/careers HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438574; expires=Mon, 14-May-2012 17:49:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fcareers%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22973

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.10. http://www.orcon.net.nz/about/careers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/careers/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/careers/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:17 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438617; expires=Mon, 14-May-2012 17:50:17 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fcareers%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22964

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.11. http://www.orcon.net.nz/about/page/Privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/Privacy

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/page/Privacy HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:55 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438594; expires=Mon, 14-May-2012 17:49:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fabout%2Fpage%2FPrivacy%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16956


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.12. http://www.orcon.net.nz/about/page/about_orcon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/about_orcon

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/page/about_orcon HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:59 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fabout%2Fpage%2Fabout_orcon%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17610


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.13. http://www.orcon.net.nz/about/page/contact_us  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/page/contact_us

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/page/contact_us HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fabout%2Fpage%2Fcontact_us%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19693


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.14. http://www.orcon.net.nz/about/sitemap  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/sitemap

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/sitemap HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:49:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:49:59 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438598; expires=Mon, 14-May-2012 17:49:59 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fsitemap%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14349

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.15. http://www.orcon.net.nz/about/sitemap/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/sitemap/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/sitemap/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:44 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:44 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438644; expires=Mon, 14-May-2012 17:50:44 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fabout%2Fsitemap%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14349

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.16. http://www.orcon.net.nz/about/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /about/staff/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /about/staff/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:14 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438614; expires=Mon, 14-May-2012 17:50:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A13%3A%22%2Fabout%2Fstaff%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 14158

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.17. http://www.orcon.net.nz/address_locator/=&type=orconatwork  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /address_locator/=&type=orconatwork

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /address_locator/=&type=orconatwork HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:06 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:06 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438666; expires=Mon, 14-May-2012 17:51:06 GMT; path=/
Connection: close
Content-Length: 12641

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.18. http://www.orcon.net.nz/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /business

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /business HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A10%3A%22%2Fbusiness%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16314


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Free review of your
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.19. http://www.orcon.net.nz/campaigns/landing/1monthfree  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /campaigns/landing/1monthfree

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /campaigns/landing/1monthfree HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 404 Not Found
Date: Sun, 15 May 2011 17:57:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439040; expires=Mon, 14-May-2012 17:57:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A30%3A%22%2Fcampaigns%2Flanding%2F1monthfree%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 12961


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.20. http://www.orcon.net.nz/home/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:55:52 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:55:52 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438952; expires=Mon, 14-May-2012 17:55:52 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fhome%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18318

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.21. http://www.orcon.net.nz/home/dial-up/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/dial-up/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/dial-up/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:54:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:54:46 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438886; expires=Mon, 14-May-2012 17:54:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fhome%2Fdial-up%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18755

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.22. http://www.orcon.net.nz/home/page/about_orcon_plus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/about_orcon_plus

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/page/about_orcon_plus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:15 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438674; expires=Mon, 14-May-2012 17:51:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fhome%2Fpage%2Fabout_orcon_plus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33732


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.23. http://www.orcon.net.nz/home/page/broadband_modems  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/broadband_modems

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/page/broadband_modems HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:52:21 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:52:22 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438741; expires=Mon, 14-May-2012 17:52:21 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fhome%2Fpage%2Fbroadband_modems%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18218


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.24. http://www.orcon.net.nz/home/page/home_email  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/home_email

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/page/home_email HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:52:23 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:52:24 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438743; expires=Mon, 14-May-2012 17:52:23 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A22%3A%22%2Fhome%2Fpage%2Fhome_email%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17644


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.25. http://www.orcon.net.nz/home/page/o_zone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/o_zone

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/page/o_zone HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:18 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438679; expires=Mon, 14-May-2012 17:51:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A18%3A%22%2Fhome%2Fpage%2Fo_zone%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19577


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.26. http://www.orcon.net.nz/home/page/orcon_homeline_and_tolls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/orcon_homeline_and_tolls

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/page/orcon_homeline_and_tolls HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438679; expires=Mon, 14-May-2012 17:51:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fhome%2Fpage%2Forcon_homeline_and_tolls%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 21493


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.27. http://www.orcon.net.nz/home/plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/plans/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:55:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:55:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438920; expires=Mon, 14-May-2012 17:55:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fhome%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 38815

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.28. http://www.orcon.net.nz/home/rural/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/rural/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /home/rural/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:54:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:54:38 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438878; expires=Mon, 14-May-2012 17:54:38 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fhome%2Frural%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=e6bc587b8bce09263088863d8fd1ecea; path=/
Connection: close
Content-Length: 22978

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.29. http://www.orcon.net.nz/img/bg_copy.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /img/bg_copy.gif

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /img/bg_copy.gif HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/css/orcon_ice.css?20110318
Cookie: exp_last_visit=990076976; exp_last_activity=1305436976; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.1.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 404 Not Found
Date: Sun, 15 May 2011 17:23:12 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305436992; expires=Mon, 14-May-2012 17:23:12 GMT; path=/
Content-Length: 12778


