XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, microsoft.com/industry/government/

Report generated by XSS.CX at Fri Aug 26 14:48:18 GMT-06:00 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |
Loading

1. Cross-site scripting (reflected)

2. Source code disclosure

2.1. http://www.microsoft.com/en-us/cloud/cloudpowersolutions/private_cloud.aspx

2.2. http://www.microsoft.com/en-us/cloud/default.aspx

2.3. http://www.microsoft.com/pl-pl/cloud/default.aspx

2.4. http://www.microsoft.com/sqlserver/en/us/default.aspx

3. Cookie scoped to parent domain

4. Cross-domain Referer leakage

4.1. http://www.microsoft.com/en-us/default.aspx

4.2. http://www.microsoft.com/en-us/default.aspx

4.3. http://www.microsoft.com/en-us/default.aspx

4.4. http://www.microsoft.com/en-us/default.aspx

4.5. http://www.microsoft.com/en-us/default.aspx

4.6. http://www.microsoft.com/en-us/default.aspx

4.7. http://www.microsoft.com/en-us/default.aspx

4.8. http://www.microsoft.com/events/series/technetmms.aspx

4.9. http://www.microsoft.com/licensing/default.aspx

4.10. http://www.microsoft.com/poland/hardware/mouseandkeyboard/productlist.aspx

5. Cross-domain script include

5.1. http://www.microsoft.com/atwork/default.aspx

5.2. http://www.microsoft.com/business/default.mspx

5.3. http://www.microsoft.com/da/dk/

5.4. http://www.microsoft.com/de/at/

5.5. http://www.microsoft.com/de/ch/

5.6. http://www.microsoft.com/download/en/default.aspx

5.7. http://www.microsoft.com/en-us/cloud/cloudpowersolutions/private_cloud.aspx

5.8. http://www.microsoft.com/en-us/cloud/default.aspx

5.9. http://www.microsoft.com/en-us/default.aspx

5.10. http://www.microsoft.com/en-us/dynamics/default.aspx

5.11. http://www.microsoft.com/en-us/security_essentials/default.aspx

5.12. http://www.microsoft.com/en/ca/

5.13. http://www.microsoft.com/en/hk/

5.14. http://www.microsoft.com/en/in/

5.15. http://www.microsoft.com/en/mt/

5.16. http://www.microsoft.com/en/us/sitemap.aspx

5.17. http://www.microsoft.com/es/ar/

5.18. http://www.microsoft.com/es/co/

5.19. http://www.microsoft.com/es/es/

5.20. http://www.microsoft.com/es/mx/

5.21. http://www.microsoft.com/es/xl/

5.22. http://www.microsoft.com/events/default.mspx

5.23. http://www.microsoft.com/events/series/technetmms.aspx

5.24. http://www.microsoft.com/fi/fi/

5.25. http://www.microsoft.com/forefront/en/us/identity-access-management.aspx

5.26. http://www.microsoft.com/forefront/endpoint-protection/en/us/try-it.aspx

5.27. http://www.microsoft.com/global/systemcenter/pl/pl/PublishingImages/Hero-SCHome-NonSL.jpg

5.28. http://www.microsoft.com/global/systemcenter/pl/pl/RenderingAssets/browserSpecificCSS.js

5.29. http://www.microsoft.com/he/il/

5.30. http://www.microsoft.com/hu/hu/

5.31. http://www.microsoft.com/hy/am/

5.32. http://www.microsoft.com/industry/government/css/solutions_stylesheet.css

5.33. http://www.microsoft.com/industry/government/solutions/usgcb/images/spacer.gif

5.34. http://www.microsoft.com/it/it/

5.35. http://www.microsoft.com/ka/ge/

5.36. http://www.microsoft.com/ko/kr/

5.37. http://www.microsoft.com/learning/en/us/default.aspx

5.38. http://www.microsoft.com/learning/en/us/training/products.aspx

5.39. http://www.microsoft.com/maps/

5.40. http://www.microsoft.com/nb/no/

5.41. http://www.microsoft.com/nl/be/

5.42. http://www.microsoft.com/nl/nl/

5.43. http://www.microsoft.com/online/pl-pl/default.aspx

5.44. http://www.microsoft.com/pl-pl/cloud/default.aspx

5.45. http://www.microsoft.com/pl-pl/security_essentials/default.aspx

5.46. http://www.microsoft.com/pl/PL/default.aspx

5.47. http://www.microsoft.com/pl/pl/

5.48. http://www.microsoft.com/pl/pl/sitemap.aspx

5.49. http://www.microsoft.com/poland/centrumprasowe/

5.50. http://www.microsoft.com/poland/developer/

5.51. http://www.microsoft.com/poland/developer/Default.aspx

5.52. http://www.microsoft.com/poland/gotowydopracy/index.aspx

5.53. http://www.microsoft.com/poland/hardware/

5.54. http://www.microsoft.com/poland/hardware/digitalcommunication/default.mspx

5.55. http://www.microsoft.com/poland/hardware/gaming/gaming.mspx

5.56. http://www.microsoft.com/poland/hardware/mouseandkeyboard/productlist.aspx

5.57. http://www.microsoft.com/poland/office/zrob-to-najlepiej/

5.58. http://www.microsoft.com/poland/office/zrob-to-najlepiej/OfficeMobile2010.aspx

5.59. http://www.microsoft.com/poland/office/zrob-to-najlepiej/excel.aspx

5.60. http://www.microsoft.com/poland/office/zrob-to-najlepiej/onenote.aspx

5.61. http://www.microsoft.com/poland/office/zrob-to-najlepiej/outlook.aspx

5.62. http://www.microsoft.com/poland/office/zrob-to-najlepiej/pakiety.aspx

5.63. http://www.microsoft.com/poland/office/zrob-to-najlepiej/powerpoint.aspx

5.64. http://www.microsoft.com/poland/office/zrob-to-najlepiej/shops.aspx

5.65. http://www.microsoft.com/poland/office/zrob-to-najlepiej/sitemap.aspx

5.66. http://www.microsoft.com/poland/office/zrob-to-najlepiej/word.aspx

5.67. http://www.microsoft.com/poland/pocztahotmail/default.aspx

5.68. http://www.microsoft.com/poland/protect/default.mspx

5.69. http://www.microsoft.com/poland/technet/security/default.mspx

5.70. http://www.microsoft.com/poland/twojanowa/default.aspx

5.71. http://www.microsoft.com/poland/windows/windowsintune/pc-management.aspx

5.72. http://www.microsoft.com/poland/windowscool/video-02.aspx

5.73. http://www.microsoft.com/products/works/default.mspx

5.74. http://www.microsoft.com/pt/br/

5.75. http://www.microsoft.com/ru/ru/

5.76. http://www.microsoft.com/security/pc-security/conficker.aspx

5.77. http://www.microsoft.com/security/pc-security/default.aspx

5.78. http://www.microsoft.com/security/pc-security/firewalls-whatis.aspx

5.79. http://www.microsoft.com/security/pc-security/malware-removal.aspx

5.80. http://www.microsoft.com/security/resources/antivirus-whatis.aspx

5.81. http://www.microsoft.com/showcase/pl/pl/

5.82. http://www.microsoft.com/showcase/pl/pl/default.aspx

5.83. http://www.microsoft.com/sqlserver/en/us/default.aspx

5.84. http://www.microsoft.com/sv/se/

5.85. http://www.microsoft.com/systemcenter/configurationmanager/pl/pl/default.aspx

5.86. http://www.microsoft.com/systemcenter/dataprotectionmanager/pl/pl/default.aspx

5.87. http://www.microsoft.com/systemcenter/en/us/dynamic-data-centers.aspx

5.88. http://www.microsoft.com/systemcenter/en/us/service-manager.aspx

5.89. http://www.microsoft.com/systemcenter/operationsmanager/pl/pl/default.aspx

5.90. http://www.microsoft.com/systemcenter/operationsmanager/pl/pl/whats-new.aspx

5.91. http://www.microsoft.com/systemcenter/pl/pl/datasheets.aspx

5.92. http://www.microsoft.com/systemcenter/pl/pl/default.aspx

5.93. http://www.microsoft.com/systemcenter/pl/pl/key-benefits.aspx

5.94. http://www.microsoft.com/systemcenter/pl/pl/management-suites.aspx

5.95. http://www.microsoft.com/systemcenter/pl/pl/news-reviews.aspx

5.96. http://www.microsoft.com/systemcenter/pl/pl/optimize-infrastructure.aspx

5.97. http://www.microsoft.com/systemcenter/pl/pl/pricing-licensing.aspx

5.98. http://www.microsoft.com/systemcenter/pl/pl/product-information.aspx

5.99. http://www.microsoft.com/systemcenter/pl/pl/products.aspx

5.100. http://www.microsoft.com/systemcenter/pl/pl/trial-software.aspx

5.101. http://www.microsoft.com/systemcenter/pl/pl/white-papers.aspx

5.102. http://www.microsoft.com/systemcenter/virtualmachinemanager/pl/pl/default.aspx

5.103. http://www.microsoft.com/ukr/ua/

5.104. http://www.microsoft.com/windows/products/winfamily/windowshomeserver/default.mspx

5.105. http://www.microsoft.com/windowsazure/free-trial/

5.106. http://www.microsoft.com/windowsmobile/pl-pl/business/default.mspx

5.107. http://www.microsoft.com/windowsmobile/pl-pl/devices/default.mspx

5.108. http://www.microsoft.com/windowsmobile/pl-pl/devices/details.mspx

5.109. http://www.microsoft.com/windowsmobile/pl-pl/devices/smartphones.mspx

5.110. http://www.microsoft.com/windowsmobile/pl-pl/downloads/default.mspx

5.111. http://www.microsoft.com/windowsmobile/pl-pl/downloads/microsoft/office-outlook-mobile.mspx

5.112. http://www.microsoft.com/windowsmobile/pl-pl/downloads/microsoft/software-office-mobile.mspx

5.113. http://www.microsoft.com/windowsmobile/pl-pl/meet/choice-is-yours.mspx

5.114. http://www.microsoft.com/windowsmobile/pl-pl/meet/default.mspx

5.115. http://www.microsoft.com/windowsmobile/pl-pl/meet/just-the-facts.mspx

5.116. http://www.microsoft.com/windowsmobile/pl-pl/meet/life-in-touch.mspx

5.117. http://www.microsoft.com/windowsmobile/pl-pl/meet/microsoft-applications.mspx

5.118. http://www.microsoft.com/windowsmobile/pl-pl/meet/secure-your-stuff.mspx

5.119. http://www.microsoft.com/windowsmobile/pl-pl/meet/windows-to-go.mspx

5.120. http://www.microsoft.com/windowsmobile/pl-pl/sitemap.mspx

5.121. http://www.microsoft.com/windowsmobile/pl-pl/worldwide.mspx

5.122. http://www.microsoft.com/windowsphone/en-us/apps/default.aspx

5.123. http://www.microsoft.com/windowsphone/en-us/buy/7/default.aspx

5.124. http://www.microsoft.com/zh/hk/

6. Cookie without HttpOnly flag set

6.1. http://www.microsoft.com/download/en/default.aspx

6.2. http://www.microsoft.com/downloads/en/default.aspx

6.3. http://www.microsoft.com/downloads/en/details.aspx

6.4. http://www.microsoft.com/en-us/default.aspx

6.5. http://www.microsoft.com/industry/government/solutions/usgcb/default.aspx

6.6. http://www.microsoft.com/security_essentials/

7. Email addresses disclosed

7.1. http://www.microsoft.com/About/Legal/EN/US/IntellectualProperty/Copyright/default.aspx

7.2. http://www.microsoft.com/en/ph/

7.3. http://www.microsoft.com/et/ee/

7.4. http://www.microsoft.com/fi/fi/

7.5. http://www.microsoft.com/industry/government/solutions/usgcb/default.aspx

7.6. http://www.microsoft.com/lt/lt/

7.7. http://www.microsoft.com/lv/lv/

7.8. http://www.microsoft.com/poland/centrumprasowe/

7.9. http://www.microsoft.com/poland/centrumprasowe/firma/kierownictwo.aspx

7.10. http://www.microsoft.com/poland/centrumprasowe/firma/misja.aspx

7.11. http://www.microsoft.com/poland/centrumprasowe/firma/siedziby.aspx

7.12. http://www.microsoft.com/poland/copyright/default.aspx

7.13. http://www.microsoft.com/poland/corp/corp.htm

7.14. http://www.microsoft.com/poland/edukacja/

7.15. http://www.microsoft.com/poland/edukacja/imaginecup/Polscy-zwyciezcy-Imagine-Cup-2011.aspx

7.16. http://www.microsoft.com/poland/gotowydopracy/index.aspx

7.17. http://www.microsoft.com/poland/oem/

7.18. http://www.microsoft.com/poland/savethemoney/

7.19. http://www.microsoft.com/windows/framework/js/omniture/s_code.js

8. HTML does not specify charset

8.1. http://www.microsoft.com/info/pl/privacy.htm

8.2. http://www.microsoft.com/library/errorpages/searchMetric.html

9. HTML uses unrecognised charset

9.1. http://www.microsoft.com/windows/products/winfamily/umpc/default.mspx

9.2. http://www.microsoft.com/windows/products/winfamily/windowshomeserver/default.mspx

10. Content type incorrectly stated

10.1. http://www.microsoft.com/global/pl/pl/RenderingAssets/NewsBand/MicrosoftNews2.xml

10.2. http://www.microsoft.com/global/pl/pl/RichMedia/WindowPane_R2.xaml

10.3. http://www.microsoft.com/pl/shared/templates/components/cspMscomNewsBand/Rss.ashx

10.4. http://www.microsoft.com/windowsmobile/components/devices09/imageengine/imageengine.aspx



1. Cross-site scripting (reflected)  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /industry/government/solutions/usgcb/default.aspx

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8fec7"style%3d"x%3aexpression(alert(1))"e5569d9e7cf was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 8fec7"style="x:expression(alert(1))"e5569d9e7cf in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.

