1. Cross-site scripting (reflected)
1.2. http://www.interop.com/lasvegas/it-expo/sponsors.php/a [REST URL parameter 4]
2. Cross-domain script include
2.1. http://www.interop.com/favicon.ico
2.2. http://www.interop.com/lasvegas/it-expo/sponsors.php
2.3. http://www.interop.com/lasvegas/it-expo/sponsors.php/a
3. Cookie without HttpOnly flag set
3.1. http://www.interop.com/lasvegas/it-expo/sponsors.php
3.2. http://www.interop.com/lasvegas/it-expo/sponsors.php/a
5.1. http://www.interop.com/favicon.ico
5.2. http://www.interop.com/js/scripts.js
5.3. http://www.interop.com/lasvegas/it-expo/sponsors.php
5.4. http://www.interop.com/lasvegas/it-expo/sponsors.php/a
7. Content type incorrectly stated
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:55 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:20:55 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62055 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <!--- File 9306f--><img src=a onerror=alert(1) --> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive Referer: http://www.interop.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx_k_189887474=1; s_cc=true; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:39:56 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:39:56 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62056 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <!--- File aafb73--><img src=a onerror=alert(1) --> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.interop.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: theme=lasvegas; __utmx=1.; __utmxx=1.; s_cc=true; s_nr=1302790870513; s_lv=1302790870514; s_lv_s=First%20Visit; us_ubm_aut=3-1; s_sq=%5B%5BB%5D%5D; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 404 Not Found Date: Thu, 14 Apr 2011 14:21:04 GMT Server: Apache X-Powered-By: PHP/5.1.6 Connection: close Content-Type: text/html Content-Length: 34737 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </title> <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme ...[SNIP]... </script> <script type="text/javascript" src="http://acme ...[SNIP]... </h2><script type="text/javascript" src="http://acme ...[SNIP]... <!-- SiteCatalyst code version: H.16. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com --> <script language="JavaScript" type="text/javascript" src="http://i.cmpnet.com ...[SNIP]... <!-- Last Modified: January 16 2009 15:31:55 --> <script src="http://acme ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:53 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:20:53 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </title> <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme ...[SNIP]... </script> <script type="text/javascript" src="http://acme ...[SNIP]... </h2><script type="text/javascript" src="http://acme ...[SNIP]... <!-- SiteCatalyst code version: H.16. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com --> <script language="JavaScript" type="text/javascript" src="http://i.cmpnet.com ...[SNIP]... <!-- Last Modified: April 08 2011 17:47:17 --> <script src="http://acme ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive Referer: http://www.interop.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx_k_189887474=1; s_cc=true; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:39:48 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:39:48 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62009 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </title> <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme <script type="text/javascript" src="http://acme ...[SNIP]... </script> <script type="text/javascript" src="http://acme ...[SNIP]... </h2><script type="text/javascript" src="http://acme ...[SNIP]... <!-- SiteCatalyst code version: H.16. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com --> <script language="JavaScript" type="text/javascript" src="http://i.cmpnet.com ...[SNIP]... <!-- Last Modified: April 08 2011 17:47:17 --> <script src="http://acme ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:53 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:20:53 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive Referer: http://www.interop.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx_k_189887474=1; s_cc=true; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:39:48 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:39:48 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62009 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | / | 
| TRACE / HTTP/1.0 Host: www.interop.com Cookie: 2a47657fad15f25 | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:53 GMT Server: Apache Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: www.interop.com Cookie: 2a47657fad15f25; theme=lasvegas | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.interop.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: theme=lasvegas; __utmx=1.; __utmxx=1.; s_cc=true; s_nr=1302790870513; s_lv=1302790870514; s_lv_s=First%20Visit; us_ubm_aut=3-1; s_sq=%5B%5BB%5D%5D; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 404 Not Found Date: Thu, 14 Apr 2011 14:21:04 GMT Server: Apache X-Powered-By: PHP/5.1.6 Connection: close Content-Type: text/html Content-Length: 34737 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <a href="mailto:feedback@techweb.com" target="_blank"> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /js/scripts.js | 
| GET /js/scripts.js HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.interop.com | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:36 GMT Server: Apache Last-Modified: Fri, 30 May 2008 18:50:11 GMT ETag: "1b48b53-2322-44e771 Accept-Ranges: bytes Content-Length: 8994 Connection: close Content-Type: application/x-javascript X-Pad: avoid browser bug // All JavaScripts for interop.com // startList handles the menu mouseover pull-down for MSIE. It is in the process of being made redundant. startList = function() { if (document.all&&do ...[SNIP]... or backwards compatibility var SWFObject=deconcept // The JavaScript Source!! http://javascript // Original: David Sosnowski (support@codefoot.com) // Web Site: http://www.codefoot.com function blockError(){return true;} window.onerror = blockError; | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:53 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:20:53 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62015 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <a href="mailto:feedback@techweb.com" target="_blank"> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /lasvegas/it-expo Host: www.interop.com Proxy-Connection: keep-alive Referer: http://www.interop.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmx_k_189887474=1; s_cc=true; __utmz=1.1302790871.1.1 | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:39:48 GMT Server: Apache X-Powered-By: PHP/5.1.6 Set-Cookie: theme=lasvegas; expires=Sat, 16-Apr-2011 14:39:48 GMT; path=/; domain=www.interop.com Connection: close Content-Type: text/html Content-Length: 62009 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <a href="mailto:feedback@techweb.com" target="_blank"> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/it-expo | 
| GET /robots.txt HTTP/1.0 Host: www.interop.com | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:53 GMT Server: Apache Last-Modified: Fri, 24 Oct 2008 21:56:25 GMT ETag: "1b4853d-4cf-45a06da Accept-Ranges: bytes Content-Length: 1231 Connection: close Content-Type: text/plain User-agent: * Disallow: /collateral/ Disallow: /lasvegas/exhibition Disallow: /lasvegas/2008/appli Disallow: /lasvegas/2008/data Disallow: /lasvegas/2008/e ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://www.interop.com | 
| Path: | /lasvegas/js/google/gwo | 
| GET /lasvegas/js/google/gwo Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.interop.com | 
| HTTP/1.1 200 OK Date: Thu, 14 Apr 2011 14:20:35 GMT Server: Apache Last-Modified: Wed, 08 Dec 2010 00:00:37 GMT ETag: "1cf0034-27-496dacf9c3340 Accept-Ranges: bytes Content-Length: 39 Connection: close Content-Type: application/x-javascript _udn = ".interop.com"; _uhash = "off"; |