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.30. http://www.orcon.net.nz/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /index.php HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.31. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P10/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /index.php/about/browse/category/acquisitions/P10/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439036; expires=Mon, 14-May-2012 17:57:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A40%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP10%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18764

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.32. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P25/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P25/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /index.php/about/browse/category/acquisitions/P25/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439040; expires=Mon, 14-May-2012 17:57:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A40%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP25%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.33. http://www.orcon.net.nz/index.php/about/browse/category/acquisitions/P5/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php/about/browse/category/acquisitions/P5/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /index.php/about/browse/category/acquisitions/P5/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:57:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439036; expires=Mon, 14-May-2012 17:57:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2FP5%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18727

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.34. http://www.orcon.net.nz/lifestyle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /lifestyle

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /lifestyle HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:56 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:56 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438656; expires=Mon, 14-May-2012 17:50:56 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A11%3A%22%2Flifestyle%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16002

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.35. http://www.orcon.net.nz/mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305437017; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.4.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:24:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:24:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437059; expires=Mon, 14-May-2012 17:24:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A2%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 17355

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.36. http://www.orcon.net.nz/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:56:17 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:56:17 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438977; expires=Mon, 14-May-2012 17:56:17 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 17317

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.37. http://www.orcon.net.nz/mobile/broadband-plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/broadband-plans

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/broadband-plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:15 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439035; expires=Mon, 14-May-2012 17:57:15 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fmobile%2Fbroadband-plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=09e4ece0388eddfc86bc7ea539fe2544; path=/
Connection: close
Content-Length: 27866

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.38. http://www.orcon.net.nz/mobile/broadband-plans/upgrade  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/broadband-plans/upgrade

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/broadband-plans/upgrade HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:15 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439035; expires=Mon, 14-May-2012 17:57:15 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fmobile%2Fbroadband-plans%2Fupgrade%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=04ea22d024062d336988fbe32aea003a; path=/
Connection: close
Content-Length: 27874

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.39. http://www.orcon.net.nz/mobile/handsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/handsets

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/handsets HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:56:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:56:20 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438979; expires=Mon, 14-May-2012 17:56:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A17%3A%22%2Fmobile%2Fhandsets%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=b3a1d71f26b693a0a754f42e1fc446e1; path=/
Connection: close
Content-Length: 22213

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.40. http://www.orcon.net.nz/mobile/plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/plans

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:15 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439034; expires=Mon, 14-May-2012 17:57:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fmobile%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=d560c6b9cc26aa1f2ce251c02c4eb80d; path=/
Connection: close
Content-Length: 35545

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.41. http://www.orcon.net.nz/mobile/plans/upgrade  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /mobile/plans/upgrade

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /mobile/plans/upgrade HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:57:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:57:14 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305439034; expires=Mon, 14-May-2012 17:57:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A22%3A%22%2Fmobile%2Fplans%2Fupgrade%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=5c456fb2a3b1024dc72d8e3c58c2c34e; path=/
Connection: close
Content-Length: 34141

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.42. http://www.orcon.net.nz/site/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /site/login HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436991; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.2.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437000; expires=Mon, 14-May-2012 17:23:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 9633

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<div class="styleBox-2">
<form id="account" method="post" action="https://orcres.cosmos.net.nz/orconmembersarea.php" name="accountlogin">
<fieldset>
...[SNIP]...

6.43. http://www.orcon.net.nz/site/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /site/login HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436991; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.2.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437000; expires=Mon, 14-May-2012 17:23:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Content-Length: 9633

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.44. http://www.orcon.net.nz/site/login/=&result=failure  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login/=&result=failure

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /site/login/=&result=failure HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436998; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.3.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437018; expires=Mon, 14-May-2012 17:23:38 GMT; path=/
Content-Length: 9706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.45. http://www.orcon.net.nz/site/login/=&result=failure  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /site/login/=&result=failure

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /site/login/=&result=failure HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436998; __utma=9264363.834091965.1305480184.1305480184.1305480184.1; __utmb=9264363.3.10.1305480184; __utmc=9264363; __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); exp_tracker=a%3A1%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:38 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:23:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437018; expires=Mon, 14-May-2012 17:23:38 GMT; path=/
Content-Length: 9706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<div class="styleBox-2">
<form id="account" method="post" action="https://orcres.cosmos.net.nz/orconmembersarea.php" name="accountlogin">
<fieldset>
...[SNIP]...