Request

GET /industry/government/solutions/usgcb/default.aspx?8fec7"style%3d"x%3aexpression(alert(1))"e5569d9e7cf=1 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: USPS_Visitor=F,0,0,0,0,999,adb3dc45-354b-4815-8800-524e872c6661,0,en,8/26/2011 12:49:35 PM; expires=Fri, 26-Aug-2061 19:49:35 GMT; path=/
VTag: 438339432200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:49:35 GMT
Content-Length: 208535


<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head id="ctl00_Head1"><link id="ctl00_browserStylesheet" rel="Stylesheet" type="text/css" href="/industry/government/MNP_1.0/mnpMaster/sty
...[SNIP]...
s.href,'ContactUsEmail');" href="/industry/government/howtobuy/ContactPartner.aspx?emailAdd=None&lar=None&slg_lar=None&org_url=http://www.microsoft.com/industry/government/solutions/usgcb/default.aspx?8fec7"style="x:expression(alert(1))"e5569d9e7cf=1&topic=buy&Referral_Type=BuySoftware&level=None&Organization=None">
...[SNIP]...

2. Source code disclosure  previous  next
There are 4 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


2.1. http://www.microsoft.com/en-us/cloud/cloudpowersolutions/private_cloud.aspx  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /en-us/cloud/cloudpowersolutions/private_cloud.aspx

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /en-us/cloud/cloudpowersolutions/private_cloud.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:54 GMT
Last-Modified: Thu, 25 Aug 2011 18:44:10 GMT
ETag: 634498694500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 43872131000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:54 GMT
Content-Length: 75424

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
<div class="box icon-blogs blogs-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?>..</a>.. <a class="more" target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-videos videos-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>"><img alt="preview" class="preview" src="<?=ThumbnailUrl?>"></a><h4><span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a><span class="runningTime"><?=Runtime?></span>
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-news news-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a></h4><p class="excerpt"><?=Content?>.. <a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Follow<?=Author?>">
...[SNIP]...
<span class="date"><?=DateString?></span><?=Content?><span class="relativeTime"><?=RelativeTime?></span>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Follow<?=Author?>"><?=Author?></a></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="eventTag<?=Id?>"> <img src="<?=ThumbnailUrl?>" width="95" height="53" alt="<?=ThumbnailUrl?>" class="float-left" />
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="eventTag<?=Id?>"><?=Title?></a>
...[SNIP]...
<h5><?=StartDate?></h5> <p><?=City?>: <?=Description?></p>
...[SNIP]...
<div id="eventToolbarShare<?=Id?>" class="toolbar-share">
...[SNIP]...
<div id="eventFbShare<?=Id?>" class="toolbar-share-logo toolbar-share-fb">
...[SNIP]...
<div id="eventTwitter<?=Id?>" class="toolbar-share-logo toolbar-share-twitter">
...[SNIP]...
<div id="eventFbLike<?=Id?>" class="toolbar-fb-like">
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="eventTag<?=Id?>"> <img src="<?=ThumbnailUrl?>" width="95" height="53" alt="<?=ThumbnailUrl?>" class="float-left" />
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="eventTag<?=Id?>"><?=Title?></a>
...[SNIP]...
<h5><?=StartDate?></h5> <p><?=Description?></p>
...[SNIP]...
<div id="eventToolbarShare<?=Id?>" class="toolbar-share">
...[SNIP]...
<div id="eventFbShare<?=Id?>" class="toolbar-share-logo toolbar-share-fb">
...[SNIP]...
<div id="eventTwitter<?=Id?>" class="toolbar-share-logo toolbar-share-twitter">
...[SNIP]...
<div id="eventFbLike<?=Id?>" class="toolbar-fb-like">
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="offerTag<?=Id?>"> <img src="<?=ThumbnailUrl?>" width="95" height="53" alt="<?=ThumbnailUrl?>" class="float-left" />
...[SNIP]...
<a href='<?=Url?>' target="_blank" class="offerTag<?=Id?>"><?=Title?></a>
...[SNIP]...
<p><?=Description?></p>
...[SNIP]...
<div id="offerToolbarShare<?=Id?>" class="toolbar-share">
...[SNIP]...
<div id="offerFbShare<?=Id?>" class="toolbar-share-logo toolbar-share-fb">
...[SNIP]...
<div id="offerTwitter<?=Id?>" class="toolbar-share-logo toolbar-share-twitter">
...[SNIP]...
<div id="offerFbLike<?=Id?>" class="toolbar-fb-like">
...[SNIP]...

2.2. http://www.microsoft.com/en-us/cloud/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /en-us/cloud/default.aspx

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /en-us/cloud/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:54 GMT
Last-Modified: Thu, 25 Aug 2011 18:44:10 GMT
ETag: 634498694500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79181230600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:53 GMT
Content-Length: 27709

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
<div class="box icon-blogs blogs-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?>..</a>.. <a class="more" target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-videos videos-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>"><img alt="preview" class="preview" src="<?=ThumbnailUrl?>"></a><h4><span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a><span class="runningTime"><?=Runtime?></span>
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-news news-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a></h4><p class="excerpt"><?=Content?>.. <a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Follow<?=Author?>">
...[SNIP]...
<span class="date"><?=DateString?></span><?=Content?><span class="relativeTime"><?=RelativeTime?></span>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Follow<?=Author?>"><?=Author?></a></li><li class="source"><?=SourceName?></li>
...[SNIP]...

2.3. http://www.microsoft.com/pl-pl/cloud/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /pl-pl/cloud/default.aspx

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /pl-pl/cloud/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:16:29 GMT
Last-Modified: Tue, 28 Jun 2011 10:04:28 GMT
ETag: 634448270680000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279682143100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:28 GMT
Content-Length: 25757

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
<div class="box icon-blogs blogs-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?>..</a>.. <a class="more" target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-videos videos-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>"><img alt="preview" class="preview" src="<?=ThumbnailUrl?>"></a><h4><span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a><span class="runningTime"><?=Runtime?></span>
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<div class="box icon-news news-<?=MicrosoftOwnerName?>">
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<span class="date"><?=DateString?></span><a target="_blank" href="<?=Link?>" title="<?=Title?>"><?=Title?></a></h4><p class="excerpt"><?=Content?>.. <a target="_blank" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...
<li class="author"><?=Author?></li><li class="source"><?=SourceName?></li>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Przejd.. do<?=Author?>">
...[SNIP]...
<span class="date"><?=DateString?></span><?=Content?><span class="relativeTime"><?=RelativeTime?></span>
...[SNIP]...
<a target="_blank" href="<?=Link?>" title="Przejd.. do<?=Author?>"><?=Author?></a></li><li class="source"><?=SourceName?></li>
...[SNIP]...

2.4. http://www.microsoft.com/sqlserver/en/us/default.aspx  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /sqlserver/en/us/default.aspx

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /sqlserver/en/us/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:45 GMT
Last-Modified: Thu, 25 Aug 2011 19:58:15 GMT
ETag: 634498738950000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279891131200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:36 GMT
Content-Length: 64628

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<li class="item<?=IsFeatured?>">
...[SNIP]...
</span><?=DateFormat?></span>
...[SNIP]...
<h3><?=Title?></h3><p class="desc"><?=Content?><a target="_blank" class="cta" href="<?=Link?>" title="<?=Title?>">
...[SNIP]...

3. Cookie scoped to parent domain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.

Request

GET /en-us/default.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314325096447-13143250964471911\\\"}\"}}","Expires":"\/Date(1322101096538)\/"}; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 02:18:21&Microsoft.VisitStartDate=08/26/2011 02:18:21&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=104&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314314327014:ss=1314314308776

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: MS0=0656da9ad4f847d7ae457c6228fdf677; domain=microsoft.com; expires=Fri, 26-Aug-2011 18:24:19 GMT; path=/
Set-Cookie: MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381257669-13143812576698286\\\"}\"}}","Expires":"\/Date(1322157259536)\/"}; domain=microsoft.com; expires=Thu, 24-Nov-2011 17:54:19 GMT; path=/
VTag: 279734142200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:54:19 GMT
Content-Length: 212167

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...

4. Cross-domain Referer leakage  previous  next
There are 10 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


4.1. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?hroid=ctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01&hroi=-1 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:34 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791448431300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:34 GMT
Content-Length: 219146

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fhroid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl00_ctl01%26hroi%3d-1&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.2. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?accid=ctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01&acci=0 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:35 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791784330900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:34 GMT
Content-Length: 217586

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3faccid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01%26acci%3d0&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<div class="hpHro_ImgWrap" style="height:320px;" rel="320"> <a href="http://clk.atdmt.com/MRT/go/332559428/direct/01/" bi:linkid="400-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/Hero/IE9_ITpro_blue_v1_530x320_lt.jpg" alt="Download Windows Internet Explorer 9." width="530" height="320" class="hpImage_Img"/
...[SNIP]...
</p> <a class="hpFeat_Link Arrow" bi:linkid="405-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="cta" bi:parenttitle="item" href="http://clk.atdmt.com/MRT/go/332559428/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.3. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?crsid=ctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01&crsci=0 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:39 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791683231200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:38 GMT
Content-Length: 218666

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fcrsid%3dctl00_ctl14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01%26crsci%3d0&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<div class="hpHro_ImgWrap" style="height:320px;" rel="320"> <a href="http://clk.atdmt.com/MRT/go/332559428/direct/01/" bi:linkid="400-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/Hero/IE9_ITpro_blue_v1_530x320_lt.jpg" alt="Download Windows Internet Explorer 9." width="530" height="320" class="hpImage_Img"/
...[SNIP]...
</p> <a class="hpFeat_Link Arrow" bi:linkid="405-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="cta" bi:parenttitle="item" href="http://clk.atdmt.com/MRT/go/332559428/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.4. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?pvti=1 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:32 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279228531000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:32 GMT
Content-Length: 211387

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<div class="hpHro_ImgWrap" style="height:320px;" rel="320"> <a href="http://clk.atdmt.com/MRT/go/332559428/direct/01/" bi:linkid="400-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/Hero/IE9_ITpro_blue_v1_530x320_lt.jpg" alt="Download Windows Internet Explorer 9." width="530" height="320" class="hpImage_Img"/
...[SNIP]...
</p> <a class="hpFeat_Link Arrow" bi:linkid="405-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="cta" bi:parenttitle="item" href="http://clk.atdmt.com/MRT/go/332559428/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.5. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?pvti=1&pvtsi=0 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:34 GMT
Last-Modified: Thu, 25 Aug 2011 16:15:38 GMT
ETag: 634498605380000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791621231500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:34 GMT
Content-Length: 208905

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fpvti%3d1%26pvtsi%3d0&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
temsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332102882/direct/01/" bi:linkid="310-13-121LMUS007473" bi:campaignname="(IE9 Consumer 2012 Q1)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/IE9Logo_sm.png" alt="Download Windows Internet Explorer 9 today." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="310-13-121LMUS007473" bi:campaignname="(IE9 Consumer 2012 Q1)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332102882/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
temsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl00_CellRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400967/direct/01/" bi:linkid="312-00-121LMUS007399" bi:campaignname="(Office Trial Q1FY12)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HB_sm.png" alt="Try Microsoft Office Home and Business 2010 for free." width="70" height="70" class="hpImag
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="312-00-121LMUS007399" bi:campaignname="(Office Trial Q1FY12)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332400967/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="312-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400786/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/342260391/direct/01/" bi:linkid="320-00-121GSUS010613" bi:campaignname="(Visual Studio LightSwitch 2011 Launch - iWorker (Trial))" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/VSLight_sm.png" alt="Watch a video overview and download a trial of Visual Studio LightSwitch 2011." width="70" heigh
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="320-00-121GSUS010613" bi:campaignname="(Visual Studio LightSwitch 2011 Launch - iWorker (Trial))" bi:type="title" href="http://clk.atdmt.com/MRT/go/342260391/direct/01/">Microsoft Visual Studio LightSwitch 2011</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="320-00-121GSUS010613" bi:campaignname="(Visual Studio LightSwitch 2011 Launch - iWorker (Trial))" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/342260391/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://www.powerpivot.com/" bi:linkid="320-00-121LSUS008758" bi:campaignname="(NEW PowerPivot campaign)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/PowerPivot_sm.png" alt="Download the free PowerPivot add-in for Microsoft Excel 2010." width="70" height="70" class="
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="320-00-121LSUS008758" bi:campaignname="(NEW PowerPivot campaign)" bi:type="title" href="http://www.powerpivot.com/">Microsoft PowerPivot for Excel 2010</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="320-00-121LSUS008758" bi:campaignname="(NEW PowerPivot campaign)" bi:index="0" bi:type="primarycta" href="http://www.powerpivot.com/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/331579191/direct/01/" bi:linkid="320-00-121LMUS007469" bi:campaignname="(Microsoft Dynamics CRM GA Campaign - Don't Get Forced)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/dynamicscrm_sm.png" alt="Try Microsoft Dynamics CRM Online for free." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="320-00-121LMUS007469" bi:campaignname="(Microsoft Dynamics CRM GA Campaign - Don't Get Forced)" bi:type="title" href="http://clk.atdmt.com/MRT/go/331579191/direct/01/">Microsoft Dynamics CRM Online</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="320-00-121LMUS007469" bi:campaignname="(Microsoft Dynamics CRM GA Campaign - Don't Get Forced)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/331579191/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
temsRepeater_ctl00_SubPivotBodyRepeater_ctl00_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl02_CellRepeater_ctl00_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332558840/direct/01/" bi:linkid="330-00-121GSUS007530" bi:campaignname="Office 365 GA midsize businesses and enterprises)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/OfficeLogo_sm.png" alt="See how a Microsoft Office 365 subscription can help power your business." width="70" height=
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="330-00-121GSUS007530" bi:campaignname="(Office 365 GA midsize businesses and enterprises)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332558840/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="150-00-000NWSW0003" bi:campaignname="(Work News item 3)" bi:index="0" bi:type="secondarycta" href="http://blogs.technet.com/b/microsoft_blog/archive/2011/08/17/the-future-of-the-living-room.aspx"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.6. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?bldi=0 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:32 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438764931100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:31 GMT
Content-Length: 211428