6.46. http://www.orcon.net.nz/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438658; expires=Mon, 14-May-2012 17:50:58 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A9%3A%22%2Fsupport%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 53631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.47. http://www.orcon.net.nz/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:57 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:57 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438417; expires=Mon, 14-May-2012 17:46:57 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A9%3A%22%2Fsupport%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 53631

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.48. http://www.orcon.net.nz/support/browse/category/cloud_computing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/browse/category/cloud_computing

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/browse/category/cloud_computing HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:51 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:44:51 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438291; expires=Mon, 14-May-2012 17:44:51 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A41%3A%22%2Fsupport%2Fbrowse%2Fcategory%2Fcloud_computing%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 38799


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Co
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.49. http://www.orcon.net.nz/support/glossary/category/a  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/glossary/category/a

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/glossary/category/a HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:42 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:42 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438402; expires=Mon, 14-May-2012 17:46:42 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fsupport%2Fglossary%2Fcategory%2Fa%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16161

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.50. http://www.orcon.net.nz/support/network_status  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/network_status

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/network_status HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:47:53 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:47:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438473; expires=Mon, 14-May-2012 17:47:53 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fsupport%2Fnetwork_status%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 19852

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.51. http://www.orcon.net.nz/support/page/how_to_call_international_destinations_from_your_mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/how_to_call_international_destinations_from_your_mobile

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/how_to_call_international_destinations_from_your_mobile HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:21 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:21 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438381; expires=Mon, 14-May-2012 17:46:21 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A70%3A%22%2Fsupport%2Fpage%2Fhow_to_call_international_destinations_from_your_mobile%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 39342

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.52. http://www.orcon.net.nz/support/page/roaming_charges_activation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/roaming_charges_activation

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/roaming_charges_activation HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:37 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:37 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438397; expires=Mon, 14-May-2012 17:46:37 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A41%3A%22%2Fsupport%2Fpage%2Froaming_charges_activation%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 81775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.53. http://www.orcon.net.nz/support/page/setting_up_your_mobile_voicemail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/setting_up_your_mobile_voicemail

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/setting_up_your_mobile_voicemail HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:45:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:45:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438354; expires=Mon, 14-May-2012 17:45:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A47%3A%22%2Fsupport%2Fpage%2Fsetting_up_your_mobile_voicemail%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33110

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.54. http://www.orcon.net.nz/support/page/what_are_your_dns_server_addresses  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/what_are_your_dns_server_addresses

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/what_are_your_dns_server_addresses HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:33 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:33 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438393; expires=Mon, 14-May-2012 17:46:33 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A49%3A%22%2Fsupport%2Fpage%2Fwhat_are_your_dns_server_addresses%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33200

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.55. http://www.orcon.net.nz/support/page/what_does_standby_mean  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/what_does_standby_mean

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/what_does_standby_mean HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:45:23 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:45:24 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438323; expires=Mon, 14-May-2012 17:45:23 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A37%3A%22%2Fsupport%2Fpage%2Fwhat_does_standby_mean%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 37053

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.56. http://www.orcon.net.nz/support/page/will_my_phone_number_change_with_orcon_homeline  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/page/will_my_phone_number_change_with_orcon_homeline

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/page/will_my_phone_number_change_with_orcon_homeline HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:46:36 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:46:36 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438396; expires=Mon, 14-May-2012 17:46:36 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A62%3A%22%2Fsupport%2Fpage%2Fwill_my_phone_number_change_with_orcon_homeline%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 36203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.57. http://www.orcon.net.nz/support/talk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/talk

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /support/talk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:47:32 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:47:32 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438452; expires=Mon, 14-May-2012 17:47:32 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fsupport%2Ftalk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 12839


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conte
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.58. http://www.orcon.net.nz/work/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fwork%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.59. http://www.orcon.net.nz/work/=&ref=iserve  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/=&ref=iserve

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/=&ref=iserve HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:22:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:22:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_visit=990076978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Set-Cookie: exp_last_activity=1305436978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Content-Length: 25007

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.60. http://www.orcon.net.nz/work/business_hosting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_hosting

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/business_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:49 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:49 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437989; expires=Mon, 14-May-2012 17:39:49 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fbusiness_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=3124d3340bbb6b50e6a4c5f0d48241b9; path=/
Connection: close
Content-Length: 24860

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.61. http://www.orcon.net.nz/work/business_internet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_internet

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/business_internet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fwork%2Fbusiness_internet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=1a88672d816fc2815ca829c6bbc91339; path=/
Connection: close
Content-Length: 24366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.62. http://www.orcon.net.nz/work/business_phone_sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_phone_sip_trunk

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/business_phone_sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438007; expires=Mon, 14-May-2012 17:40:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fbusiness_phone_sip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23240

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.63. http://www.orcon.net.nz/work/hosting_plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/hosting_plans/

Issue detail

The page contains a form which POSTs data to the domain www.salesforce.com. The form contains the following fields:

Request

GET /work/hosting_plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437994; expires=Mon, 14-May-2012 17:39:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fwork%2Fhosting_plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 43575

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<div class="styleBox-21">
<form method="post" id="sendEnquiry" action="https://www.salesforce.com/servlet/servlet.WebToLead?encoding=UTF-8" name="sendEnquiry">
<input type=hidden name="oid" value="00D200000000jvY">
...[SNIP]...

6.64. http://www.orcon.net.nz/work/hosting_plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/hosting_plans/

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/hosting_plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437994; expires=Mon, 14-May-2012 17:39:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fwork%2Fhosting_plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 43575

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.65. http://www.orcon.net.nz/work/page/business_broadband_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_broadband_overview

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_broadband_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fwork%2Fpage%2Fbusiness_broadband_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23332


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.66. http://www.orcon.net.nz/work/page/business_phone_line  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_phone_line

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_phone_line HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Fbusiness_phone_line%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22344


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.67. http://www.orcon.net.nz/work/page/business_server_dedicated  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_dedicated

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_server_dedicated HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A37%3A%22%2Fwork%2Fpage%2Fbusiness_server_dedicated%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24691


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.68. http://www.orcon.net.nz/work/page/business_server_hosting_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_hosting_overview

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_server_hosting_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:06 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:06 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437946; expires=Mon, 14-May-2012 17:39:06 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A44%3A%22%2Fwork%2Fpage%2Fbusiness_server_hosting_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22925


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.69. http://www.orcon.net.nz/work/page/business_server_software  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_software

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_server_software HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fbusiness_server_software%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25514


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.70. http://www.orcon.net.nz/work/page/business_server_virtual  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_virtual

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/business_server_virtual HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A35%3A%22%2Fwork%2Fpage%2Fbusiness_server_virtual%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24396


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.71. http://www.orcon.net.nz/work/page/case_study_certus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_certus

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/case_study_certus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:33 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437973; expires=Mon, 14-May-2012 17:39:33 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fcase_study_certus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25348


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.72. http://www.orcon.net.nz/work/page/case_study_speedscan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_speedscan

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/case_study_speedscan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fcase_study_speedscan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25529


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.73. http://www.orcon.net.nz/work/page/case_study_zeald  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_zeald

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/case_study_zeald HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fwork%2Fpage%2Fcase_study_zeald%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25380


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.74. http://www.orcon.net.nz/work/page/cloud_computing_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/cloud_computing_overview

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/cloud_computing_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:10 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:10 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437950; expires=Mon, 14-May-2012 17:39:10 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fcloud_computing_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22975


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.75. http://www.orcon.net.nz/work/page/co-location  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/co-location

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/co-location HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:29 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:29 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437969; expires=Mon, 14-May-2012 17:39:29 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Fco-location%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24773


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.76. http://www.orcon.net.nz/work/page/domain_names_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/domain_names_overview

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/domain_names_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437956; expires=Mon, 14-May-2012 17:39:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A33%3A%22%2Fwork%2Fpage%2Fdomain_names_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24137


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.77. http://www.orcon.net.nz/work/page/fibre_optic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/fibre_optic

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/fibre_optic HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:01 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Ffibre_optic%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24785


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.78. http://www.orcon.net.nz/work/page/free_domain_hosting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/free_domain_hosting

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/free_domain_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437960; expires=Mon, 14-May-2012 17:39:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Ffree_domain_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22441


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.79. http://www.orcon.net.nz/work/page/hosted_exchange  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hosted_exchange

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/hosted_exchange HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:27 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:27 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437967; expires=Mon, 14-May-2012 17:39:27 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fhosted_exchange%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26840


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.80. http://www.orcon.net.nz/work/page/hsns  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hsns

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/hsns HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:02 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:02 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437942; expires=Mon, 14-May-2012 17:39:02 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A16%3A%22%2Fwork%2Fpage%2Fhsns%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24630


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.81. http://www.orcon.net.nz/work/page/register_a_domain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/register_a_domain

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/register_a_domain HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:26 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:26 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437966; expires=Mon, 14-May-2012 17:39:26 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fregister_a_domain%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22206


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.82. http://www.orcon.net.nz/work/page/sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A21%3A%22%2Fwork%2Fpage%2Fsip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25404


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.83. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk_data_sheet

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/sip_trunk_data_sheet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fsip_trunk_data_sheet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26751


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.84. http://www.orcon.net.nz/work/page/wan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/wan

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/wan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:04 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:05 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437944; expires=Mon, 14-May-2012 17:39:04 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fwork%2Fpage%2Fwan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24986


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.85. http://www.orcon.net.nz/work/page/zealous_support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/zealous_support

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/page/zealous_support HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fzealous_support%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 28147


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.86. http://www.orcon.net.nz/work/plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/plans

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:35 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437975; expires=Mon, 14-May-2012 17:39:35 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fwork%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34246

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

6.87. http://www.orcon.net.nz/work/wholesale_services  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/wholesale_services

Issue detail

The page contains a form which POSTs data to the domain orcres.cosmos.net.nz. The form contains the following fields:

Request

GET /work/wholesale_services HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A25%3A%22%2Fwork%2Fwholesale_services%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</p>
                                   <form id="account" name="accountlogin" action="https://orcres.cosmos.net.nz/orconmembersarea.php" method="post" autocomplete="off">
                                       <fieldset>
...[SNIP]...