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fbldi%3d0&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<div class="hpHro_ImgWrap" style="height:320px;" rel="320"> <a href="http://clk.atdmt.com/MRT/go/332559428/direct/01/" bi:linkid="400-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/Hero/IE9_ITpro_blue_v1_530x320_lt.jpg" alt="Download Windows Internet Explorer 9." width="530" height="320" class="hpImage_Img"/
...[SNIP]...
</p> <a class="hpFeat_Link Arrow" bi:linkid="405-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="cta" bi:parenttitle="item" href="http://clk.atdmt.com/MRT/go/332559428/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.7. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/default.aspx?mnui=0 HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:32 GMT
Last-Modified: Mon, 22 Aug 2011 18:53:24 GMT
ETag: 634496108040000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438759031200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:31 GMT
Content-Length: 211393

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div id="ctl00_ctl07_SecondaryItemsRepeater_ctl01_ctl01_featureItemID_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332400780/direct/01/" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/Office2010HS_sm.png" alt="Buy and download Microsoft Office Home and Student 2010 today." width="70" height="70" clas
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="001-00-121LMUS007430" bi:campaignname="(Buy Office_FY12_Q1_US)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332400780/direct/01/">Microsoft Office Home and Student 2010</a>
...[SNIP]...
<li> <a class="hpFeat_Link" bi:name1="val1" bi:name2="val2" bi:name3="val3" bi:name4="val4" bi:index="0" bi:type="list" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" target="_blank" title="Facebook" bi:index="1" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&WT.mc_id=twitter" target="_blank" title="Twitter" bi:index="2" bi:type="sharepopularlink"> <span class="hpShr_IconContainer">
...[SNIP]...
<li > <a href="http://cang.baidu.com/do/add?it=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&iu=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&fr=ien&dc=&WT.mc_id=baidu" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://delicious.com/save?=v=5&amp;jump=close&amp;url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&amp;title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=delicious" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://digg.com/submit?phase=2&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&title=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=digg" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.facebook.com/sharer.php?u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&t=Microsoft+Corporation%3a+Software%2c+Smartphones%2c+Online%2c+Games%2c+Cloud+Computing%2c+IT+Business+Technology%2c+Downloads&WT.mc_id=facebook" bi:index="4" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://wd.sharethis.com/api/sharer.php?destination=messenger&url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&WT.mc_id=messenger" bi:index="0" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.stumbleupon.com/submit?url=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&title=Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads&WT.mc_id=stumbleupon" bi:index="1" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://www.tumblr.com/share?v=3&u=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&t=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&s=&WT.mc_id=tumblr" bi:index="2" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li > <a href="http://twitter.com/home?status=http%3a%2f%2fwww.microsoft.com%2fen-us%2fhomepage%2fdefault.aspx%3fmnui%3d0&WT.mc_id=twitter" bi:index="3" bi:type="sharelink" target="_blank"> <span class="hpShr_white">
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.gamesforwindows.com/en-US/">PC gaming</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.xbox.com/">Xbox home</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://www.zune.com/">Zune</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://explore.live.com/windows-live-hotmail">Windows Live Hotmail</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://explore.live.com/windows-live-messenger">Windows Live Messenger</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="2" href="http://explore.live.com/windows-live-skydrive">Windows Live SkyDrive</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="0" href="http://www.microsoftstore.com/store/msstore/en_US/cat/parentCategoryID.37946100/categoryID.50799400?WT.mc_id=MSCOM_HP_US_BL_BuyBizSoftware">Business software</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="1" href="http://www.ieaddons.com/">Internet Explorer Downloads</a>
...[SNIP]...
<li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:index="9" href="http://explore.live.com/windows-live-essentials">Windows Live Essentials</a>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<div class="hpHro_ImgWrap" style="height:320px;" rel="320"> <a href="http://clk.atdmt.com/MRT/go/332559428/direct/01/" bi:linkid="400-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/Hero/IE9_ITpro_blue_v1_530x320_lt.jpg" alt="Download Windows Internet Explorer 9." width="530" height="320" class="hpImage_Img"/
...[SNIP]...
</p> <a class="hpFeat_Link Arrow" bi:linkid="405-13-121LSUS008430" bi:campaignname="(IE9 IT Pro NDGP_2012_Q1_US)" bi:type="cta" bi:parenttitle="item" href="http://clk.atdmt.com/MRT/go/332559428/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="410-00-121GMUS007396" bi:campaignname="(Windows Intune_2012_Q1_Global)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332400593/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="412-00-121GMUS007257" bi:campaignname="(Microsoft Security Essentials_2012_Q1)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/332544001/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
14_PivotItemsRepeater_ctl00_SubPivotBodyRepeater_ctl01_ctl01_ColumnRepeater_ctl00_RowRepeater_ctl01_CellRepeater_ctl00_ctl01_Item_Image" class="hpFeat_ImageContainer" bi:parenttitle="item"> <a href="http://clk.atdmt.com/MRT/go/332372534/direct/01/" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="image" class="hpImage_Link"><img src="http://i.microsoft.com/global/en-us/homepage/PublishingImages/thumbnails/CARE_sm.jpg" alt="Evaluate Microsoft products for your company." width="70" height="70" class="hpImage_Img"/>
...[SNIP]...
<h5 class="hpFeat_Wrap hpFeat_Title hpFeat_Item" bi:titleflag="item" bi:title="item"><a class="hpFeat_Link" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:type="title" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/">Download free trials</a>
...[SNIP]...
<li > <a class="hpFeat_Link Arrow" bi:linkid="420-00-121GMUS007346" bi:campaignname="(CARE: Guided Technical Software Evaluation)" bi:index="0" bi:type="primarycta" href="http://clk.atdmt.com/MRT/go/332372534/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="450-00-121LSUS007972" bi:campaignname="(NACMG Cloud Power Q1 MSCOM)" bi:index="0" bi:type="secondarycta" href="http://clk.atdmt.com/MRT/go/334247564/direct/01/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000017" bi:index="3" bi:type="secondarycta" href="http://crm.dynamics.com/en-us/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000028" bi:index="1" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/categoryID.50606600"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000032" bi:index="5" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/cat/parentCategoryID.44067000/categoryID.50791300"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000033" bi:index="6" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000036" bi:index="9" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.50606600/categoryID.50789900"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000047" bi:index="7" bi:type="secondarycta" href="http://www.microsoftstore.com/store/msstore/list/parentCategoryID.44066900/categoryID.50787200"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000067" bi:index="0" bi:type="secondarycta" href="http://www.bing.com/travel/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000068" bi:index="1" bi:type="secondarycta" href="http://www.bing.com/finance/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000069" bi:index="2" bi:type="secondarycta" href="http://www.bing.com/images/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000070" bi:index="3" bi:type="secondarycta" href="http://www.bing.com/music/lyrics"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000071" bi:index="4" bi:type="secondarycta" href="http://www.bing.com/maps/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000072" bi:index="5" bi:type="secondarycta" href="http://www.bing.com/music"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000073" bi:index="6" bi:type="secondarycta" href="http://www.bing.com/"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000074" bi:index="7" bi:type="secondarycta" href="http://www.bing.com/shopping"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000075" bi:index="8" bi:type="secondarycta" href="http://www.bing.com/news"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000076" bi:index="9" bi:type="secondarycta" href="http://www.bing.com/videos"><span class="hpFeat_Text">
...[SNIP]...
<li> <a class="hpFeat_Link Arrow" bi:linkid="050-00-111SEO000077" bi:index="10" bi:type="secondarycta" href="http://www.bing.com/weather/search?q=weather"><span class="hpFeat_Text">
...[SNIP]...

4.8. http://www.microsoft.com/events/series/technetmms.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /events/series/technetmms.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /events/series/technetmms.aspx?tab=webcasts HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438461800400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:22 GMT
Content-Length: 41014


<html>
<LINK href="css/seriesTabbed.css" type="text/css" rel="stylesheet" />
<script type='text/javascript' language='Javascript' src='/events/mnp_utility.mspx/menujs?mnpshell=%2fevents%2fConfigur
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<p class="container"><a class="containerLink" href="http://www.securevantage.com/ACSTraining.aspx" onclick="&#xD;&#xA; javascript: wwe=window.open('http://www.securevantage.com/ACSTraining.aspx','wwe','toolbar=yes,location=yes,directories=no,status=no,menubar=yes,scrollbars=yes,resizable=yes,width=1020,height=600,left=0,top=0'); wwe.focus(); return false;&#xD;&#xA; ">ACS Training Webcasts from Secure Vantage</a>
...[SNIP]...
<p class="container"><a class="containerLink" href="http://technetwidget.com/" onclick="&#xD;&#xA; javascript: wwe=window.open('http://technetwidget.com/','wwe','toolbar=yes,location=yes,directories=no,status=no,menubar=yes,scrollbars=yes,resizable=yes,width=1020,height=600,left=0,top=0'); wwe.focus(); return false;&#xD;&#xA; ">TechNet Widget</a>
...[SNIP]...
<p class="container"><a class="containerLink" href="http://www.microsoftbroadcaster.com/en-US/Login/Default" onclick="&#xD;&#xA; javascript: wwe=window.open('http://www.microsoftbroadcaster.com/en-US/Login/Default','wwe','toolbar=yes,location=yes,directories=no,status=no,menubar=yes,scrollbars=yes,resizable=yes,width=1020,height=600,left=0,top=0'); wwe.focus(); return false;&#xD;&#xA; ">Microsoft Broadcaster</a>
...[SNIP]...
<noscript><img border="0" name="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsjwb9vb00000c932fd0rjc7_5p3t/njs.gif?dcsuri=/nojavascript&WT.js=No"/></noscript>
...[SNIP]...

4.9. http://www.microsoft.com/licensing/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /licensing/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /licensing/default.aspx?WT.mc_id=MSCOM_HP_US_BL_Licensing HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:40:06 GMT
Last-Modified: Tue, 23 Aug 2011 19:30:35 GMT
ETag: 634496994350000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 791421843200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:30:06 GMT
Content-Length: 45939

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><!-- Define element HTML --> <html xmlns="http://www.w3.org/1999/xhtml" dir=
...[SNIP]...
<li class="tweet-link"><a href="http://twitter.com/Msft_VL" title='' onclick="dcsMultiTrack('DCS.dcsuri','/licensing/Tweet_icon','WT.ti','Tweet_icon');"></a></li> <li class="blog-link"><a href="http://blogs.technet.com/b/volume-licensing" title='' onclick="dcsMultiTrack('DCS.dcsuri','/licensing/Blog_icon','WT.ti','Blog_icon');"></a>
...[SNIP]...
<p class="connect_links"><a href="http://blogs.technet.com/b/volume-licensing" target="_blank"><img src="/global/licensing/PublishingImages/backgrounds/icons/icon_vl_blog_16.png"/>
...[SNIP]...
<p class="connect_links"><a href="http://twitter.com/Msft_VL" target="_blank"><img src="/global/licensing/PublishingImages/backgrounds/icons/icon_twitter.png"/>
...[SNIP]...
<p><a href="http://www.msn.com">MSN.com</a>
...[SNIP]...
<noscript><img alt="" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsjwb9vb00000c932fd0rjc7_5p3t/njs.gif?dcsuri=/nojavascript&WT.js=No"></noscript>
...[SNIP]...

4.10. http://www.microsoft.com/poland/hardware/mouseandkeyboard/productlist.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/hardware/mouseandkeyboard/productlist.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /poland/hardware/mouseandkeyboard/productlist.aspx?type=Keyboard&AdditionalType=Sets HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791376300400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:36 GMT
Content-Length: 46306


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script src="http://content.channelintelligence.com/scripts/ykb_PopupWindow.js" type="text/javascript"></script>

<script src="http://microsoft.links.channelintelligence.com/scripts/cii_CBL_DataService_API.asp" type="text/javascript"></script>

<script src="http://content.channelintelligence.com/scripts/cii_embeddedfunctions.asp" type="text/javascript"></script>
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
<noscript><img border="0" name="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsjwb9vb00000c932fd0rjc7_5p3t/njs.gif?dcsuri=/nojavascript&WT.js=No"/></noscript>
...[SNIP]...

5. Cross-domain script include  previous  next
There are 124 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


5.1. http://www.microsoft.com/atwork/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /atwork/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /atwork/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:27:34 GMT
Last-Modified: Mon, 22 Aug 2011 07:05:51 GMT
ETag: 634495683510000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79158900200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:33 GMT
Content-Length: 57910

... <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="e
...[SNIP]...
<!-- for the ad controls --> <script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.2. http://www.microsoft.com/business/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /business/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /business/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 49537
Content-Type: text/html; charset=iso-8859-1
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279264330500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:02 GMT


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><META name="MS.LOCALE" content="en-us"><title>Microsoft for Business and Industry</title><meta name="desc
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.3. http://www.microsoft.com/da/dk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /da/dk/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /da/dk/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:50:52 GMT
Last-Modified: Thu, 18 Aug 2011 12:31:35 GMT
ETag: 634492422950000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279271442300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:40:52 GMT
Content-Length: 102919

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="da"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.4. http://www.microsoft.com/de/at/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /de/at/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /de/at/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:50:52 GMT
Last-Modified: Mon, 22 Aug 2011 15:23:28 GMT
ETag: 634495982080000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279251042500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:40:52 GMT
Content-Length: 87462

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="de"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.5. http://www.microsoft.com/de/ch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /de/ch/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /de/ch/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:50:53 GMT
Last-Modified: Mon, 22 Aug 2011 08:57:24 GMT
ETag: 634495750440000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438390742600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:40:52 GMT
Content-Length: 86876

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="de"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.6. http://www.microsoft.com/download/en/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /download/en/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /download/en/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:38:23 GMT
Last-Modified: Tue, 23 Aug 2011 17:51:05 GMT
ETag: 634496934650000000
Server: Microsoft-IIS/7.5
Set-Cookie: MS_SRDR=downloadOptInState=optIn&downloadSiteID=982E5968-67CF-4DCD-891E-39CC43A50DDB; expires=Sat, 27-Aug-2011 19:28:23 GMT; path=/
X-AspNet-Version: 2.0.50727
VTag: 791192410300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:23 GMT
Content-Length: 144873

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
</script><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script></head><body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...