7. Cross-domain script include  previous  next
There are 12 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


7.1. http://www.orcon.net.nz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:48:39 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:48:39 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438519; expires=Mon, 14-May-2012 17:48:39 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<![endif]-->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.2/swfobject.js"></script>
...[SNIP]...

7.2. http://www.orcon.net.nz/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /business

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /business HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A10%3A%22%2Fbusiness%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16314


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Free review of your
...[SNIP]...
<div id="bannerThickbox">
           <script src="http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=rsb&c=28&pli=1686177&PluID=0&w=920&h=160&ord=[timestamp]&ucm=true&z=0"></script>
...[SNIP]...

7.3. http://www.orcon.net.nz/home/page/about_orcon_plus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /home/page/about_orcon_plus

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /home/page/about_orcon_plus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:14 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:15 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438674; expires=Mon, 14-May-2012 17:51:14 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fhome%2Fpage%2Fabout_orcon_plus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 33732


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Cont
...[SNIP]...
</p>
<script src="http://maps.google.com/maps?file=api&amp;v=2&amp;key=ABQIAAAAlt_mvyma7GWDlHCDIsia0xSKULicE8eFSQo17az4YQ2sVLt_eRRjIpkxR99uWqU5MNsHvwlUiXLR3A"
type="text/javascript">
</script>
...[SNIP]...

7.4. http://www.orcon.net.nz/index.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /index.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /index.php HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:51:08 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:51:08 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438668; expires=Mon, 14-May-2012 17:51:08 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A5%3A%22index%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 18082

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<![endif]-->

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/swfobject/2.2/swfobject.js"></script>
...[SNIP]...

7.5. http://www.orcon.net.nz/work/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fwork%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<div id="bizCampaignBannerId">
                   <script src="http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=rsb&c=28&pli=1686177&PluID=0&w=920&h=160&ord=[timestamp]&ucm=true&z=0"></script>
...[SNIP]...

7.6. http://www.orcon.net.nz/work/=&ref=iserve  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/=&ref=iserve

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/=&ref=iserve HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:22:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:22:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_visit=990076978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Set-Cookie: exp_last_activity=1305436978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Content-Length: 25007

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<div id="bizCampaignBannerId">
                   <script src="http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=rsb&c=28&pli=1686177&PluID=0&w=920&h=160&ord=[timestamp]&ucm=true&z=0"></script>
...[SNIP]...

7.7. http://www.orcon.net.nz/work/business_internet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_internet

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/business_internet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fwork%2Fbusiness_internet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=1a88672d816fc2815ca829c6bbc91339; path=/
Connection: close
Content-Length: 24366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

7.8. http://www.orcon.net.nz/work/page/business_broadband_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_broadband_overview

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/page/business_broadband_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fwork%2Fpage%2Fbusiness_broadband_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23332


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

7.9. http://www.orcon.net.nz/work/page/fibre_optic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/fibre_optic

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/page/fibre_optic HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:01 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Ffibre_optic%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24785


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

7.10. http://www.orcon.net.nz/work/page/hsns  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hsns

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/page/hsns HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:02 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:02 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437942; expires=Mon, 14-May-2012 17:39:02 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A16%3A%22%2Fwork%2Fpage%2Fhsns%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24630


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

7.11. http://www.orcon.net.nz/work/page/wan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/wan

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/page/wan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:04 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:05 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437944; expires=Mon, 14-May-2012 17:39:04 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fwork%2Fpage%2Fwan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24986


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

7.12. http://www.orcon.net.nz/work/plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/plans

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /work/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:35 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437975; expires=Mon, 14-May-2012 17:39:35 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fwork%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34246

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js"></script>
...[SNIP]...

8. TRACE method is enabled  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /

Issue description

The TRACE method is designed for diagnostic purposes. If enabled, the web server will respond to requests which use the TRACE method by echoing in its response the exact request which was received.

Although this behaviour is apparently harmless in itself, it can sometimes be leveraged to support attacks against other application users. If an attacker can find a way of causing a user to make a TRACE request, and can retrieve the response to that request, then the attacker will be able to capture any sensitive data which is included in the request by the user's browser, for example session cookies or credentials for platform-level authentication. This may exacerbate the impact of other vulnerabilities, such as cross-site scripting.

Issue remediation

The TRACE method should be disabled on the web server.

Request

TRACE / HTTP/1.0
Host: www.orcon.net.nz
Cookie: d715480c9fd4708e

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: 60.234.4.67
Cookie: d715480c9fd4708e
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.orcon.net.nz
X-Forwarded-Server: rp1-www
Connection: Keep-Alive


9. Email addresses disclosed  previous  next
There are 34 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


9.1. http://www.orcon.net.nz/lifestyle  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /lifestyle

Issue detail

The following email address was disclosed in the response:

Request

GET /lifestyle HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:50:56 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:50:56 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438656; expires=Mon, 14-May-2012 17:50:56 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A11%3A%22%2Flifestyle%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 16002

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conten
...[SNIP]...
<a href="mailto:feedback@orcon.net.nz">feedback@orcon.net.nz</a>
...[SNIP]...

9.2. http://www.orcon.net.nz/lifestyle/rss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /lifestyle/rss

Issue detail

The following email addresses were disclosed in the response:

Request

GET /lifestyle/rss HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:47 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Tue, 01 Mar 2011 00:31:40 GMT
Last-Modified: Mon, 28 Feb 2011 23:31:40 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/xml; charset=utf-8
Set-Cookie: exp_last_activity=1305438287; expires=Mon, 14-May-2012 17:44:47 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Flifestyle%2Frss%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34490

<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:admin="http://webns.net/
...[SNIP]...
<a href="mailto:quentin.reade@team.orcon.net.nz?subject=OGB%20Wellington">
...[SNIP]...
<author>quentin.reade@team.orcon.net.nz (author)</author>
...[SNIP]...
<a href="mailto:quentin.reade@team.orcon.net.nz?subject=iPhone%20app%20-%20query%20via%20website">
...[SNIP]...
<author>quentin.reade@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>thomas.salmen@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>quentin.reade@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>shehryar.khalid@team.orcon.net.nz (author)</author>
...[SNIP]...
<a href="mailto:quentin.reade@team.orcon.net.nz">quentin.reade@team.orcon.net.nz</a>
...[SNIP]...
<author>quentin.reade@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>duncan.blair@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>shehryar.khalid@team.orcon.net.nz (author)</author>
...[SNIP]...
<author>duncan.blair@team.orcon.net.nz (author)</author>
...[SNIP]...
</span>. Let us know you would like to come along by dropping us an email: greatblend@orcon.net.nz with your Orcon username as our lovely new venue has a strictly limited capacity. We will drop you an email back to let you know that we have saved you a place.</p>
...[SNIP]...
<br />
RSVP: greatblend@orcon.net.nz with your username</div>
...[SNIP]...
<author>duncan.blair@team.orcon.net.nz (author)</author>
...[SNIP]...

9.3. http://www.orcon.net.nz/scripts/jquery.pngFix.pack.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /scripts/jquery.pngFix.pack.js

Issue detail

The following email address was disclosed in the response:

Request

GET /scripts/jquery.pngFix.pack.js HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.orcon.net.nz/work/=&ref=iserve
Cookie: exp_last_visit=990076976; exp_last_activity=1305436976

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:01 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
Last-Modified: Sun, 30 May 2010 02:42:05 GMT
ETag: "9c4002-9bf-487c6af875940"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: application/x-javascript
Content-Length: 2495

/**
* --------------------------------------------------------------------
* jQuery-Plugin "pngFix"
* Version: 1.1, 11.09.2007
* by Andreas Eberhard, andreas.eberhard@gmail.com
* http://jquery.andreaseberhard.de/
*
* Copyright (c) 2007 Andreas Eberhard
* Licensed under GPL (http://www.opensource.org/licenses/gpl-license.php)
*/
eval(function(p
...[SNIP]...

9.4. http://www.orcon.net.nz/support/network_status_rss  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/network_status_rss

Issue detail

The following email address was disclosed in the response:

Request

GET /support/network_status_rss HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:44:46 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Tue, 10 May 2011 04:18:47 GMT
Last-Modified: Tue, 10 May 2011 03:18:47 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/xml; charset=utf-8
Set-Cookie: exp_last_activity=1305438286; expires=Mon, 14-May-2012 17:44:46 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fsupport%2Fnetwork_status_rss%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 8160

<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:admin="http://webns.net/
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...
<author>support@orcon.net.nz (Orcon Internet Ltd.)</author>
...[SNIP]...

9.5. http://www.orcon.net.nz/support/talk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /support/talk

Issue detail

The following email address was disclosed in the response:

Request

GET /support/talk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:47:32 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:47:32 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438452; expires=Mon, 14-May-2012 17:47:32 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A14%3A%22%2Fsupport%2Ftalk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 12839


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Conte
...[SNIP]...
<a href="mailto:support@orcon.net.nz">support@orcon.net.nz</a>
...[SNIP]...