5.7. http://www.microsoft.com/en-us/cloud/cloudpowersolutions/private_cloud.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/cloud/cloudpowersolutions/private_cloud.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/cloud/cloudpowersolutions/private_cloud.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:54 GMT
Last-Modified: Thu, 25 Aug 2011 18:44:10 GMT
ETag: 634498694500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 43872131000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:54 GMT
Content-Length: 75424

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
</title> <script type="text/javascript" src="http://static.meteorsolutions.com/metsol.js"></script>
...[SNIP]...
<ul class="adunit"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</noscript> <script type="text/javascript" src="http://dnn506yrbagrg.cloudfront.net/pages/scripts/0011/1935.js"> </script>
...[SNIP]...

5.8. http://www.microsoft.com/en-us/cloud/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/cloud/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/cloud/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:54 GMT
Last-Modified: Thu, 25 Aug 2011 18:44:10 GMT
ETag: 634498694500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79181230600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:53 GMT
Content-Length: 27709

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
</title> <script type="text/javascript" src="http://static.meteorsolutions.com/metsol.js"></script>
...[SNIP]...
<ul class="adunit"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</noscript> <script type="text/javascript" src="http://dnn506yrbagrg.cloudfront.net/pages/scripts/0011/1935.js"> </script>
...[SNIP]...

5.9. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/default.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314325096447-13143250964471911\\\"}\"}}","Expires":"\/Date(1322101096538)\/"}; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 02:18:21&Microsoft.VisitStartDate=08/26/2011 02:18:21&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=104&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314314327014:ss=1314314308776

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: MS0=0656da9ad4f847d7ae457c6228fdf677; domain=microsoft.com; expires=Fri, 26-Aug-2011 18:24:19 GMT; path=/
Set-Cookie: MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381257669-13143812576698286\\\"}\"}}","Expires":"\/Date(1322157259536)\/"}; domain=microsoft.com; expires=Thu, 24-Nov-2011 17:54:19 GMT; path=/
VTag: 279734142200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:54:19 GMT
Content-Length: 212167

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...
<body class="ltr" bi:type="hpMaster"> <script src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...
<div class="hpMst_Content" bi:type="hpPage"> <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.10. http://www.microsoft.com/en-us/dynamics/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/dynamics/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en-us/dynamics/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:55 GMT
Last-Modified: Thu, 25 Aug 2011 19:22:07 GMT
ETag: 634498717270000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279104031100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:54 GMT
Content-Length: 68703

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.11. http://www.microsoft.com/en-us/security_essentials/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/security_essentials/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en-us/security_essentials/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:57 GMT
Last-Modified: Mon, 18 Jul 2011 20:49:00 GMT
ETag: 634465937400000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791254330800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:56 GMT
Content-Length: 127233

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en"><head><title>Virus, Spyware & Malware Protection |
...[SNIP]...
<body bi:type="oneMscomMaster"> <script src="http://code.jquery.com/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...

5.12. http://www.microsoft.com/en/ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/ca/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en/ca/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:21 GMT
Last-Modified: Tue, 23 Aug 2011 04:00:40 GMT
ETag: 634496436400000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 791757731000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:21 GMT
Content-Length: 88412

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.13. http://www.microsoft.com/en/hk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/hk/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en/hk/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:22 GMT
Last-Modified: Wed, 24 Aug 2011 08:10:13 GMT
ETag: 634497450130000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 438185031600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:22 GMT
Content-Length: 86360

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_0"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.14. http://www.microsoft.com/en/in/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/in/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en/in/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:23 GMT
Last-Modified: Tue, 09 Aug 2011 05:51:24 GMT
ETag: 634484406840000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 791920630500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:23 GMT
Content-Length: 69782

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.15. http://www.microsoft.com/en/mt/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/mt/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en/mt/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:25 GMT
Last-Modified: Fri, 08 Apr 2011 11:18:09 GMT
ETag: 634378330890000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 279872531300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:25 GMT
Content-Length: 101984

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.16. http://www.microsoft.com/en/us/sitemap.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/us/sitemap.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /en/us/sitemap.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:40 GMT
Last-Modified: Thu, 18 Aug 2011 06:02:30 GMT
ETag: 634492189500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 43845200600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:39 GMT
Content-Length: 106483

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<div class="smp_vertAd" style="width:160px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.17. http://www.microsoft.com/es/ar/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /es/ar/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /es/ar/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:44 GMT
Last-Modified: Thu, 25 Aug 2011 13:51:50 GMT
ETag: 634498519100000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 27950300800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:43 GMT
Content-Length: 55097

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="es"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_1"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.18. http://www.microsoft.com/es/co/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /es/co/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /es/co/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:45 GMT
Last-Modified: Thu, 11 Aug 2011 20:44:03 GMT
ETag: 634486670430000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791766100600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:45 GMT
Content-Length: 79838

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="es"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.19. http://www.microsoft.com/es/es/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /es/es/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /es/es/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:48 GMT
Last-Modified: Wed, 24 Aug 2011 08:22:58 GMT
ETag: 634497457780000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 43892500300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:47 GMT
Content-Length: 70312

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="es"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.20. http://www.microsoft.com/es/mx/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /es/mx/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /es/mx/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:49 GMT
Last-Modified: Thu, 25 Aug 2011 15:55:22 GMT
ETag: 634498593220000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279265400400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:49 GMT
Content-Length: 68969

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="es"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.21. http://www.microsoft.com/es/xl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /es/xl/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /es/xl/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:53:58 GMT
Last-Modified: Thu, 25 Aug 2011 20:16:16 GMT
ETag: 634498749760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279241400500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:43:57 GMT
Content-Length: 74064

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="es"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_0"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.22. http://www.microsoft.com/events/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /events/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /events/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=iso-8859-1
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:17:23 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438633900100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:22 GMT
Content-Length: 44846


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><META name="MS.LOCALE" content="en-us"><title>Events and Webcasts Home Page</title><meta name="descriptio
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.23. http://www.microsoft.com/events/series/technetmms.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /events/series/technetmms.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /events/series/technetmms.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279123800700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:21 GMT
Content-Length: 34747


<html>
<LINK href="css/seriesTabbed.css" type="text/css" rel="stylesheet" />
<script type='text/javascript' language='Javascript' src='/events/mnp_utility.mspx/menujs?mnpshell=%2fevents%2fConfigur
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.24. http://www.microsoft.com/fi/fi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /fi/fi/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /fi/fi/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:06 GMT
Last-Modified: Wed, 24 Aug 2011 10:08:40 GMT
ETag: 634497521200000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438928942100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:06 GMT
Content-Length: 77500

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="fi"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.25. http://www.microsoft.com/forefront/en/us/identity-access-management.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /forefront/en/us/identity-access-management.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /forefront/en/us/identity-access-management.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:36 GMT
Last-Modified: Fri, 17 Dec 2010 20:29:07 GMT
ETag: 634281857470000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438263630700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:36 GMT
Content-Length: 71174

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.26. http://www.microsoft.com/forefront/endpoint-protection/en/us/try-it.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /forefront/endpoint-protection/en/us/try-it.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /forefront/endpoint-protection/en/us/try-it.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:40 GMT
Last-Modified: Mon, 03 Jan 2011 17:23:25 GMT
ETag: 634296434050000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791682031000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:39 GMT
Content-Length: 32887

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633959010811208960" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.27. http://www.microsoft.com/global/systemcenter/pl/pl/PublishingImages/Hero-SCHome-NonSL.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /global/systemcenter/pl/pl/PublishingImages/Hero-SCHome-NonSL.jpg

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /global/systemcenter/pl/pl/PublishingImages/Hero-SCHome-NonSL.jpg HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/systemcenter/pl/pl/default.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370497018:ss=1314370462746; MS0=0656da9ad4f847d7ae457c6228fdf677

Response

HTTP/1.1 404 Page not available
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279507342100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:56:53 GMT
Content-Length: 106870

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><base href
...[SNIP]...
<div class="smp_vertAd" style="width:160px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.28. http://www.microsoft.com/global/systemcenter/pl/pl/RenderingAssets/browserSpecificCSS.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /global/systemcenter/pl/pl/RenderingAssets/browserSpecificCSS.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /global/systemcenter/pl/pl/RenderingAssets/browserSpecificCSS.js HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/systemcenter/pl/pl/default.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370497018:ss=1314370462746; MS0=0656da9ad4f847d7ae457c6228fdf677

Response

HTTP/1.1 404 Page not available
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438614843100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:56:33 GMT
Content-Length: 106869

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><base href
...[SNIP]...
<div class="smp_vertAd" style="width:160px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.29. http://www.microsoft.com/he/il/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /he/il/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /he/il/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:17 GMT
Last-Modified: Wed, 24 Aug 2011 08:39:45 GMT
ETag: 634497467850000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79123042600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:16 GMT
Content-Length: 79184

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="rtl" lang="he"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.30. http://www.microsoft.com/hu/hu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /hu/hu/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /hu/hu/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:02 GMT
Last-Modified: Wed, 24 Aug 2011 09:46:42 GMT
ETag: 634497508020000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279399742000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:01 GMT
Content-Length: 64561

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="hu"><head><title>
...[SNIP]...
</script><script type="text/javascript" src="http://code.jquery.com/jquery-latest.js"></script>
...[SNIP]...

5.31. http://www.microsoft.com/hy/am/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /hy/am/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /hy/am/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:14 GMT
Last-Modified: Wed, 12 Jan 2011 22:49:41 GMT
ETag: 634304405810000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791176143000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:14 GMT
Content-Length: 110874

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="hy"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.32. http://www.microsoft.com/industry/government/css/solutions_stylesheet.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /industry/government/css/solutions_stylesheet.css

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /industry/government/css/solutions_stylesheet.css HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.microsoft.com
Cookie: msdn=L=1033; A=I&I=AxUFAAAAAABrBwAAEAfVJtxA+clHaDOfUxclgQ!!&M=1; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=a1233315-4e9b-463b-9f55-ca31a12b010d&Microsoft.CreationDate=08/26/2011 20:33:22&Microsoft.LastVisitDate=08/26/2011 20:35:43&Microsoft.NumberOfVisits=2&SessionCookie.Id=E7A396DF492CE888BCDAD2B976D4DDEE; MSID=Microsoft.CreationDate=08/26/2011 20:33:22&Microsoft.LastVisitDate=08/26/2011 20:35:43&Microsoft.VisitStartDate=08/26/2011 20:33:22&Microsoft.CookieId=c2afb6c4-b8d4-4699-b9a5-91b450a8c97a&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=2&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0424-4116-0868-9284; MC1=GUID=b9a5a4f722f8264b834cb9d69a104d9f&HASH=f7a4&LV=20118&V=3; MS0=fbe10a73803743f39b0fa28318052ff2

Response

HTTP/1.1 404 Page not available
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279820942800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:38:07 GMT
Content-Length: 106854

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><base href
...[SNIP]...
<div class="smp_vertAd" style="width:160px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.33. http://www.microsoft.com/industry/government/solutions/usgcb/images/spacer.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /industry/government/solutions/usgcb/images/spacer.gif

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /industry/government/solutions/usgcb/images/spacer.gif HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: www.microsoft.com
Cookie: msdn=L=1033; A=I&I=AxUFAAAAAABrBwAAEAfVJtxA+clHaDOfUxclgQ!!&M=1; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=a1233315-4e9b-463b-9f55-ca31a12b010d&Microsoft.CreationDate=08/26/2011 20:33:22&Microsoft.LastVisitDate=08/26/2011 20:35:43&Microsoft.NumberOfVisits=2&SessionCookie.Id=E7A396DF492CE888BCDAD2B976D4DDEE; MSID=Microsoft.CreationDate=08/26/2011 20:33:22&Microsoft.LastVisitDate=08/26/2011 20:35:43&Microsoft.VisitStartDate=08/26/2011 20:33:22&Microsoft.CookieId=c2afb6c4-b8d4-4699-b9a5-91b450a8c97a&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=2&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0424-4116-0868-9284; MC1=GUID=b9a5a4f722f8264b834cb9d69a104d9f&HASH=f7a4&LV=20118&V=3; MS0=fbe10a73803743f39b0fa28318052ff2

Response

HTTP/1.1 404 Page not available
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438872341700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:38:03 GMT
Content-Length: 106859

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><base href
...[SNIP]...
<div class="smp_vertAd" style="width:160px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.34. http://www.microsoft.com/it/it/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /it/it/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /it/it/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:01 GMT
Last-Modified: Fri, 26 Aug 2011 16:04:03 GMT
ETag: 634499462430000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79112243100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:00 GMT
Content-Length: 95946

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="it"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.35. http://www.microsoft.com/ka/ge/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /ka/ge/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ka/ge/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:09 GMT
Last-Modified: Mon, 18 Apr 2011 13:19:49 GMT
ETag: 634387043890000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791502442500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:08 GMT
Content-Length: 70379

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="ka"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.36. http://www.microsoft.com/ko/kr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /ko/kr/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ko/kr/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:22 GMT
Last-Modified: Mon, 22 Aug 2011 01:53:38 GMT
ETag: 634495496180000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438580642800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:21 GMT
Content-Length: 122626

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="ko"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.37. http://www.microsoft.com/learning/en/us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /learning/en/us/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /learning/en/us/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:58:51 GMT
Last-Modified: Wed, 10 Aug 2011 13:05:35 GMT
ETag: 634485531350000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791375031800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:48:50 GMT
Content-Length: 79103

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.38. http://www.microsoft.com/learning/en/us/training/products.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /learning/en/us/training/products.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /learning/en/us/training/products.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:58:52 GMT
Last-Modified: Wed, 10 Aug 2011 13:05:35 GMT
ETag: 634485531350000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791957932300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:48:51 GMT
Content-Length: 89997

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.39. http://www.microsoft.com/maps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /maps/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /maps/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438461800400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:22 GMT
Content-Length: 22237


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<hea
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.5.2.min.js"></script>
...[SNIP]...

5.40. http://www.microsoft.com/nb/no/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /nb/no/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /nb/no/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:03 GMT
Last-Modified: Mon, 08 Aug 2011 13:07:53 GMT
ETag: 634483804730000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279872143000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:03 GMT
Content-Length: 61910

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="nb"><head><title>
...[SNIP]...
<div class="cspAd"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.41. http://www.microsoft.com/nl/be/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /nl/be/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /nl/be/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:59:24 GMT
Last-Modified: Mon, 22 Aug 2011 06:55:36 GMT
ETag: 634495677360000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438183832400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:49:23 GMT
Content-Length: 87986

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="nl"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.42. http://www.microsoft.com/nl/nl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /nl/nl/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /nl/nl/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:59:29 GMT
Last-Modified: Thu, 25 Aug 2011 08:44:57 GMT
ETag: 634498334970000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438989531800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:49:29 GMT
Content-Length: 76465

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="nl"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.43. http://www.microsoft.com/online/pl-pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /online/pl-pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /online/pl-pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279807143200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:28 GMT
Content-Length: 33625


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><m
...[SNIP]...
<!-- This control writes out the Atlas JavaScript tag --><script language="JavaScript" src="http://view.atdmt.com/jaction/mrth2e_FY11BPOSFY11EntHmpgHomepageLP_1"></script>
...[SNIP]...

5.44. http://www.microsoft.com/pl-pl/cloud/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pl-pl/cloud/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pl-pl/cloud/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:16:29 GMT
Last-Modified: Tue, 28 Jun 2011 10:04:28 GMT
ETag: 634448270680000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279682143100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:28 GMT
Content-Length: 25757

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><!-- mobile redirector --><head id="ctl00_Head1"><meta id="ctl00_metaCompatibility" http-equiv="X-UA-Compatible" conten
...[SNIP]...
</span><script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...
<ul class="adunit"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</noscript> <script type="text/javascript" src="http://dnn506yrbagrg.cloudfront.net/pages/scripts/0011/1935.js"> </script>
...[SNIP]...

5.45. http://www.microsoft.com/pl-pl/security_essentials/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pl-pl/security_essentials/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pl-pl/security_essentials/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:16:28 GMT
Last-Modified: Tue, 19 Jul 2011 01:54:34 GMT
ETag: 634466120740000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438405643100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:28 GMT
Content-Length: 124585

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="pl"><head><title>Ochrona przed wirusami, programami sz
...[SNIP]...
<body bi:type="oneMscomMaster"> <script src="http://code.jquery.com/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...

5.46. http://www.microsoft.com/pl/PL/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pl/PL/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pl/PL/default.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl%7CstickyTabIndex%3A0%2Cpath%3A/pl/pl; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:55:35&Microsoft.NumberOfVisits=3&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MS0=0656da9ad4f847d7ae457c6228fdf677; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; s_cc=true; s_sq=%5B%5BB%5D%5D; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:56:24&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=110&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370582111:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:06:37 GMT
Last-Modified: Fri, 26 Aug 2011 15:07:48 GMT
ETag: 634499428680000000
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279336142000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:56:37 GMT
Content-Length: 95286

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_0"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.47. http://www.microsoft.com/pl/pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pl/pl/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pl/pl/ HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/en-us/default.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.NumberOfVisits=1&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=105&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; MS0=0656da9ad4f847d7ae457c6228fdf677; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370477301:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:04:44 GMT
Last-Modified: Fri, 26 Aug 2011 15:07:48 GMT
ETag: 634499428680000000
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279834142400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:54:44 GMT
Content-Length: 95286

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_0"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.48. http://www.microsoft.com/pl/pl/sitemap.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pl/pl/sitemap.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pl/pl/sitemap.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:04 GMT
Last-Modified: Tue, 09 Aug 2011 05:00:29 GMT
ETag: 634484376290000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438217442400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:04 GMT
Content-Length: 92894

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head><title>
...[SNIP]...
<div class="smp_vertAd" style="width:180px;"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.49. http://www.microsoft.com/poland/centrumprasowe/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/centrumprasowe/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/centrumprasowe/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791979942700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:01 GMT
Content-Length: 18534


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Microsoft Cent
...[SNIP]...
<div id="add" class="adserving">
   <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.50. http://www.microsoft.com/poland/developer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/developer/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/developer/ HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/pl/pl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370497018:ss=1314370462746; MS0=0656da9ad4f847d7ae457c6228fdf677

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791441742200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:56:55 GMT
Content-Length: 17508

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<div id="add">
   <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.51. http://www.microsoft.com/poland/developer/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/developer/Default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/developer/Default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438339600200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:24 GMT
Content-Length: 17508

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:la
...[SNIP]...
<div id="add">
   <script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.52. http://www.microsoft.com/poland/gotowydopracy/index.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/gotowydopracy/index.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/gotowydopracy/index.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279235210100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:59:53 GMT
Content-Length: 7782


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pl" lang="pl">
<head><meta http-e
...[SNIP]...
</script>

<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.53. http://www.microsoft.com/poland/hardware/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/hardware/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /poland/hardware/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791376300400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:41 GMT
Content-Length: 31878


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link type='text/c
...[SNIP]...
</title>
<script language="JavaScript" src="http://content.channelintelligence.com/scripts/ykb_PopupWindow.js"
type="text/javascript">
</script>
<script language="JavaScript" src="http://microsoft.links.channelintelligence.com/scripts/cii_CBL_DataService_API.asp"
type="text/javascript">
</script>
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.54. http://www.microsoft.com/poland/hardware/digitalcommunication/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/hardware/digitalcommunication/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/hardware/digitalcommunication/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:01:40 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791999500800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:39 GMT
Content-Length: 38317


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=windows-1250"><META name="MS.LOCALE" content="pl-pl">

<link rel="stylesheet" type="text/css" href="/poland/har
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.55. http://www.microsoft.com/poland/hardware/gaming/gaming.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/hardware/gaming/gaming.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/hardware/gaming/gaming.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:01:41 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438118500300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:40 GMT
Content-Length: 28739


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=windows-1250"><META name="MS.LOCALE" content="pl-pl">

<link rel="stylesheet" type="text/css" href="/poland/har
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.56. http://www.microsoft.com/poland/hardware/mouseandkeyboard/productlist.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/hardware/mouseandkeyboard/productlist.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /poland/hardware/mouseandkeyboard/productlist.aspx?type=Keyboard&AdditionalType=Sets HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791376300400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:36 GMT
Content-Length: 46306


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

<script src="http://content.channelintelligence.com/scripts/ykb_PopupWindow.js" type="text/javascript"></script>

<script src="http://microsoft.links.channelintelligence.com/scripts/cii_CBL_DataService_API.asp" type="text/javascript"></script>

<script src="http://content.channelintelligence.com/scripts/cii_embeddedfunctions.asp" type="text/javascript"></script>
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.57. http://www.microsoft.com/poland/office/zrob-to-najlepiej/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/ HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/pl/pl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl%7CstickyTabIndex%3A0%2Cpath%3A/pl/pl; MS0=0656da9ad4f847d7ae457c6228fdf677; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370523587:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279110600500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:00:46 GMT
Content-Length: 20061


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>


       
...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.58. http://www.microsoft.com/poland/office/zrob-to-najlepiej/OfficeMobile2010.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/OfficeMobile2010.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/OfficeMobile2010.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791467100200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:00:57 GMT
Content-Length: 17169


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.59. http://www.microsoft.com/poland/office/zrob-to-najlepiej/excel.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/excel.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/excel.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791468600100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:00 GMT
Content-Length: 21547


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.60. http://www.microsoft.com/poland/office/zrob-to-najlepiej/onenote.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/onenote.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/onenote.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279963900500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:00 GMT
Content-Length: 21773


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.61. http://www.microsoft.com/poland/office/zrob-to-najlepiej/outlook.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/outlook.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/outlook.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791376300400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:00 GMT
Content-Length: 21932


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.62. http://www.microsoft.com/poland/office/zrob-to-najlepiej/pakiety.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/pakiety.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/pakiety.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279952410200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:00:32 GMT
Content-Length: 21816


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.63. http://www.microsoft.com/poland/office/zrob-to-najlepiej/powerpoint.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/powerpoint.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/powerpoint.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438939200100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:00 GMT
Content-Length: 22361


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.64. http://www.microsoft.com/poland/office/zrob-to-najlepiej/shops.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/shops.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/shops.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279833100200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:00:57 GMT
Content-Length: 21435


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>


       <
...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.65. http://www.microsoft.com/poland/office/zrob-to-najlepiej/sitemap.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/sitemap.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/sitemap.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79120000600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:00 GMT
Content-Length: 16552


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.66. http://www.microsoft.com/poland/office/zrob-to-najlepiej/word.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/office/zrob-to-najlepiej/word.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/office/zrob-to-najlepiej/word.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791797200700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:00:56 GMT
Content-Length: 21759


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

   <head>

       

...[SNIP]...
</a>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.67. http://www.microsoft.com/poland/pocztahotmail/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/pocztahotmail/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/pocztahotmail/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 43866742300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:02 GMT
Content-Length: 16335


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   W
...[SNIP]...
</script>
   <script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.68. http://www.microsoft.com/poland/protect/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/protect/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/protect/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:05:24 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79142041900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:05:24 GMT
Content-Length: 33246


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=windows-1250"><META name="MS.LOCALE" content="pl-pl"><title>Microsoft . bezpiecze.stwo w domu . zapobieganie kradzie.
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.69. http://www.microsoft.com/poland/technet/security/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/technet/security/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/technet/security/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:01:19 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279963900500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:01:18 GMT
Content-Length: 42321


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=windows-1250"><META name="MS.LOCALE" content="pl-pl"><title>Centrum Bezpiecze.stwa Microsoft TechNet</title><meta nam
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.70. http://www.microsoft.com/poland/twojanowa/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/twojanowa/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/twojanowa/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438481743200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:02 GMT
Content-Length: 11727


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pl" lang="pl">
<ME
...[SNIP]...
</script>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.71. http://www.microsoft.com/poland/windows/windowsintune/pc-management.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/windows/windowsintune/pc-management.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/windows/windowsintune/pc-management.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279157831600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:03:49 GMT
Content-Length: 102752


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html dir="ltr" xmlns:og="http://opengraphprotocol.org/schema/" xmlns:fb="http://developers.facebook.com
...[SNIP]...
<div id="ctl00_ctl00_ctl00_BaseBody_uxAdvertisement_uxStandardAd">
   
<script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.72. http://www.microsoft.com/poland/windowscool/video-02.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/windowscool/video-02.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /poland/windowscool/video-02.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279855241900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:06 GMT
Content-Length: 19632


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv=
...[SNIP]...
</script>
<script type="text/javascript" src="http://pro.hit.gemius.pl/gemius.js"></script>
...[SNIP]...

5.73. http://www.microsoft.com/products/works/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /products/works/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /products/works/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=iso-8859-1
Expires: -1
Last-Modified: Fri, 26 Aug 2011 12:00:46 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 43820400200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:25 GMT
Content-Length: 28581


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><META name="MS.LOCALE" content="en-us">

<link rel="stylesheet" type="text/css" Href="/products/wor
...[SNIP]...
<center><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.74. http://www.microsoft.com/pt/br/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /pt/br/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pt/br/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 20:14:33 GMT
Last-Modified: Thu, 25 Aug 2011 14:52:30 GMT
ETag: 634498555500000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438818430800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:04:32 GMT
Content-Length: 96841

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pt"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.75. http://www.microsoft.com/ru/ru/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /ru/ru/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ru/ru/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:12 GMT
Last-Modified: Fri, 26 Aug 2011 12:36:13 GMT
ETag: 634499337730000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79112243100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:11 GMT
Content-Length: 169061

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="ru"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.76. http://www.microsoft.com/security/pc-security/conficker.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security/pc-security/conficker.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/pc-security/conficker.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:04 GMT
Last-Modified: Wed, 10 Aug 2011 21:16:33 GMT
ETag: 634485825930000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438706831600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:04 GMT
Content-Length: 92694

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en"
...[SNIP]...
<!-- for the ad control --><script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

5.77. http://www.microsoft.com/security/pc-security/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security/pc-security/default.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/pc-security/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:04 GMT
Last-Modified: Tue, 09 Aug 2011 18:14:29 GMT
ETag: 634484852690000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791603730900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:04 GMT
Content-Length: 91012

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en"
...[SNIP]...
<!-- for the ad control --><script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

5.78. http://www.microsoft.com/security/pc-security/firewalls-whatis.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security/pc-security/firewalls-whatis.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/pc-security/firewalls-whatis.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:04 GMT
Last-Modified: Mon, 11 Jul 2011 17:13:13 GMT
ETag: 634459759930000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438224830800000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:03 GMT
Content-Length: 86405

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en"
...[SNIP]...
<!-- for the ad control --><script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

5.79. http://www.microsoft.com/security/pc-security/malware-removal.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security/pc-security/malware-removal.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/pc-security/malware-removal.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:03 GMT
Last-Modified: Wed, 10 Aug 2011 21:16:48 GMT
ETag: 634485826080000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791544430700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:03 GMT
Content-Length: 89839

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en"
...[SNIP]...
<!-- for the ad control --><script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

5.80. http://www.microsoft.com/security/resources/antivirus-whatis.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security/resources/antivirus-whatis.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/resources/antivirus-whatis.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:05 GMT
Last-Modified: Wed, 10 Aug 2011 21:15:48 GMT
ETag: 634485825480000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279726431500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:04 GMT
Content-Length: 86122

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" xml:lang="en" lang="en"
...[SNIP]...
<!-- for the ad control --><script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...