9.6. http://www.orcon.net.nz/work/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A6%3A%22%2Fwork%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.7. http://www.orcon.net.nz/work/=&ref=iserve  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/=&ref=iserve

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/=&ref=iserve HTTP/1.1
Host: www.orcon.net.nz
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:22:58 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:22:58 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_visit=990076978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Set-Cookie: exp_last_activity=1305436978; expires=Mon, 14-May-2012 17:22:58 GMT; path=/
Content-Length: 25007

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.8. http://www.orcon.net.nz/work/business_hosting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_hosting

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/business_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:49 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:49 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437989; expires=Mon, 14-May-2012 17:39:49 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fbusiness_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=3124d3340bbb6b50e6a4c5f0d48241b9; path=/
Connection: close
Content-Length: 24860

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.9. http://www.orcon.net.nz/work/business_internet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_internet

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/business_internet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A24%3A%22%2Fwork%2Fbusiness_internet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Set-Cookie: PHPSESSID=1a88672d816fc2815ca829c6bbc91339; path=/
Connection: close
Content-Length: 24366

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.10. http://www.orcon.net.nz/work/business_phone_sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/business_phone_sip_trunk

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/business_phone_sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438007; expires=Mon, 14-May-2012 17:40:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fbusiness_phone_sip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23240

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.11. http://www.orcon.net.nz/work/hosting_plans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/hosting_plans/

Issue detail

The following email address was disclosed in the response:

Request

GET /work/hosting_plans/ HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:54 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:54 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437994; expires=Mon, 14-May-2012 17:39:54 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A20%3A%22%2Fwork%2Fhosting_plans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 43575

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Reseller%20query%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz?subject=Enquiry%20about%20Web%20Hosting%20">
...[SNIP]...

9.12. http://www.orcon.net.nz/work/page/business_broadband_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_broadband_overview

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_broadband_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:00 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A39%3A%22%2Fwork%2Fpage%2Fbusiness_broadband_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23332


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.13. http://www.orcon.net.nz/work/page/business_phone_line  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_phone_line

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_phone_line HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Fbusiness_phone_line%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22344


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.14. http://www.orcon.net.nz/work/page/business_server_dedicated  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_dedicated

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_server_dedicated HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A37%3A%22%2Fwork%2Fpage%2Fbusiness_server_dedicated%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24691


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20Dedicated%20Business%20Server">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.15. http://www.orcon.net.nz/work/page/business_server_hosting_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_hosting_overview

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_server_hosting_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:06 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:06 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437946; expires=Mon, 14-May-2012 17:39:06 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A44%3A%22%2Fwork%2Fpage%2Fbusiness_server_hosting_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22925


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.16. http://www.orcon.net.nz/work/page/business_server_software  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_software

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_server_software HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fbusiness_server_software%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25514


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20Business%20Server%20Software">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.17. http://www.orcon.net.nz/work/page/business_server_virtual  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/business_server_virtual

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/business_server_virtual HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:07 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437947; expires=Mon, 14-May-2012 17:39:07 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A35%3A%22%2Fwork%2Fpage%2Fbusiness_server_virtual%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24396


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.18. http://www.orcon.net.nz/work/page/case_study_certus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_certus

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/case_study_certus HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:33 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437973; expires=Mon, 14-May-2012 17:39:33 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fcase_study_certus%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25348


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.19. http://www.orcon.net.nz/work/page/case_study_speedscan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_speedscan

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/case_study_speedscan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fcase_study_speedscan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25529


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.20. http://www.orcon.net.nz/work/page/case_study_zeald  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/case_study_zeald

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/case_study_zeald HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:34 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:34 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437974; expires=Mon, 14-May-2012 17:39:34 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A28%3A%22%2Fwork%2Fpage%2Fcase_study_zeald%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25380


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.21. http://www.orcon.net.nz/work/page/cloud_computing_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/cloud_computing_overview

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/cloud_computing_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:10 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:10 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437950; expires=Mon, 14-May-2012 17:39:10 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fwork%2Fpage%2Fcloud_computing_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22975


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.22. http://www.orcon.net.nz/work/page/co-location  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/co-location

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/co-location HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:29 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:29 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437969; expires=Mon, 14-May-2012 17:39:29 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Fco-location%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24773


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20co-location">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.23. http://www.orcon.net.nz/work/page/domain_names_overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/domain_names_overview

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/domain_names_overview HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:16 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:16 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437956; expires=Mon, 14-May-2012 17:39:16 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A33%3A%22%2Fwork%2Fpage%2Fdomain_names_overview%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24137


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.24. http://www.orcon.net.nz/work/page/fibre_optic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/fibre_optic

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/fibre_optic HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:00 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:01 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437940; expires=Mon, 14-May-2012 17:39:00 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A23%3A%22%2Fwork%2Fpage%2Ffibre_optic%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24785


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20fibre">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.25. http://www.orcon.net.nz/work/page/free_domain_hosting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/free_domain_hosting

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/free_domain_hosting HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:20 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437960; expires=Mon, 14-May-2012 17:39:20 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A31%3A%22%2Fwork%2Fpage%2Ffree_domain_hosting%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22441


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.26. http://www.orcon.net.nz/work/page/hosted_exchange  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hosted_exchange

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/hosted_exchange HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:27 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:27 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437967; expires=Mon, 14-May-2012 17:39:27 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fhosted_exchange%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26840