5.81. http://www.microsoft.com/showcase/pl/pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /showcase/pl/pl/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /showcase/pl/pl/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 1.0
X-AspNet-Version: 2.0.50727
VTag: 438307943000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:42 GMT
Content-Length: 52929


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...
</div>
<script type='text/javascript' src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.82. http://www.microsoft.com/showcase/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /showcase/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /showcase/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 1.0
X-AspNet-Version: 2.0.50727
VTag: 279225741700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:37 GMT
Content-Length: 53244


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><title
...[SNIP]...
</div>
<script type='text/javascript' src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.83. http://www.microsoft.com/sqlserver/en/us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /sqlserver/en/us/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /sqlserver/en/us/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:45 GMT
Last-Modified: Thu, 25 Aug 2011 19:58:15 GMT
ETag: 634498738950000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279891131200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:36 GMT
Content-Length: 64628

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.84. http://www.microsoft.com/sv/se/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /sv/se/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /sv/se/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:07 GMT
Last-Modified: Tue, 23 Aug 2011 15:19:43 GMT
ETag: 634496843830000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791532842300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:07 GMT
Content-Length: 42686

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="sv"><head><title>
...[SNIP]...
<li id="vrtc_ad_default" class="vrtc_ad_hidden"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.85. http://www.microsoft.com/systemcenter/configurationmanager/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/configurationmanager/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/configurationmanager/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:24 GMT
Last-Modified: Tue, 12 Oct 2010 14:20:00 GMT
ETag: 634224648000000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791544430700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:24 GMT
Content-Length: 42595

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.86. http://www.microsoft.com/systemcenter/dataprotectionmanager/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/dataprotectionmanager/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/dataprotectionmanager/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:27 GMT
Last-Modified: Tue, 12 Oct 2010 14:24:07 GMT
ETag: 634224650470000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 27989431600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:25 GMT
Content-Length: 40503

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.87. http://www.microsoft.com/systemcenter/en/us/dynamic-data-centers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/en/us/dynamic-data-centers.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/en/us/dynamic-data-centers.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:09 GMT
Last-Modified: Tue, 12 Jul 2011 15:13:22 GMT
ETag: 634460552020000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438120831300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:07 GMT
Content-Length: 62249

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.88. http://www.microsoft.com/systemcenter/en/us/service-manager.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/en/us/service-manager.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/en/us/service-manager.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:09 GMT
Last-Modified: Tue, 12 Jul 2011 15:13:22 GMT
ETag: 634460552020000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791224231500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:09 GMT
Content-Length: 94110

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.89. http://www.microsoft.com/systemcenter/operationsmanager/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/operationsmanager/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/operationsmanager/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:23 GMT
Last-Modified: Tue, 12 Oct 2010 14:26:18 GMT
ETag: 634224651780000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279215530600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:22 GMT
Content-Length: 55198

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.90. http://www.microsoft.com/systemcenter/operationsmanager/pl/pl/whats-new.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/operationsmanager/pl/pl/whats-new.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/operationsmanager/pl/pl/whats-new.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:19 GMT
Last-Modified: Tue, 12 Oct 2010 14:26:18 GMT
ETag: 634224651780000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791224231500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:19 GMT
Content-Length: 29728

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.91. http://www.microsoft.com/systemcenter/pl/pl/datasheets.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/datasheets.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/datasheets.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:12 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791114130600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:11 GMT
Content-Length: 34496

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.92. http://www.microsoft.com/systemcenter/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/pl/pl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370493080:ss=1314370462746; MS0=0656da9ad4f847d7ae457c6228fdf677

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:05:41 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279145242200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:55:40 GMT
Content-Length: 41217

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.93. http://www.microsoft.com/systemcenter/pl/pl/key-benefits.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/key-benefits.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/key-benefits.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/systemcenter/pl/pl/default.aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.NumberOfVisits=2&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:50&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=106&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl%7CstickyTabIndex%3A0%2Cpath%3A/pl/pl; MS0=0656da9ad4f847d7ae457c6228fdf677; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370528527:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:10:48 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 27920200600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:00:48 GMT
Content-Length: 39147

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.94. http://www.microsoft.com/systemcenter/pl/pl/management-suites.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/management-suites.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/management-suites.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:16 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279918731100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:15 GMT
Content-Length: 28450

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.95. http://www.microsoft.com/systemcenter/pl/pl/news-reviews.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/news-reviews.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/news-reviews.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:12 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 27989431600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:11 GMT
Content-Length: 33960

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.96. http://www.microsoft.com/systemcenter/pl/pl/optimize-infrastructure.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/optimize-infrastructure.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/optimize-infrastructure.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:14 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791114130600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:14 GMT
Content-Length: 37753

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.97. http://www.microsoft.com/systemcenter/pl/pl/pricing-licensing.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/pricing-licensing.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/pricing-licensing.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:18 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791603730900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:17 GMT
Content-Length: 26993

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.98. http://www.microsoft.com/systemcenter/pl/pl/product-information.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/product-information.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/product-information.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:10 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438632431500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:10 GMT
Content-Length: 22950

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.99. http://www.microsoft.com/systemcenter/pl/pl/products.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/products.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/products.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:10 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438632431500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:10 GMT
Content-Length: 35437

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.100. http://www.microsoft.com/systemcenter/pl/pl/trial-software.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/trial-software.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/trial-software.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:15 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791114130600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:15 GMT
Content-Length: 34708

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.101. http://www.microsoft.com/systemcenter/pl/pl/white-papers.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/pl/pl/white-papers.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/pl/pl/white-papers.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:13 GMT
Last-Modified: Tue, 12 Oct 2010 14:12:56 GMT
ETag: 634224643760000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438632431500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:12 GMT
Content-Length: 32926

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="pl"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.102. http://www.microsoft.com/systemcenter/virtualmachinemanager/pl/pl/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /systemcenter/virtualmachinemanager/pl/pl/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /systemcenter/virtualmachinemanager/pl/pl/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:28 GMT
Last-Modified: Tue, 12 Oct 2010 14:34:49 GMT
ETag: 634224656890000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438120831300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:26 GMT
Content-Length: 46203

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head id="ctl
...[SNIP]...
<div id="AdControl633355178776511904" class="adControl"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.103. http://www.microsoft.com/ukr/ua/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /ukr/ua/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ukr/ua/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:14 GMT
Last-Modified: Tue, 23 Aug 2011 14:02:19 GMT
ETag: 634496797390000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791804742000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:13 GMT
Content-Length: 131091

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="ukr"><head><title
...[SNIP]...
<meta name="DCSext.wt_pt" content="HP" scheme="" /><script type="text/javascript" src="http://mc.yandex.ru/resource/watch.js"></script>
...[SNIP]...

5.104. http://www.microsoft.com/windows/products/winfamily/windowshomeserver/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windows/products/winfamily/windowshomeserver/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windows/products/winfamily/windowshomeserver/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279374242200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:11 GMT
Content-Length: 59176


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=utf-16"><title>Windows Home Server ... media server, backup and data recovery solution</title><meta name="description
...[SNIP]...
</script><script language="JavaScript" src="http://view.atdmt.com/jaction/FY10_WindowsHomeServer_Vue_Ini_LP"></script>
...[SNIP]...

5.105. http://www.microsoft.com/windowsazure/free-trial/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsazure/free-trial/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsazure/free-trial/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:28 GMT
Last-Modified: Wed, 17 Aug 2011 18:13:46 GMT
ETag: 634491764260000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279454030700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:28 GMT
Content-Length: 20616

...<!DOCTYPE html><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"> <head><title>Sign up for the Windows Azure Platform Free Trial | Windows Azure Platform</title><meta http-equiv="X-
...[SNIP]...
<![endif]--> <script src="http://code.jquery.com/jquery-1.5.1.min.js" type="text/javascript"></script>
...[SNIP]...

5.106. http://www.microsoft.com/windowsmobile/pl-pl/business/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/business/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/business/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:15 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438657242100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:14 GMT
Content-Length: 57762


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.107. http://www.microsoft.com/windowsmobile/pl-pl/devices/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/devices/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/devices/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:17 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279440542000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:17 GMT
Content-Length: 64950


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.108. http://www.microsoft.com/windowsmobile/pl-pl/devices/details.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/devices/details.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/devices/details.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:28:30 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279231710100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:30 GMT
Content-Length: 52149


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.109. http://www.microsoft.com/windowsmobile/pl-pl/devices/smartphones.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/devices/smartphones.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/devices/smartphones.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:18 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279236041900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:18 GMT
Content-Length: 114124


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.110. http://www.microsoft.com/windowsmobile/pl-pl/downloads/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/downloads/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/downloads/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:06:49 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438424642200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:49 GMT
Content-Length: 60500


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.111. http://www.microsoft.com/windowsmobile/pl-pl/downloads/microsoft/office-outlook-mobile.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/downloads/microsoft/office-outlook-mobile.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/downloads/microsoft/office-outlook-mobile.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:06:52 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438250941700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:52 GMT
Content-Length: 68919


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.112. http://www.microsoft.com/windowsmobile/pl-pl/downloads/microsoft/software-office-mobile.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/downloads/microsoft/software-office-mobile.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/downloads/microsoft/software-office-mobile.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:21 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791736842700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:21 GMT
Content-Length: 41294


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.113. http://www.microsoft.com/windowsmobile/pl-pl/meet/choice-is-yours.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/choice-is-yours.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/choice-is-yours.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:24 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438657242100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:23 GMT
Content-Length: 61889


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.114. http://www.microsoft.com/windowsmobile/pl-pl/meet/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/default.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 19:06:34 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279649742300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:24 GMT
Content-Length: 56161


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.115. http://www.microsoft.com/windowsmobile/pl-pl/meet/just-the-facts.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/just-the-facts.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/just-the-facts.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:25 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279374242200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:25 GMT
Content-Length: 61407


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.116. http://www.microsoft.com/windowsmobile/pl-pl/meet/life-in-touch.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/life-in-touch.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/life-in-touch.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:26 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438657242100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:25 GMT
Content-Length: 63266


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.117. http://www.microsoft.com/windowsmobile/pl-pl/meet/microsoft-applications.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/microsoft-applications.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/microsoft-applications.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:27 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279374242200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:26 GMT
Content-Length: 59916


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.118. http://www.microsoft.com/windowsmobile/pl-pl/meet/secure-your-stuff.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/secure-your-stuff.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/secure-your-stuff.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:33 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438619041900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:32 GMT
Content-Length: 60925


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.119. http://www.microsoft.com/windowsmobile/pl-pl/meet/windows-to-go.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/meet/windows-to-go.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/meet/windows-to-go.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:27 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438249642500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:34 GMT
Content-Length: 64023


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.120. http://www.microsoft.com/windowsmobile/pl-pl/sitemap.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/sitemap.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/sitemap.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:14:57 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438810443100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:14:56 GMT
Content-Length: 64900


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.121. http://www.microsoft.com/windowsmobile/pl-pl/worldwide.mspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsmobile/pl-pl/worldwide.mspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsmobile/pl-pl/worldwide.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=windows-1250
Expires: -1
Last-Modified: Fri, 26 Aug 2011 20:15:05 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438810443100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:15:05 GMT
Content-Length: 66878


<html xmlns:MED="null" xmlns:IP="http://www.microsoft.com/MSCOM/MNP2/Schemas" xmlns:mnp="http://www.microsoft.com/MSCOM/MNP2" dir="LTR"><head><META http-equiv="Content-Type" content="text/html; chars
...[SNIP]...
<!-- Call to DAP.js Library (in INT) -->
<script type="text/javascript" src="http://ads1.msn.com/library/dap.js"></script>
...[SNIP]...

5.122. http://www.microsoft.com/windowsphone/en-us/apps/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsphone/en-us/apps/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsphone/en-us/apps/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791480443200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:30:04 GMT
Content-Length: 30529

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!-- Portal Version: 01.03.1125.0002 -->
<!-- Render date: 8/26/2011 11:30:0
...[SNIP]...
</script>
<script src='http://ads1.msn.com/library/dap.js' type="text/javascript"></script>
...[SNIP]...

5.123. http://www.microsoft.com/windowsphone/en-us/buy/7/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windowsphone/en-us/buy/7/default.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /windowsphone/en-us/buy/7/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438217442400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:29:57 GMT
Content-Length: 78702

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!-- Portal Version: 01.03.1125.0002 -->
<!-- Render date: 8/26/2011 11:29:5
...[SNIP]...
</script>
<script src='http://ads1.msn.com/library/dap.js' type="text/javascript"></script>
...[SNIP]...

5.124. http://www.microsoft.com/zh/hk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /zh/hk/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /zh/hk/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:23 GMT
Last-Modified: Wed, 24 Aug 2011 08:12:47 GMT
ETag: 634497451670000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279641942600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:23 GMT
Content-Length: 85051

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<li class="vrtc_ad_hidden" id="vrtc_ad_0"><script type="text/javascript" src="http://Ads1.msn.com/library/dap.js"></script>
...[SNIP]...

6. Cookie without HttpOnly flag set  previous  next
There are 6 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



6.1. http://www.microsoft.com/download/en/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /download/en/default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /download/en/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:38:23 GMT
Last-Modified: Tue, 23 Aug 2011 17:51:05 GMT
ETag: 634496934650000000
Server: Microsoft-IIS/7.5
Set-Cookie: MS_SRDR=downloadOptInState=optIn&downloadSiteID=982E5968-67CF-4DCD-891E-39CC43A50DDB; expires=Sat, 27-Aug-2011 19:28:23 GMT; path=/
X-AspNet-Version: 2.0.50727
VTag: 791192410300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:23 GMT
Content-Length: 144873

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...

6.2. http://www.microsoft.com/downloads/en/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /downloads/en/default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /downloads/en/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Location: Http://www.microsoft.com/download/en/default.aspx
Server: Microsoft-IIS/7.5
Set-Cookie: MS_SRDR=downloadOptInState=optIn&downloadSiteID=982E5968-67CF-4DCD-891E-39CC43A50DDB; expires=Sat, 25-Aug-2012 18:50:52 GMT; path=/
VTag: 438895131100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:52 GMT
Content-Length: 0


6.3. http://www.microsoft.com/downloads/en/details.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /downloads/en/details.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /downloads/en/details.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Location: Http://www.microsoft.com/download/en/details.aspx
Server: Microsoft-IIS/7.5
Set-Cookie: MS_SRDR=downloadOptInState=optIn&downloadSiteID=982E5968-67CF-4DCD-891E-39CC43A50DDB; expires=Sat, 25-Aug-2012 19:28:28 GMT; path=/
VTag: 438598810200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:27 GMT
Content-Length: 0


6.4. http://www.microsoft.com/en-us/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en-us/default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /en-us/default.aspx HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314325096447-13143250964471911\\\"}\"}}","Expires":"\/Date(1322101096538)\/"}; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 02:18:21&Microsoft.VisitStartDate=08/26/2011 02:18:21&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=104&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314314327014:ss=1314314308776

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: MS0=0656da9ad4f847d7ae457c6228fdf677; domain=microsoft.com; expires=Fri, 26-Aug-2011 18:24:19 GMT; path=/
Set-Cookie: MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381257669-13143812576698286\\\"}\"}}","Expires":"\/Date(1322157259536)\/"}; domain=microsoft.com; expires=Thu, 24-Nov-2011 17:54:19 GMT; path=/
VTag: 279734142200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:54:19 GMT
Content-Length: 212167

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html dir="ltr" lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml"
...[SNIP]...

6.5. http://www.microsoft.com/industry/government/solutions/usgcb/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /industry/government/solutions/usgcb/default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /industry/government/solutions/usgcb/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: USPS_Visitor=F,0,0,0,0,300,fea7bb9a-04cb-4d61-8606-e50d01bc4e36,0,en,8/26/2011 12:48:45 PM; expires=Fri, 26-Aug-2061 19:48:45 GMT; path=/
VTag: 438707332400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:48:46 GMT
Content-Length: 208425


<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head id="ctl00_Head1"><link id="ctl00_browserStylesheet" rel="Stylesheet" type="text/css" href="/industry/government/MNP_1.0/mnpMaster/sty
...[SNIP]...

6.6. http://www.microsoft.com/security_essentials/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /security_essentials/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /security_essentials/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: /en-us/security_essentials/geo/
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: mkt=en-us; path=/
VTag: 791619410300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:22 GMT
Content-Length: 156

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fen-us%2fsecurity_essentials%2fgeo%2f">here</a>.</h2>
</body></html>

7. Email addresses disclosed  previous  next
There are 19 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


7.1. http://www.microsoft.com/About/Legal/EN/US/IntellectualProperty/Copyright/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /About/Legal/EN/US/IntellectualProperty/Copyright/default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /About/Legal/EN/US/IntellectualProperty/Copyright/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 19:00:06 GMT
Last-Modified: Wed, 13 Jul 2011 21:09:58 GMT
ETag: 634461629980000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791447531200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:06 GMT
Content-Length: 72248

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<a href="mailto:webmaster@msn.com">webmaster@msn.com</a>
...[SNIP]...
<a href="mailto:support@hotmail.com">support@hotmail.com</a>
...[SNIP]...
<a href="mailto:abuse@hotmail.com">abuse@hotmail.com</a> or <a href="mailto:hotmailprivacy@hotmail.com">hotmailprivacy@hotmail.com</a>
...[SNIP]...
<a href="mailto:piracy@microsoft.com">piracy@microsoft.com</a>
...[SNIP]...

7.2. http://www.microsoft.com/en/ph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /en/ph/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/ph/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:37:27 GMT
Last-Modified: Wed, 10 Aug 2011 09:04:49 GMT
ETag: 634485386890000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
VTag: 79133331200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:27:26 GMT
Content-Length: 50293

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en"><head><title>
...[SNIP]...
<a href="mailto:phlisten@microsoft.com" title="Email us">
...[SNIP]...
<a href="mailto:phlisten@microsoft.com">phlisten@microsoft.com</a>
...[SNIP]...
<a href="mailto:phlisten@microsoft.com" title="Email us">
...[SNIP]...
<a href="mailto:phlisten@microsoft.com">phlisten@microsoft.com</a>
...[SNIP]...

7.3. http://www.microsoft.com/et/ee/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /et/ee/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /et/ee/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:50:54 GMT
Last-Modified: Mon, 25 Jul 2011 11:17:07 GMT
ETag: 634471642270000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438563142300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:40:53 GMT
Content-Length: 77828

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="et"><head><title>
...[SNIP]...
<a href="http://support.microsoft.com/contactus/?ws=support">MICROSOFTI KLIENDITEENINDUS JA TEHNILINE TUGI: 686 8868 E-R 8-20 estinfo@microsoft.com</a>
...[SNIP]...
<a href="mailto:rain.laane@microsoft.com">
...[SNIP]...

7.4. http://www.microsoft.com/fi/fi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /fi/fi/

Issue detail

The following email address was disclosed in the response:

Request

GET /fi/fi/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:06 GMT
Last-Modified: Wed, 24 Aug 2011 10:08:40 GMT
ETag: 634497521200000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438928942100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:06 GMT
Content-Length: 77500

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="fi"><head><title>
...[SNIP]...
<a href="mailto:finland@microsoft.com" cpgn="Highlights" cid="04-00-111LFI10031">
...[SNIP]...

7.5. http://www.microsoft.com/industry/government/solutions/usgcb/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /industry/government/solutions/usgcb/default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /industry/government/solutions/usgcb/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: USPS_Visitor=F,0,0,0,0,300,fea7bb9a-04cb-4d61-8606-e50d01bc4e36,0,en,8/26/2011 12:48:45 PM; expires=Fri, 26-Aug-2061 19:48:45 GMT; path=/
VTag: 438707332400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:48:46 GMT
Content-Length: 208425


<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head id="ctl00_Head1"><link id="ctl00_browserStylesheet" rel="Stylesheet" type="text/css" href="/industry/government/MNP_1.0/mnpMaster/sty
...[SNIP]...
<a onclick="createlink1('ContactUsEmail');" class="default_link" href="mailto:msfdcc@microsoft.com">
...[SNIP]...
<a class="default_link" href="mailto:msfdcc@microsoft.com?subject=USGCB%20inquiry">
...[SNIP]...
<a class="default_link" href="mailto:msfdcc@microsoft.com">
...[SNIP]...
<a class="default_link" href="mailto:msfdcc@microsoft.com?subject=SDCC%20inquiry">
...[SNIP]...
<a class="default_link" href="mailto:midas-qa@microsoft.com?subject=Midas%20inquiry">
...[SNIP]...
<a class="default_link" href="mailto:msfdcc@microsoft.com">
...[SNIP]...

7.6. http://www.microsoft.com/lt/lt/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /lt/lt/

Issue detail

The following email address was disclosed in the response:

Request

GET /lt/lt/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:02 GMT
Last-Modified: Tue, 16 Aug 2011 14:34:19 GMT
ETag: 634490768590000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279271442300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:01 GMT
Content-Length: 62897

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="lt"><head><title>
...[SNIP]...
<a href="/lietuva/about/contacts.mspx">Microsoft klient.. aptarnavimo centras: +370 5 2051151 (darbo d.: 8.00 ... 20.00) lithinfo@microsoft.com</a>
...[SNIP]...

7.7. http://www.microsoft.com/lv/lv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /lv/lv/

Issue detail

The following email address was disclosed in the response:

Request

GET /lv/lv/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/html; charset=utf-8
Expires: Fri, 26 Aug 2011 18:51:07 GMT
Last-Modified: Thu, 18 Aug 2011 18:00:44 GMT
ETag: 634492620440000000
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438217442400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:41:06 GMT
Content-Length: 74837

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="lv"><head><title>
...[SNIP]...
<a href="http://www.microsoft.com/latvija/about/contacts.mspx">Klientu apkalpo..ana +371 67852152 (darbdien..s 08:00-20:00) latinfo@microsoft.com</a>
...[SNIP]...

7.8. http://www.microsoft.com/poland/centrumprasowe/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/centrumprasowe/

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/centrumprasowe/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791979942700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:01 GMT
Content-Length: 18534


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Microsoft Cent
...[SNIP]...
<a href="mailto:v-mazale@microsoft.com?body=Chc.. otrzymywa.. informacje prasowe firmy Microsoft.%0A%0AImi.. i&nbsp;nazwisko:%0ARedakcja:%0Ae-mail:%0Atelefon stacjonarny:%0Afaks:%0Atelefon kom..rkowy:%0A%0ARodzaj informacji prasowych (Tak/
...[SNIP]...

7.9. http://www.microsoft.com/poland/centrumprasowe/firma/kierownictwo.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/centrumprasowe/firma/kierownictwo.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/centrumprasowe/firma/kierownictwo.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438481743200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:05:54 GMT
Content-Length: 18686


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Kierownictwo -
...[SNIP]...
<a href="mailto:v-mazale@microsoft.com?body=Chc.. otrzymywa.. informacje prasowe firmy Microsoft.%0A%0AImi.. i&nbsp;nazwisko:%0ARedakcja:%0Ae-mail:%0Atelefon stacjonarny:%0Afaks:%0Atelefon kom..rkowy:%0A%0ARodzaj informacji prasowych (Tak/
...[SNIP]...

7.10. http://www.microsoft.com/poland/centrumprasowe/firma/misja.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/centrumprasowe/firma/misja.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/centrumprasowe/firma/misja.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438547441900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:05 GMT
Content-Length: 14651


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Misja i&nbsp;w
...[SNIP]...
<a href="mailto:v-mazale@microsoft.com?body=Chc.. otrzymywa.. informacje prasowe firmy Microsoft.%0A%0AImi.. i&nbsp;nazwisko:%0ARedakcja:%0Ae-mail:%0Atelefon stacjonarny:%0Afaks:%0Atelefon kom..rkowy:%0A%0ARodzaj informacji prasowych (Tak/
...[SNIP]...

7.11. http://www.microsoft.com/poland/centrumprasowe/firma/siedziby.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/centrumprasowe/firma/siedziby.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/centrumprasowe/firma/siedziby.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279146742400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:00 GMT
Content-Length: 14742


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Siedziby firmy
...[SNIP]...
<a href="mailto:v-mazale@microsoft.com?body=Chc.. otrzymywa.. informacje prasowe firmy Microsoft.%0A%0AImi.. i&nbsp;nazwisko:%0ARedakcja:%0Ae-mail:%0Atelefon stacjonarny:%0Afaks:%0Atelefon kom..rkowy:%0A%0ARodzaj informacji prasowych (Tak/
...[SNIP]...

7.12. http://www.microsoft.com/poland/copyright/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/copyright/default.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /poland/copyright/default.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791305742500000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:05 GMT
Content-Length: 18283


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Zasady u..
...[SNIP]...
<a href="mailto:www@microsoft.com">
www@microsoft.com</a> lub <a href="mailto:webmaster@msn.com">webmaster@msn.com</a>
...[SNIP]...

7.13. http://www.microsoft.com/poland/corp/corp.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/corp/corp.htm

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/corp/corp.htm HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: text/html
Last-Modified: Fri, 12 Mar 2004 13:22:22 GMT
Accept-Ranges: bytes
ETag: "07b24d358c41:0"
Server: Microsoft-IIS/7.5
VTag: 438547441900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:09 GMT
Content-Length: 1313


<HTML><HEAD><TITLE>Zasady u.ytkowania witryny Microsoft</TITLE>
<meta http-equiv="PICS-Label"
content='(PICS-1.1 "&lt;http://www.rsac.org/ratingsv01.html&gt;" l gen true comment "RSACi North America Server" by "inet@microsoft.com &lt;mailto:inet@microsoft.com&gt;" on "1997.06.30T14:48-0500" r (n 0 s 0 v 0 l 0))'>
...[SNIP]...

7.14. http://www.microsoft.com/poland/edukacja/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/edukacja/

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/edukacja/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 791793342600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:05:24 GMT
Content-Length: 66505


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Microsoft Eduk
...[SNIP]...
<a href="mailto:janklecz@microsfot.com">janklecz@microsfot.com</a>
...[SNIP]...

7.15. http://www.microsoft.com/poland/edukacja/imaginecup/Polscy-zwyciezcy-Imagine-Cup-2011.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/edukacja/imaginecup/Polscy-zwyciezcy-Imagine-Cup-2011.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/edukacja/imaginecup/Polscy-zwyciezcy-Imagine-Cup-2011.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438346542100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:05:23 GMT
Content-Length: 19602


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="X-
...[SNIP]...
<a href="mailto:icpoland@microsoft.com">
...[SNIP]...

7.16. http://www.microsoft.com/poland/gotowydopracy/index.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/gotowydopracy/index.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/gotowydopracy/index.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279235210100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:59:53 GMT
Content-Length: 7782


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pl" lang="pl">
<head><meta http-e
...[SNIP]...
<a href="mailto:oemwspl@microsoft.com">oemwspl@microsoft.com</a>
...[SNIP]...

7.17. http://www.microsoft.com/poland/oem/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/oem/

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/oem/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438707143100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:05:23 GMT
Content-Length: 10290


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   OEM
</tit
...[SNIP]...
<a href="mailto:pomoc@microsoft.com">pomoc@microsoft.com</a>
...[SNIP]...

7.18. http://www.microsoft.com/poland/savethemoney/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /poland/savethemoney/

Issue detail

The following email address was disclosed in the response:

Request

GET /poland/savethemoney/ HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: cookieActive=true; expires=Fri, 26-Aug-2011 20:05:59 GMT; path=/
Set-Cookie: setSilverlightInstalled=true; expires=Fri, 26-Aug-2011 20:33:59 GMT; path=/
VTag: 27986630900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 20:03:59 GMT
Content-Length: 20029


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta name="desc
...[SNIP]...
<a id="writeUs" href="mailto:pomoc@microsoft.com" title="Napisz do nas" target="_blank">
...[SNIP]...