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20Hosted%20Exchange">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.27. http://www.orcon.net.nz/work/page/hsns  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/hsns

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/hsns HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:02 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:02 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437942; expires=Mon, 14-May-2012 17:39:02 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A16%3A%22%2Fwork%2Fpage%2Fhsns%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24630


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20UNS">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.28. http://www.orcon.net.nz/work/page/register_a_domain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/register_a_domain

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/register_a_domain HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:26 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:26 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437966; expires=Mon, 14-May-2012 17:39:26 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A29%3A%22%2Fwork%2Fpage%2Fregister_a_domain%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 22206


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.29. http://www.orcon.net.nz/work/page/sip_trunk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/sip_trunk HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A21%3A%22%2Fwork%2Fpage%2Fsip_trunk%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 25404


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.30. http://www.orcon.net.nz/work/page/sip_trunk_data_sheet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/sip_trunk_data_sheet

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/sip_trunk_data_sheet HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:31 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:31 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437971; expires=Mon, 14-May-2012 17:39:31 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A32%3A%22%2Fwork%2Fpage%2Fsip_trunk_data_sheet%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 26751


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.31. http://www.orcon.net.nz/work/page/wan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/wan

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/wan HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:04 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:05 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437944; expires=Mon, 14-May-2012 17:39:04 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A15%3A%22%2Fwork%2Fpage%2Fwan%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 24986


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.32. http://www.orcon.net.nz/work/page/zealous_support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/page/zealous_support

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/page/zealous_support HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:09 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:09 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437949; expires=Mon, 14-May-2012 17:39:09 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A27%3A%22%2Fwork%2Fpage%2Fzealous_support%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 28147


       <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Ty
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20Zealous!%20Support">
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.33. http://www.orcon.net.nz/work/plans  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/plans

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/plans HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:39:35 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:39:35 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305437975; expires=Mon, 14-May-2012 17:39:35 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A12%3A%22%2Fwork%2Fplans%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 34246

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

9.34. http://www.orcon.net.nz/work/wholesale_services  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/wholesale_services

Issue detail

The following email addresses were disclosed in the response:

Request

GET /work/wholesale_services HTTP/1.1
Host: www.orcon.net.nz
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: __utmz=9264363.1305480184.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=9264363.834091965.1305480184.1305480184.1305480184.1; exp_last_visit=990076976; __utmc=9264363; exp_last_activity=1305437095; __utmb=9264363.7.10.1305480184; exp_tracker=a%3A4%3A%7Bi%3A0%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A1%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A2%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A3%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D;

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:40:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
X-Powered-By: PHP/5.2.0-8+etch11
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Last-Modified: Sun, 15 May 2011 17:40:19 GMT
Pragma: no-cache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: exp_last_activity=1305438019; expires=Mon, 14-May-2012 17:40:19 GMT; path=/
Set-Cookie: exp_tracker=a%3A5%3A%7Bi%3A0%3Bs%3A25%3A%22%2Fwork%2Fwholesale_services%2F%22%3Bi%3A1%3Bs%3A36%3A%22%2Fabout%2Fbrowse%2Fcategory%2Facquisitions%2F%22%3Bi%3A2%3Bs%3A7%3A%22%2Fabout%2F%22%3Bi%3A3%3Bs%3A8%3A%22%2Fmobile%2F%22%3Bi%3A4%3Bs%3A12%3A%22%2Fsite%2Flogin%2F%22%3B%7D; path=/
Connection: close
Content-Length: 23203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" con
...[SNIP]...
<a href="mailto:sales@orcon.net.nz?subject=Enquiry%20about%20wholesale%20services">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:sales@orcon.net.nz">sales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsales@orcon.net.nz">hostingsales@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:hostingsupport@orcon.net.nz">hostingsupport@orcon.net.nz</a>
...[SNIP]...
<a href="mailto:technical@orcon.net.nz">technical@orcon.net.nz</a>
...[SNIP]...

10. Robots.txt file  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orcon.net.nz
Path:   /work/=&ref=iserve

Issue detail

The web server contains a robots.txt file.

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.

Issue remediation

The robots.txt file is not itself a security threat, and its correct use can represent good practice for non-security reasons. You should not assume that all web robots will honour the file's instructions. Rather, assume that attackers will pay close attention to any locations identified in the file. Do not rely on robots.txt to provide any kind of protection over unauthorised access.

Request

GET /robots.txt HTTP/1.0
Host: www.orcon.net.nz

Response

HTTP/1.1 200 OK
Date: Sun, 15 May 2011 17:23:01 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch11
Last-Modified: Wed, 04 Mar 2009 03:06:47 GMT
ETag: "48c9ae-39-4644257975fc0"
Accept-Ranges: bytes
Content-Length: 57
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Connection: close

User-agent: *
Disallow: /external/
Disallow: /campaigns/

Report generated by XSS.CX at Sun May 15 14:45:11 CDT 2011.