7.19. http://www.microsoft.com/windows/framework/js/omniture/s_code.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /windows/framework/js/omniture/s_code.js

Issue detail

The following email address was disclosed in the response:

Request

GET /windows/framework/js/omniture/s_code.js HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/windowsmobile/pl-pl/devices/details.mspx?id=1633
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; s_cc=true; s_sq=%5B%5BB%5D%5D; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:56:40&Microsoft.NumberOfVisits=4&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:56:40&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=111&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370597750:ss=1314370462746; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl%7CstickyTabIndex%3A0%2Cpath%3A/pl/pl%7CstickyTabIndex%3A0%2Cpath%3A/pl/PL; MS0=0656da9ad4f847d7ae457c6228fdf677

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: application/x-javascript
Last-Modified: Tue, 28 Jun 2011 20:55:25 GMT
Accept-Ranges: bytes
ETag: "801cefb3d535cc1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
VTag: 438424642200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:56:51 GMT
Content-Length: 50546

/* SiteCatalyst code version: H.20.3 */

var _om_gbls = {
   s_account : "", host : "", path : "", href : "", extraRsids : "", extraevars : "", extraRsids : "", extraRsidsArr : "",
   apl : "", spli
...[SNIP]...
=s.mr($C,(vt@tt`Zvt)`fs.hav()+q+(qs?qs:s.rq(^5)),0,id,ta);qs`g;"
+"`Rm('t')`5s.p_r)s.p_r(`I`a`g}^I(qs);^Q`u($3;`j$3`c^1,`G$O1',vb`I@M=^G=s.`Q`r=s.`Q^2=`H`m`g`5s.pg)`H^w@M=`H^weo=`H^w`Q`r=`H^w`Q^2`g`5!id@Vs.tc^ztc=1;s.flush`U()}`4#7`Ctl`0o,t,n,vo`2;s.@M=$Go`I`Q^2=t"
+";s.`Q`r=n;s.t($3}`5pg){`H^wco`0o){`P^s\"_\",1,$8`4$Go)`Cwd^wgs`0u@v`P^sun,1,$8`4s.t()`Cwd^wdc`0u@v`P^sun,$8`4s.t()}}@8=(`H`M`k`9`3'@Os^y0`Id
...[SNIP]...

8. HTML does not specify charset  previous  next
There are 2 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


8.1. http://www.microsoft.com/info/pl/privacy.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /info/pl/privacy.htm

Request

GET /info/pl/privacy.htm HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: text/html
Last-Modified: Tue, 03 Feb 2004 21:19:23 GMT
Accept-Ranges: bytes
ETag: "5d8125659beac31:0"
Server: Microsoft-IIS/7.5
VTag: 438292400400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:17:18 GMT
Content-Length: 134

<!--TOOLBAR_EXEMPT-->
<HTML>
<HEAD>
<meta http-equiv=refresh content="0;URL=/info/pl/privacy.mspx" />
</head>
<body />
</html>

8.2. http://www.microsoft.com/library/errorpages/searchMetric.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microsoft.com
Path:   /library/errorpages/searchMetric.html

Request

GET /library/errorpages/searchMetric.html HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: text/html
Last-Modified: Fri, 13 Jun 2008 16:29:48 GMT
Accept-Ranges: bytes
ETag: "50d7b7b272cdc81:0"
Server: Microsoft-IIS/7.5
VTag: 279410510200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:29 GMT
Content-Length: 437

...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >

<head>
<title>ErrorSearch
...[SNIP]...

9. HTML uses unrecognised charset  previous  next
There are 2 instances of this issue:

Issue background

Applications may specify a non-standard character set as a result of typographical errors within the code base, or because of intentional usage of an unusual character set that is not universally recognised by browsers. If the browser does not recognise the character set specified by the application, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


9.1. http://www.microsoft.com/windows/products/winfamily/umpc/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /windows/products/winfamily/umpc/default.mspx

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /windows/products/winfamily/umpc/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 438247342300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:13 GMT
Content-Length: 74473


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=utf-16"><title>Windows Ultra-Mobile PC</title><meta name="description" content="Your life. At the touch of your finge
...[SNIP]...

9.2. http://www.microsoft.com/windows/products/winfamily/windowshomeserver/default.mspx  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.microsoft.com
Path:   /windows/products/winfamily/windowshomeserver/default.mspx

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /windows/products/winfamily/windowshomeserver/default.mspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279374242200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:06:11 GMT
Content-Length: 59176


<html dir="LTR"><head><META http-equiv="Content-Type" content="text/html; charset=utf-16"><title>Windows Home Server ... media server, backup and data recovery solution</title><meta name="description
...[SNIP]...

10. Content type incorrectly stated  previous
There are 4 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


10.1. http://www.microsoft.com/global/pl/pl/RenderingAssets/NewsBand/MicrosoftNews2.xml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.microsoft.com
Path:   /global/pl/pl/RenderingAssets/NewsBand/MicrosoftNews2.xml

Issue detail

The response contains the following Content-type statement:The response states that it contains XML. However, it actually appears to contain unrecognised content.

Request

GET /global/pl/pl/RenderingAssets/NewsBand/MicrosoftNews2.xml HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: text/xml
Last-Modified: Tue, 16 Aug 2011 06:05:55 GMT
Accept-Ranges: bytes
ETag: "4543a8fda5bcc1:0"
Server: Microsoft-IIS/7.5
VTag: 791664730700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 18:50:06 GMT
Content-Length: 2638

...<rss version="2.0" >
<channel>
<title>Najnowsze informacje</title>
<link>http://www.microsoft.com/presspass</link>
<description>Najnowsze informacje Microsoft</descr
...[SNIP]...

10.2. http://www.microsoft.com/global/pl/pl/RichMedia/WindowPane_R2.xaml  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.microsoft.com
Path:   /global/pl/pl/RichMedia/WindowPane_R2.xaml

Issue detail

The response contains the following Content-type statement:The response states that it contains XML. However, it actually appears to contain unrecognised content.

Request

GET /global/pl/pl/RichMedia/WindowPane_R2.xaml HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/pl/pl/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.NumberOfVisits=1&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=105&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; MS0=0656da9ad4f847d7ae457c6228fdf677; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370484050:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: max-age=900
Content-Type: application/xaml+xml
Last-Modified: Mon, 01 Mar 2010 13:02:18 GMT
Accept-Ranges: bytes
ETag: "de7f226c3fb9ca1:0"
Server: Microsoft-IIS/7.5
VTag: 791829742000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:55:31 GMT
Content-Length: 19963

...<Canvas
   xmlns="http://schemas.microsoft.com/client/2007"
   xmlns:x="http://schemas.microsoft.com/winfx/2006/xaml"
   Width="690" Height="325"
   x:Name="FullPanelWipeIn" Loaded="onWindowPaneLoaded
...[SNIP]...

10.3. http://www.microsoft.com/pl/shared/templates/components/cspMscomNewsBand/Rss.ashx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.microsoft.com
Path:   /pl/shared/templates/components/cspMscomNewsBand/Rss.ashx

Issue detail

The response contains the following Content-type statement:The response states that it contains XML. However, it actually appears to contain unrecognised content.

Request

GET /pl/shared/templates/components/cspMscomNewsBand/Rss.ashx?u=http%3A%2F%2Fwww.microsoft.com%2Fglobal%2Fpl%2Fpl%2FRenderingAssets%2FNewsBand%2FMicrosoftNews2.xml&_=1314381284054 HTTP/1.1
Host: www.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.microsoft.com/pl/pl/
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
Accept: application/xml, text/xml, */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=9f1d1666ec7f6f4383aa85f0621e05dc&HASH=6616&LV=20117&V=3; MUID=9D76DAC5D4D147139C18D454161BD61E; .ASPXANONYMOUS=nuzFzPx-zAEkAAAAMTAyY2E5YjctZjkzYS00NmFmLWIzNDYtNzRlMDlmMDM3NjRlE3vc5R7wx2QY9vRNIbS1pMGmi4s1; msresearch=%7B%22version%22%3A%224.6%22%2C%22state%22%3A%7B%22name%22%3A%22IDLE%22%2C%22url%22%3Aundefined%2C%22timestamp%22%3A1312474856377%7D%2C%22lastinvited%22%3A1312474856377%2C%22userid%22%3A%2213124748563777579888615291566%22%2C%22vendorid%22%3A1%2C%22surveys%22%3A%5Bundefined%5D%7D; ixpLightBrowser=0; WT_NVR_RU=0=msdn|technet|expression:1=:2=; 11b31887-495f-4481-aabb-9ac86f4f6021=%7B%22parent_id%22%3A%22%22%2C%22referrer%22%3A%22http%3A%2F%2Foffice.microsoft.com%2Fen-us%2F%22%2C%22id%22%3A%22Y6kYTwuOCCK%22%2C%22wom%22%3Afalse%2C%22entry_point%22%3A%22http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Foffice365%2Fbuy-small-business.aspx%3FWT.mc_id%3DODC_ENUS_O365_OfficeHome_Hero%22%2C%22url_tag%22%3A%22NOMTAG%22%7D; WRUID=0; _opt_vi_TKSBM7DI=92AB9AFF-EDCD-481A-96EB-E249A9A9A6F3; R=200036905-8/13/2011 17:17:48; WT_O365_FPC=id=2f8d73dfdc08894d0671313262977009:lv=1313413119160:ss=1313413119160; op_refUrl=http%3A//office.microsoft.com/en-us/; op390productpage-officeskus-basicbuytgum=a0v01qd2gi278lr01j2kl5000; __unam=289c965-131c4d913ee-bef313d-2; mscomhp=stickyTabIndex%3A0%2Cpath%3A/ar/xm%7CstickyTabIndex%3A0%2Cpath%3A/nl/nl; op_siteTorb=3; A=I&I=AxUFAAAAAABjBwAA6B3K009OGZmGwcq0PuxobA!!&GO=122&M=1&CS=127Yri00011010002h10100; mcI=Thu, 01 Sep 2011 21:54:48 GMT; omniID=1312474778371_ca1f_74c4_9668_7286adce6a18; msdn=L=1033; tsa1v546=uvidd8cd1ad727e627c4d94070596659848126932; s_nr=1314309761033-Repeat; mbox=PC#1314309728929-434329.19#1316912667|check#true#1314320727|session#1314320666089-815271#1314322527; s_vnum=1314903443621%26vn%3D3; WT_NVR=1=ja-jp|maps|pinpointwidgets|en-us|zh-cn:2=ja-jp/opinionleaders|downloads/ja-jp|windowsmobile/pt-br|communities/blogs|download/en|maps/developers|fr/xf|es/ar|nl/nl|ar/xm|ar/eg|zh/hk|vi/vn|vietnam/news|vietnam/promotions|vietnam/businesssolutions|vietnam/windows7|vietnam/savingmoney|ar/ly|en/us|windows/windowsintune:3=ja-jp/opinionleaders/citizenship_ict|ja-jp/opinionleaders/edge|australia/windows/pc-scout|netherlands/windowslive/views|windowsmobile/pt-br/meet|security/msrc/collaboration|security/msrc/report|office/webapps/demo|technet/security/bulletin|vietnam/products/office|showcase/zh/cn|hk/office365/chinese|business/smb/common|egypt/ar/betheone; _opt_vi_64WS79UG=2548909D-2078-46D6-A318-EBDD3F0FE428; stFI=Sun%2C%2025%20Sep%202011%2001%3A04%3A40%20GMT; MS_WT=ta_M={"Value":"{\"_wt.control-327131-ta_M\":{\"value\":\"{\\\"runid\\\":\\\"345246\\\",\\\"testid\\\":\\\"345238\\\",\\\"trackid\\\":\\\"345249\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_M-345246-345249\\\",\\\"uid\\\":\\\"4834447173222307880\\\",\\\"userSession\\\":\\\"1314381256798-13143812567989000\\\"}\"}}","Expires":"\/Date(1322157258049)\/"}; MICROSOFTSESSIONCOOKIE=Microsoft.CookieId=65971b23-addc-49a2-b65d-18853a6efe05&Microsoft.CreationDate=08/26/2011 17:54:29&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.NumberOfVisits=1&SessionCookie.Id=AB6548AD24E88CBB5B0386F24A9A88C1; MSID=Microsoft.CreationDate=07/21/2011 22:50:10&Microsoft.LastVisitDate=08/26/2011 17:54:29&Microsoft.VisitStartDate=08/26/2011 17:54:29&Microsoft.CookieId=1f3c966e-de93-48a0-a622-dd22c1d969f7&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=105&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0656-4650-6340-5940; MS0=0656da9ad4f847d7ae457c6228fdf677; WT_FPC=id=50.23.123.106-2332126736.30164984:lv=1314370484050:ss=1314370462746

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/xml; charset=utf-8
Expires: Fri, 26 Aug 2011 18:11:37 GMT
Last-Modified: Tue, 16 Aug 2011 06:05:55 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 79112243100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 17:55:27 GMT
Content-Length: 2635

<rss version="2.0" >
<channel>
<title>Najnowsze informacje</title>
<link>http://www.microsoft.com/presspass</link>
<description>Najnowsze informacje Microsoft</descript
...[SNIP]...

10.4. http://www.microsoft.com/windowsmobile/components/devices09/imageengine/imageengine.aspx  previous

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.microsoft.com
Path:   /windowsmobile/components/devices09/imageengine/imageengine.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /windowsmobile/components/devices09/imageengine/imageengine.aspx HTTP/1.1
Host: www.microsoft.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
VTag: 279519610300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Fri, 26 Aug 2011 19:28:32 GMT
Content-Length: 15

IMAGE NOT FOUND

Report generated by XSS.CX at Fri Aug 26 14:48:18 GMT-06:00 2011.